avram: (Default)
[personal profile] avram
If you see a post that just says:

this is very interesting.

...don’t click it! It’s an annoying and potentially dangerous hack that’ll hijack your browser post itself in your journal, and could be sending your password to someone nasty. I think it’s just a demonstration of a security hole, but avoid it anyway. Some discussion going on in [livejournal.com profile] lj_dev.

Oh, and if you did click it? Clear out your browser cache, delete your cookies, and come back to LJ and change your password.

Update: According to some discussion I’ve read, it doesn’t actually grab your password, so you may be safe if you just log out and back in, maybe clearing cookies first. I dunno. I changed my password, ’cause I was overdue for it anyway.

(no subject)

Date: 2004-06-12 06:35 pm (UTC)
From: [identity profile] stormsweeper.livejournal.com
If you turn off javascript you can go to the page and see how it works. It has a form in the page that is basically a copy of the update journal page, and uses javascript to submit it. The authentication is specified to be "cookie" based, so it doesn't even matter what you put in the first form field. It's viral, but not really harmful, unless it was modified to exploit some browser vulnerability.

The only lasting effect is they may be logging the value you submit and the IP you posted from, which again could be used for nefarious purposes if they were so inclined.

(no subject)

Date: 2004-06-13 08:11 pm (UTC)
From: [identity profile] mamishka.livejournal.com
How do you clear your cookies?

March 2026

S M T W T F S
1234567
891011121314
15161718192021
22232425262728
293031    

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags