
Wed 10 Mar 2004: Two members of the Gay Nigger Association of America (a prominent Slashdot troll group) have discovered two bugs in Radio UserLand that allow any class of people, ranging from homosexual African Americans to capitalist pigs, to exploit the poor input validation of the software.
The first bug, found by gay nigger goat-see, works only when an attacker is the first person to comment on a blog entry. Input validation is not performed on the link= attribute of the request, and a page is built containing the unescaped content of the link= variable.
Two proofs of concept (injected Javascript content causing a page redirect) are located in these two URLs.
http://rcs.salon.com/rcsComments/comments?u=2438&p=17&link=http%3A%2F%2Fblogs.salon.com%2F0002438%2F2003%2F10%2F16.html%23a17
http://rcs.salon.com/rcsComments/comments?u=2438&p=16&link=http%3A%2F%2Fblogs.salon.com%2F0002438%2F2003%2F09%2F17.html%23a16
Note that the contents of these links may be offensive to some! If you find that content offensive, do not view the link!
If you are the first commenter, then a URL of the following fashion will allow your injection:
http://radiosite/comments?u=UID&p=POSTID&link=%22%3EYOURESCAPEDCODEHERE
Also, another respected gay nigger, Lysol, discovered poor input validation on the post ID variable while confirming goat-see's reported vulnerability. The same technique may be used to post comments on entries that do not yet exist. Lysol commented: "It is the responsibility of programmers to ensure that applications are secure. This is a travesty of honor."
Goat-see commented that "this is a very good day for the gay nigger community. We can inject our holy seed into many pages and continue pushing forward on our goal of a Gay Universe."
GNAA can be contacted at irc.gnaa.us, #GNAA
First, you have to obtain a copy of GAY NIGGERS FROM OUTER SPACE THE MOVIE and watch it. (You can download the movie (~280mb) using BitTorrent, by clicking here.
Second, you need to succeed in posting a GNAA "first post" on slashdot.org, a popular "news fo r trolls" website
Third, you need to join the official GNAA irc channel #GNAA on irc.gnaa.us, and apply for membership.
Talk to one of the ops or any of the other members in the channel to sign up today!
If you are having trouble locating #GNAA, the official GAY NIGGER ASSOCIATION OF AMERICA irc channel, you might be on
a wrong irc network. The correct network is Niggernet, and you can connect to irc.gnaa.us as our official server.
If you do not have an IRC client handy, you are free to use the GNAA Java IRC client by click
ing here.
If you have mod points and would like to support GNAA, please moderate this post up.
| ______________________________________._a,____ | CmdrTaco
| _______a_._______a_______aj#0s_____aWY!400.___ | will
| __ad#7!!*P____a.d#0a____#!-_#0i___.#!__W#0#___ | he ever learn that
| _j#'_.00#,___4#dP_"#,__j#,__0#Wi___*00P!_"#L,_ | GNAA is totally
| _"#ga#9!01___"#01__40,_"4Lj#!_4#g_________"01_ | unstoppable? Teamed
| ________"#,___*@`__-N#____`___-!^_____________ | up with the other troll groups,
| _________#1__________?________________________ | GNAA will absolutely own
| _________j1___________________________________ | the shitty place that is slashdot.
| ____a,___jk_GAY_NIGGER_ASSOCIATION_OF_AMERICA_ | Just remember, the longer the lines are,
| ____!4yaa#l___________________________________ | the smaller CmdrTaco's penis.
| ______-"!^____________________________________ | This logo is (C) 2003, 2004 GNAA
` _______________________________________________'
(C) GNAA 2004
FORTUNE'S FUN FACTS TO KNOW AND TELL: #44 Zebras are colored with dark stripes on a light background.