blizzard.com XSS - fixed within a day menu
100% Up to 1000$
4.9/5
150% Up to 200$ & 20 Freespins
4.8/5
Up to 1 BTC
4.9/5
20% Cashback
4.8/5
Up to 5 BTC
4.8/5
100% Up to 1 BTC
4.7/5
Up to 5 BTC
4.7/5
110% Up to 1 BTC
4.6/5

User Tag List

Page 1 of 3 123 LastLast
Results 1 to 15 of 36
  1. #1
    reduction's Avatar Member
    Reputation
    19
    Join Date
    Jan 2009
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    blizzard.com XSS - fixed within a day

    blizzard.com XSS - fixed within a day
    This was the XSS:
    https://www.blizzard.com/login/logout.xml?referer=http://www.worldofwarcraft.com/%22;alert(%27xss%27);function%20setTimeout()%20{}//&loginType=wow

    Blizzard seems to have fixed it within a day of me posting it. They obviously monitor these forums. Anyone have an idea of how I can share future discoveries like this more discreetly?
    Last edited by reduction; 03-05-2009 at 09:14 PM.

    blizzard.com XSS - fixed within a day
  2. #2
    cloudafloat's Avatar Member
    Reputation
    10
    Join Date
    Jan 2009
    Posts
    36
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Did it just stop working cause it wont work for me anymore.


    Edit: lol fixed in a day.
    Last edited by cloudafloat; 03-05-2009 at 10:34 PM.

  3. #3
    Liquid Malfunction's Avatar Banned
    Reputation
    53
    Join Date
    Sep 2008
    Posts
    521
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    donate and post in the contrib/donar section

  4. #4
    hellojoe's Avatar Member
    Reputation
    2
    Join Date
    Mar 2007
    Posts
    93
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    What was the link?

  5. #5
    Stimorol's Avatar Member
    Reputation
    6
    Join Date
    Jul 2008
    Posts
    19
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by reduction View Post
    This was the XSS:
    https://www.blizzard.com/login/logout.xml?referer=http://www.worldofwarcraft.com/%22;alert(%27xss%27);function%20setTimeout()%20{}//&loginType=wow

    Blizzard seems to have fixed it within a day of me posting it. They obviously monitor these forums. Anyone have an idea of how I can share future discoveries like this more discreetly?
    You know you could have made alot of muney selling that on blackchat forums right? Most likeley 1k- 10k $

  6. #6
    wowpew's Avatar Active Member
    Reputation
    27
    Join Date
    Jul 2006
    Posts
    121
    Thanks G/R
    0/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    And since Blizz fixed this, they are probably monitoring it. So now they know who you all are

  7. #7
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    They don't have to monitor MMOwned to find their vulnerabilities. Trust me, as soon as anyone have exploited it, they'll be 5 minute from the fix no matter what.

  8. #8
    Iraq's Avatar Contributor
    Reputation
    128
    Join Date
    Sep 2008
    Posts
    534
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Y R U A NUB ? View Post
    They don't have to monitor MMOwned to find their vulnerabilities. Trust me, as soon as anyone have exploited it, they'll be 5 minute from the fix no matter what.
    your ignorance amazes me, stop nut hugging blizzard, they are not gods.

    there are many exploits which blizzard has no knowledge of, and if they did, the exploiters would have been facing some hard jail time.

  9. #9
    Y R U A NUB ?'s Avatar Banned
    Reputation
    103
    Join Date
    Nov 2007
    Posts
    436
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by nod43 View Post
    your ignorance amazes me, stop nut hugging blizzard, they are not gods.

    there are many exploits which blizzard has no knowledge of, and if they did, the exploiters would have been facing some hard jail time.
    Oh, yeah, Blizzard would definitely browse MMOwned every day to look for the newest 1337 hacks. /sarcasm

    I don't "hug nuts", I'm telling my opinions, capish? You shut your mouth.

  10. #10
    TunakTun's Avatar Member
    Reputation
    5
    Join Date
    Dec 2008
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Y R U A NUB ? View Post
    Oh, yeah, Blizzard would definitely browse MMOwned every day to look for the newest 1337 hacks. /sarcasm

    I don't "hug nuts", I'm telling my opinions, capish? You shut your mouth.
    Someone ban this troll please, every single post he has made is completely negative, ignoring all of the forums rules.

  11. #11
    ZombieSnail's Avatar Active Member
    Reputation
    15
    Join Date
    Sep 2008
    Posts
    23
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Sorry but what can you do with a Blizzard XSS? Just wondering what it is?

  12. #12
    blackfang500's Avatar Member
    Reputation
    35
    Join Date
    Apr 2007
    Posts
    491
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    What if a blizzard employee was a contributor or they donated (More likely)?

  13. #13
    Remus's Avatar Banned

    Reputation
    402
    Join Date
    Nov 2007
    Posts
    1,697
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    oh look another place to pounce on ya nub.. all you have done is troll and it is starting to obviously get on other peoples nerves.

    you call me a child yet i am 20 years old. you call me a what was it .. oh yes, "brat" .. for someone to call me that you would have to be atleast 50 years old..

    so "dad" your ignorance has been noted. yes they watch these forums, no they dont fix everything.. hell it was a year and counting before they finally did something about account theft en mass and even changed their site layout to stop some phishers

    not to mention there are people who browse here and report it to blizzard, had to ban a few, that much i know.

    take your opinions elsewhere, we dont want them you negative nancy.

  14. #14
    hellojoe's Avatar Member
    Reputation
    2
    Join Date
    Mar 2007
    Posts
    93
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Can someone explain what this Blizzard.com XSS is?

  15. #15
    Obama's Avatar Legendary
    Reputation
    721
    Join Date
    Dec 2006
    Posts
    2,321
    Thanks G/R
    2/7
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If you think it is genuinely good. Then give it to a high ranked user such as myself and I will post it in a higher section and direct all rep to be given to you.

    Donator 6/2008.
    Contrib 8/2008.Elite 10/2008.Newsteam 11/2008.Legendary 2/2009.

Page 1 of 3 123 LastLast
All times are GMT -5. The time now is 08:40 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search