Back to Epicmafia

Epicly vulernable.

over 8 years

I'm bored, so I thought I might let you in on some of the vulnerable-ish features over EM. If any mod / admin ever feel like making this place really secure, here's a few points for you.

note: I won't be going into too much detail on this, so this doesn't become an epicmafia script-kiddie cheatsheet.

Ordered by how critical they are, up to my opinion.

remote code exec via fileupload to family page.

  • Most of the files (i.e profile pictures) are uploaded to em-uploads, which is a seperate image server, so in case somebody ever bypasses the file format ( I won't go into detail as to how you do it unless mods refer to me with it, but the formatter doesnt check nullbytes correctly ), you get access to some meainingless server that nobody cares about. Although, family pictures are saved on the server: I.e https://epicmafia.com/family/9055 - our image is saved at /uploads/families/9055_original.jpg , localpath.

CSRF in comments.

  • The comments posted have zero (0) CSRF protection in them. I could legit just make a dude post his password with the right parameters, post a link to a page i made, and passwords will be floating around the comments.

XSS

  • I won't go into details because everyone could literally just use this now, but try making an image link to an image (![[image number][description]][desc]) and see what happens. That breaks context, and in some of the areas of the site there is a vulnerability. For further details, have a mod contact me personally, I can demonstrate.

same origin policy bypass.

  • If somebody does find the XSS, there's certain places where you could freely upload an image from an outside source (that's not imgur or EM uploads, and thus can be a personal domain). Using side channel attacks, you could bypass same origin policy.

Proxied DoS (It's a feature!) in games.

  • Many of the in-game features are protected in the clientside. I mean, are you serious? Ghost game comments has a character limit of 100 per comment, but if you edit the max-character attribute I could legit post any size I want that gets into HTTP, that means DDoS on players that goes through the server.

DoS via file extensions on avatars.

  • The file extensions on avatars arnt checked properly. That allows you to upload some of those cool gifs as avis, but that can also create a large set of unmonitored traffic if you abuse it a certain way.

DoS via bad indexing.

  • Somebody needs to teach Lucid how to use nginx. Are you legit redirecting into the most traffic-ful page when somebody goes to a badly indexed page?

open redirect.

  • There is an open redirect through the error pages with a certain HTTP header.

information disclosure at login.

  • The way EM handles a log-in allows to figure if a certain username exists or not. That isn't very vulnerable, because there is a good captcha at use, although it's not a good practice.

Feel free to ask whatever, but Im saying ahead I wont answer much as to how to do most of these ( except to a mod or an admin that are willing to fix it ).

I challange you, EM, to fix half of these in a week.

Is EM secure
47
Nope
7
Not really
about 8 years
Heh, yes.
about 8 years
LOOK AT ME IM A HACKER AND NEED ATTENTION

why was this thread bumped
about 8 years

juke says

The only thing "epicly vulernable" here is your spelling.


niiiiiiiiiiice
about 8 years
The only thing "epicly vulernable" here is your spelling.
about 8 years
Up to recent checks, about time everything except CSRF is closed. I might make a new thread with the current issues with this site. There's some IAuth ( in-site links, unlike OAuth ) like mechanism thats really flawed, for the most part, with identifying tokens to games.
deletedabout 8 years
do tell
about 8 years
In hindsight - the only relevant one left is the RCE through family page. I've got new ones though, too lazy to type them out. When I first started this thread I felt enthusiasem, now its fading...
about 8 years
oh and also its for my mod campaign

ill make EM great again femz im trashtier at the game but i can help yo
about 8 years
poser fem, weve already had the dramas with animeavis, this is a broadcast to everyone cuz im too lazy to put up a list on anyone whod care. its also so edark knows i can steal lucids lunchmoney ( the first one mentioned allows my inner bully to do exactly that ), and to showoff how im very cool and worthy of doges.

usually lucid would have to pay a couple bucks for this kinda work, i did it for free tho, lemme have my moment
about 8 years
I don't see why you'd be posting these here and letting people exploit them rather than telling the mods :P
about 8 years
1,2,6,7 still exist.
about 8 years
is that u abc? u joining the military?
about 8 years
Bump because I want to know the progress and status report of the bugfixes.
about 8 years
If I were to make this thread and not Linker, it'd look somewhat like this~

1'm b0r3d, 50 1 7h0u6h7 1 m16h7 l37 y0u 1n 0n 50m3 0f 7h3 vuln3r4bl3-15h f347ur35 0v3r 3m. 1f 4ny m0d / 4dm1n 3v3r f33l l1k3 m4k1n6 7h15 pl4c3 r34lly 53cur3, h3r3'5 4 f3w p01n75 f0r y0u.

n073: 1 w0n'7 b3 601n6 1n70 700 much d3741l 0n 7h15, 50 7h15 d035n'7 b3c0m3 4n 3p1cm4f14 5cr1p7-k1dd13 ch3475h337.

0rd3r3d by h0w cr171c4l 7h3y 4r3, up 70 my 0p1n10n.
about 8 years
@Gio Fem I'm foreign I get to do whatever I wanna you should be thankful this isnt in l33tsp34k
about 8 years
*epically
about 8 years
XSS is closed. (:
about 8 years
guys i've got the tech to get into the site

about 8 years

Linker says

Talked with lucid, the Proxied DoS is fixed, working on the rest. Im going to the military though, for now.


seems like a weird way to cope with epicmafia bugs but good luck
about 8 years
DELETE THIS
deletedover 8 years
oh, damn. have a nice time!
over 8 years
Talked with lucid, the Proxied DoS is fixed, working on the rest. Im going to the military though, for now.
deletedover 8 years

sweetnkind says

someone mod linker


did he cheat
over 8 years

Linker says


sweetnkind says


Linker says

Hey weebs, Im contributing. You're not. Got professional criticism, let me know. Otherwise, I'm not up to wasting my time on the drama show you're trying to create.


to be fair tho ur up to wasting your time to make a java mafia website that the owner doesnt care ab ...


I talked with lucid @ gmail, and solace over skype, we're actually gonna fix stuff.


you still haven't said what the thread is for, it's clearly not because you're contributing
deletedover 8 years
someone mod linker