Skip to content
TORNLIFE More

Todays attack

Started by PatBenatar [420347] on in General Discussion.

153 replies · 2.31k views · thread synced · 6 days ago · View on torn.com

Posts archived: 154 / 154 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

DEA7TH [90220]

Just use CSRF tokens everywhere, Rails provides them automatically out of the box for every POST form There should be an easy to use library for PHP.

Bloody PHP...

Edit: Don't forget to add them to AJAX POST requests (i.e. POST requests not from a form). With the right API (like Rails's), it is trivial to do so.

https://gist.github.com/anonymous/33b3b5b9617a03706448
(I had to place the code in gist because Torn keep telling me "your post is empty" when I tried to edit it.)

As easy as that! Works regardless of what other logic the page has. It wouldn't be much harder in PHP with a good library.
Plornt [1799359]

Haha, CSRF is not related to XSS AT ALL. Torn already has CSRF protection, check in your network log, notice the "rfcv" - That is what torn uses to verify the request came from you. Also, this would have nothing to do with PHP, PHP is not a framework, it is a language, most PHP frameworks however DO have XSS and CSRF protection out of the box - Look up Laravel for an example.
DEA7TH [90220]

Huh, you're right - XSS was the thing with the malicious JS from your own DB. The story sounded like CSRF though, and I could login via CURL, passing only player and password, no tokens - not useful for an attacker, but clearly they don't do CSRF by default.

I know what is PHP, my point is that I only know they're using PHP, not which framework. Anyway, what's your deal with trying to make others look stupid? I don't get it. When people get negative conditioning in response to trying to help, they will be less likely to help next time. You could have phrased your criticism politely.
Plornt [1799359]

Sorry, my response was worded like that because it came off as though you was saying "PHP is bad because PHP" rather than understanding it was an error on the part of the developers. However my other issue is essentially because by spreading misinformation you can do a lot of damage. As an example, CSRF is used on torn as and where an attacker would gain an advantage, the framework they have built admittedly does not seem to automatically include this CSRF protection on any form they create or any page however its not a major deal if the only pages this is not included on is on the login page.
1958872 [1958872]

Yup. And is pushed the fix to this vurnerability forward. But you can't stop people from making a thread about it. *sigh*
Mauk [1494436]

It's definitely not automatic. They launched RESPO with CSRF protection missing in several places.

And while it's not a major deal, the unlocked login could be used to tie someone's ip address to a malicious account, for example. I notified Ched a while ago; not sure if it was ignored or just unseen.
DEA7TH [90220]

@Tom: I'm pleasantly surprised to see that we can be polite :) I had thought the whole point was to be hostile - glad to be wrong.

IMO PHP is quite bad and I did suggest that, but it's not useful discussion. However if the problem is really JS injection rather than CSRF then I don't think I can help - one of my applications (in development) still has this vulnerability. In this part:

<>

Actually I could just print it row by row and escape the parts which come from the DB.

Edit: Torn just ate all my code! Here it is anyway: https://gist.github.com/anonymous/c16e955ceb1001289aa0
Mauk [1494436]

Well.. JSON is JSON. You don't have to escape strings if you treat them as such. If setCustomerData doesn't use them as HTML, you are safe.
Evil-Duck [1182047]

False. If setCustomerData uses them as HTML and the JSON is HTML. So when the CSRF is used the JS injection overrides it and causes a mismatch of entities within the DB. The problem here is that iFrame was overlooked and the cron for the C:D drive of the server held the PHP which resulted in easy access via a gidden direct rout held within the HTML.

Then HACK PASSWARD
>

This results in the C being totally SHUT DOWN and the user comprimised. HTML PHP is a no no , it will get you hacked within seconds. The way around this is as follows:

Clear cache

Peace
Plornt [1799359]

What?! Did you not understand anything about the SOAP network request connecting to the REST api? The nodePhp server directly queried the CSS attributes for the plumbus which caused the attack connecting over CSRF. Once you have the source of the mongo memcache AST you have the fault of the cache. The cache was not caused by the C being totally shut down as the resources of the AMD ram would not allow such a trivial thing to happen. They obviously did not clear their cookies.
Evil-Duck [1182047]

I beg to differ. Let me put it in simple terms for you.

The AMD ram failed this the falback method was to direct PHP via iframe TO the C. Because of this the DB flooded and leaked information back to the VPN CSRF user module. The misconception seems to tbe that the SOAP network IS the REST API, which is what everyone seems to be missing. The mongo memcache AST does cause a fault, I'll concede that one but your forgetting CookieTron2xx which was released back in June, this appears to delete users cookies but infact feeds it over the JS Connection and gives the attacker a backdoor. Cache + turn wifi router off/on would solve

Peace
Plornt [1799359]

Look I am not getting into this argument again with you. You always just fall back to the defence that is the epitome of useless. Let me disect your argument for a moment:


The AMD ram failed this the falback method was to direct PHP via iframe TO the C


How can you not understand that it was not to direct to PHP via iframe but instead the sql injection protocol stating it is not of proper staging.


The misconception seems to tbe that the SOAP network IS the REST API, which is what everyone seems to be missing. The mongo memcache AST does cause a fault, I'll concede that one but your forgetting CookieTron2xx which was released back in June, this appears to delete users cookies but infact feeds it over the JS Connection and gives the attacker a backdoor.


Again with the overzealous network request IRC debacle fronting for transmission over wifi javascript connection websocket rays.

In essence what you are saying is just a load of gibberish, those of us in the real tech industry understands when an exchange goes down I'll be the first to the cabinet containing the backup power generating zorpalorp cisco firewall. Its difficult to explain in terms you would understand but if you wait 10 minutes and come back again whilst logging in and out this issue will be rectified in the flux parser.
cyberdude [1613175]

Guess this makes it the second time ever in Torn history that I liked a Evil-Duck post... Well-played sir, well-played...

Peace
Evil-Duck [1182047]

You're wrong in more ways than one. You're completely overlooking the STRINGs here, you're looking at the borderline enteties that are hazing the PGP reaching the AMD console. I cant be bothered to school you on why or how this works, if I did i would have to charge alot and my time is expensive.

Just know that the zorpalorp cisco 2015 firewall is backed up via the cabinet but it is connected to the exchange 3rd away (in-line) with the target host using the protocol in question. The flux parser is only the beginning, you're thinking way too simple. Sometimes the TCTP Protocol CX is kept WITHIN the cookie flux. Think of it like a fortune cookie, there's something kept inside and quite frankly you and I wont know what string it contains, we can only hazard a guess by looking at the effects it had on the C

Peace
Plornt [1799359]

Cant you just leave it alone? The ENCRYPTION RFC 2324 clearly describes in detail the PGP connection methods over SSL during the interchange upgrade transformer. SMTP dictates that the ISP connection is not secure enough for the imtp email hackernews controller.

The strings are not the cause here because the boolean binary CPU gets mangled output when passed to the flux cookies. The be end and end tool which is contained ON THE OUTSIDE is just not happening here. If you would think of it like peeling an ONION you will get many tor requests originating from the Interlectual Property of the RIAA sending DCMA to C. Telnet me this, why is a hazard of charging the ZNC a loaded shotgun burst waiting to happen?

Frankly mr shankly you do not see the effect of the recourse of your actions if you cannot see typing Peace at the end of your forum messages causes everything to Intel.
Unknown_Element [450910]

gotta love all the "geniouses" who googled info to make them try to look smart. im just waiting for their games to come out so i can play them.. oh wait... they dont have any games.... nm