Tarsnap email confirmation bypass
daemonology.net
Tarsnap email confirmation bypass
1–10 of 51 posts
Re: Tarsnap email confirmation bypass
#2a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code.
also, there is no bug bounties for the tarsnap website, only for tarsnap code.
Re: Tarsnap email confirmation bypass
#3tl;dr a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. also, there is no bug bounties for the tarsnap website, only for tarsnap code.
That's a decent summary, but I didn't think I was all that long-winded...
Re: Tarsnap email confirmation bypass
#4tl;dr a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. also, there is no bug bounties for the tarsnap website, only for tarsnap code.
a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. That's a decent summary, but I didn't think I was all that long-winded...
Re: Tarsnap email confirmation bypass
#5Re: Tarsnap email confirmation bypass
#6tl;dr a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. also, there is no bug bounties for the tarsnap website, only for tarsnap code.
a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. That's a decent summary, but I didn't think I was all that long-winded...
Re: Tarsnap email confirmation bypass
#7Never "hide" sensitive data in those hidden input fields.
Re: Tarsnap email confirmation bypass
#8Re: Tarsnap email confirmation bypass
#9Earlier quoted context omitted.
a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. That's a decent summary, but I didn't think I was all that long-winded...
Oh it really is just a summary, and no commentary as to whether TFA was long-winded or not. That's left to decide for each individually.
Re: Tarsnap email confirmation bypass
#10The value of writing comments intended for your future self was confirmed in a strange way for me: I once found myself googling some faintly obscure question of systems programming, and soon found an article that answered my question perfectly. At that point I noticed with considerable surprise that I was reading a web archive of a Usenet posting I had made myself, some 10 years prior - of all the people to randomly…