FA VIRUS!!! (The secret of the universe is so simple)
14 years ago
AM I STUPID, OR DOES FA SUCK FOR HAVING SUCH A VULNERABILITY?
If you see the below link..
CLICK HERE. This guy NEEDS to be banned.
Do not click.
Also, I can't see why this problem exists.
this is sick.. FA, you suck.
If you see the below link..
CLICK HERE. This guy NEEDS to be banned.
Do not click.
Also, I can't see why this problem exists.
this is sick.. FA, you suck.
FA+
That's a fake page. QUickly, change your password.
Just curious, does this attack require the victim to click the link in question? Or is it one of those attacks were simply viewing the offending post is enough to do the damage?
My first guess is that this is pretty much something
What I'm pretty sure is going on:
the page contains some code that submits a journal consisting of the same text to your FA.
What FA Needs to do: Require that a unique code to be submitted for each FA action, that varies each time you're logged in. Ergo, a journal can't be posted unless it uses that code. :/
>Implying FA does anything about security
Though with security-discussing people like Pi and Eevee becoming grumpy and cynical, it's hard to listen to their valid complaints. They all seem like they need to pull sticks out of their asses when discussing this stuff.
Whoooaaa now, baby steps, man. Let's start with: "caring enough about their users' security that they actually feel an obligation to improve it".
This sounds very similar to the comment deletion/watcher addition cross-site forgery issue that was POC'd many months ago.
Wait. Scratch that. It doesn't sound similar to it, it sounds exactly like it.
Kinda like here.
PETER GRIFFIN: "Aah, that's a lotta baloney."
WEIRD AL (on TV): Virus alert! Delete immediately before someone get hurt!...
PETER: *die*