TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Imgur Vulnerability Patched

13 点作者 mukyu超过 9 年前

2 条评论

sktrdie超过 9 年前
What could the hacker accomplish even if they were able to execute some code? They're still in a browser tab and you can only do limited things. My thinking is that if the code was somewhat executed on 4chan, they could inject a <script> tag on the page that sends the cookie information you have on 4chan (which might include your session id) so others can login with your account. However, Reddit doesn't load images on their site directly so this type of attack would not be possible.
sepharoth213超过 9 年前
For context: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;4chan&#x2F;comments&#x2F;3lutoo&#x2F;imgur_is_doing_fishy_things_with_4chan_screencaps&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;4chan&#x2F;comments&#x2F;3lutoo&#x2F;imgur_is_doin...</a>