Avoid imgur

Talk about non-ss13 stuff here.
Post Reply
User avatar
Takeguru
Joined: Wed May 07, 2014 5:20 pm
Byond Username: TakeGuru

Avoid imgur

Post by Takeguru » #120311

Exploit discovered, allows images to have appended javascript

Right now, the guy who's using it is targeting 8chan, but it can be used for more malicious purposes.

Check /g/ for more info, I'm basically just a messenger and am too stupid to really understand the nuances of what it entails

Noscript and similar extensions basically shut it down, but if you haven't already you should probably delete flash from your machine
Image
User avatar
ExplosiveCrate
Joined: Fri Apr 18, 2014 8:04 pm
Byond Username: ExplosiveCrate

Re: Avoid imgur

Post by ExplosiveCrate » #120317

Fucking *Bui* of all people? Holy shit, I'm dying over here.
i dont even know what the context for my signature was
User avatar
Takeguru
Joined: Wed May 07, 2014 5:20 pm
Byond Username: TakeGuru

Re: Avoid imgur

Post by Takeguru » #120319

It's probably not Bui

He doesn't seem the kind of person capable of it, because apparently the code being used is pretty fucking clever.

Or his act is the perfect cover, who knows
Image
User avatar
Ricotez
Joined: Thu Apr 17, 2014 9:21 pm
Byond Username: Ricotez
Location: The Netherlands

Re: Avoid imgur

Post by Ricotez » #120355

do browsers detect these attacks as XSS attacks? because that would explain why I sometimes randomly get pop-ups about XSS blocks when I'm browsing something heavy on images
MimicFaux wrote:I remember my first time, full of wonderment and excitement playing this game I had heard so many stories about.
on the arrival shuttle, I saw the iconic toolbox on the ground. I clubbed myself in the head with it trying to figure out the controls.
Setting the tool box, now bloodied, back on the table; I went to heal myself with a medkit. I clubbed myself in the head with that too.
I've come a long ways from asking how to switch hands.
Spoiler:
#coderbus wrote:<MrPerson> How many coders does it take to make a lightbulb? Three, one to make it, one to pull the pull request, and one to fix the bugs
Kor wrote:The lifeweb playerbase is primarily old server 2 players so technically its our cancer that invaded them
peoplearestrange wrote:Scared of shadows whispers in their final breath, "/tg/station... goes on the tabl..."
DemonFiren wrote:Please, an Engineer's first response to a problem is "throw it into the singulo".
tedward1337 wrote:Donald Trump is literally what /pol/ would look like as a person
CrunchyCHEEZIT wrote:why does everything on this server have to be a federal fucking issue.
Saegrimr wrote:One guy was running around popping hand tele portals down in the halls before OPs even showed up and got several stranded out on lavaland.
The HoP just toolboxes someone to death out of nowhere, then gets speared by a chemist who saw him murder a guy, then the chemist gets beaten to death because someone else saw him kill the HoP.
Tele-man somehow dies and gets its looted by an atmos tech who managed to use it to send two nuke ops to lavaland, who were then surrounded by several very angry people from earlier and some extra golems on top of it.
Captain dies, gets cloned/revived, lasers the guy holding the disk into crit to take it back.
Some idiot tries to welderbomb the AI hiding out at mining for no discernible reason.
Two permabans and a dayban, i'm expecting a snarky appeal from one of them soon. What the fuck.
ShadowDimentio wrote:I am the problem
User avatar
Saegrimr
Joined: Thu Jul 24, 2014 4:39 pm
Byond Username: Saegrimr

Re: Avoid imgur

Post by Saegrimr » #120505

tl;dr
Imgur allowed someone to upload an HTML page instead of actually an image. The "direct link" to the image like /whatever.jpg actually sends you to that HTML page.
The page has the image you were hoping to see on it (in hopes to look legit), except its not properly aligned, resized, or has the correct background color usually. If you've noticed any of that on images, congrats you were affected. It also disguised itself to load the proper direct image link after its already infected you, so you'll only see the odd image load once.
The exploit loaded a flash object off screen, which then saved some sneaky scripts into your localStorage.

Fortunately, the person who did this is an autist and instead of doing any actual real damage, it was made to do -something- to 8chan servers. The problem here is it still allows arbitrary code execution because imgur was retarded.

TO REMOVE IT:
Clear your cache and localStorage. Theres plenty of guides on google for whatever specific browser you use to clear it. If you use firefox, the Foundstone HTML5 Local Storage plugin works great for just nuking the entire thing. Worst case scenario is you have to log back in to whatever websites you have remembering your logins, and local page display settings. Alternatively if you have CCleaner, just use that.

Uninstall/disable Flash. That's the method of delivery, and once again flash is responsible for retarded exploits. If you absolutely need flash for something (remember, youtube has an HTML5 player), there are settings to have flash ASK YOU if you want to run the plugin on a specific page when you load the page.

Use NoScript, it takes measures against XSS exploits.

The affected sites (8chan/imgur) have claimed to have fixed issue but that doesn't stop the people who were already affected.
tedward1337 wrote:Sae is like the racist grandad who everyone laughs at for being racist, but deep down we all know he's right.
User avatar
oranges
Code Maintainer
Joined: Tue Apr 15, 2014 9:16 pm
Byond Username: Optimumtact
Github Username: optimumtact
Location: #CHATSHITGETBANGED

Re: Avoid imgur

Post by oranges » #121686

thats a browser setting, in firefox you can set it in about:addons - set flash to be always ask (nb you can tell it to remember the setting on sites like youtube or your favourite porn site)
Post Reply

Who is online

Users browsing this forum: No registered users