+ Reply to Thread
Results 1 to 3 of 3

Thread: TBdev CRSF vulnerable? yes it is.

  1. #1

    Join Date
    25.06.09
    P2P Client
    uTorrent, StrongDC
    Posts
    14
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 sssssss14

    TBdev CRSF vulnerable? yes it is.

    Not discovered by me.
    Tested by some mates on few TBDEV based sites and it worked.
    I'm curious how long it takes for t-staffs to fix it :)
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    anonftw (26.06.09)

  3. #2
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,540
    Activity Longevity
    12/20 19/20
    Today Posts
    2/5 ssss39540
    I want to add that CSRF = cross-site request forgery
    Cross-site request forgery, also known as a one-click attack or session riding and abbreviated as CSRF ("sea-surf") or XSRF, is a type of malicious exploit of a website whereby unauthorized commands are transmitted from a user that the website trusts. Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user's browser.
    So (almost) all TBdev-based trackers would be vulnerable to such an attack? Bad news for admins, I guess.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  4. #3

    Join Date
    25.06.09
    P2P Client
    uTorrent, StrongDC
    Posts
    14
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 sssssss14
    One tried to report to admins and he god rejected, well, they deserve to get owned with entire of their db leeched and still vulnerable because noone know where is the little hole of it
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •