Security Warning (CSS Hack) - Page 2 - Torrent Invites! Get your free private torrent tracker invites !




Search Today's Posts Mark Forums Read
Reply

 
LinkBack (11) Thread Tools Display Modes
Old 10-09-2009, 01:09 AM   #11 (permalink)
 
Stellar's Avatar
 
Stellar has no status.
Join Date: May 2009
Posts: 642
Stellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to all
iGiver: (61)
Default

Thanks for the info, I disabled my browser history
  Reply With Quote
Santrex Torrent Seedboxes
Old 10-09-2009, 01:20 AM   #12 (permalink)
 
airman's Avatar
 
airman has no status.
The Exalted
Join Date: Jul 2009
Posts: 313
airman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud ofairman has much to be proud of
iGiver: (9)
Default

It's a vulnerability that checks your Browser History (not your cookies) through CSS. The gist of the hack is that CSS allows you to specify different responses/styles if a link has been visited or not - thus allowing the website to effectively query your browser history.

Any news on other trackers that are using this, or only x264 so far?
  Reply With Quote
Old 10-09-2009, 01:29 AM   #13 (permalink)
 
Stellar's Avatar
 
Stellar has no status.
Join Date: May 2009
Posts: 642
Stellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to all
iGiver: (61)
Default

This sucks, if I completely disable browser history a lot of /browse.php pages don't work (log me out or redirect to home). I'm hoping for security update for Opera :S
  Reply With Quote
Old 10-09-2009, 01:55 AM   #14 (permalink)
 
wtfmate's Avatar
 
wtfmate has no status.
Join Date: Aug 2009
Location: *cough* Demonoid
Posts: 226
wtfmate has a spectacular aura aboutwtfmate has a spectacular aura about
iGiver: (22)
Default

No disabling browse history will not log you out of anything steller and everything will function as normal. I've never ever kept browser history on FF.
  Reply With Quote
Old 10-09-2009, 02:21 AM   #15 (permalink)
 
redbanana's Avatar
 
redbanana has no status.
Join Date: Sep 2009
Posts: 24
redbanana is an unknown quantity at this point
iGiver: (0)
Default

Thanks for the tip the chrome feature mentioned is awsome!
  Reply With Quote
Old 10-09-2009, 03:04 AM   #16 (permalink)
 
Stellar's Avatar
 
Stellar has no status.
Join Date: May 2009
Posts: 642
Stellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to allStellar is a name known to all
iGiver: (61)
Default

@wtfmate
Do you want a video or something?
If I say it does to me, it means it does, I can't win anything out of it by lying
  Reply With Quote
Old 10-09-2009, 03:20 AM   #17 (permalink)
 
osx86's Avatar
 
osx86 has no status.
Join Date: Oct 2009
Posts: 32
osx86 is an unknown quantity at this point
iGiver: (0)
Default

Quote: Originally Posted by princest.zelda View Post

If you are using mozilla:
First of all, open your history tabs, delete all with keyword torrent-invites.com.
Then install below plugin :
History Blocker
Add *.torrent-invites.com as your blacklist.

Sweet action, thanks for the tip. History Blocker works wonders.
  Reply With Quote
Old 10-09-2009, 03:22 AM   #18 (permalink)
 
Maksimir's Avatar
 
Maksimir has no status.
Join Date: Aug 2009
Posts: 286
Maksimir is a jewel in the roughMaksimir is a jewel in the roughMaksimir is a jewel in the roughMaksimir is a jewel in the rough
iGiver: (27)
Default

Quote: Originally Posted by Stellar Cascade View Post
@wtfmate
Do you want a video or something?
If I say it does to me, it means it does, I can't win anything out of it by lying
LOL... I get it too, though after I log back in everything is alright in both firefox (mac) and chrome (pc).
  Reply With Quote
Old 10-09-2009, 03:50 AM   #19 (permalink)
 
rHA2Or8z's Avatar
 
rHA2Or8z has no status.
Join Date: Sep 2009
Posts: 251
rHA2Or8z is on a distinguished road
iGiver: (2)
Default

Quote: Originally Posted by princest.zelda View Post
Then install below plugin :
History Blocker
Add *.torrent-invites.com as your blacklist.

they want me to login before i can download it
seems like they're not much better than the guys i wanna fight with that
  Reply With Quote
Old 10-09-2009, 03:54 AM   #20 (permalink)
 
rHA2Or8z's Avatar
 
rHA2Or8z has no status.
Join Date: Sep 2009
Posts: 251
rHA2Or8z is on a distinguished road
iGiver: (2)
Default

Quote: Originally Posted by airman View Post
Any news on other trackers that are using this, or only x264 so far?
what and gft but what is the #1 regarding spy things generally.
  Reply With Quote

Reply

Tags
css, hack, security, warning

LinkBacks (?)
LinkBack to this Thread: http://www.torrent-invites.com/announcements-bittorrent-news/39723-security-warning-css-hack.html
Posted By For Type Date
ha.ckers.org web application security lab This thread Refback 10-30-2009 08:14 AM
Webappsec ha.ckers.org web application security lab This thread Refback 10-26-2009 11:51 PM
Google Reader - ha.ckers.org web application security lab This thread Refback 10-25-2009 12:59 PM
Google Reader - This thread Refback 10-15-2009 05:41 AM
Google Reader - This thread Refback 10-13-2009 02:55 AM
ha.ckers.org web application security lab This thread Refback 10-13-2009 02:46 AM
DELPAI : [CSS History Hack] ๋‚˜๋Š” ๋‹น์‹ ์ด ์–ด๋–ค ์‚ฌ์ดํŠธ์— ๋ฐฉ๋ฌธํ–ˆ๋Š”์ง€ ์•Œ๊ณ  ์žˆ๋‹ค. This thread Refback 10-10-2009 01:23 PM
www.okc2600.com :: View topic - Stealing Browser History - New Metasploit Module This thread Refback 10-10-2009 09:13 AM
ha.ckers.org web application security lab This thread Refback 10-10-2009 06:20 AM
Du hast die falschen Freunde (sagt dein Browser) ซ partikelfernsteuerung This thread Pingback 10-09-2009 07:14 PM
CSS History Hack Used To Ban Torrent Users ha.ckers.org web application security lab This thread Refback 10-09-2009 11:15 AM

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +10. The time now is 10:47 PM.

Top Top


Affilates : Torrent Invites | Torrent Forums | Tracker Invites | Scene Releases | Seedbox Hosting | TI Folding Team

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ฉ 2007 - 2010 Torrent-Invites all Rights Reserved

Shoutbox