Post
Topic
Board Meta
Re: whiskers75 Hacked
by
TradeFortress 🏕
on 03/11/2013, 01:14:39 UTC
On a related note during my "security audit" I noticed there was also an IP filter on inputs.io. I found out that it can be circumvented by tricking the account owner into visiting a site with some simple JS that takes advantage of an old DNS rebinding attack and allows me to essentially use their browser as a proxy to access inputs.io or any other website of my choosing.
Thanks for the report, this has been patched Smiley