Software Alternatives & Reviews

How I hacked chess.com with a rookie exploit

Lichess Chess.com
  1. The complete chess experience, play and compete in tournaments with friends others around the world.
    Pricing:
    • Open Source

    #Chess #Games #Online Games 893 social mentions

  2. Play chess on Chess.
    Clearly chess.com was using something like "starts with" to process the re-upload. Basically don't re-upload if it starts with https://chess.com, but filter out if it starts with https://chess.com/registration-invite Typically same origin policies are relaxed for things like images by default [0]. So they came up with a trampoline, they created a chess.com.theirDomain.tld to get past the re-upload filter, which in turn returned a redirect, which the browser followed. [0] https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy#cross-origin_network_access.

    #Chess #Games #Online Games 11425 social mentions

Discuss: How I hacked chess.com with a rookie exploit

Log in or Post with