PMOG Forum
civilized discourse for an uncivilized gameworld
(advertisements appear if you're not logged in or need to create an account)
| Author | Thread |
kyo![]() Level 10 Posts: 28 |
I am making this thread by being forced to from some nifty javascript code. if this works, you should check referers when getting POST requests <snip> please copy and paste this link in your url bar. On a side note, something seems to be wrong with your link parsing system as well. I could not get it to show up properly when I tried to. |
kyo![]() Level 10 Posts: 28 |
and apparently deleting posts doesn't work either. |
kyo![]() Level 10 Posts: 28 |
I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is. |
kyo![]() Level 10 Posts: 28 |
I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is. |
joe![]() Level 10 Posts: 145 |
I don't know what's going on, but apparently this is serious. |
|
mikey Level 20 Posts: 205 |
it's not that serious, just making a post to the forum page... |
tulsatrey![]() Level 11 Posts: 37 |
No, mikey -- this is SERIOUS. |
medlar![]() Level 9 Posts: 4 |
I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is |
kyo![]() Level 10 Posts: 28 |
see medlars post. Let me just add that this is not all you can do with it (asides from the fact that identity theft itself can be a serious issue) You could force people to buy stuff they don't want to buy, you could make them deploy crates and other stuff. You should check if the referer is right, but because some firewalls block referers you should also accept a request if there is no request at all. |
siva-guren![]() Level 12 Posts: 65 |
I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is. |
|
mikey Level 20 Posts: 205 |
not really serious at all, they just need some sort of session state and this type of attack will just go away.. |
kyo![]() Level 10 Posts: 28 |
Yes, mikey. It is easy to fix indeed, but that does not stop it from being serious. Maybe you'll change your mind after I stole all your money using this (I'm not going to) |
|
suttree Trustee ![]() Level 13 Posts: 188 |
Hi kyo. Can I start by pointing out that if you feel there is a security issue you should contact us directly first, rather than making a post in the forum. It is the accepted practice for anyone who discovers a security hole to contact the website directly, in private, rather than drawing attention to the problem for your own ends. With regards to this issue, I don't see the problem. You've used a form on another website to create a forum post. There is no identity theft taking place, no has 'forced' you to make the post, and anyone who has done the same thing has *actively* chosen to do that, they have not been forced or coerced into doing anything. Further, the result of this action has not lead to any harm, exploit or release of data. However, if you feel that this issue could lead to other problems, please contact me directly - duncan at gamelayers dot com. |
kyo![]() Level 10 Posts: 28 |
Yeah, sorry about that. I was testing if it works, so I had to, but I'll keep that in the mind in the future. <snip> |
|
suttree Trustee ![]() Level 13 Posts: 188 |
Thanks for the example, kyo. I've removed it, however, as I specifically stated in my previous post that if you have any concerns you should contact me directly and *not* post them in a public forum. I appreciate that you have valid security concerns but posting them in a public forum only increases the likelihood that you will suffer as a consequence of them. I will repeat what I said earlier - if you have any concerns please contact me directly - duncan at gamelayers dot com -and I will deal with them. Making your concerns public, even when specifically asked not to, makes you look unprofessional. |
kyo![]() Level 10 Posts: 28 |
Well it's pretty much out in public anyway now, isn't it? 'cause you know. Anybody who doesn't know what CSRF is won't be able to do this anyway... That's why I kept posting this in here, but sure, I'll email from now on. Oh well, I hope you realize why this is serious and fix it now. I'll keep you guys updated if I find any other issues (per email!) |
|
suttree Trustee ![]() Level 13 Posts: 188 |
It's only out in the public since you posted the details in here, kyo. And anyone who doesn't know what CSRF is could easily have follow your instructions - that's the problem with posting them in a public forum and not contacting the developers directly. Had we not responded to your concerns, I'd say making them public was a valid course of action, but you seem to have decided that drawing attention to yourself was more important. I do appreciate the seriousness of CSRF and we'll work to close any and all loopholes in PMOG as we become aware of them. |








