Unable to load image
Reported by:

[metadrama] Username/IP Leak

Hi guys, as you all might know I'm a !codecel. Recently I discovered a vulnerability in the site, which from what I can tell has existed for a while. In exchange for the countless hours of work I put into combing through the code and testing exploits, I'd like a little sum sum from @A (not monetary, just stupid shit/basic respect, see below) but he does not seem interested in cooperating with me.

Among the options presented to @A he had were reinstating HeyMoon or calling me on groomercord/snapchat, both of which he denied without explanation. I'm happy to help him out with his (arguably transphobic) website, but I'm not going to just spoonfeed him code while he gives me the cold shoulder. I would like to mention that HeyMoon (@CarpathianMoon) had utterly no knowledge or consent or anything to do with this, I just recently heard about the drama and thought that it's something nice that I could do as, from what I have heard, HeyMoon was unjustly removed.

For your information: I am NOT going to give this info out to anyone or use it nefariously. I INTEND to do good for the website; I have not stolen any IPs or anything, but I have verified that the exploit works and would give an attacker that ability. I would best describe my alignment as "Chaotic Good". I'm not intending to hold this over anyone or anything; I will NEVER release the exploit unless given explicit permission from @A after it's patched. But I would like to use my small bit of leverage that I've stumbled upon to improve the site, further my own (innocuous) goals, and maybe take @A down a peg.

Please note that an IP/username leak isn't the worst in the world either. Worst case scenario, people figure out what city you live in and your ISP. Note that large institutions might be their own ISP, so people might, by extension, be able to figure out where you work. (Of course, law enforcement would be able to find you too). But otherwise it's not that bad. If you are super concerned about this, you should be using TOR or a VPN anyways, as any website on the internet can see your IP. The real kicker here is that this exploit allows you to connect a username to an IP, which is perhaps a bit more information than many would be willing to give out.

TL;DR: There is an IP leak exploit. I would like to work with @A to remedy this on my own terms, but he is refusing. Use a VPN if you care, or don't idgaf.

THIS IS MY GIRLBOSS ARC.

72
Jump in the discussion.

No email address required.

Prove it by posting my IP, I give consent or whatever

Jump in the discussion.

No email address required.

109.148.188.174

United Kingdom, Kettering

Firefox (116.0)

Windows 10

Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/116.0

host109-148-188-174.range109-148.btcentralplus.com

British Telecommunications PLC

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/16940531560758302.webp

God darn she's right

Jump in the discussion.

No email address required.

Can't they execute you there for posting current meta soyjacks?

Jump in the discussion.

No email address required.

Local britbong chud posts sharty jacks -- JAILED for hate speech. Many such cases!

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

GEM

Jump in the discussion.

No email address required.

LMAO is this actually correct?

If so I kneel

:marsey#kingcrown: :m#arseykneel:

(pls dont doxx me queen)

Jump in the discussion.

No email address required.

:marsey#agree:

Jump in the discussion.

No email address required.

Pls don't compare revealing your city to doxxing, it's not even close.

Jump in the discussion.

No email address required.

>it's not even close

Assuming the average city-region contains 2 million people, this is already around 12 bits of entropy of the 33 you need. You get another bit for the poster being male, and I suppose around 4 for the likely age group of our userbase, so only 16 to go. So you need to filter out half of the remaining population only 16 times in a row to find the person.

Add username, linked reddit accounts, leaked info about hobbies, job, interests, married/incel status, and it becomes plausible that you can filter out enough people to hone in a very small set of plausible people that an account might belong too.

Jump in the discussion.

No email address required.

If they had revealed some much about themselves, then it wasn't the IP that doxxed them.

It's not like it matters anyway, why would somebody come to your house if you're not a giga power user. Neighbors afraid of the doxx think way too highly of themselves.

Jump in the discussion.

No email address required.

If you live in the US, you can't be blackmailed with your account. In europe, you would at least face social repercussions.

I agree that if the user leaks tons of information, country + maybe city is already in the open. IP just makes it easier to find.

Jump in the discussion.

No email address required.

Prove it

Jump in the discussion.

No email address required.

>Prove it

https://i.rdrama.net/images/16940594098758018.webp

Jump in the discussion.

No email address required.

Call your IP and say the password

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/16940612037957392.webp

Jump in the discussion.

No email address required.

:#marseyfedpostglow:

Jump in the discussion.

No email address required.

:marseyv#eryworried:


:!marseybooba:

Jump in the discussion.

No email address required.

:marseybong: EW

Jump in the discussion.

No email address required.

Post mine

Jump in the discussion.

No email address required.

too many people are asking and i got other stuff to do. but i did it with multiple ppl already in this thread. im doing it manually rn bc i havent written any kind of script to harvest them or anything

Jump in the discussion.

No email address required.

All good, I'm using a mobile network atm.

It's 108.147.102.32 , in case you maybe wanted to verify further or something. doesn't matter much since some r-slur keeps getting us banned from 4cuck for posting racism on /k/

Jump in the discussion.

No email address required.

do me do me do me do me do me

Jump in the discussion.

No email address required.

192.168.0.1

Jump in the discussion.

No email address required.

when the frick did you get access to my router you creep

Jump in the discussion.

No email address required.

programmer socks

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

69.80.08.69

Jump in the discussion.

No email address required.

She's right

https://i.rdrama.net/images/16940526742854366.webp

Jump in the discussion.

No email address required.

Ooo ooo do me next do me next

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.