Page 1 of 1

NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Sat May 09, 2015 9:14 am
by GoranZ
Accused:
NoSurvivors

The accused are suspected of: Severe PM Abuse
His message:
DO NOT CLICK ON THE LINK!!!
CC User wrote:I would like to invite you to join the Campaign NoSs campaign!.

Click (DO NOT CLICK)here to check it out.

Problematic link is following: http://www.conquerclub.com/player.php?submit=JoinTournament&tournament_id=2685
The part: "submit=JoinTournament" has a task for joining a tournament, but I have no idea which tournament, what it has, absolutely nothing.
To make it more problematic he says "Click here to check it out", so I expect some tournament page to open, not to join a tournament.
The tournament has entry requirement of 200 Conquer Credits, so can be considered also as Conquer Credits farming.

Comments:
What is Clickjacking can be found on appropriate Wikipedia page: http://en.wikipedia.org/wiki/Clickjacking

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 10:30 am
by Gilligan
wait, what are campaigns? this is essentially betting on games (because there are only two players in the game) which I thought was strictly prohibited?

Gambling on or through this site is not allowed.
HIDE: GAMBLING SPECIFICS
This is a casual gaming site, not a serious one. If you want to bet money or "real-world items", then you'll have to find another site.
Wagering CC points is also not allowed.
The Conquer Cup is of course not considered gambling just because there is an entry fee associated with participation!

viewtopic.php?t=7785#p1759438

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 11:46 am
by Dukasaur
@Goran: While NS's link is in poor taste, you do have an option to cancel after you click, so I'm not sure if it can be called true clickjacking.

@Gilligan: Yeah, it's gambling. Potentially a problem, but there's been a constituency that wants it, so they got it.

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 11:48 am
by Gilligan
Dukasaur wrote:@Goran: While NS's link is in poor taste, you do have an option to cancel after you click, so I'm not sure if it can be called true clickjacking.

@Gilligan: Yeah, it's gambling. Potentially a problem, but there's been a constituency that wants it, so they got it.


with only two players in the campaign, wouldn't it immediately start?

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 1:04 pm
by DoomYoshi
I think those are not NoS clickjacking, but a feature of the site. One which perhaps can be changed. This belongs in Bugs or Suggs (Which really should be the same forum); not C&A.

We have just tested for a 2-player campaign. It auto-joins, but still allows a cancel.

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 1:55 pm
by GoranZ
Dukasaur wrote:@Goran: While NS's link is in poor taste, you do have an option to cancel after you click, so I'm not sure if it can be called true clickjacking.

its true clickjacking ;) 100% genuine one.

DoomYoshi wrote:I think those are not NoS clickjacking, but a feature of the site.

:lol: Weakness presented as a feature =D> Thats a good one, made me lough.


Gilligan wrote:
Dukasaur wrote:@Goran: While NS's link is in poor taste, you do have an option to cancel after you click, so I'm not sure if it can be called true clickjacking.

@Gilligan: Yeah, it's gambling. Potentially a problem, but there's been a constituency that wants it, so they got it.

with only two players in the campaign, wouldn't it immediately start?

DoomYoshi wrote:One which perhaps can be changed. This belongs in Bugs or Suggs (Which really should be the same forum); not C&A.

We have just tested for a 2-player campaign. It auto-joins, but still allows a cancel.

There is Cancel because the campaign requires Conquer Credits, but if it doesn't require Conquer Credits...

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 4:31 pm
by DoomYoshi
Even when doing a no credit campaign, there is still a button which says, please confirm you would like to join this campaign. I don't see the issue here, although the wording could be better for sure.

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sat May 09, 2015 7:46 pm
by Razorvich
I clicked the link when it was sent to me, and once i found out the settings were freestyle, i hit cancel.

There was an option to confirm whether you really wanted in or not.

It was not a link that automaticly put me into a game, I had the option to abort...which i did cause I suck at freestyle games

Re: NoSurvivors is using CC Clickjacking weakness

PostPosted: Sun May 10, 2015 8:08 pm
by king achilles
Razorvich wrote:I clicked the link when it was sent to me, and once i found out the settings were freestyle, i hit cancel.

There was an option to confirm whether you really wanted in or not.

It was not a link that automaticly put me into a game, I had the option to abort...which i did cause I suck at freestyle games

This.

Re: NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Sun May 10, 2015 8:46 pm
by Gilligan
he should still be warned, or at least noted. he can just as easily link to the tournament without the join popup happening. that is what SHOULD be done.

Re: NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Sun May 10, 2015 9:15 pm
by DoomYoshi
Gilligan wrote:he should still be warned, or at least noted. he can just as easily link to the tournament without the join popup happening. that is what SHOULD be done.


He didn't send the PM. The site did. It's stupid that it says from "user" without it ever going into the user's outbox, but that's how it works.

Re: NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Mon May 11, 2015 12:08 am
by KraphtOne
DoomYoshi wrote:
Gilligan wrote:he should still be warned, or at least noted. he can just as easily link to the tournament without the join popup happening. that is what SHOULD be done.


He didn't send the PM. The site did. It's stupid that it says from "user" without it ever going into the user's outbox, but that's how it works.



yuuuuup. more nonsense

Re: NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Mon May 11, 2015 5:14 am
by NoSurvivors
Eek.. I didn't realize it was an auto join link. I simply sent a bunch of people the link to the "details" page. I guess it must be a glitch. Don't want anyone joining that doesn't want to, it's just hard to find people who like FS so I sent it to a bunch of players.

Re: NoSurvivors is using CC Clickjacking weakness [ka]

PostPosted: Mon May 11, 2015 11:58 am
by Gilligan
DoomYoshi wrote:
Gilligan wrote:he should still be warned, or at least noted. he can just as easily link to the tournament without the join popup happening. that is what SHOULD be done.


He didn't send the PM. The site did. It's stupid that it says from "user" without it ever going into the user's outbox, but that's how it works.


okay, then obviously NoS doesn't have any malicious intent here. this should still be changed, in the automated PM.