This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2012-10-18 20:50:56

l0ve1y
Scratcher
Registered: 2011-08-27
Posts: 100+

A glitch that could get people hacked?

I'm not sure if this belongs here.  hmm



I think I found a glitch that could allow people to get hacked easily.

Here's how I found it:


I was on my email, looking through my old messages. I found two 'forgotten password' messages that you receive when you ask to regain your password. Just for fun, I copied and pasted the password recovery URL into my browser's URL bar at the top. And then I had a thought. In the page, it automatically shows your old password in the 'old password' box. So I got an idea, and in the URL bar, I replaced the name 'l0ve1y' with someone else's username, and pressed the enter key. Sure enough, instead of 'l0ve1y', the text 'Resetting the password for username [insert username here]' said the username I had typed in at the top. Which means the password in the box could have changed, too. I don't know for sure, but I'd rather be safe than sorry. If the password does change, then this is an easy way for people to get hacked- all the hacker has to do is request a password recovery, copy and paste the URL into their browser, change the name to whoever they want to hack, click 'reset', and boom. They've hacked a user. Now, I don't want to test this, because if I changes someone's password without telling them, it would be very mean, and they would have to use a password reset. So I'm not sure if it works. But if it does work, it should be stopped somehow so that people don't get hacked.







l0ve1y


http://www.tagmybffs.com/upics/v2l4v5b78olj3x.png

Offline

 

#2 2012-10-18 22:10:57

cheddargirl
Scratch Team
Registered: 2008-09-15
Posts: 1000+

Re: A glitch that could get people hacked?

Hi l0vely,

I sent a message to the Scratch Team about it and, I got this reply back.

"Yeah, you can do those steps to change the prompt, but it doesn't work to actually change their password."

So I guess that trick is not much of a threat. ^^


http://i.imgur.com/8QRYx.png
Everything is better when you add a little cheddar, because when you have cheese your life is at ease  smile

Offline

 

#3 2012-10-19 10:44:37

l0ve1y
Scratcher
Registered: 2011-08-27
Posts: 100+

Re: A glitch that could get people hacked?

cheddargirl wrote:

Hi l0vely,

I sent a message to the Scratch Team about it and, I got this reply back.

"Yeah, you can do those steps to change the prompt, but it doesn't work to actually change their password."

So I guess that trick is not much of a threat. ^^

Ohh, good. :3 I'll delete this, then.


http://www.tagmybffs.com/upics/v2l4v5b78olj3x.png

Offline

 

#4 2012-10-19 11:16:01

RedRocker227
Scratcher
Registered: 2011-10-26
Posts: 1000+

Re: A glitch that could get people hacked?

Tip: if you discover an amazing new way to hack people, don't publicly post it in the forums!!


Why

Offline

 

#5 2012-10-19 11:28:26

mythbusteranimator
Scratcher
Registered: 2012-02-28
Posts: 1000+

Re: A glitch that could get people hacked?

RedRocker227 wrote:

Tip: if you discover an amazing new way to hack people, don't publicly post it in the forums!!

lol


http://www.foxtrot.com/comics/2012-04-01-fdb37077.gif
clicky

Offline

 

#6 2012-10-19 12:38:33

dvd4
Scratcher
Registered: 2010-06-30
Posts: 1000+

Re: A glitch that could get people hacked?

mythbusteranimator wrote:

RedRocker227 wrote:

Tip: if you discover an amazing new way to hack people, don't publicly post it in the forums!!

lol

lol


I made a mod  big_smile  It's called blook!
http://i49.tinypic.com/16ia63p.png

Offline

 

#7 2012-10-19 12:39:21

fay6
New Scratcher
Registered: 2011-07-21
Posts: 17

Re: A glitch that could get people hacked?

dvd4 wrote:

mythbusteranimator wrote:

RedRocker227 wrote:

Tip: if you discover an amazing new way to hack people, don't publicly post it in the forums!!

lol

lol

lol

Offline

 

#8 2012-10-19 12:47:14

jvvg
Scratcher
Registered: 2008-03-26
Posts: 1000+

Re: A glitch that could get people hacked?

I tried this one someone, but it still changed my old password.


http://tiny.cc/zwgbewhttp://tiny.cc/e1gbewhttp://tiny.cc/zygbewhttp://tiny.cc/izgbew
Goodbye, Scratch 1.4  sad                                                        Hello Scratch 2.0!  smile

Offline

 

#9 2012-10-19 12:57:30

Molybdenum
Scratcher
Registered: 2012-06-17
Posts: 1000+

Re: A glitch that could get people hacked?

fay6 wrote:

dvd4 wrote:

mythbusteranimator wrote:


lol

lol

lol

lol


"The Enrichment Center is required to remind you that you will be baked, and then there will be cake."
(|Balls and Platforms: Stay on!|) (|NaOS-H: An operating system... Or is it?|)

Offline

 

#10 2012-10-19 12:59:04

Willpower
Scratcher
Registered: 2012-01-26
Posts: 1000+

Re: A glitch that could get people hacked?

Don't panic everyone! I tried to hack into my Willpower_Reviews account and it came up with this

http://i48.tinypic.com/rvj42f.png


http://i49.tinypic.com/e84kdj.png

Offline

 

#11 2012-10-19 13:19:32

Firedrake969
Scratcher
Registered: 2011-11-24
Posts: 1000+

Re: A glitch that could get people hacked?

Oh, that's good.
10th post and 100th view on this thread!   big_smile


Click the sign.
https://s3.amazonaws.com/eterna/eterna2/logo2.png

Offline

 

#12 2012-10-22 10:01:55

scimonster
Community Moderator
Registered: 2010-06-13
Posts: 1000+

Re: A glitch that could get people hacked?

cheddargirl wrote:

Hi l0vely,

I sent a message to the Scratch Team about it and, I got this reply back.

"Yeah, you can do those steps to change the prompt, but it doesn't work to actually change their password."

So I guess that trick is not much of a threat. ^^

I remember a topic from some time ago where some people tested it, and got the same result (obviously).

Offline

 

Board footer