DragonFireGamesLvl 11
;)
MonsterYT_DaGamerLvl 8
- Android
DragonFireGames oh yes, that explains everything
DragonFireGamesLvl 11
- Edited
MonsterYT_DaGamer Short summary, I can block inspect console & data browser at the same time.
[WUT] AdamLvl 13
- Windows
Give. Now.
DragonFireGamesLvl 11
- Edited
[WUT] Adam Now, here is the problem, it gives you TOTAL access to all of the inspect console from within a gamelab project. You can execute scripts on the behalf of anyone running the project. I can create a project which when run will replace your projects with copies of that project and publish them. Do you understand the security issue this presents?
DragonFireGamesLvl 11
- Edited
A proper demonstration of it's power.
EDIT: Removed video since it don't work
Awards
- â’¸ 1 from
ackvonhuelio
Comment: ☹ - Ⓒ 10 from
MonsterYT_DaGamer
Comment: The video doesn't work, but don't worry. Just give it to me and I'll help with dat B)
DragonFireGames Video won't play for me :(
- Windows
Jibberjay unfortuante :)
MonsterYT_DaGamerLvl 8
- Android
DragonFireGames imma need that
- macOS
If i had coins i would give
MonsterYT_DaGamerLvl 8
- Android
imreallyhuman don't you have 1.6 coins
DragonFireGamesLvl 11
I've decided to report it as a bug to code.org since I realize the devastating potential of an exploit like this. For now, I shall wait until it is patched. Cry about it, but it's the responsible thing to do.
ackvonhuelioLvl 41
imreallyhuman
owokoyo pfp crazy
[WUT] AdamLvl 13
- Windows
DragonFireGames Damn 😔
but that is the responsible thing to do ngl
Letti42Lvl 6
- iPhone
DragonFireGames thats not good
Binary_CoderLvl 2
DragonFireGames Did CDO ever respond or fix it? And would it be any less dangerous with the new gallery preventing publishing?
DragonFireGamesLvl 11
Binary_Coder Nope, never happened, and yes it is less dangerous without public project publishing.
Awards
- â’¸ 0.1 from
Varrience
Comment: Still can delete your account though lulz
DragonFireGamesLvl 11
- Edited
The main issue with the vulnerability is that it allows projects to run scripts that can literally delete or edit projects in your account. I could make a project, that, when run, copies it's source code to all of your projects and then auto publishes them to the public gallery, propagating the worm across cdo wiping millions of projects.
Awards
- â’¸ 1 from
SquirrelGuy-5
Comment: woof
birthdayboy224Lvl 2
- Windows
DragonFireGames such power
- iPhone
If someone was good enough I’m sure that your inspect console blocker wouldn’t work against them.