YTMNDCNW: Javascript Exploit
Created on: June 3rd, 2006
YTMNDCNW: Javascript Exploit
zaz 
Backslashes in JavaScript strings need to be escaped. See http://forums.ytmnd.com/showthread.php?t=76534
hax

Sponsorships:

Vote metrics:

rating total votes favorites comments
(3.43) 210 6 99

View metrics:

today yesterday this week this month all time
0 2 0 1 4,514

Inbound links:

views url
44 https://www.bing.com
6 http://www.google.com.hk
2 https://www.google.com/
1 http://www.google.com
1 http://www.google.com/search?sourceid=navclient&ie=UTF-8&rlz=1T4

Add a comment

Please login or register to comment.
June 3rd, 2006
(0)
pop up!
June 3rd, 2006
(0)
how did you do the O RLY?
June 3rd, 2006
(0)
wtf?!
June 3rd, 2006
(0)
watttttttt
June 3rd, 2006
(0)
the code is in the preview, lol.
June 3rd, 2006
(0)
Wait... what just happened?!
June 3rd, 2006
(0)
OMG
June 3rd, 2006
(0)
But only because of the pop up thingie,
June 3rd, 2006
(0)
wow lol
(0)
Lol O rly. Eh, pretty cool
June 3rd, 2006
(0)
hax
June 3rd, 2006
(0)
mach-rider's right..but that's still awesome!
June 3rd, 2006
(0)
I have submitted a bug report on the forums. The hole should be easy to fix. It's tough to fully exploit because the comment lines have a length limit... I'm not sure redirect, for example, is possible. But popups and auto 5-ing are.
June 3rd, 2006
(0)
so what is the code? i can't see it :(
June 3rd, 2006
(0)
I won't give out the code, but it's pretty obvious if you look at the domain & the source of this page.
June 3rd, 2006
(0)
BTW, I did get redirect to work. You have to get the 3 lines to work together to implement longer code. Track this issue here: http://forums.ytmnd.com/showthread.php?t=76534
June 3rd, 2006
(0)
I figured it out!
(0)
i still haven't figured it out, 'cause i'm a total *ss =(
June 3rd, 2006
(0)
Could SOMEONE help by telling me the exact code?
June 3rd, 2006
(0)
5 for popups which i was in the vent during the discovery of. FTW.
June 3rd, 2006
(0)
ytmnd.com has several weaknesses.
June 3rd, 2006
(0)
AHHHHHH I HAVE A VIRUS
June 3rd, 2006
(0)
Pretty clever. He did it by exploiting the code for the 3d text thingy using this statement (I believe): ");alert('O RLY');//
June 3rd, 2006
(0)
Yes, this can be used for evil. My earlier Test Site auto-5'd itself when viewed. Max needs to fix this.
June 3rd, 2006
(0)
ugh, this is gonna suck. I hope the bug gets fixed before too many pop up sites come around
June 3rd, 2006
(0)
ooh, that is evil. Stop giving people ideas ;)
June 3rd, 2006
(0)
New fad! and I know how!
June 3rd, 2006
(0)
good work on finding the hole...your work is appreciated
June 3rd, 2006
(0)
Good job finding a bug, bad job telling 117000 people how to abuse it
June 3rd, 2006
(0)
See http://fourlines.ytmnd.com/ for fad ideas until this is fixed. :-) Popups are a lame fad.
June 3rd, 2006
(0)
I got it.
June 3rd, 2006
(0)
zaz, you did it again.
June 3rd, 2006
(0)
omg it made me auto-5!!! haxhaxhax!!!
June 3rd, 2006
(0)
Points for raising the bar.
June 3rd, 2006
(0)
Sorry, there's no auto-5 code on this site, and I deleted the test site that did it. I won't show people how to do that.
June 3rd, 2006
(0)
yeah it's this line: new Array("");alert('O RLY');//", "", ""); the double backslashes escape javascript code unlike vbscript which doesn't need it, although I prefer javascript to vbscript
June 3rd, 2006
(0)
n****r
June 3rd, 2006
(0)
lol
June 3rd, 2006
(0)
hey! who broke my internet?!
(0)
interesting
June 3rd, 2006
(0)
Again, remember, popups != picture/sound/text. Please see http://fourlines.ytmnd.com/ for good fad ideas. (For as long as this lasts... I want it fixed, along with DoctorGarbage deleted.)
June 3rd, 2006
(0)
Of course now every ytmnd is gonna have it. Great...
June 3rd, 2006
(0)
POP-UP!
June 3rd, 2006
(0)
silly js
June 3rd, 2006
(0)
Image/sound source?
June 3rd, 2006
(0)
GIS, and the Debussy song used in the UFO fad or whatever you call it.
June 3rd, 2006
(0)
:O Pretty fancy work and an issue that needs to be noticed the hard way: by being in the top rated YTMNDs. 5'd.
June 3rd, 2006
(0)
that cat scares me as does the fact that my vote may be abused!
June 3rd, 2006
(0)
i hope this gets fixed jsut because i dont know how to do it and others probably do
June 3rd, 2006
(0)
Anyone else get freaked out by that cat?
June 3rd, 2006
(0)
Yes, the cat is a bit spooky. :)
June 3rd, 2006
(0)
the music is familiar
June 3rd, 2006
(0)
huh? o rly?
June 3rd, 2006
(0)
Whats the source for this cat, I need to see more.
June 3rd, 2006
(0)
oh, sh*t, fixed
June 3rd, 2006
(0)
Fixed! :)
June 3rd, 2006
(0)
5 stars for max
June 3rd, 2006
(0)
It doesnt work anymore.. :(
June 3rd, 2006
(0)
FIVE BILLION STARS FOR TOMITA!!!!!! HOLY SHIIIIIIIIIIIIIIIIIT!
June 3rd, 2006
(0)
lol, fixed
June 3rd, 2006
(0)
lol max probably caught on to it..
June 3rd, 2006
(0)
doctor garbage deleted too?
June 3rd, 2006
(0)
well... I'll have to delete my site now that it's rendered useless.
June 3rd, 2006
(0)
onetf'd
June 3rd, 2006
(0)
Yeah, also someone please deleted doctor garbage. He Keeps spamming suicide video links.
June 3rd, 2006
(0)
Oops, still not fixed. :)
June 3rd, 2006
(0)
Hacks!
June 3rd, 2006
(0)
And no, DoctorGarbage appears to live on.
June 3rd, 2006
(0)
oh poop, you got it working again
June 3rd, 2006
(0)
I find the music peaceful
June 3rd, 2006
(0)
Four Lines is back in action as well with a slight change: http://fourlines.ytmnd.com
(0)
i do not know why but this has to be by far the scariest ytmnd i have ever seen and i will no longer be able to sleep at night untill the day i die because of it
June 3rd, 2006
(0)
NOW it's fixed. I think... let me check.
June 3rd, 2006
(0)
FranzGooseball: I'm glad you like it. :-) I was saving the cat for a rainy NEDM, but I like it this way too.
June 3rd, 2006
(0)
maaaaan.. fixed before I got home to see it in action. :(
June 4th, 2006
(0)
nice cat
June 7th, 2006
(0)
NEDM?
June 7th, 2006
(0)
Im not gonna lie....this is a bit creepy.
June 7th, 2006
(0)
...I also have no idea what this seems to really be about.
June 7th, 2006
(0)
:( I missed it before the fix.
June 8th, 2006
(0)
i have been dreaming of this cat lately, thank you for fulfilling my fantasy.
June 8th, 2006
(0)
.. no really, you changed my life with this image. i need to send you a personal cheque.
(0)
deserves top 15
June 8th, 2006
(0)
source of the sound?
June 8th, 2006
(0)
Jesus Christ...state your sources....and.........creepy Cat ;_;
June 8th, 2006
(0)
please for my sanity, release more info about this cat and sound.
June 8th, 2006
(0)
GIS, and the Debussy song used in the UFO fad or whatever you call it. oh, my bad.. you are still a genius.
June 8th, 2006
(0)
The song is "Arabesque #1" by Claude DeBussy and it might sound familiar to you if you ever saw the 5 minute long PBS astonomy show "Star Gazer" (aka "Star Hustler" back in the day...lol) Keep looking up!
June 8th, 2006
(0)
BTW, I checked the Star Gazer website and the song "Arabesque #1" is performed by Isao Tomita on the still available "Snowflakes Are Dancing" album.
June 9th, 2006
(0)
hey slayerkeith, you got an mp3 kicking around?
June 9th, 2006
(0)
The cat is a ballet dancer from a place where people are cats and cats dance the ballet.
June 10th, 2006
(0)
zaz: check out... original-1337.ytmnd.com only one image... the non short film version...
June 11th, 2006
(0)
Sorry hydrogenic, unfortunately I don't...
June 15th, 2006
(0)
F*cking Psycho Sh*t
July 3rd, 2006
(0)
Ok, I've seen you change your site title and read all the comments, but still.... The combination of the image and the sound is still f*cking psycho sh*t, lol
July 12th, 2006
(0)
;/
July 14th, 2006
(0)
Okay :)
July 22nd, 2006
(0)
ha, another well-deserved 1.
July 22nd, 2006
(0)
You're certainly putting a lot of work into this, archives. But you missed one.