Cookie Stealing no MOAR

General Discussion

Everybody can Add Topics, Everybody can Reply to this Topic.

Add New Topic Category Index Forum Index
1 2
  Sunday, September 16th, 2007 at 7:20:04 PM #307
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

Not that I've ever had problems with cookie stealing, but I've devised a way to make cookie stealing efforts impossible.

This new system isn't done yet, but when it is, I'll publicly post my session cookie and we'll see who's 1337 enough 2 hax me.

Member Added Image
  Monday, September 17th, 2007 at 8:47:27 AM #309
DarkestAngel
Removed Account

You enjoy tempting fate, don't you?
  Monday, September 17th, 2007 at 12:04:48 PM #310
RedSmurf
Removed Account

yes, I'm pretty sure he does enjoy tempting fate.

hah I'll steal your cookies, then I'll eat them
  Monday, September 17th, 2007 at 1:31:23 PM #311
FreakDesign
Removed Account

Wow thats daring. Will that make this site super un-hackable?
  Monday, September 17th, 2007 at 4:52:05 PM #312
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

Tempting fate is fun, but like weasel, the more people that attempt exploits on my site, the better of a programmer I become.

I can't really discuss how this new system will work, because I believe it'll be so ironclad, that I could possibly get a patent on it.

This won't fix everything that could be fucked with, FreakDesign. This will only prevent the use of cookies to gain access to accounts.

Member Added Image
  Monday, September 17th, 2007 at 5:14:08 PM #313
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

Here's my session cookie data. If it changes, I'll update this post:

90b0af5e05e05c9fea37ac27fd7b299b

Everybody will have to log back in to get the new system to take effect.

Member Added Image
  Tuesday, September 18th, 2007 at 4:48:24 PM #314
ecko
ecko
Member
'MMA Expert'
Level 27
Posts: 1,782
Submissions: 66
ecko is Offline

You and Weasel both fixed it! =D


Member Added Image
Member Added Image
Member Added Image
Member Added Image
  Tuesday, September 18th, 2007 at 7:08:11 PM #315
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

No, you can steal RE's cookies and still get accounts.

I just posted my cookie data, and you can change your cookie to my data and it won't work.

Mine pwnz.

Member Added Image
  Sunday, September 23rd, 2007 at 11:48:11 AM #322
K1LL3RCL0WN
K1LL3RCL0WN
Member
'ASSASSINO!'
Level 14
Posts: 651
Submissions: 62
K1LL3RCL0WN is Offline

sounds wonderlicious, NO ONE KEN H4X UR SYTE!

Visit and Comment on my Wordpress blog at LINK!!
Thanks!
  Tuesday, October 2nd, 2007 at 1:30:19 PM #339
DarkestAngel
Removed Account

No one haxxed yet? Thats sexalicious!
  Tuesday, December 16th, 2008 at 7:42:42 PM #8197
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

Nobody can hax me!

Member Added Image
  Tuesday, December 16th, 2008 at 7:51:25 PM #8201
DarkestAngel
Removed Account

BA! Stop purpling!
  Tuesday, December 16th, 2008 at 7:57:27 PM #8203
Darkharbinger
Darkharbinger
Member
'lord of teh lulz'
Level 14
Posts: 3,048
Submissions: 16
Darkharbinger is Offline

way to go boss, one up RE once again

Don't EVER try to outweird me, I get stranger things than you free with my breakfast cereal.
  Tuesday, December 16th, 2008 at 8:14:44 PM #8210
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

I've one-upped them over a year agoMember Added Image

Member Added Image
  Tuesday, December 16th, 2008 at 9:27:00 PM #8230
DarkestAngel
Removed Account

Hell even I can 1-up Re and I dont know the first thing about programming!
  Thursday, December 18th, 2008 at 9:12:39 AM #8374
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

^learn what this means:

if ($blockedip = $_SERVER['REMOTE_ADDR'])
{
die;
}

Then you'll have like 200 up on REMember Added Image

Member Added Image
  Thursday, December 18th, 2008 at 9:13:43 AM #8375
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

Add another = sign in there...

$blockedip == (etc)


Good thing I'm not programming right now...

Member Added Image
  Thursday, December 18th, 2008 at 4:54:15 PM #8423
DarkestAngel
Removed Account

Oh I can learn what that means! BA what does it mean?Member Added Image
  Thursday, December 18th, 2008 at 5:00:04 PM #8426
DeadLazyBum
DeadLazyBum
Site Admin
'♥'
Level 33
Posts: 2,964
Submissions: 137
DeadLazyBum is Offline

Quote:
if ($blockedip = $_SERVER['REMOTE_ADDR'])
{
die;
}

If the variable blockedip is equal the remote address, the connection is killed. I'm assuming its his IP ban.

Member Added Image
Member Added Image
Member Added Image
Member Added Image
Member Added Image
  Friday, December 19th, 2008 at 10:43:25 AM #8509
Toasty
Toasty
SysOp
Level 40
Posts: 7,388
Submissions: 227
Toasty is Offline

I wrote that free hand, I don't really publish much of the code I use on my own sites...better I catch a fuck up than 2,000,000 people all over the internet while I'm at work.

Member Added Image
1 2