Skip to content
  • Categories
  • Recent
  • Groups
  • Users
  • Tags
  • Popular
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Regular Blogs
  3. Warning about textem.net

Warning about textem.net

Scheduled Pinned Locked Moved Regular Blogs
12 Posts 4 Posters 622 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mapleundefined Offline
    mapleundefined Offline
    maple
    Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
    wrote on last edited by maple
    #1

    this is a public vulnerability disclosure, cus i cant reach the developers of textem.net and i noticed bdns users (even staff members) use this site often.

    tl;dr: textem has multiple vulnerabilities, potentially compromising all your texts, password, email address. i suggest deleting your account asap and using a different platform.


    textem is an old texting site from 2006 and still seemingly popular. here are three vulnerabilities ive found, the exact details are withheld to avoid malicious attacks on users.

    1. broken access control (+ config file misconfiguration)
    while this is technically a category of vulnerability, i wasnt able to pinpoint the exact vuln name. however because of a misconfiguration in a certain file and lack of adequate access controls, any user's texts are revealed to the public. as a user, you cannot prevent this or retroactively remove your texts. this is extremely easy to take advantage of.

    2. improperly sanitized input.
    this one is far more dangerous, however slightly more technical (involving writing exploit code) as it allows an attacker to essentially control any user's browser, without warning or alert. this means steal your passwords, read your texts, show you fake login websites for your email, bdns, etc. and you wouldnt even know it.

    3. lack of rate limiting, poor password standards, and weak admin passwords
    im editing this one in cus i forgot about it. but essentally any user's account is typically extremely easy to bruteforce. in fact, while testing, i could hack the admin account in less than 10 minutes.


    the presence of these easily exploitable vulnerabilities means theres likely even more issues, potentially even more dangerous. if you are a user, please follow these steps:

    1. if you rely on textem to communicate, immediately switch to a different website.
    2. change passwords (ideally to something unique and even forgettable, make sure you never reused it anywhere else - after all, youll be leaving the website anyway)
    3. if you discussed private matters in texts (e.g sharing passwords), assume its public and act accordingly.
    4. delete your account if possible.

    again, i havent been able to contact the developers, but if they ever fix this, ill update this post :3

    she/her, 16

    TheZwick32undefined 1 Reply Last reply
    2
    • pawtheticundefined Offline
      pawtheticundefined Offline
      pawthetic
      Trans chronically online Cuddle Puddle Complete Dumbahh ΟωΟ | Certified Puppy Anti-Clanker IT'S OKAY TO PUNCH NAZIS ♥ Sweetheart ♥
      wrote on last edited by
      #2

      shit i just remembered im ontextem

      dumb insecure puppygirl

      she/her if you use he/him on me i will hunt you down and kindly remind you to use she/her :heart:

      1 Reply Last reply
      0
      • Yanderemenheraundefined Offline
        Yanderemenheraundefined Offline
        Yanderemenhera
        Public Relations Senior Staff canida 🥀 😭🙏
        wrote on last edited by
        #3

        personally, i'll continue to use it, because its old and if a hacker looking for something of vaule came along, they would find nadda. but i personally recommend you do listen to maple on this one, the devs of this site never respond to my emails and haven't been active online since 2019 on facebook. i think they abandoned textem.net and just didn't get around to shutting it down or were simply too lazy too.

        wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
        hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
        my new grounds account is called phroggered
        look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

        1 Reply Last reply
        1
        • Yanderemenheraundefined Offline
          Yanderemenheraundefined Offline
          Yanderemenhera
          Public Relations Senior Staff canida 🥀 😭🙏
          wrote on last edited by
          #4

          i'll try to find names and such to message them personally

          wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
          hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
          my new grounds account is called phroggered
          look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

          1 Reply Last reply
          0
          • Yanderemenheraundefined Offline
            Yanderemenheraundefined Offline
            Yanderemenhera
            Public Relations Senior Staff canida 🥀 😭🙏
            wrote on last edited by
            #5

            but given the fact we have google reading your sms already and stuff i myself am not that afraid of this. data breaches are everywhere now adays, but still i will try to find names, emails ect. and message them.

            wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
            hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
            my new grounds account is called phroggered
            look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

            1 Reply Last reply
            0
            • mapleundefined Offline
              mapleundefined Offline
              maple
              Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
              wrote on last edited by
              #6

              i forgot to mention i hacked teh admin account accidentally cus of bad authentication practices. this site is fucked

              she/her, 16

              TheZwick32undefined 1 Reply Last reply
              1
              • Yanderemenheraundefined Offline
                Yanderemenheraundefined Offline
                Yanderemenhera
                Public Relations Senior Staff canida 🥀 😭🙏
                wrote on last edited by
                #7

                eh, i already know of alternative sites

                wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
                hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
                my new grounds account is called phroggered
                look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

                1 Reply Last reply
                0
                • Yanderemenheraundefined Offline
                  Yanderemenheraundefined Offline
                  Yanderemenhera
                  Public Relations Senior Staff canida 🥀 😭🙏
                  wrote on last edited by
                  #8

                  do you wanna do "security tests" on em?

                  wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
                  hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
                  my new grounds account is called phroggered
                  look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

                  1 Reply Last reply
                  0
                  • Yanderemenheraundefined Offline
                    Yanderemenheraundefined Offline
                    Yanderemenhera
                    Public Relations Senior Staff canida 🥀 😭🙏
                    wrote on last edited by
                    #9

                    i'll give you links in the resource center gc

                    wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
                    hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
                    my new grounds account is called phroggered
                    look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

                    1 Reply Last reply
                    0
                    • Yanderemenheraundefined Offline
                      Yanderemenheraundefined Offline
                      Yanderemenhera
                      Public Relations Senior Staff canida 🥀 😭🙏
                      wrote on last edited by
                      #10

                      alright, i sent maple a link, the resource center will get a list of safer alternatives out shortly

                      wilford bremly, sep, 27th 1934 to Aug, 1st, 2020
                      hit me up on discord, my username is wilfordbremly and I will talk to you 'bout daibetus
                      my new grounds account is called phroggered
                      look at dat to see ''exclusive'' content or whatever. YouTube is far too toxic for me tbh.

                      1 Reply Last reply
                      0
                      • mapleundefined maple referenced this topic on
                      • mapleundefined maple

                        this is a public vulnerability disclosure, cus i cant reach the developers of textem.net and i noticed bdns users (even staff members) use this site often.

                        tl;dr: textem has multiple vulnerabilities, potentially compromising all your texts, password, email address. i suggest deleting your account asap and using a different platform.


                        textem is an old texting site from 2006 and still seemingly popular. here are three vulnerabilities ive found, the exact details are withheld to avoid malicious attacks on users.

                        1. broken access control (+ config file misconfiguration)
                        while this is technically a category of vulnerability, i wasnt able to pinpoint the exact vuln name. however because of a misconfiguration in a certain file and lack of adequate access controls, any user's texts are revealed to the public. as a user, you cannot prevent this or retroactively remove your texts. this is extremely easy to take advantage of.

                        2. improperly sanitized input.
                        this one is far more dangerous, however slightly more technical (involving writing exploit code) as it allows an attacker to essentially control any user's browser, without warning or alert. this means steal your passwords, read your texts, show you fake login websites for your email, bdns, etc. and you wouldnt even know it.

                        3. lack of rate limiting, poor password standards, and weak admin passwords
                        im editing this one in cus i forgot about it. but essentally any user's account is typically extremely easy to bruteforce. in fact, while testing, i could hack the admin account in less than 10 minutes.


                        the presence of these easily exploitable vulnerabilities means theres likely even more issues, potentially even more dangerous. if you are a user, please follow these steps:

                        1. if you rely on textem to communicate, immediately switch to a different website.
                        2. change passwords (ideally to something unique and even forgettable, make sure you never reused it anywhere else - after all, youll be leaving the website anyway)
                        3. if you discussed private matters in texts (e.g sharing passwords), assume its public and act accordingly.
                        4. delete your account if possible.

                        again, i havent been able to contact the developers, but if they ever fix this, ill update this post :3

                        TheZwick32undefined Offline
                        TheZwick32undefined Offline
                        TheZwick32
                        No Snow
                        wrote on last edited by TheZwick32
                        #11

                        @maple Warning: only read if ur a developer

                        by the way anybody calling themself a hacker would know what "improperly sanitized" means: they're rendering something (probably texts in this case) as HTML and not plaintext, which means somebody could literally just SEND SOMEBODY CODE which would run on their machine.

                        Please follow me on all the platforms:
                        Scratch: @Silvan_Zwick
                        Juxtaposition: @TheZwick32
                        Switchbru Friend Code: SB-2763-9560-4220
                        3DS: 1777-9379-7833
                        Switch: SW-6420-7232-0931
                        Pokémon TCG Pocket: 9240-9307-1399-5945
                        TCGLive: TheZwick32
                        www.silvanzwick.com

                        1 Reply Last reply
                        1
                        • mapleundefined maple

                          i forgot to mention i hacked teh admin account accidentally cus of bad authentication practices. this site is fucked

                          TheZwick32undefined Offline
                          TheZwick32undefined Offline
                          TheZwick32
                          No Snow
                          wrote on last edited by
                          #12

                          @maple when you hack the admin ACCIDENTALLY 💀

                          Please follow me on all the platforms:
                          Scratch: @Silvan_Zwick
                          Juxtaposition: @TheZwick32
                          Switchbru Friend Code: SB-2763-9560-4220
                          3DS: 1777-9379-7833
                          Switch: SW-6420-7232-0931
                          Pokémon TCG Pocket: 9240-9307-1399-5945
                          TCGLive: TheZwick32
                          www.silvanzwick.com

                          1 Reply Last reply
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Groups
                          • Users
                          • Tags
                          • Popular