<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://www.spyroforum.com/extern.php?action=feed&amp;tid=6084&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Spyro the Dragon Forums / Possible exploit found in Spyrochat]]></title>
		<link>https://www.spyroforum.com/viewtopic.php?id=6084</link>
		<description><![CDATA[The most recent posts in Possible exploit found in Spyrochat.]]></description>
		<lastBuildDate>Sun, 27 Jul 2008 00:17:34 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=180148#p180148</link>
			<description><![CDATA[<p>This is best to be locked now as well yeah I have no reason for a change &lt;_&gt;</p>]]></description>
			<author><![CDATA[dummy@example.com (DanteAndVergil)]]></author>
			<pubDate>Sun, 27 Jul 2008 00:17:34 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=180148#p180148</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=180146#p180146</link>
			<description><![CDATA[<p>How the heck did you ever think this was a fight? Don&#039;t dig up old threads.</p>]]></description>
			<author><![CDATA[dummy@example.com (Spyrorocks)]]></author>
			<pubDate>Sun, 27 Jul 2008 00:17:08 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=180146#p180146</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=180145#p180145</link>
			<description><![CDATA[<div class="quotebox"><cite>Hail The Ice Dragon wrote:</cite><blockquote><div><p>&gt;_&lt; Sounds like a fight... *puts on whistle and black pants with striped shirt* Round 1! Doppel V.S. SR</p></div></blockquote></div><p>Um, this thread is from nine days ago...=S</p>]]></description>
			<author><![CDATA[dummy@example.com (Aicebo)]]></author>
			<pubDate>Sun, 27 Jul 2008 00:16:26 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=180145#p180145</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=180142#p180142</link>
			<description><![CDATA[<p>&gt;_&lt; Sounds like a fight... *puts on whistle and black pants with striped shirt* Round 1! Doppel V.S. SR</p>]]></description>
			<author><![CDATA[dummy@example.com (Hail The Ice Dragon)]]></author>
			<pubDate>Sun, 27 Jul 2008 00:09:50 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=180142#p180142</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=173944#p173944</link>
			<description><![CDATA[<p>I&#039;m going to take a try on doing VPNs.</p>]]></description>
			<author><![CDATA[dummy@example.com (Doppelgangergang)]]></author>
			<pubDate>Thu, 17 Jul 2008 17:39:12 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=173944#p173944</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=173939#p173939</link>
			<description><![CDATA[<p>Say Hello to my VPN server.</p>]]></description>
			<author><![CDATA[dummy@example.com (Spyrorocks)]]></author>
			<pubDate>Thu, 17 Jul 2008 17:32:33 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=173939#p173939</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=173932#p173932</link>
			<description><![CDATA[<p>No, it&#039;s just a &quot;what-if&quot; scenario for example. <img src="https://www.spyroforum.com/img/smilies/tongue.png" width="15" height="auto" alt="tongue" /></p><p>Also, do school/work administrators can log URLs the students/employees go to? I think they can. <img src="https://www.spyroforum.com/img/smilies/neutral.png" width="15" height="auto" alt="neutral" /></p><p>(But say hello to my SSL home proxy. :devil:)</p>]]></description>
			<author><![CDATA[dummy@example.com (Doppelgangergang)]]></author>
			<pubDate>Thu, 17 Jul 2008 17:24:18 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=173932#p173932</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=173916#p173916</link>
			<description><![CDATA[<p>And doppel, you CANNOT sniff the communications from other people logging in UNLESS they are on the same LAN as you. Its all SERVER side, none of other people&#039;s login info passes through your router. It goes from their PC to the Spyroforum Server, where they are authenticated and get a session id unique to them.</p><p>I don&#039;t know where you came up with this crazy stuff about you being able to log other members over the internet.</p>]]></description>
			<author><![CDATA[dummy@example.com (Spyrorocks)]]></author>
			<pubDate>Thu, 17 Jul 2008 17:07:29 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=173916#p173916</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=173697#p173697</link>
			<description><![CDATA[<p>Oh dear that is bad...</p>]]></description>
			<author><![CDATA[dummy@example.com (cynderfan)]]></author>
			<pubDate>Thu, 17 Jul 2008 08:29:48 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=173697#p173697</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=172604#p172604</link>
			<description><![CDATA[<p>Communications from the SF server to everyone else are unencrypted.</p><p>If someone is sniffing your wireless, they can possibly capture your spyroforum password as you login, or any other password for any site that you visit that has unencrypted communications.</p><p>Its really not a big deal. If you are paranoid, get an anonymous VPN. Your spyroforum/spyrochat account is not useful to anyone who is looking for passwords, as they want banking info for credit cards, not a forum account to chat about a purple dragon.</p><br /><p>As for impersonation, thats just how IRC works. You can change your nick to anything, unless you use this command in the chat to register your nickname:</p><div class="quotebox"><blockquote><div><p>/ns register &lt;password&gt; &lt;your email&gt;</p></div></blockquote></div><p>To register your nickname so others cannot use it. BUT, if you do that, you will need to type this in every time you login:</p><div class="quotebox"><blockquote><div><p>/ns identify &lt;password&gt;</p></div></blockquote></div>]]></description>
			<author><![CDATA[dummy@example.com (Spyrorocks)]]></author>
			<pubDate>Tue, 15 Jul 2008 21:41:55 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=172604#p172604</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=172298#p172298</link>
			<description><![CDATA[<p>Also, I have demonstrated that I can impersonate people.</p><p>I can use a program and punch in &quot;DragonFireOKN&quot; and I can chat under your name.</p><p>Change your passwords regularly.</p>]]></description>
			<author><![CDATA[dummy@example.com (Doppelgangergang)]]></author>
			<pubDate>Tue, 15 Jul 2008 16:49:08 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=172298#p172298</guid>
		</item>
		<item>
			<title><![CDATA[Re: Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=172241#p172241</link>
			<description><![CDATA[<p>I&#039;ve noticed this ever since I got on the site. Since you could have seen our passwords, something needs to be done.</p>]]></description>
			<author><![CDATA[dummy@example.com (DragonFireOKN)]]></author>
			<pubDate>Tue, 15 Jul 2008 15:43:12 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=172241#p172241</guid>
		</item>
		<item>
			<title><![CDATA[Possible exploit found in Spyrochat]]></title>
			<link>https://www.spyroforum.com/viewtopic.php?pid=172091#p172091</link>
			<description><![CDATA[<p>I noticed that the SpyroChat sends usernames and passwords in URLs. With the right stuff (I don&#039;t wanna go to details) I logged every URL I go to, including this:</p><div class="codebox"><pre><code>http://www.spyrochat.com/index.php?rand=748745461&amp;su=Doppelgangergang&amp;pw=&lt;REMOVED&gt;&amp;</code></pre></div><p>That&#039;s the actual URL, minus my password of course. Seriously, if I am running a network and applied my magic on a router, I would have captured your logins when you go on my network and went on Spyrochat.</p><p>What do you think?</p><p>EDIT: I can also see it on my History.</p>]]></description>
			<author><![CDATA[dummy@example.com (Doppelgangergang)]]></author>
			<pubDate>Tue, 15 Jul 2008 05:07:11 +0000</pubDate>
			<guid>https://www.spyroforum.com/viewtopic.php?pid=172091#p172091</guid>
		</item>
	</channel>
</rss>
