Back to Epicmafia

What happened

over 8 years

Me and lucid figured out what happened. It was an old XSS that somehow wasn't patched. I'll keep you up to date as to when it's fixed here.

deletedover 8 years
Maybe it's a sign for you to stop wasting time on comp, sinead
over 8 years

sineadiio says

So arcbell should I even bother playing my hearts of am I gonna get fked over again


I'll message you an account you can click on to test and see when lucid's fixed the exploit. You can *probably* play your hearts but it's not outside the realm of possibility that another attack will happen if it doesn't get fixed soon.
deletedover 8 years
So arcbell should I even bother playing my hearts of am I gonna get fked over again
deletedover 8 years
deletedover 8 years

REALLYLOOOOOOONGNAME says


Jimbei says

Changing your password is a good security practice, anyways, PonyLove.


i bet this user uses the same email and password for EM as she does for her bank account


seems like a good idea to me.
deletedover 8 years

thecolonel says

it could have been anypony


over 8 years

ArieI says

wonder who could have done this...


Considering it's an XSS that's been public and we thought was fixed for months, anyone who had the idea to try it and see if it still worked and has enough coding knowledge to deliver a payload that phishes passwords leveraging the trust users place in the site itself could have done it.

In plain english, any amateur who got lucky and tested some code that was made public months ago.

Jimbei says

Changing your password is a good security practice, anyways, PonyLove.


i bet this user uses the same email and password for EM as she does for her bank account
over 8 years
you are so funny..
over 8 years
it could have been anypony
deletedover 8 years
If it happened once it'll happen again
over 8 years
wonder who could have done this...
deletedover 8 years
yeah, ponylove
deletedover 8 years
Changing your password is a good security practice, anyways, PonyLove.
deletedover 8 years

PonyLove says


Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.


blasphemy! on the contrary, if you don't change your password, you will lose your hard earned pixelated trophies and points that have earned you nothing
over 8 years
yes it is ponylove. there is an open XSS in the angular that's gone unfixed for months and which anyone who logged in on a specific day months ago could have access to
over 8 years

PonyLove says


Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.


mod lono
over 8 years

Lono says

this is a huge security risk, people's accounts are on the line


I mean, honestly, people can do whatever they want, change the password or not, I mean, if changing your password will make you feel better, do it, but this thing isn't affecting the average em person.
deletedover 8 years
yeah pony, you don't know whats going on
over 8 years

PonyLove says

It is fine. I talked to him earlier, there is no need to scare everyone Arcbell


ponylove you dont know what's going on. the only sense of safety (about your account) you should have right now is that the attacker probably won't do it twice in a row on the same day, and may not be gathering pw's en masse
deletedover 8 years
and then the pony mod abuses. i believe there is a rule that prohibits this
deletedover 8 years
demod ponylove please ive had enough
deletedover 8 years
this is a huge security risk, people's accounts are on the line
over 8 years
PONYLOVE IS THE BAD MAN
over 8 years
It is fine. I talked to him earlier, there is no need to scare everyone Arcbell