codelikecraze — 6/18/2022, 3:36:17 PM

@ee i feel like I am pretty notorious for hacking…. something. I can’t tell for anonymity purposes, but @micahlt knows who I am, and what I found….. a few vulnerabilitys in.

♥ 2 ↩ 0 💬 18 comments

comments

oren:

What, is it one of my projects? Or the scratch project archive? Or smth else?

6/18/2022, 3:40:05 PM
codelikecraze:

I hacked a Micahlt project. I will reveal no more for anonymity.

6/18/2022, 3:41:09 PM
oren:

Xss?

6/18/2022, 3:42:34 PM
codelikecraze:

m a n y xss

6/18/2022, 3:42:57 PM
oren:

Oof

6/18/2022, 3:45:29 PM
oren:

Was it hard to hack?

6/18/2022, 3:45:56 PM
codelikecraze:

No… it was a mess. 99% of all user input was not sanitized.

6/18/2022, 3:47:54 PM
oren:

Must have been hastily built bc Micah doesn't usually make stuff that badly, and its actually really easy to sanitize input. Even just a RegEx can do a lot

6/18/2022, 3:50:55 PM
codelikecraze:

It was one of his biggest and most popular projects.

6/18/2022, 3:51:28 PM
oren:

:O did i overestimate him?

6/18/2022, 3:52:27 PM
codelikecraze:

yes. and after all the vulnerabilities were fixed, and he had an amazing developer friendly site, he… completely restarted the project. :clap:

6/18/2022, 3:53:34 PM
codelikecraze:

And someone else found a vulnerability that allowed you to log into anyones account.

6/18/2022, 3:54:18 PM
oren:

Is it itchy?

6/18/2022, 3:55:28 PM
codelikecraze:

I am not confirming nor denying any questions about what project it is. Remember, anonymity.

6/18/2022, 3:56:10 PM
oren:

Ok, l understand sorry

6/18/2022, 4:05:51 PM
micahlt:

It’s a bug in Modchat. You’re right, I don’t do things hastily, but I do have no idea what I’m doing when it comes with security. Modchat is the first standalone app I’ve built that requires me to save usernames and passwords, and it’s been a big learning curve for me. As far as restarting the project, the original Modchat’s codebase was absolutely awful and not maintainable. We started over and I’m much happier about where the code is now.

6/18/2022, 8:29:21 PM
oren:

Oh oof sorry about that

6/18/2022, 8:34:27 PM
micahlt:

No problem - we're aware of the current vulnerability and we're working on a fix at the moment.

6/18/2022, 8:43:18 PM