PMOG
The Passively Multiplayer Online Game

PMOG Forum

civilized discourse for an uncivilized gameworld



Forums » Misadventures (Bug Reports) » XSS and taking money away from other players


(advertisements appear if you're not logged in or need to create an account)

Author Thread
kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

remember when i had all this money? well I found out why I did. I tried buying negative amounts of mines in the shoppe, in order to test if it gave me money. I thought it didn't work, but turns out it WAS giving me money, and my toolbar was simply not refreshing my amount of money. The bug seems to be patched now, which means that you most likely found and repaired what I thought that wasn't broken in first place.

Well anyway, enough of that, today after further investigation, I found two other critical vulnerabilities in the system, one allowing injecting XSS on any website to PMOG players and another one allowing me to make anyone i want lose money.
I really don't want to tell you guys how to do either publically, because I fear that some might abuse it, so it'd be nice if anyone here on the forums could give me an email I could write to, or if somebody from the programming squad could contact me. per email (you have my email, as I registred with it)

by kyo 10 months ago
| Permalink

kyo


avatar image of kyo

Level 10
Destroyer Destroyer
Posts: 28

hey, any time. I think this game has a lot of potential, and I'm doing my part to help it :P

by kyo 10 months ago
| Permalink

suttree
Trustee


avatar image of suttree

Level 13
Pathmaker Pathmaker
Posts: 188

Thanks kyo - negative datapoints giving you lots of datapoints in return! Heh, I'm glad we closed that loophole :D

by suttree 10 months ago
| Permalink

| Back


(advertisements appear if you're not logged in or need to create an account)