Post Reply XSS when visiting a thread
15180 cr points
Send Message: Send PM GB Post
☆Land of sweets☆
Online
Posted 2/7/18 , edited 2/8/18
this is the thread in question: http://www.crunchyroll.com/forumtopic-1000823/best-manga-art
(link not made active for obvious reasons)


trying to visit the 1st page, and it gives me this pop up, asking for an id and password.
i don't trust the pop-up window (even the X), so i just force-close firefox.
(pop up appears to be from a pirate source)
Otter Modder
53216 cr points
Send Message: Send PM GB Post
25 / M / Florida
Offline
Posted 2/8/18 , edited 2/8/18
This looks to just be a case of trying to hot link to an image that is behind an auth wall. Because of the way browsers handle third-party hosted images and such, that website is just trying to prompt you to log in to access non-public content. That user has already edited their post to be a link instead of an embedded image so it shouldn't be a problem anymore.
Der Zoodirektor
27067 cr points
Send Message: Send PM GB Post
36 / M / Germany
Offline
Posted 2/8/18 , edited 2/8/18

beardfist wrote:

This looks to just be a case of trying to hot link to an image that is behind an auth wall. Because of the way browsers handle third-party hosted images and such, that website is just trying to prompt you to log in to access non-public content. That user has already edited their post to be a link instead of an embedded image so it shouldn't be a problem anymore.


No, it was me who edited it to be a link.
15180 cr points
Send Message: Send PM GB Post
☆Land of sweets☆
Online
Posted 2/8/18 , edited 2/8/18
ah, so it wasn't anything malicious, good to know.
the issue has been fixed. thank you.
You must be logged in to post.