Skip to content
TORNLIFE More

Dubass: forum

Dubass [2548596] Level 7

Forum posts (Torn's count)
2 observed
Archived posts
2
Threads started (archived)
1

Boards

From the 2 newest archived posts.

Threads started

Most-liked posts

Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.

suggestion to modify the XID of players. · · 0 likes

Right now, the player id is something like https://www.torn.com/profiles.php?XID=XXXXXXX . This starts at 0000001 and the rest are player profiles. This makes scraping very easy and can be exploited, The docs state they will know if a non API request is sent, but that isn't true, there are many ways around it.
How can this be a problem?
scanning through all the public stats(health, level) of every player on torn, and mapping out weak targets(less health, high level.. etc) on mass scale, etc.
Previously there was a little bug where torn didn't strip off EXIF data from images, which can possibly have player's location, device name etc. This could've been scraped easily on a mass scale as well. But they fixed this recently. which is good.
What's the solution?
Encrypt/Hash the user id with a key. from the current 7 digits number to a hash. This can be a permanent solution to this possible exploit.
so, from
https://www.torn.com/profiles.php?XID=XXXXXXX to https://www.torn.com/profiles.php?XID=lpf/nDYR7Yt98PuzbZtAyQ==
AES encryption, with the key = torn.
User experience?
The user experience will be the same. You'll only see a different URL when you visit their profile, searching will be the same. but will be based on their name than their userid.

Recent archived posts

suggestion to modify the XID of players. ·

As I said, there are ways around undetectable non-api reqs. and third party devs won't be affected by this change as they call from APIs. the bots are safe

suggestion to modify the XID of players. ·

Right now, the player id is something like https://www.torn.com/profiles.php?XID=XXXXXXX . This starts at 0000001 and the rest are player profiles. This makes scraping very easy and can be exploited, The docs state they will know if a non API request is sent, but that isn't true, there are many ways around it.
How can this be a problem?
scanning through all the public stats(health, level) of every player on torn, and mapping out weak targets(less health, high level.. etc) on mass scale, etc.
Previously there was a little bug where torn didn't strip off EXIF data from images, which can possibly have player's location, device name etc. This could've been scraped easily on a mass scale as well. But they fixed this recently. which is good.
What's the solution?
Encrypt/Hash the user id with a key. from the current 7 digits number to a hash. This can be a permanent solution to this possible exploit.
so, from
https://www.torn.com/profiles.php?XID=XXXXXXX to https://www.torn.com/profiles.php?XID=lpf/nDYR7Yt98PuzbZtAyQ==
AES encryption, with the key = torn.
User experience?
The user experience will be the same. You'll only see a different URL when you visit their profile, searching will be the same. but will be based on their name than their userid.