No userscripts, no inspect console, pure code.org tomfoolery

Awards

  • â’¸ 1 from Varrience
    Comment: :0
  • â’¸ 20 from [WUT] Adam
    Comment: GIVE.
  • â’¸ 1 from imreallyhuman
    Comment: comment
  • â’¸ 1000 from miztis
    Comment: give it to me

    [WUT] Adam Now, here is the problem, it gives you TOTAL access to all of the inspect console from within a gamelab project. You can execute scripts on the behalf of anyone running the project. I can create a project which when run will replace your projects with copies of that project and publish them. Do you understand the security issue this presents?

      A proper demonstration of it's power.

      EDIT: Removed video since it don't work

      Awards

      • â’¸ 1 from ackvonhuelio
        Comment: ☹
      • â’¸ 10 from MonsterYT_DaGamer
        Comment: The video doesn't work, but don't worry. Just give it to me and I'll help with dat B)

        I've decided to report it as a bug to code.org since I realize the devastating potential of an exploit like this. For now, I shall wait until it is patched. Cry about it, but it's the responsible thing to do.

          2 months later

          Binary_Coder Nope, never happened, and yes it is less dangerous without public project publishing.

          Awards

          • â’¸ 0.1 from Varrience
            Comment: Still can delete your account though lulz

          Chat