Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
JakeSkii
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
JakeSkii
3y ago
Thank you!
2.
▲
by
JakeSkii
3y ago
A video by WIRED came up in my YouTube feed about it.
3.
▲
by
JakeSkii
3y ago
Sent you an email!
4.
▲
by
JakeSkii
3y ago
Hi, I've sent you an email.
5.
▲
by
JakeSkii
3y ago
Thank you!
6.
▲
by
JakeSkii
3y ago
OP - Wow, can't believe I missed that! Thanks!
7.
▲
by
JakeSkii
3y ago
Interesting, thanks for the insight!
8.
▲
by
JakeSkii
3y ago
Thank you, will take a look!
9.
▲
by
JakeSkii
3y ago
Just to clarify, the PHPSESSID cookie was HttpOnly - I could extract the new value because I had overwritten it. Most of the cookies were set correctly (thankfully) however there was a lot of SPII stored in JS variables which I was able to
10.
▲
by
JakeSkii
3y ago
Around 4/5 hours if I recall correctly. It was over a year ago so not 100% sure.
11.
▲
by
JakeSkii
3y ago
OP - I'm honestly not sure what happened, it could be just based on the naming or something else to do with it. Either way, when I visited it, Googles Safe Browsing alert popped up with "Deceptive site ahead - recentley detected p
12.
▲
by
JakeSkii
3y ago
OP Here - Like the others have said, it wasn't a proper same-origin check. We'll never know for sure how it was handled beacuse it was all done server-side but I'm guessing it was something like an if in statement on the FQDN
13.
▲
by
JakeSkii
3y ago
Hi, OP here! Thank you all so much for the positive commments. To give some background: I'm a 17 year old student in the UK doing my A-Levels, still deciding what uni to go to and looking for degree apprenticeship options! You can chec
14.
▲
by
JakeSkii
3y ago
This was one of my favorite security research findings and I decided to write my first ever blog post on it. Would love to hear everyones thoughts and any constructive criticism on it!
15.
▲
How I Hacked Chess.com
(skii.dev)
4 points
by
JakeSkii
3y ago
|
1 comments