4 ms·
I think it was the same exploit which used free.aol.com. They had a 3-step sign up process with the first step letting you choose a name. It would validate the
by notadev 4y ago
I think it was the same exploit which used free.aol.com. They had a 3-step sign up process with the first step letting you choose a name. It would validate the name was >= 3 chars in length, started with a letter, and didn’t contain banned words. Once validated, the name was stored in a hidden input value in the source of the second page. Someone saved the webpage offline so you could replace the sn variable with any name not on use on AOL. Then open it locally and go right to step 3 where you enter credit details. This let you creat indents, 2chars, banned words, and steal AIMs.
- sejje 4y agoInteresting. Ours used some dos32.bas-style interaction with the AOL 5.0 client during their de-facto sign up process. > started with a capital letter Fixed that for you. We had an lcase exploit, of course.
- notadev 4y agoWas this using master AOL/star tool and invoking an FDO token that generated the modal?