Aug 2008 Amaethwr Posts: 14,634 Opal Posts by user Forum Profile RuneMetrics Profile D: Amæ Life as we know it could be gone in a minute Selective Completionist 05-Dec-2013 22:30:08
Meredith wtf Posts: 4,160 Adamant Posts by user Forum Profile RuneMetrics Profile Currently, Linkify protects against someone using the eval function, which is pretty dangerous, but, obviously, there are ways around that. I think the easiest way to break this exploit is to grab the post content with JavaScript instead of PHP, but that mostly falls on Jagex to fix. 05-Dec-2013 22:35:59
Aug 2008 Amaethwr Posts: 14,634 Opal Posts by user Forum Profile RuneMetrics Profile So basically Jagex dun goof'd E: How long do you think for them to fix it? Lol Amæ Life as we know it could be gone in a minute Selective Completionist 05-Dec-2013 22:37:55 - Last edited on 05-Dec-2013 22:42:00 by Amaethwr
Meredith wtf Posts: 4,160 Adamant Posts by user Forum Profile RuneMetrics Profile I'm not sure If they truly understand how serious this is, they'll have it done by tomorrow But I think there's a good chance that they won't take it that seriously I mean, someone can be phished without ever leaving the RS site. That's really bad. 05-Dec-2013 22:45:02
Boeing Posts: 8,706 Rune Posts by user Forum Profile RuneMetrics Profile As Indecent Act said before, she'll have a fix before jagex even takes a breath and looks at it. http://puu.sh/5D5ex 05-Dec-2013 22:47:47
Dec 2023 Sal VJ Posts: 21,325 Opal Posts by user Forum Profile RuneMetrics Profile it's mostly the eval() function that I'm concerned about. Glad that Linkify patched that. Never drop a valuable item. Ikki blaka niður virðismikil ting. 05-Dec-2013 23:24:07
Meredith wtf Posts: 4,160 Adamant Posts by user Forum Profile RuneMetrics Profile Ehh... Patching the eval exploit was one step, but you can do anything without eval that you can do with it. 05-Dec-2013 23:28:14
Keighlea Posts: 40,455 Sapphire Posts by user Forum Profile RuneMetrics Profile Go Indy, fixing the forums since.. 2008? 1995?! Feels like forever, and it's been awesome the whole way This exploit sounds a bit scary lol ~~~Zaros is the way Forward~~~ Lady of Zaros Proud Linkify user - Become one of the Family! 06-Dec-2013 00:38:26
Toastcrumbs Posts: 5,801 Rune Posts by user Forum Profile RuneMetrics Profile General idea of the past 2 pages that I got, was... If it contains too many numbers and a function, don't be quoting that shit. and: Meredith wtf said : you can do anything without eval that you can do with it. 06-Dec-2013 01:42:35
Indecent Act Posts: 7,456 Rune Posts by user Forum Profile RuneMetrics Profile I was thinking about this before I went to sleep, was going to test a simple alert in post but it looks like I don't need to. I'll do another update very soon to sort some of these examples 06-Dec-2013 02:39:07 - Last edited on 06-Dec-2013 02:40:54 by Indecent Act