Forum Settings
Forums

[Fixed] Vulnerability in URLs entered by the user.

New
Nov 14, 2018 6:50 AM
#1
Offline
May 2011
8
Like this
Which changes the site user was before opening newtab to one that can be prepared by an attacker to make user login again if the site looks like MAL login page and gather paswords.

https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/

edit:
For now the only way to be protected from this is to open links with mousescroll click or PPM > open in newtab
LunaNov 19, 2018 7:35 AM
Nov 14, 2018 10:30 AM
#2
四十二

Offline
Mar 2016
441
That's quite interesting considering that MAL was put offline a few weeks ago due to security reasons.
HTCPCP/1.0  ★ MetaMAL  ★ Picture credits: Living & 1041uuu
Nov 14, 2018 10:46 AM
#3

Offline
Oct 2018
907

You can right click and open the link in a new tab. I'll just do that from now on.




i'm a worm
Nov 14, 2018 2:23 PM
#4

Offline
Apr 2014
4947
well damn. mal hiatus part 2 when?
Nov 14, 2018 3:14 PM
#5
Offline
Jul 2018
564612
I think the devs have stopped giving f*ck (and now I'm trying my hardest to be polite). This problem you're describing is not the only one they have right now.

They have left Vue JS in dev mode, which gives access to the Vuex store. I noticed that you might be able to bypass the entire payment process when buying a manga from MAL (I'm not going to actually try it, since I most likely can get in trouble for it).

I emailed them about turning Vue into production mode (like 1 or 2 weeks ago), but nothing has yet to happen, hence me now calling them out and claiming that the devs are giving 0 f*cks. Maybe the developers are underpaid, maybe they have a lot on their hands 'cause they got hacked recently, but come on...
Wasn't it also revealed that MAL stored password in plain text (before the hack)? Like that's the first thing you learn NOT to do when you get into web development. It's like making a car without any locks at all. It just boggles my mind....

Edit: I don't care if this comment could get me banned. I have already exported my lists, and all I have to say now is "bring it".
removed-userNov 14, 2018 3:28 PM
Nov 14, 2018 5:36 PM
#6
Community Admin
sunny moment

Offline
May 2010
2700
If there's no examples of this kind of phishing happening on MAL, then I'm not sure if someone will look into patching it--if that's generally possible cuz I haven't really read it properly.

@Fexell
I don't think MAL has ever stored passwords in plain text... and no, no-one's going to ban you.
Nov 15, 2018 12:55 AM
#7
Offline
Jul 2018
564612
Tensho said:
If there's no examples of this kind of phishing happening on MAL, then I'm not sure if someone will look into patching it--if that's generally possible cuz I haven't really read it properly.

@Fexell
I don't think MAL has ever stored passwords in plain text... and no, no-one's going to ban you.


Okay, then I can rest easy with spreading the word of vulnerabilities on your site.

Can you please answer me why there are so many vulnerabilities? What are the devs doing? Vue is still in dev mode. It's not that difficult to set it to production. If they've set it up right, it's literally just changing a word from "dev" to "production" (or similar).

There are also a bunch of other error-messages in the console, which kind of indicates that they are developing on the live server (I could be wrong, though). Who in their right mind does that?
Nov 15, 2018 3:49 AM
#8
四十二

Offline
Mar 2016
441
If you take a look at the latest DeNA financial results you'll find out that the main source of income of the company is based on games (they've recently partnered with Nintendo) and e-commerce.

IP-generating platforms like MAL are categorized under the "New Businesses and Others" section; in the last few quarters, the operating profit of this category was about -1.8%. In other words, they're losing money.

Thus, at least from a financial point of view, it's much better to deploy more resources where they know for sure that they'll improve the revenue (gaming and e-commerce) rather than wasting them in some money-burning project like MAL.

Don't take me wrong, I love MAL and I don't like the situation we're in.
However, it doesn't surprise me that we haven't seen any major improvement of MAL in the last years (except for the introduction of the Manga Store, the DeNA's e-commerce platform redesigned for MAL).
HTCPCP/1.0  ★ MetaMAL  ★ Picture credits: Living & 1041uuu
Nov 15, 2018 4:09 AM
#9

Offline
Aug 2014
70729
Fexell said:
Tensho said:
If there's no examples of this kind of phishing happening on MAL, then I'm not sure if someone will look into patching it--if that's generally possible cuz I haven't really read it properly.

@Fexell
I don't think MAL has ever stored passwords in plain text... and no, no-one's going to ban you.


Okay, then I can rest easy with spreading the word of vulnerabilities on your site.

Can you please answer me why there are so many vulnerabilities? What are the devs doing? Vue is still in dev mode. It's not that difficult to set it to production. If they've set it up right, it's literally just changing a word from "dev" to "production" (or similar).

There are also a bunch of other error-messages in the console, which kind of indicates that they are developing on the live server (I could be wrong, though). Who in their right mind does that?

Just so you know, mods here aren't devs. We know just as little as you guys.
Nov 15, 2018 4:39 AM
★★★★★

Offline
Sep 2008
19246
The devs are currently looking into these 2 issues mentioned in this thread. This is all I know about the situation though - I'm not involved in the actual dev work so I can't answer any questions about this.
Nov 15, 2018 8:23 AM
Offline
Jul 2018
564612
Luna said:
The devs are currently looking into these 2 issues mentioned in this thread. This is all I know about the situation though - I'm not involved in the actual dev work so I can't answer any questions about this.


Okay, great!
Nov 15, 2018 10:24 AM
Offline
Jul 2018
564612
More than 90% of all time, when I'm trying to post on MAL forums I get this error:
------------------------------
myanimelist.net says

Your message must contain 30 characters excluding BBCode quotes,
images, and spaces.

Current character count:3(or any other random number)

Warning: Please do not bypass blablabla...
---------------------------------------------------------------------------

I've sent this to support but they never respond.
This is the first website, and the first time that I've encountered such problem.
=.= so annoyed by this!
Nov 15, 2018 10:28 AM
四十二

Offline
Mar 2016
441
DejectedSoul said:
More than 90% of all time, when I'm trying to post on MAL forums I get this error:
------------------------------
myanimelist.net says

Your message must contain 30 characters excluding BBCode quotes,
images, and spaces.

Current character count:3(or any other random number)

Warning: Please do not bypass blablabla...
---------------------------------------------------------------------------

I've sent this to support but they never respond.
This is the first website, and the first time that I've encountered such problem.
=.= so annoyed by this!

You should probably open a separated topic for this.
HTCPCP/1.0  ★ MetaMAL  ★ Picture credits: Living & 1041uuu
Nov 15, 2018 10:30 AM
Offline
Jul 2018
564612
ZeroCrystal said:
DejectedSoul said:
More than 90% of all time, when I'm trying to post on MAL forums I get this error:
------------------------------
myanimelist.net says

Your message must contain 30 characters excluding BBCode quotes,
images, and spaces.

Current character count:3(or any other random number)

Warning: Please do not bypass blablabla...
---------------------------------------------------------------------------

I've sent this to support but they never respond.
This is the first website, and the first time that I've encountered such problem.
=.= so annoyed by this!

You should probably open a separated topic for this.
If the "Support" don't care, then what's the point?!
Nov 15, 2018 1:39 PM
Offline
Jul 2018
564612
ZeroCrystal said:
If you take a look at the latest DeNA financial results you'll find out that the main source of income of the company is based on games (they've recently partnered with Nintendo) and e-commerce.

IP-generating platforms like MAL are categorized under the "New Businesses and Others" section; in the last few quarters, the operating profit of this category was about -1.8%. In other words, they're losing money.

Thus, at least from a financial point of view, it's much better to deploy more resources where they know for sure that they'll improve the revenue (gaming and e-commerce) rather than wasting them in some money-burning project like MAL.

Don't take me wrong, I love MAL and I don't like the situation we're in.
However, it doesn't surprise me that we haven't seen any major improvement of MAL in the last years (except for the introduction of the Manga Store, the DeNA's e-commerce platform redesigned for MAL).


"In the last years" is a bit of an understatement. Taking a look at their source code they are STILL using tables for the design. This might have been acceptable for 10+ years ago, but right now it's such an outdated method, it's not even funny.

MAL definitely needs a facelift, in a lot of places - and of course, a lot of improvements to the security and so on.
I have no idea who the devs are, but if they are understaffed, or have some other reason for not being able to work on MAL as much is needed, they should start thinking about making it open-source. I bet there are a lot of developers on this site that would be happy to help. Me included.
Nov 15, 2018 2:21 PM
四十二

Offline
Mar 2016
441
I would love to see MAL being open-sourced, however that won't be the case as long as it won't be part of DeNA business plan.

I've seen different people on IRC interested on helping with the code (some of them were quite obsessed with that idea), but I doubt that DeNA will allow any stranger to contribute with the development of MAL.
Plus, they're a Japanese company; the language/cultural barrier shouldn't be underestimated.
HTCPCP/1.0  ★ MetaMAL  ★ Picture credits: Living & 1041uuu
Nov 15, 2018 7:19 PM

Offline
Aug 2012
168
ZeroCrystal said:
I would love to see MAL being open-sourced, however that won't be the case as long as it won't be part of DeNA business plan.

I've seen different people on IRC interested on helping with the code (some of them were quite obsessed with that idea), but I doubt that DeNA will allow any stranger to contribute with the development of MAL.
Plus, they're a Japanese company; the language/cultural barrier shouldn't be underestimated.


I was not really paying attention, and didn't realize DeNA owned MAL for a while. I still wish that the site was kept as it's own entity and not sold to a company who has no interest in the website itself. I want this site to be updated and given attention to by a dev team who actually cares about the product and it's users.

I've also seen people on IRC express interest in doing this, but it likely will never happen.
Nov 15, 2018 10:21 PM
Offline
Jul 2018
564612
Cladocera- said:
DejectedSoul said:
More than 90% of all time, when I'm trying to post on MAL forums I get this error:
------------------------------
myanimelist.net says

Your message must contain 30 characters excluding BBCode quotes,
images, and spaces.

Current character count:3(or any other random number)

Warning: Please do not bypass blablabla...
---------------------------------------------------------------------------

I've sent this to support but they never respond.
This is the first website, and the first time that I've encountered such problem.
=.= so annoyed by this!
That's not an error but a rule. I feel like you already know that tho.
If I only type "LOL" with 3 letters and get that error, and that's a rule?! I don't see the logic?!
Nov 16, 2018 2:12 AM
Offline
Jul 2018
564612
Cladocera said:
DejectedSoul said:
If I only type "LOL" with 3 letters and get that error, and that's a rule?! I don't see the logic?!
It's used to avoid spamming/shitposting and encorage disscussion. Back before it was a thing, the forum is full of chain-quoting with just "This" or "lol" or "+1" from the people who don't have anything to say and some just there to increase post count. Those replies make it hard to follow the actual conversation while don't contribute anything meaningful.

Kineta explained it here.
"LOL" was just an example to show that it doesn't matter, if I post several lines of text with IMG attached to it, or just one word, I still get the same error. And regarding the spamming/shit-posting...nevermind, I just got Support response.
Nov 19, 2018 7:40 AM
★★★★★

Offline
Sep 2008
19246
The vulnerability reported in the first post has been fixed.

I was told that the Vue JS issue doesn't need a fix since there are apparently multiple safeguards in place that will prevent people from hacking into the system.
Nov 19, 2018 9:07 AM
Offline
Jul 2018
564612
Luna said:
The vulnerability reported in the first post has been fixed.

I was told that the Vue JS issue doesn't need a fix since there are apparently multiple safeguards in place that will prevent people from hacking into the system.


Here ya go: https://imgur.com/a/IoP83E6
Nov 19, 2018 3:29 PM

Offline
Aug 2012
168
Fexell said:
Luna said:
The vulnerability reported in the first post has been fixed.

I was told that the Vue JS issue doesn't need a fix since there are apparently multiple safeguards in place that will prevent people from hacking into the system.


Here ya go: https://imgur.com/a/IoP83E6


Living that dangerous life. Would be interesting if you PM'd @Luna the steps you did so she can send it to the devs.
Nov 23, 2018 11:36 AM
Offline
Jul 2018
564612
Yuno said:
Fexell said:


Here ya go: https://imgur.com/a/IoP83E6


Living that dangerous life. Would be interesting if you PM'd @Luna the steps you did so she can send it to the devs.

What dangerous life? I very clearly pointed out this flaw with keeping Vue in dev mode in a previous comment of this thread. It's their own fault for not heeding my warning. I specifically pointed that out.

Why should I give away how I did it? My point all along was to put Vue in production mode. This is starting to get stupid, even. I'm currently thinking about PMing someone to delete my account.
If they don't take security seriously, why should I take this site seriously?

Edit: I am currently also pretty much seeing red because this makes me furious. Really fucking furious. I think I would just start insulting people (which I'm trying my hardest not to do) if I were to start doing their fucking developers job for them...............

More topics from this board

» Backup

Vapor_AU - 9 hours ago

1 by pichipichiHiro »»
9 hours ago

Sticky: » Inactive Username Request Thread ( 1 2 3 4 5 ... Last Page )

Kineta - Sep 21, 2015

3368 by L2Dragon »»
11 hours ago

» ishinashi has 300 alt accounts and counting ( 1 2 3 )

deg - Jun 16, 2023

125 by traed »»
Yesterday, 4:53 PM

» MAL Export

Devileeee - Sep 25, 2023

3 by zororo12 »»
Apr 23, 3:52 AM

» Problem with API OAuth2 Authentication Login

bidgetfoss_4000 - Apr 23

0 by bidgetfoss_4000 »»
Apr 23, 3:44 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login