header1
header2 header3 header4 header5 header6 header7 header8 header9 header10 header11 header10 header11 header10 header11 header12 header13 header14
Browsing in exploits

StickyDrama was among the many faggots who found themselves unable to PM hearts to cute boys this week.

Now, hearts appear as a nonsensical string of characters. The problem occurs only in PMs, not main chats; and it occurs in both chatrooms and LIves. No official word for the reason behind this latest Stickam snafu, but rumor is that it’s a side-effect of the company’s efforts to prevent Carb0n and Rancid’s chatroom attacks, or their usurpation of user’s sessions.

Fie, a thousand times fie on Stickam’s developers, who have denied us our hearts in order to protect an annoying spamming statutory rapist.

In the constellation of Stickam’s celebrities, there are the everyday stars who shine steadily, with whom we have long been familiar. And then there are those who flare up suddenly like a supernova, stunning the network in fear and awe of their brilliance. Such is the case with Carb0n and his accomplice Rancid, who have been owning the bejesus out of several popular chatrooms and (to StickyDrama’s delight) the spammer-rapist-faggot John Hock.

Beginning early this morning and continuing throughout the day—even as this post was being written and uploaded—Carb0n and Rancid seized control of Hock’s Live session God only knows how many times, replacing the video stream with Hock’s mugshot and slurpy cocksucking noises until Admins de-activated the account. StickyDrama was sent several screen-recordings, and managed to make one of our own as well.

Carb0n contacted StickyDrama this past weekend, introducing himself as a 21-year old-programmer somewhere in America. (As for the most pertinent detail of all, no word yet on the cocksize. Sorry, faggots.) He went on to address a few inaccuracies in our first post about the ownage of Hock’s LIve. The most significant correction was that Hock’s Live was in fact usurped by Rancid, an online friend of Carb0n who streamed a vague credit during his stunt. (Carb0n himself prefers to attack only chatrooms, not Lives.)

Carb0n further explained that he initally wrote a program which, in his words, “emulates Stickam’s web application.” The program injects HTML commands (not java, as had been frequently mentioned by various persons) containing Flash content into a session, allowing Carb0n to control the chat—namely adding text and videos where they would not ordinarily appear. On MSN he explained the basics:

He denied merely having purchased a software that anyone could use to perform similar hacks, insisting he had written the program himself.

Unfortunately for Carb0n, and the users who rather enjoyed his lulzy assaults, Stickam recently managed to determine and resolve that vulnerability. However, Rancid took Carb0n’s program and made some further tweaks, whereby he is able to wrest control of a Live stream. As of this post, that vulnerability remains in both Lives and chatrooms.

As long as Carb0n and Rancid continue to demonstrate such sagacity in their choice of targets, StickyDrama hopes that Stickam won’t close this vulnerability anytime soon. In recognition of their skills and lulz, we have awarded them our top banner for as long as the attacks continue. Details of how you can win our top banner are provided here.

http://stick.carb0n.org

The recent pornographic attacks on Stickam’s chatrooms and LIves are increasing in both their frequency and obscenity, and the company’s web security officer seems unable to close whatever vulnerability the attackers are exploiting. StickyDrama was visiting the Gay & Bi chatroom when we managed to screen-record the latest round of mischief.


While initially StickyDrama was amused by the naughty little clips—we almost never complain about cock on Stickam—last night things went too far. Whereas before reloading the chatroom ended the attack, now reloading does not resolve the problem. To rid our own room of attackers, it was necessary to kick all users we did not know—pretty much all but a dozen or so regulars—and then reload. In this regard StickyDrama fared much better than other large rooms such as Gay & Bi, Show N Tell and Singles Chat, who had fallen far down the chatroom list; as of this post the other large rooms have not fully recovered their usual traffic.

Being the only large chatroom has its headaches, namely the constant onslaught of spam—especially the dreaded “white space” spam. While we’re on the subject of security, and hopefully have the attention of someone in a position to improve the status quo, may we humbly suggest 3 improvements to combat spammers and other rogue users:

Enable chatrooms to ban users, even when they’re not in the chatroom. Unlike Lives, chatrooms cannot ban users; chatrooms should have a ban list too. (Giving chatroom hosts the option to turn PMs on or off would be nice too.)

Limit the number of lines of text or code users may post in main chats. No one except a spammer would use 50 lines text! Five lines should be more than enough for anything that anyone has to say.

For both chatrooms and Lives, hosts should be able to lookup statistics of which mod kicked which user, and when. This would enable hosts to identify which of their mods’ accounts had been usurped by another user—usually to kick a room empty. Hosts should have a “mod list,” much like a ban list, and be able to de-mod a user even if they are no longer in a chatroom or Live.

“A powerful programmer named Carb0n” suddenly struck Stickam’s larger chatrooms earlier tonight, disrupting hundreds of sleazy faggots and str8s looking for their evening camwhore partners.

For those readers unfamiliar with this lulzy form of assault, “rickrolled” refers to forcing one’s victims to watch the corny music video “Never Gonna Give You Up” by Rick Astley. According to an April 2008 poll by SurveyUSA, at least 18 million Americans have been rickrolled.

The attacks came suddenly, without any of the threats or boasts which little hackers and script kiddies tend to make. Targets were confined to the larger chatrooms; besides StickyDrama, Singles Chat, Gay & Bi, Show N Tell, and LTN*AZN*BLK*WHT were also victims of the exploit.

There is some debate as to whether these attacks were actually initiated by Carb0n, or whether Carb0n is the person who wrote whatever program exploits the vulnerability in Stickam’s code. Many users on Stickam have the display name Carb0n.

In addition to Carb0n’s credit which StickyDrama managed to screen-record during the first round, some users reported seeing the following message during subsequent attacks: “Stickam is exclusively for jews, niggers and emo fags who drag the blade from side to side.”

StickyDrama hates Stickam’s new player, and we’re not alone.

Let your voice be heard.


Sign to Change Back

SamProof has started an online “Put It Back” petition to persuade Stickam to return to its previous player, which gave all viewers the choice of which cam to view on their main camspot in Lives. Now, all viewers see only whom the host chooses, and cannot change the main cam.

The problem is, fapping sessions have become much less enjoyable. Even the host cannot maximize his or her partner’s cam, without minimizing his or her own; so one fapper is always gypped out of the higher-resolution image. And even during non-fap moments, let’s be honest: we all maximize whomever we find cutest in the room, and suddenly being deprived of this option is frustrating even to 14-year-olds who never ever flash their goodies on-cam.

To protest this insufferable situation, StickyDrama now reveals a simple exploit within the new player that will turn off all camspots in any Live except the host’s, and is completely untraceable by the host or Admins. Simply click and hold the camfeed icon on the left of any cam spot, then quickly drag your mouse over to the right of the same cam spot and click the X; and very quickly turn your own cam on and off in that same spot.

This 4-step process will permanently turn off that person’s feed in the room for ALL viewers including the host, forcing that person to exit and re-enter in order to be seen again. You cannot have your cam on to begin with.

camexploit2.jpg

Have fun, kids!

http://www.stickam.com/profile/samproof