0 Users appreciate this thread.
Users IP address leaked
SpriteMite (2016-03-28 16:03:02)Most of those users are the same users repeated over and over.
And it's the best to report this type of thing to an admin
2016-03-28 16:04:50
Your everyday boring person.
jdhs7 (2016-03-28 16:07:45)Yes, I realize the list is repeating but it is still an issue. And I posted it publicly for all the users to see and to realise that plaza is full of security issues.
Bean (2016-03-28 19:07:55)Sorry, but I had to remove that list for sharing personal information.
Unfortunately, Rob doesn't do anything with this site anymore so these shall remain. If we're lucky, he could notice this thread but I doubt it.
~~~
Please note that disclosing these sort of information publicly isn't a good idea, even if you intend to prove a point.
You're better off disclosing the vulnerability to Rob (the site owner) and later (after being resolved) publicly disclosing it here.
And yes, he still sorts out these sort of issues.
Security researcher, web developer, artist, and tech enthusiast.
jdhs7 (2016-03-28 22:09:23)Erman, a list of IP addresses is hardly pointless and a key part of doxxing somebody. Learn what you are talking about before you go to spouting useless bullcrap.
jdhs7 (2016-03-30 05:13:01)And I have now discovered even more user IP addresses along with other things. Security is truly shoddy here.
It's really not hard to get anyone's IP address from anywhere. You can get it by simply knowing someone's Skype username...it's the risk of using the internet to visit any site.
Still, someone would have to actually know what they're doing and where to look to find simply a list of user's IPs...you hadn't mentioned how you found the IPs, so I can assume it's not like they're completely out in the open and you innocently stumbled upon them.
If you're worried about getting doxed then get a proxy or try incognito.
Of course, it would be ideal if IPs were more private, but it isn't strictly a Plaza problem, just so you know.
Bean (2016-03-30 23:09:39)It may not be a strictly Plaza problem but it's still a massive problem.
Luckily, no one here previously has discovered this because the people who threatened to find IPs and all that were what you would call "script kiddies."
If anyone here could forward this thread to Rob, that would be great
~~~
^^^^ If you're using an SQL injection vulnerability to collect the IP addresses then you would've obtained all of those IPs in one go rather than being able to resume later on.
Also, Lani is right.
Whip out a packet sniffer like Wireshark and use a P2P application such as Skype or Omegle. You would be able to see the IP of the recipient on the other end.
Most web servers by default log your user agent and IP(s).
Want to get someone's IP? You can easily create a little script that can log their IP without their interaction.
If you want to attempt to become truely anonymous, use a proxy that doesn't hold your real IP in header(s) and really limit your browser when it comes to JavaScript and plug-ins like Java and Flash Player (being very restrictive with their settings, disabling them), (maybe) change your user agent, change your browser window size...
You're really going to end up barricading your browser and that has downfalls of its own.
Sure, IPs can be useful for things like locations and identifying the network used along with the information assigned to the IP. Like user agents and referers, the data is unreliable. They can be changed (even though the IP isn't necessarily arbitrary).
There's going to be risk of (D)Dos attacks, especially when you have at least one port opened. In that case, it's the responsibility of whoever owns the modem/router to manage and maintain what service(s) run under it.
Too Long; Did not Read! your real IP is not safe unless you really want to limit yourself.
UPDATE: Turns out to be some old ban log. This was deleted.
2016-04-03 22:23:58
Security researcher, web developer, artist, and tech enthusiast.
Just wanted to pop in.
If you could report the method of acquiring these to olivier [dot] the [dot] olive [at] gmail [dot] com, I may take a look at it. (PGP/GPG accepted, my public key can be found at pool.sks-keyservers.net if desired)
As for other matters, I believe that Skype is no longer a P2P application, though I'm not assuring anything.
Getting IP addresses is nothing serious (there are many ways to get these) but associating them with a user isn't *ideal* in some people's eyes.
SomeLuigi is changing in 2015.
Perfect_Chaos (2016-04-01 06:32:14)"Luckily, no one here previously has discovered this" this is like the third time this thread has been made.
This topic is closed, so you can not post a comment.
Back to forum: This Plaza
New registered users today: 7
Newest registered user: ElegantVulpes
[Removed]
That is just to name a few and is a perfect example of security through obscurity.
It literally turned into a 53 page PDF of nothing but usernames and and the corresponding IP address
2016-03-28 19:06:32