avram: (Default)
[personal profile] avram
If you see a post that just says:

this is very interesting.

...don’t click it! It’s an annoying and potentially dangerous hack that’ll hijack your browser post itself in your journal, and could be sending your password to someone nasty. I think it’s just a demonstration of a security hole, but avoid it anyway. Some discussion going on in [livejournal.com profile] lj_dev.

Oh, and if you did click it? Clear out your browser cache, delete your cookies, and come back to LJ and change your password.

Update: According to some discussion I’ve read, it doesn’t actually grab your password, so you may be safe if you just log out and back in, maybe clearing cookies first. I dunno. I changed my password, ’cause I was overdue for it anyway.

(no subject)

Date: 2004-06-12 06:35 pm (UTC)
From: [identity profile] stormsweeper.livejournal.com
If you turn off javascript you can go to the page and see how it works. It has a form in the page that is basically a copy of the update journal page, and uses javascript to submit it. The authentication is specified to be "cookie" based, so it doesn't even matter what you put in the first form field. It's viral, but not really harmful, unless it was modified to exploit some browser vulnerability.

The only lasting effect is they may be logging the value you submit and the IP you posted from, which again could be used for nefarious purposes if they were so inclined.

(no subject)

Date: 2004-06-13 08:11 pm (UTC)
From: [identity profile] mamishka.livejournal.com
How do you clear your cookies?

April 2017

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags