2
[metadrama] Username/IP Leak
rdrama.netHi guys, as you all might know I'm a !codecel. Recently I discovered a vulnerability in the site, which from what I can tell has existed for a while. In exchange for the countless hours of work I put into combing through the code and testing exploits, I'd like a little sum sum from @A (not monetary, just stupid shit/basic respect, see below) but he does not seem interested in cooperating with me.
Among the options presented to @A he had were reinstating HeyMoon or calling me on groomercord/snapchat, both of which he denied without explanation. I'm happy to help him out with his (arguably transphobic) website, but I'm not going to just spoonfeed him code while he gives me the cold shoulder. I would like to mention that HeyMoon (@CarpathianMoon) had utterly no knowledge or consent or anything to do with this, I just recently heard about the drama and thought that it's something nice that I could do as, from what I have heard, HeyMoon was unjustly removed.
For your information: I am NOT going to give this info out to anyone or use it nefariously. I INTEND to do good for the website; I have not stolen any IPs or anything, but I have verified that the exploit works and would give an attacker that ability. I would best describe my alignment as "Chaotic Good". I'm not intending to hold this over anyone or anything; I will NEVER release the exploit unless given explicit permission from @A after it's patched. But I would like to use my small bit of leverage that I've stumbled upon to improve the site, further my own (innocuous) goals, and maybe take @A down a peg.
Please note that an IP/username leak isn't the worst in the world either. Worst case scenario, people figure out what city you live in and your ISP. Note that large institutions might be their own ISP, so people might, by extension, be able to figure out where you work. (Of course, law enforcement would be able to find you too). But otherwise it's not that bad. If you are super concerned about this, you should be using TOR or a VPN anyways, as any website on the internet can see your IP. The real kicker here is that this exploit allows you to connect a username to an IP, which is perhaps a bit more information than many would be willing to give out.
### TL;DR: There is an IP leak exploit. I would like to work with @A to remedy this on my own terms, but he is refusing. Use a VPN if you care, or don't idgaf.
## THIS IS MY GIRLBOSS ARC.
You must log in or register to comment.