Page 2 of 2 FirstFirst 12
Results 16 to 29 of 29
  1. #16
    Fucking Moron's Avatar
    Join Date
    Mar 2014
    Gender
    male
    Location
    I need smoke
    Posts
    5,529
    Reputation
    1371
    Thanks
    1,618
    My Mood
    Buzzed
    Quote Originally Posted by Zaczero View Post
    Hello MPGH!

    Recently I found a way to leak IP addresses of the MPGH users and here is my proof of work.
    I'm also providing a quick and easy fix for the staff members.

    Let's start with the way how MPGH handles user images and signatures.
    What it does is simply include the image in the HTML (no cdn, no proxy, just a direct connection).
    There is nothing bad in this by itself but I found a smart way of matching the request with the mpgh username.



    Every request sends the referrer header with the url where the file is loaded from.


    Knowing this you can create a bot which checks the Who's Online page (https://www.mpgh.net/forum/online.php)
    and looks for people who are viewing our XYZ thread where the image has been loaded from.

    For optimal performance you can sort the list by "Last Activity" entry by adding ?sort=time parameter.


    The last step is to include the dummy image in your signature or thread and gather data.

    Data which you can gather using this method:
    * Thread id
    * Time
    * User id
    * Username
    * IP address
    * Country
    * Browser used


    And here goes my proof of work:


    How efficient it is?
    By running the bot for 3 days I was able to dump ~2000 users multiple times (25.000 requests).

    How effective it is?
    Sometimes you get false results so in order to make them more trustworthy you should dump a user at least 3-4 times.
    Success rate is around 80%

    How to fix it (easy way)
    Add referrer-policy header on server response which will restrict data being send from the client inside the referrer.
    I suggest using strict-origin-when-cross-origin.
    Read more here: https://developer.mozilla.org/en-US/...eferrer-Policy
    * note: it still will be possible to gather data using who's online but success rate will fall to around 10%
    * note2: for full fix I'd suggest disabling who's online feature for normal users

    How to fix it (hard way)
    Create cdn server which will redirect all media requests through it.

    Final words
    Please don't ban me lmao. This data is available for everyone anyways and I'm just showing the problem so it can be fixed quickly :3
    Also I want to show that you are not safe on the internet without VPN even if you visit trusted sites only.
    Also please consider switching to Tor https://www.torproject.org/ <3

    Donate for my small research and making MPGH a safer place for all of us ?
    BTC: 1NjW3K26ZPZeveW4st4sC249MfyW2w5ZP8
    ETH: 0x56b4ED755b7bDD75A954e168EB96f4501F75342d
    did u sql inject?????
    or were was original leak or thought from

  2. #17
    Zaczero's Avatar
    Join Date
    Oct 2013
    Gender
    male
    Location
    localhost
    Posts
    3,288
    Reputation
    1517
    Thanks
    14,263
    My Mood
    Angelic
    Quote Originally Posted by Organized Chaos View Post


    did u sql inject?????
    or were was original leak or thought from
    everything is explained in the thread uwu
    . . . malsignature.com . . .



    [ global rules ] [ scam report ] [ image title ] [ name change ] [ anime force ]
    [ league of legends marketplace rules ] [ battlefield marketplace rules ]

    "because everytime you post a picture of anime in here
    your virginity's time increases by 1 month"
    ~Smoke 2/18/2018


    Former Staff 09-29-2018
    Battlefield Minion 07-21-2018
    Premium Seller 03-04-2018
    Publicist 12-10-2017
    League of Legends Minion 05-31-2017
    Premium 02-05-2017
    Member 10-13-2013

  3. #18
    Fucking Moron's Avatar
    Join Date
    Mar 2014
    Gender
    male
    Location
    I need smoke
    Posts
    5,529
    Reputation
    1371
    Thanks
    1,618
    My Mood
    Buzzed
    Quote Originally Posted by Zaczero View Post
    everything is explained in the thread uwu
    Bro I read the first two sentences And then the images lol
    U need. Tl:dr

  4. The Following User Says Thank You to Fucking Moron For This Useful Post:

    Zaczero (04-10-2019)

  5. #19
    I love myself
    나도 너를 사랑해

    Former Staff
    Premium Member
    Jhem's Avatar
    Join Date
    Mar 2012
    Gender
    male
    Location
    167,646,447
    Posts
    5,150
    Reputation
    1220
    Thanks
    7,393
    My Mood
    Stressed
    And then the online page got deleted. good work dave.

  6. The Following User Says Thank You to Jhem For This Useful Post:

    Zaczero (04-10-2019)

  7. #20
    Zaczero's Avatar
    Join Date
    Oct 2013
    Gender
    male
    Location
    localhost
    Posts
    3,288
    Reputation
    1517
    Thanks
    14,263
    My Mood
    Angelic
    Quote Originally Posted by Jhem View Post
    And then the online page got deleted. good work dave.
    silent said its a temporary fix
    . . . malsignature.com . . .



    [ global rules ] [ scam report ] [ image title ] [ name change ] [ anime force ]
    [ league of legends marketplace rules ] [ battlefield marketplace rules ]

    "because everytime you post a picture of anime in here
    your virginity's time increases by 1 month"
    ~Smoke 2/18/2018


    Former Staff 09-29-2018
    Battlefield Minion 07-21-2018
    Premium Seller 03-04-2018
    Publicist 12-10-2017
    League of Legends Minion 05-31-2017
    Premium 02-05-2017
    Member 10-13-2013

  8. The Following User Says Thank You to Zaczero For This Useful Post:

    Jhem (04-10-2019)

  9. #21
    I love myself
    나도 너를 사랑해

    Former Staff
    Premium Member
    Jhem's Avatar
    Join Date
    Mar 2012
    Gender
    male
    Location
    167,646,447
    Posts
    5,150
    Reputation
    1220
    Thanks
    7,393
    My Mood
    Stressed
    Quote Originally Posted by Zaczero View Post
    silent said its a temporary fix
    This is actually excellent findings, dave should give you something, like ban himself for a whole year.

  10. #22
    Zaczero's Avatar
    Join Date
    Oct 2013
    Gender
    male
    Location
    localhost
    Posts
    3,288
    Reputation
    1517
    Thanks
    14,263
    My Mood
    Angelic
    Quote Originally Posted by Jhem View Post


    This is actually excellent findings, dave should give you something, like ban himself for a whole year.
    lma o
    . . . malsignature.com . . .



    [ global rules ] [ scam report ] [ image title ] [ name change ] [ anime force ]
    [ league of legends marketplace rules ] [ battlefield marketplace rules ]

    "because everytime you post a picture of anime in here
    your virginity's time increases by 1 month"
    ~Smoke 2/18/2018


    Former Staff 09-29-2018
    Battlefield Minion 07-21-2018
    Premium Seller 03-04-2018
    Publicist 12-10-2017
    League of Legends Minion 05-31-2017
    Premium 02-05-2017
    Member 10-13-2013

  11. #23
    Psiyix's Avatar
    Join Date
    Apr 2019
    Gender
    male
    Posts
    835
    Reputation
    24
    Thanks
    55
    My Mood
    Cool
    Great work my friend. Appreciate the information which is
    beyond the scope of many. I am definitely going to look
    at protecting myself more while on the internet.

    I'm sure Tor has it's limitations as well and would be good
    to know how to really protect yourself for max privacy.

    Will the who's online be disabled on here as per your
    suggestion?

    Thanks again bro, appreciate you.
    Last edited by Psiyix; 04-12-2019 at 09:42 AM.

  12. #24
    ikennafree's Avatar
    Join Date
    Apr 2019
    Gender
    male
    Posts
    16
    Reputation
    10
    Thanks
    0
    didn't know you couldn't use Vpns here

  13. #25
    Zaczero's Avatar
    Join Date
    Oct 2013
    Gender
    male
    Location
    localhost
    Posts
    3,288
    Reputation
    1517
    Thanks
    14,263
    My Mood
    Angelic
    Quote Originally Posted by Psiyix View Post
    Great work my friend. Appreciate the information which is
    beyond the scope of many. I am definitely going to look
    at protecting myself more while on the internet.

    I'm sure Tor has it's limitations as well and would be good
    to know how to really protect yourself for max privacy.

    Will the who's online be disabled on here as per your
    suggestion?

    Thanks again bro, appreciate you.
    'Who's online' has been temporarily disabled by staff until the media CDN is completed

    - - - Updated - - -

    Quote Originally Posted by ikennafree View Post
    didn't know you couldn't use Vpns here
    You can unless you post something in the marketplace (you have to disable it temporarily while making the post there)

    - - - Updated - - -

    Quote Originally Posted by ikennafree View Post
    didn't know you couldn't use Vpns here
    You can unless you post something in the marketplace (you have to disable it temporarily while making the post there)
    . . . malsignature.com . . .



    [ global rules ] [ scam report ] [ image title ] [ name change ] [ anime force ]
    [ league of legends marketplace rules ] [ battlefield marketplace rules ]

    "because everytime you post a picture of anime in here
    your virginity's time increases by 1 month"
    ~Smoke 2/18/2018


    Former Staff 09-29-2018
    Battlefield Minion 07-21-2018
    Premium Seller 03-04-2018
    Publicist 12-10-2017
    League of Legends Minion 05-31-2017
    Premium 02-05-2017
    Member 10-13-2013

  14. #26
    trini599's Avatar
    Join Date
    Mar 2016
    Gender
    male
    Posts
    1,412
    Reputation
    127
    Thanks
    497
    Very fine explanation with a detailed report

  15. #27
    DizzyDrop's Avatar
    Join Date
    Apr 2019
    Gender
    female
    Location
    Morroco
    Posts
    345
    Reputation
    37
    Thanks
    100
    My Mood
    Happy
    Well Done. I think They're already Fix

  16. #28
    ReplacementsNX's Avatar
    Join Date
    Feb 2018
    Gender
    male
    Posts
    999
    Reputation
    744
    Thanks
    1,845
    I use some VPN for good time and not have issues with bans but if you register with VPN and same day wants to sell Samsung s9 for $50, I guess u will get banned

  17. #29
    Enneagram's Avatar
    Join Date
    Jan 2017
    Gender
    male
    Posts
    97
    Reputation
    10
    Thanks
    9
    Quote Originally Posted by ReplacementsNX View Post
    I use some VPN for good time and not have issues with bans but if you register with VPN and same day wants to sell Samsung s9 for $50, I guess u will get banned
    Yoo man. What's gonna happen to your customers who still have their warranties from the N3X4 shop?

    I have my Grammarly, NordVPN and Netflix bro.

Page 2 of 2 FirstFirst 12

Similar Threads

  1. Why you should buy USED PC parts.
    By AdobeStock in forum Computer Builds & Upgrades
    Replies: 64
    Last Post: 10-31-2020, 10:42 AM
  2. Do you guys use VPN on MPGH?
    By GUG85t75r64H*&& in forum Marketplace Talk
    Replies: 8
    Last Post: 12-17-2016, 02:52 AM
  3. Why you should play on Insanes MPGH server
    By GBot! in forum Minecraft Discussions
    Replies: 8
    Last Post: 11-10-2010, 01:04 PM
  4. Replies: 24
    Last Post: 08-30-2006, 08:06 PM
  5. You should of used Diet...
    By arunforce in forum Entertainment
    Replies: 8
    Last Post: 06-08-2006, 09:05 AM

Tags for this Thread