Skip to content
  • Categories
  • Recent
  • Groups
  • Users
  • Tags
  • Popular
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Categories
  3. Regular Blogs
  4. Warning about textem.net

Warning about textem.net

Scheduled Pinned Locked Moved Regular Blogs
12 Posts 4 Posters 264 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mapleM Offline
    mapleM Offline
    maple
    resource center Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
    wrote on last edited by maple
    #1

    this is a public vulnerability disclosure, cus i cant reach the developers of textem.net and i noticed bdns users (even staff members) use this site often.

    tl;dr: textem has multiple vulnerabilities, potentially compromising all your texts, password, email address. i suggest deleting your account asap and using a different platform.


    textem is an old texting site from 2006 and still seemingly popular. here are three vulnerabilities ive found, the exact details are withheld to avoid malicious attacks on users.

    1. broken access control (+ config file misconfiguration)
    while this is technically a category of vulnerability, i wasnt able to pinpoint the exact vuln name. however because of a misconfiguration in a certain file and lack of adequate access controls, any user's texts are revealed to the public. as a user, you cannot prevent this or retroactively remove your texts. this is extremely easy to take advantage of.

    2. improperly sanitized input.
    this one is far more dangerous, however slightly more technical (involving writing exploit code) as it allows an attacker to essentially control any user's browser, without warning or alert. this means steal your passwords, read your texts, show you fake login websites for your email, bdns, etc. and you wouldnt even know it.

    3. lack of rate limiting, poor password standards, and weak admin passwords
    im editing this one in cus i forgot about it. but essentally any user's account is typically extremely easy to bruteforce. in fact, while testing, i could hack the admin account in less than 10 minutes.


    the presence of these easily exploitable vulnerabilities means theres likely even more issues, potentially even more dangerous. if you are a user, please follow these steps:

    1. if you rely on textem to communicate, immediately switch to a different website.
    2. change passwords (ideally to something unique and even forgettable, make sure you never reused it anywhere else - after all, youll be leaving the website anyway)
    3. if you discussed private matters in texts (e.g sharing passwords), assume its public and act accordingly.
    4. delete your account if possible.

    again, i havent been able to contact the developers, but if they ever fix this, ill update this post :3

    she/her, 16, maple is teh best

    TheZwick32T 1 Reply Last reply
    3
    • pawtheticP Offline
      pawtheticP Offline
      pawthetic
      Trans Crazy In Love. chronically online Cuddle Puddle Complete Dumbahh ΟωΟ | Certified Puppy Anti-Clanker IT'S OKAY TO PUNCH NAZIS ♥ Sweetheart ♥ Banned
      wrote on last edited by
      #2

      shit i just remembered im ontextem

      dumb insecure puppygirl

      she/her if you use he/him on me i will hunt you down and kill you :heart:

      1 Reply Last reply
      0
      • YanderemenheraY Offline
        YanderemenheraY Offline
        Yanderemenhera
        But 20$ is 20$ resource center Forum Services
        wrote on last edited by
        #3

        personally, i'll continue to use it, because its old and if a hacker looking for something of vaule came along, they would find nadda. but i personally recommend you do listen to maple on this one, the devs of this site never respond to my emails and haven't been active online since 2019 on facebook. i think they abandoned textem.net and just didn't get around to shutting it down or were simply too lazy too.

        owothe mighty
        i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
        no offense to edaters. i just dont want to.

        currently i have limited Internet access

        1 Reply Last reply
        1
        • YanderemenheraY Offline
          YanderemenheraY Offline
          Yanderemenhera
          But 20$ is 20$ resource center Forum Services
          wrote on last edited by
          #4

          i'll try to find names and such to message them personally

          owothe mighty
          i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
          no offense to edaters. i just dont want to.

          currently i have limited Internet access

          1 Reply Last reply
          0
          • YanderemenheraY Offline
            YanderemenheraY Offline
            Yanderemenhera
            But 20$ is 20$ resource center Forum Services
            wrote on last edited by
            #5

            but given the fact we have google reading your sms already and stuff i myself am not that afraid of this. data breaches are everywhere now adays, but still i will try to find names, emails ect. and message them.

            owothe mighty
            i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
            no offense to edaters. i just dont want to.

            currently i have limited Internet access

            1 Reply Last reply
            0
            • mapleM Offline
              mapleM Offline
              maple
              resource center Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
              wrote on last edited by
              #6

              i forgot to mention i hacked teh admin account accidentally cus of bad authentication practices. this site is fucked

              she/her, 16, maple is teh best

              TheZwick32T 1 Reply Last reply
              1
              • YanderemenheraY Offline
                YanderemenheraY Offline
                Yanderemenhera
                But 20$ is 20$ resource center Forum Services
                wrote on last edited by
                #7

                eh, i already know of alternative sites

                owothe mighty
                i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
                no offense to edaters. i just dont want to.

                currently i have limited Internet access

                1 Reply Last reply
                0
                • YanderemenheraY Offline
                  YanderemenheraY Offline
                  Yanderemenhera
                  But 20$ is 20$ resource center Forum Services
                  wrote on last edited by
                  #8

                  do you wanna do "security tests" on em?

                  owothe mighty
                  i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
                  no offense to edaters. i just dont want to.

                  currently i have limited Internet access

                  1 Reply Last reply
                  0
                  • YanderemenheraY Offline
                    YanderemenheraY Offline
                    Yanderemenhera
                    But 20$ is 20$ resource center Forum Services
                    wrote on last edited by
                    #9

                    i'll give you links in the resource center gc

                    owothe mighty
                    i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
                    no offense to edaters. i just dont want to.

                    currently i have limited Internet access

                    1 Reply Last reply
                    0
                    • YanderemenheraY Offline
                      YanderemenheraY Offline
                      Yanderemenhera
                      But 20$ is 20$ resource center Forum Services
                      wrote on last edited by
                      #10

                      alright, i sent maple a link, the resource center will get a list of safer alternatives out shortly

                      owothe mighty
                      i do not do edating. especially with kid halve a decade or more younger. please, just don't bother trying to rizz me up
                      no offense to edaters. i just dont want to.

                      currently i have limited Internet access

                      1 Reply Last reply
                      0
                      • mapleM maple referenced this topic on
                      • mapleM maple

                        this is a public vulnerability disclosure, cus i cant reach the developers of textem.net and i noticed bdns users (even staff members) use this site often.

                        tl;dr: textem has multiple vulnerabilities, potentially compromising all your texts, password, email address. i suggest deleting your account asap and using a different platform.


                        textem is an old texting site from 2006 and still seemingly popular. here are three vulnerabilities ive found, the exact details are withheld to avoid malicious attacks on users.

                        1. broken access control (+ config file misconfiguration)
                        while this is technically a category of vulnerability, i wasnt able to pinpoint the exact vuln name. however because of a misconfiguration in a certain file and lack of adequate access controls, any user's texts are revealed to the public. as a user, you cannot prevent this or retroactively remove your texts. this is extremely easy to take advantage of.

                        2. improperly sanitized input.
                        this one is far more dangerous, however slightly more technical (involving writing exploit code) as it allows an attacker to essentially control any user's browser, without warning or alert. this means steal your passwords, read your texts, show you fake login websites for your email, bdns, etc. and you wouldnt even know it.

                        3. lack of rate limiting, poor password standards, and weak admin passwords
                        im editing this one in cus i forgot about it. but essentally any user's account is typically extremely easy to bruteforce. in fact, while testing, i could hack the admin account in less than 10 minutes.


                        the presence of these easily exploitable vulnerabilities means theres likely even more issues, potentially even more dangerous. if you are a user, please follow these steps:

                        1. if you rely on textem to communicate, immediately switch to a different website.
                        2. change passwords (ideally to something unique and even forgettable, make sure you never reused it anywhere else - after all, youll be leaving the website anyway)
                        3. if you discussed private matters in texts (e.g sharing passwords), assume its public and act accordingly.
                        4. delete your account if possible.

                        again, i havent been able to contact the developers, but if they ever fix this, ill update this post :3

                        TheZwick32T Offline
                        TheZwick32T Offline
                        TheZwick32
                        No Snow
                        wrote last edited by TheZwick32
                        #11

                        @maple Warning: only read if ur a developer

                        by the way anybody calling themself a hacker would know what "improperly sanitized" means: they're rendering something (probably texts in this case) as HTML and not plaintext, which means somebody could literally just SEND SOMEBODY CODE which would run on their machine.

                        Please follow me on all the platforms:
                        Scratch: @Silvan_Zwick
                        Juxtaposition: @TheZwick32
                        Switchbru Friend Code: SB-2763-9560-4220
                        3DS: 1777-9379-7833
                        Switch: SW-6420-7232-0931
                        Pokémon TCG Pocket: 9240-9307-1399-5945
                        TCGLive: TheZwick32
                        www.silvanzwick.com

                        1 Reply Last reply
                        1
                        • mapleM maple

                          i forgot to mention i hacked teh admin account accidentally cus of bad authentication practices. this site is fucked

                          TheZwick32T Offline
                          TheZwick32T Offline
                          TheZwick32
                          No Snow
                          wrote last edited by
                          #12

                          @maple when you hack the admin ACCIDENTALLY 💀

                          Please follow me on all the platforms:
                          Scratch: @Silvan_Zwick
                          Juxtaposition: @TheZwick32
                          Switchbru Friend Code: SB-2763-9560-4220
                          3DS: 1777-9379-7833
                          Switch: SW-6420-7232-0931
                          Pokémon TCG Pocket: 9240-9307-1399-5945
                          TCGLive: TheZwick32
                          www.silvanzwick.com

                          1 Reply Last reply
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Groups
                          • Users
                          • Tags
                          • Popular