PMOG
The Passively Multiplayer Online Game

PMOG Forum

civilized discourse for an uncivilized gameworld




(advertisements appear if you're not logged in or need to create an account)

Author Thread
kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

I am making this thread by being forced to from some nifty javascript code. if this works, you should check referers when getting POST requests

<snip>

please copy and paste this link in your url bar.

On a side note, something seems to be wrong with your link parsing system as well. I could not get it to show up properly when I tried to.

by kyo 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

and apparently deleting posts doesn't work either.

by kyo 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is.

by kyo 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is.

by kyo 10 months ago
| Permalink

joe


avatar image of joe

Level 10
Seer Seer
Posts: 145

I don't know what's going on, but apparently this is serious.

by joe 10 months ago
| Permalink

mikey


avatar image of mikey

Level 20
Pathmaker Pathmaker
Posts: 205

it's not that serious, just making a post to the forum page...

by mikey 10 months ago
| Permalink

tulsatrey


avatar image of tulsatrey

Level 11
Pathmaker Pathmaker
Posts: 37

No, mikey -- this is SERIOUS.

by tulsatrey 10 months ago
| Permalink

medlar


avatar image of medlar

Level 9
Pathmaker Pathmaker
Posts: 4

I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is

by medlar 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

see medlars post.

Let me just add that this is not all you can do with it (asides from the fact that identity theft itself can be a serious issue)

You could force people to buy stuff they don't want to buy, you could make them deploy crates and other stuff.

You should check if the referer is right, but because some firewalls block referers you should also accept a request if there is no request at all.

by kyo 10 months ago
| Permalink

siva-guren


avatar image of siva-guren

Level 12
Seer Seer
Posts: 65

I am not making this post, instead I was forced to by the post forcer ( http://wocares.com/pf3.php ) - this post is a demonstration of how serious this issue is.

by siva-guren 10 months ago
| Permalink

mikey


avatar image of mikey

Level 20
Pathmaker Pathmaker
Posts: 205

not really serious at all, they just need some sort of session state and this type of attack will just go away..

by mikey 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

Yes, mikey. It is easy to fix indeed, but that does not stop it from being serious.

Maybe you'll change your mind after I stole all your money using this (I'm not going to)

by kyo 10 months ago
| Permalink

suttree
Trustee


avatar image of suttree

Level 13
Pathmaker Pathmaker
Posts: 188

Hi kyo.

Can I start by pointing out that if you feel there is a security issue you should contact us directly first, rather than making a post in the forum.

It is the accepted practice for anyone who discovers a security hole to contact the website directly, in private, rather than drawing attention to the problem for your own ends.

With regards to this issue, I don't see the problem. You've used a form on another website to create a forum post. There is no identity theft taking place, no has 'forced' you to make the post, and anyone who has done the same thing has *actively* chosen to do that, they have not been forced or coerced into doing anything. Further, the result of this action has not lead to any harm, exploit or release of data.

However, if you feel that this issue could lead to other problems, please contact me directly - duncan at gamelayers dot com.

by suttree 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

Yeah, sorry about that. I was testing if it works, so I had to, but I'll keep that in the mind in the future.

<snip>

by kyo 10 months ago
| Permalink

suttree
Trustee


avatar image of suttree

Level 13
Pathmaker Pathmaker
Posts: 188

Thanks for the example, kyo. I've removed it, however, as I specifically stated in my previous post that if you have any concerns you should contact me directly and *not* post them in a public forum.

I appreciate that you have valid security concerns but posting them in a public forum only increases the likelihood that you will suffer as a consequence of them.

I will repeat what I said earlier - if you have any concerns please contact me directly - duncan at gamelayers dot com -and I will deal with them. Making your concerns public, even when specifically asked not to, makes you look unprofessional.

by suttree 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

Well it's pretty much out in public anyway now, isn't it?

'cause you know. Anybody who doesn't know what CSRF is won't be able to do this anyway...

That's why I kept posting this in here, but sure, I'll email from now on.

Oh well, I hope you realize why this is serious and fix it now. I'll keep you guys updated if I find any other issues (per email!)

by kyo 10 months ago
| Permalink

suttree
Trustee


avatar image of suttree

Level 13
Pathmaker Pathmaker
Posts: 188

It's only out in the public since you posted the details in here, kyo. And anyone who doesn't know what CSRF is could easily have follow your instructions - that's the problem with posting them in a public forum and not contacting the developers directly.

Had we not responded to your concerns, I'd say making them public was a valid course of action, but you seem to have decided that drawing attention to yourself was more important.

I do appreciate the seriousness of CSRF and we'll work to close any and all loopholes in PMOG as we become aware of them.

by suttree 10 months ago
| Permalink

This thread is locked and therefore cannot be posted to.

Back


(advertisements appear if you're not logged in or need to create an account)