Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. Site Bugs / Suggestions
  4. SERIOUS ISSUE with the site - vulnerability found

SERIOUS ISSUE with the site - vulnerability found

Scheduled Pinned Locked Moved Site Bugs / Suggestions
comtoolshelptutorial
4 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    B Offline
    Bryian Tan
    wrote on last edited by
    #1

    I think there need to have some sort of captcha or something to prevent replay attack on the registration page[^] . I'm able to register at least 5 users [start with Soyabean] using Fiddler, just modify my username then submit. I'm sure someone out there already been exploring this vulnerability by registering many accounts. Please look into it. Some Example: Are these username generated by the system[^] @Chris-Maunder @Sean-Ewington

    Bryian Tan

    OriginalGriffO 1 Reply Last reply
    0
    • B Bryian Tan

      I think there need to have some sort of captcha or something to prevent replay attack on the registration page[^] . I'm able to register at least 5 users [start with Soyabean] using Fiddler, just modify my username then submit. I'm sure someone out there already been exploring this vulnerability by registering many accounts. Please look into it. Some Example: Are these username generated by the system[^] @Chris-Maunder @Sean-Ewington

      Bryian Tan

      OriginalGriffO Offline
      OriginalGriffO Offline
      OriginalGriff
      wrote on last edited by
      #2

      There is a hyphen in Chris-Maunder if you want to attract his attention. But ... it shouldn't be necessary here, I think he gets automatically notified of any new threads here; certainly, he checks here regularly.

      Sent from my Amstrad PC 1640 Never throw anything away, Griff Bad command or file name. Bad, bad command! Sit! Stay! Staaaay... AntiTwitter: @DalekDave is now a follower!

      "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
      "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

      B 1 Reply Last reply
      0
      • OriginalGriffO OriginalGriff

        There is a hyphen in Chris-Maunder if you want to attract his attention. But ... it shouldn't be necessary here, I think he gets automatically notified of any new threads here; certainly, he checks here regularly.

        Sent from my Amstrad PC 1640 Never throw anything away, Griff Bad command or file name. Bad, bad command! Sit! Stay! Staaaay... AntiTwitter: @DalekDave is now a follower!

        B Offline
        B Offline
        Bryian Tan
        wrote on last edited by
        #3

        Thanks :) . look like the adversary already injected thousands of fake account into the system already (that my speculation).

        Bryian Tan

        OriginalGriffO 1 Reply Last reply
        0
        • B Bryian Tan

          Thanks :) . look like the adversary already injected thousands of fake account into the system already (that my speculation).

          Bryian Tan

          OriginalGriffO Offline
          OriginalGriffO Offline
          OriginalGriff
          wrote on last edited by
          #4

          Which is odd, because the names are more distinctive of spam than the default "Member nnnnnnnn", but easy to find as a "bloc" because the MID's still stay pretty much contiguous. And I'd trust "Member nnnnnnnn" slightly more than "gdfsrysdeax" or similar ... :laugh:

          Sent from my Amstrad PC 1640 Never throw anything away, Griff Bad command or file name. Bad, bad command! Sit! Stay! Staaaay... AntiTwitter: @DalekDave is now a follower!

          "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
          "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups