XSS hole closed, sorry for the trouble
June 29, 2008 by JTV Staff

There was an XSS hole (we forgot to sanitize one of our fields properly), and as a result some accounts were compromised. I’ve closed the hole, removed the infected data, and changed all the cookies. We hash your password, so don’t worry, not even we know what your password actually is.

I’ll be taking another look through our codebase now to see if there are any other fields we might have missed.

Filed under:   The Info
7 Comments
paul said:

O MY!!!!!!

June 29, 2008 at 4:55 pm.
William said:

What about the myspace and facebook passwords that JTV asks for to get the profile complete badge? Were they compromised while thedefaced.org’s iframe was chillin on jtv? This is huge and i hope that you can tell me they weren’t.

I <3 JTV (no homo)

June 30, 2008 at 3:40 pm.
Emmett said:

We don’t keep those passwords ourselves, so don’t worry – no one can get them, even if they guess your JTV password or we get hacked.

June 30, 2008 at 5:34 pm.
MrFloris said:

What a shame that this happened, some accounts involved were: honestguy, tia_marie, krystyl, myself, laggie, chinny, magicrich, thecoop, ..

July 1, 2008 at 2:23 pm.
MrFloris said:

I talked to jtv/mikeyy today and he also reported a few security issues to jtv, they seem to be fixed now. If your account got exploited your about me will say ‘i love mikeyy’. Mikeyy says unlike the others, he doesn’t compromise any account data.

July 1, 2008 at 3:48 pm.
HG said:
July 2, 2008 at 11:28 am.
red said:
October 3, 2008 at 3:54 am.

You must be logged in to post a comment.