Me Paranoid ?
19 posts
• Page 2 of 2 • 1, 2
- Rizze

-
- Posts: 2414
- Joined: Sun Sep 02, 2007 9:06 pm
- Location: Just About Everywhere
You might like:
Fatdogmendoza wrote:Rizze wrote:Did anyone read into what I posted, anyone connect the dots?
Not funny you know, I am being quite serious.
But this is
Has your penis got a face...thats not funny, thats serious rizze....
Seriously can you explain for dummies, Im good with the hardware but shite with software and programming
Yes anyone with the right script can get your e-mail and ip from your posts, without them replying to your said post by using a similar script such as this.
- Code: Select all
if request.POST:
current_user = users.get_current_user()
u = models.user_test.User.get_or_insert(current_user.user_id())
u.email = request.POST.get('email', current_user.email())
u.save()
return http.HttpResponseRedirect('/user/settings')
And the user I pointed out user_test_csrf
If you read my first link you may get an idea.
browserscope

http://ufomaniacs.blogspot.com/
http://tiny.cc/Rizzesearch
"The greatest things on earth are us,supposedly.
Why don't we act accordingly, with humanity" Rizze
- Perry LaGuardia

-
- Posts: 5587
- Joined: Tue Jan 04, 2011 4:05 pm
- Location: Left of centre
Shit Rizze, you are right, its not funny and its more than joining the dots.... 


- Kinninigan

-
- Posts: 5314
- Joined: Sat May 14, 2011 10:00 pm
- Location: Zin-Uru
i clicked on the link you gave rizze.....WTF is going on??????
..and why does it do that to my profile......


I think there are 2 things going on.
user_test_csrf
CSRF stands for 'cross site request forgery' which is an attack that tries to get the user to execute code on their system by clicking on a link. The link looks normal on the web page but is actually structured to do something naughty. There's a good explanation of it here. http://en.wikipedia.org/wiki/Cross-site_request_forgery User_test_csrf is way to obvious a user name to think it is being used for that purpose unless your server admin is actually testing CSRF on DTV. Which I think is probably the case and should definitely be checked out with the admin.
btrendbaby
Is some sort of scam but you actually have to email them. If you search 'btrendbaby' on Google she pops up on a lot of dating sites and the romantic DTV. The troubling part about this is that whoever is doing this has a way of getting new user names. They then send an email like the one I got from btrendbaby's DTV profile hoping to hook someone. User shaden27, derekyoung902, and user_test_csrf all have a message from her because these are accounts created in the last few days like mine.
They don't necessarily have to penetrate the server deeply to get the user names. If they were able to do a directory traversal of http://www.disclose.tv/members/action/myprofile/ and compare it to a scan they did the day before they would have the user name of everyone new that signs up. There are a number of ways to see if that is the case that the server or network admin should be able to provide.
user_test_csrf
CSRF stands for 'cross site request forgery' which is an attack that tries to get the user to execute code on their system by clicking on a link. The link looks normal on the web page but is actually structured to do something naughty. There's a good explanation of it here. http://en.wikipedia.org/wiki/Cross-site_request_forgery User_test_csrf is way to obvious a user name to think it is being used for that purpose unless your server admin is actually testing CSRF on DTV. Which I think is probably the case and should definitely be checked out with the admin.
btrendbaby
Is some sort of scam but you actually have to email them. If you search 'btrendbaby' on Google she pops up on a lot of dating sites and the romantic DTV. The troubling part about this is that whoever is doing this has a way of getting new user names. They then send an email like the one I got from btrendbaby's DTV profile hoping to hook someone. User shaden27, derekyoung902, and user_test_csrf all have a message from her because these are accounts created in the last few days like mine.
They don't necessarily have to penetrate the server deeply to get the user names. If they were able to do a directory traversal of http://www.disclose.tv/members/action/myprofile/ and compare it to a scan they did the day before they would have the user name of everyone new that signs up. There are a number of ways to see if that is the case that the server or network admin should be able to provide.
I'd rather be an ascending ape than a fallen creation.
Kinninigan wrote::ohno:
i clicked on the link you gave rizze.....WTF is going on??????
..and why does it do that to my profile......
That's not your profile.
I got half a star.
How did that happen?
I'd rather be an ascending ape than a fallen creation.
- Disclosetv

-
- Posts: 898
- Joined: Sun Mar 18, 2007 7:03 pm
Rizze wrote:I have a theory of what may prove critical to DTV members.
I know a small amount about scripts and how to use them to get information, Today whilst browsing new members, I saw something very familiar to me, it was a word that is used in scripting for webmasters and hackers.
So I delved a bit deeper and found this browserscope a part of this script can be used to get user names, e-mail and ip addresses.
The keyword for here is user_test_csrf
What do you think, anyone here know if I am right or just a bit paranoid.
Do you think there is some foundation to this theory of mine?
user_test_csrf is a test user of our developers for testing our "ANTI-HACKING" measurements. CSRF = Cross-Site Request Forgery.
So, no worries, but thanks anyways. Could have been something sinister.
Lukas
Disclose.tv Site Admin
- domdabears

-
- Posts: 14318
- Joined: Thu Jul 31, 2008 4:45 pm
- Location: Illihio
Like a boss

Nothing in this world thats worth having comes easy
19 posts
• Page 2 of 2 • 1, 2
-
- Related topics
- Replies
- Views
- Last post
-
- How Paranoid are You??
1, 2, 3by just_the_flu » Wed Jan 23, 2013 5:29 am - 27 Replies
- 894 Views
- Last post by Naranja

Mon Jan 28, 2013 2:55 am
- How Paranoid are You??
-
- Chemtrails : The ultimate in paranoid fantasy
1, 2, 3, 4, 5by notgeoffrey » Sun Jan 25, 2009 10:52 pm - 41 Replies
- 739 Views
- Last post by hesop

Mon Jan 26, 2009 9:35 pm
- Chemtrails : The ultimate in paranoid fantasy





