Homebrew PeggleCrew Hijacking /r/3dshacks Subreddit

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
It's back to normal now, but what I want to know is what exactly did they insert into the page and do we need to be worried about possible driveby exploits?

If anything this can only affect serverside rather than reader side. Reddit will always have a cached copy but it wont change the fact that unless they find out who's compromised, it wont stop.

Actually, I didn't get the time to analyze that image, but there's nothing preventing it from being an image-based exploit. Remember libtiff on the PSP?
 
  • Like
Reactions: Misledz

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,374
Trophies
4
Location
Space
XP
13,978
Country
Norway
If anything this can only affect serverside rather than reader side. Reddit will always have a cached copy but it wont change the fact that unless they find out who's compromised, it wont stop.
Anything that is sent to the client side has the potential to affect the client side if they make use of driveby exploits. Basically driveby exploits are exploits in software on the client side which once an infected page is visited can be used to install malware without the user's knowledge or consent.
I didn't get a chance to have a look at the source code of the part they added or the image itself, which is why I'm wondering.
 
  • Like
Reactions: Misledz

Misledz

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
1,053
Trophies
0
Age
33
Location
Philippines
XP
766
Country
Philippines
Actually, I didn't get the time to analyze that image, but there's nothing preventing it from being an image-based exploit. Remember libtiff on the PSP?
Similar to the one on devhook days? If so then yeah, but Chrome for some reason can sort out these kind of exploits so Im not so worried. If Im having a hard time getting exploit pages to run on chrome than on my Wii U, then I guess Google's doing a good job :P
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
Similar to the one on devhook days? If so then yeah, but Chrome for some reason can sort out these kind of exploits so Im not so worried. If Im having a hard time getting exploit pages to run on chrome than on my Wii U, then I guess Google's doing a good job :P

Exploits in chrome require ROP. Memory protection. And on top of that, you also have to get out of the sandbox. Firefox, on the other hand...you may want to turn off JIT.

Also, the 3DS and WiiU technically are WebKit, not Blink.
 
Last edited by chaoskagami,
  • Like
Reactions: Misledz

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,374
Trophies
4
Location
Space
XP
13,978
Country
Norway
Similar to the one on devhook days? If so then yeah, but Chrome for some reason can sort out these kind of exploits so Im not so worried. If Im having a hard time getting exploit pages to run on chrome than on my Wii U, then I guess Google's doing a good job :P
Browser devs make continuous efforts to block known exploits, but there are always new ones being found that aren't publicly known yet, so you're not protected from everything. Even antivirus, firewall and antispyware software won't protect you from everything.
These people seem like just your average skiddie though, so they probably wouldn't have access to unpatched exploits, but you never know.

Exploits in chrome require ROP. Memory protection. And on top of that, you also have to get out of the sandbox. Firefox, on the other hand...you may want to turn off JIT.

Also, the 3DS and WiiU technically are WebKit, not Blink.
I have NoScript and reddit.com is disabled on it, is that good enough? :P (Firefox though)
 
Last edited by The Real Jdbye,
  • Like
Reactions: Misledz

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
Browser devs make continuous efforts to block known exploits, but there are always new ones being found that aren't publicly known yet, so you're not protected from everything. Even antivirus, firewall and antispyware software won't protect you from everything.
These people seem like just your average skiddie though, so they probably wouldn't have access to unpatched exploits, but you never know.

Yeah, I doubt it. Though there's nothing stopping them from targeting fixed exploits in hope someone hasn't updated.
 

Misledz

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
1,053
Trophies
0
Age
33
Location
Philippines
XP
766
Country
Philippines
Browser devs make continuous efforts to block known exploits, but there are always new ones being found that aren't publicly known yet, so you're not protected from everything. Even antivirus, firewall and antispyware software won't protect you from everything.
These people seem like just your average skiddie though, so they probably wouldn't have access to unpatched exploits, but you never know.


I have NoScript and reddit.com is disabled on it, is that good enough? :P (Firefox though)

Exploits in chrome require ROP. Memory protection. And on top of that, you also have to get out of the sandbox. Firefox, on the other hand...you may want to turn off JIT.

Also, the 3DS and WiiU technically are WebKit, not Blink.

I have learned much today. Thanks Sensei's
 
  • Like
Reactions: DarkFlare69

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
Browser devs make continuous efforts to block known exploits, but there are always new ones being found that aren't publicly known yet, so you're not protected from everything. Even antivirus, firewall and antispyware software won't protect you from everything.
These people seem like just your average skiddie though, so they probably wouldn't have access to unpatched exploits, but you never know.


I have NoScript and reddit.com is disabled on it, is that good enough? :P (Firefox though)

For scripts, yes. Not images.
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
...HAHAHAHAHAHAHAHA! Remember kids, don't use your browser's built in password saver.

And remember: use a combination of capital/lowercase letters, numbers, symbols and use more than two words!
 
  • Like
Reactions: Deleted User

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,374
Trophies
4
Location
Space
XP
13,978
Country
Norway
For scripts, yes. Not images.
I doubt they found some image exploit, but I wasn't actually able to save the image to have a look at it (the option wasn't there in the right-click menu, probably because it used some weird CSS or JS as I've experienced the same problem on other sites, even here on GBAtemp) so I can't know for sure. I just tend to be paranoid about computer security (and most other things :P )
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
I have a txt that contains all my random character passwords and a 19 digit password on the zip. None of the random passwords are labeled.
FITE ME

Better than a closed source password management tool or a browser plugin.

I hope you're using AES and not ZipCrypto, though.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
    +1
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87 cents. Free shipping from China... It arrived it works and honestly I don't understand how it was so cheap.
    +1
    Psionic Roshambo @ Psionic Roshambo: @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87... +1