Back to Epicmafia

What happened

almost 8 years

Me and lucid figured out what happened. It was an old XSS that somehow wasn't patched. I'll keep you up to date as to when it's fixed here.

deletedalmost 8 years
Maybe it's a sign for you to stop wasting time on comp, sinead
almost 8 years

sineadiio says

So arcbell should I even bother playing my hearts of am I gonna get fked over again


I'll message you an account you can click on to test and see when lucid's fixed the exploit. You can *probably* play your hearts but it's not outside the realm of possibility that another attack will happen if it doesn't get fixed soon.
deletedalmost 8 years
So arcbell should I even bother playing my hearts of am I gonna get fked over again
deletedalmost 8 years
deletedalmost 8 years

REALLYLOOOOOOONGNAME says


Jimbei says

Changing your password is a good security practice, anyways, PonyLove.


i bet this user uses the same email and password for EM as she does for her bank account


seems like a good idea to me.
deletedalmost 8 years

thecolonel says

it could have been anypony


almost 8 years

ArieI says

wonder who could have done this...


Considering it's an XSS that's been public and we thought was fixed for months, anyone who had the idea to try it and see if it still worked and has enough coding knowledge to deliver a payload that phishes passwords leveraging the trust users place in the site itself could have done it.

In plain english, any amateur who got lucky and tested some code that was made public months ago.
almost 8 years

Jimbei says

Changing your password is a good security practice, anyways, PonyLove.


i bet this user uses the same email and password for EM as she does for her bank account
almost 8 years
you are so funny..
almost 8 years
it could have been anypony
deletedalmost 8 years
If it happened once it'll happen again
almost 8 years
wonder who could have done this...
deletedalmost 8 years
yeah, ponylove
deletedalmost 8 years
Changing your password is a good security practice, anyways, PonyLove.
deletedalmost 8 years

PonyLove says


Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.


blasphemy! on the contrary, if you don't change your password, you will lose your hard earned pixelated trophies and points that have earned you nothing
almost 8 years
yes it is ponylove. there is an open XSS in the angular that's gone unfixed for months and which anyone who logged in on a specific day months ago could have access to
almost 8 years

PonyLove says


Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.


mod lono
almost 8 years

Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.
deletedalmost 8 years
yeah pony, you don't know whats going on
almost 8 years

PonyLove says

It is fine. I talked to him earlier, there is no need to scare everyone Arcbell


ponylove you dont know what's going on. the only sense of safety (about your account) you should have right now is that the attacker probably won't do it twice in a row on the same day, and may not be gathering pw's en masse
deletedalmost 8 years
and then the pony mod abuses. i believe there is a rule that prohibits this
deletedalmost 8 years
demod ponylove please ive had enough
deletedalmost 8 years
this is a huge security risk, people's accounts are on the line
almost 8 years
PONYLOVE IS THE BAD MAN
almost 8 years
It is fine. I talked to him earlier, there is no need to scare everyone Arcbell