Back to Epicmafia

Oracle is potential spyware

deletedabout 7 years

So I just downloaded Oracle and I performed a login on EM and looked under Chrome's network activity tab and this is what Oracle is doing.

https://imgur.com/a/z1JnL

If you look at the part that is boxed in red, you can see that EVERY time you log in, Oracle is automatically sending a GET request to the following ip address: http://45.63.17.67/

Included with that request are a few suspicious parameters. I believe the p parameter (circled in red) is a hashed version of your password.

So whats probably going on is...every time you log in...Oracle takes a copy of your password, sends it to 45.63.17.67 (a server that is "epicmafia.net" and saves it somewhere. So the extension is just building a database of usernames and passwords.

For reference..here is what a log on looks like without Oracle.

https://imgur.com/a/9K1ov

Notice how without Oracle there is just a simple login POST to epicmafia.

You can try this yourself with the following steps.

Install Oracle on the chrome web store

Log out of your account

Right click on your screen and click inspect element

Go to the Network tab

Perform a login

Then you'll see in the network tab that your browser is making a get request to an ip address owned by lailai and its sending a few hashed parameters

There is no reason why Oracle needs to make this request. Nothing about oracle's functionality requires it. It's very likely that it is just logging your password and saving it

deletedabout 7 years

Arcbell says

I'm starting a skype group for this, hmu


nice try ip address selling mother f*cker
about 7 years
glad i never used oracle
deletedabout 7 years
is this how lailai made his first million?
about 7 years
I'm starting a skype group for this, hmu

We're going to figure out what to do about this
about 7 years
also this is good cause i can post this meme as fresh now
about 7 years

Dalypso says

it's not proof he's the one that hacked the site, but yes - he has the password of anyone that downloaded and logged in using his extension


hMMM
deletedabout 7 years
Yeah, who would want autorefreshing! I love joining full games! Such a thrill to get kicked out...
about 7 years
copy that arcbell, standing by *beep*
about 7 years
I'm going to attempt to open dialogue with him stand by everyone.
about 7 years
my vote 4 lailai being the best admin was vindicated
about 7 years

The says

Lailai currently has the password of everyone who is using the script. Uninstall immediately and change your password.


Who would even install Oracle.. -.- Your lazyness to do things the "easy way" got you here.

Any reasonable person did not install it.
deletedabout 7 years
You guys thought he was the lamest epicmafia admin ever but look at you now
about 7 years
hahahahahah
about 7 years

sky says

ok so is this how he got my password or not like im not smart enough for those screenshots?


Yes 100%
about 7 years
What do you guys think.. did he throw that code in at the last second, or was it his plan all along when writing the thing
about 7 years
i 100% think lailai did this to get acess to nudes
deletedabout 7 years
it's not proof he's the one that hacked the site, but yes - he has the password of anyone that downloaded and logged in using his extension
about 7 years
hahahhhahahaahahahahha
about 7 years
Lailai currently has the password of everyone who is using the script. Uninstall immediately and change your password.
about 7 years
ok so is this how he got my password or not like im not smart enough for those screenshots?
about 7 years
He's f*cked.
about 7 years
That's confirmation it was him by the way, and also proof
about 7 years
Hahahahahahahaha
deletedabout 7 years

shaGuar says

Someone file a class action law suit here. Lets demand a BTC donation into an "Epicmafia User Fund." Let's get everyone some coin


Hold up hold up let me get hacked before we shake him down
deletedabout 7 years
we do not mention throne of lies on these parts.