Rook to XSS: How I hacked chess.com with a rookie exploit
skii.dev
skii.dev
Also: stop calling it meta everyone. Don't let them get away with such a poor away to hide their past & also claim a powerful word like that.
What would you recommend OP applies for?
What are the pros and cons of the option that you suggest vs. the alternative?
As for the evilness, i will not argue. Everyone is entitled to their opinions.
For the OP in question, Facebook will provide the best career launch pad, so i will continue to suggest that. I have been to Google and Facebook, so can compare the two.
Carry on. OP, definitely cut your teeth in a place like that!
Everywhere else afterward will likely feel like a vacation, in comparison.
Same reason I referred very little number of people if any in the past.
Edit: oh, is this degree apprentice thing a UK thing I'm not familiar with?
https://thehustle.co/how-one-17-year-old-coded-a-number-one-...
I'd be very happy to talk more about this w/ you - email in my desc.
.. And if you go into IT learn about contract negotiations and finances
Eric (founder) had politely asked me for a more formal audit (to which I declined, not wanting to out myself as an 11 year old script kiddie) but I did explain the RegExp needed for the chat room censor and we tackled the ultimate problem; how to detect cheaters in asynchronous environments.
After consideration I informed him the only way to possibly detect cheaters is to compare every (game-significant/high-mu) move made against the known optimal moves from engines, and use statistical inference to discriminate good humans from cheaters.
Of course, at the time, this was laughably unfeasible - which was the answer we had concluded on. But for a barely out of elementary kid to discuss those kinda nuances with a legit webmaster (Hello Eric!), it is one of my more favorable internet memories.
why would this be the only way? I can think of many different things you can do to detect cheaters
Response time and strength consistency could be detected regardless of having another computer.
If a person is always playing fast moves, or playing very consistently or very inconsistently good moves, they could be detected.
- Response time
- Strength consistency within current game
- Strength consistency across all of user's games
- Is user switching windows
I bet these are already integrated in current cheat detection.
Back then the document object in javascript were way to powerful because everyone was so naive.
Internet Explorer knew/could easily infer its absolute coordinates from the origin on the desktop, would gladly serve the majority of your C: drive to any website that asked nicely enough, and a plethora of now-incredulous things.
It was possible to know if you had moved the window by dragging or by Cascade windows, had another window (this was before tabs were invented) that was being referenced nearly every turn, or even if the user had referenced an application from the Start Menu.
That was all the stuff that "wasn't" supposed to be done. The obvious, yet cat-and-mouse tricks, such as mouse/keyboard jitter, fingerprinting profiles, style/chat stylelemoetry, behavior meta-game analysis, were in their relative infancy, but were making strides.
Well damn, I get older every day
<scr<script>ipt>For the implementation all the real HTML tags should be generated by the formatter and not originate from the original input. When formarring the valid tags get deleted from the input and everything else is properly HTML escaped.
As a primitive example imagine that the only HTML tags the formatter is able to output is <b> and </b> tags alongside HTML escaped text. That means it will be impossible for a script tag to ever be outputed by the formatter.
There are plenty of threads about this too if you Google it. No idea if chess.com have fixed this in the last few months, but they didn't want to listen when I tried to report it.
All these games were when I was not logged into the site. It's never happened to me whilst logged in, but I don't play chess that often as it's no good for my blood pressure!
Author knows their stuff. I admire how much dedication that kind of craft takes. Spending so much time to get further along. Would make for an interesting career.
I instantly felt old.
My question to OP about this event: how did you learn about this? Darknet Diaries, or via something else?
I am old enough to have a fuzzy memory of it happening at the time, but here is the podcast with Samy that cemented it in my brain:
Hardly in the spirit of a bug-bountry program.
[0] https://github.com/daffainfo/AllAboutBugBounty/blob/master/O...
Typically same origin policies are relaxed for things like images by default [0]. So they came up with a trampoline, they created a chess.com.theirDomain.tld to get past the re-upload filter, which in turn returned a redirect, which the browser followed.
[0] https://developer.mozilla.org/en-US/docs/Web/Security/Same-o...
Google did not like me setting up a chess.com subdomain, and a couple of weeks later, my domain got flagged for "phishing." - I had to contact them to explain and manually remove it as it affected my whole domain.
What? Google’s domain registrar will close your account if you have a subdomain which just happens to be named another website?I learned that because, at work, I architected a system for serving certain assets for customer sites at a subdomain off a shared root domain, keyed by their full domain (like example.com.example.org—where example.com is the customer’s site domain). We ended up changing to example-com.example.org which is far better anyways since this feature started breaking stuff once it rolled out.
But this is a Chrome feature and should not affect your rankings themselves. But couldn’t hurt to take it down just in case.
Goddammit young people :D
Why isn’t the PHPSESSID cookie HttpOnly?
And why if the XSS was already known had they not fixed it?!
Not marking the cookie httpOnly ironically doesn't surprise me.
TLDR: if you aren't going to look up the very basics of security just use a trusted library
The best I’ve found.
It’s also crowd funded and they talk about their interest tech as well.
It’s also impossible to discuss anything related to chess.com on here or Reddit because lichess people tend to downvote and brigade anyone who doesn’t praise it.
The free and (to me) intuitive analysis tools on Lichess are the killer feature for me.
I wonder if the peaceful co-existence of lichess and chess.com co-existing somehow disturbs some esoteric ideology.
I don't hate lichess but I hardly see chesscom as evil.
The streamers will be fine. Eric Rosen is one steamer who refuses to sell out to chess.com. Chess.com is beginner friendly but not fee, doesn't even let you analyse your games properly without a subscription.
I do see harm in it, considering their competitor is a non-profit which has done great things for the chess community. Including open sourcing many things like icons and webassembly chess engines.
Combine that with their competitor being a non-profit organization which has created numerous open source[1] chess tools like engines, icons and boards and I would call them pretty harmful.
> In a nutshell, Chess.com is sponsoring me to continue making my free YouTube/Twitch content, but playing on their site.
Apparently, some people thought Chess.com was trying to paywall chess streaming content. Strange
Personally never had issues with people rejecting games on lichess.com. But lichess is a non-profit that has done great things for the world of chess and open source and open source chess. You'll find almost all better players there, with the exception of those who are payed by chess.com to only play on their platform. Part of the reason is that chess.com has some latency issues.
It's hard not to like lichess, considering their competitor needs to pay dozens of twitch streamers to stay on top, and require you to pay for a subscription just to have a decent game analysis.
As well as communism.
> Maker of lichess.org, a hippie communist chess server for drug fueled atheists.
Do hippies frighten you because they represent a more egalitarian and prosperous ideology than your narrow minded brain can conceive of?
Do communists make you quake in your boots because you don't believe you could get on in a society where you might not be able to solve all of your problems with money? indeed, imagine if you might have to rely upon people liking you; I also fear for your ability to get on.
Is it the "drug fueled" portion, because you perhaps feel some right to tell other consenting adults (whom probably know much better about their bodies and their own lives than you do about yours) what to do on their spare time?
Or are you waking up to the fact that we, as a society, are becoming more secular[0], and thus you see the advance of atheism as an attack against the institution of your personal sky daddy?
And these are all reasonable things to think of you, since you only wave vaguely at a collection of adjectives while expressing some nebulous form of disdain. Perhaps either clarify the nature of your disagreement, or continue to persist in the shadow of intellectual doubt and fear you appear to be laboring under... which is a disease very common to people who appear to believe as you do.
[0] https://web.archive.org/web/20240123000719/https://www.nytim...