Skip to content
TORNLIFE More

Tooltip Manipulation

Started by MightyGoober [812478] on in Bugs & Issues.

14 replies · 326 views · thread synced · 7 days ago · View on torn.com
About this thread

Posts archived: 15 / 15 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
15
Discussion span
→
People posting
11
Likes on archived posts
20
Posts by staff, officers and moderators
2
Authority score
59 / 100
Historical score
37 / 100
Story score
48 / 100
Engagement score
64 / 100

Most-liked replies

MightyGoober [812478]

Hello "

Hover over threads that contain quotes. The javascript is not blackslashing special characters. Not sure if any type of injection attack would be possible (probably not, as it's only javascript). But worth looking into.

See:

[image: i.imgur.com]



And this thread is going to say Hello because it stops reading it after the quote.



Tired of my reporting yet?
saeed [1826888]

Definitely should have gone about this differently. Generally speaking, PMing a staff member about any possible exploits/injections is the best method... not telling everyone that may want to harm users that it's possible is not the best idea. next thing you know, i'm redirecting you to pornhub.



just sayin.
PMV [1577993]

Agreed. It's likely they're now gone for the weekend so wont even see this until Monday. That's a hell of a lot of time for bads to figure this out and exploit it.
Ahab [1735214]

Is a point where full disclourse is best and what this could do was already posted just nothing was done.
saeed [1826888]

I'm saying the thread never should have existed. :P not the place to argue though. full disclosure of exploits is also never a good idea period