Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Conversation

Notices

  1. GeniusMusing (geniusmusing@nu.federati.net)'s status on Thursday, 27-Jan-2022 10:56:54 EST GeniusMusing GeniusMusing
    This NFT on OpenSea Will Steal Your IP Address
    https://www.vice.com/en/article/xgdvaz/nft-steal-ip-address-opensea

    >NFTs are usually passive affairs. A consumer buys the token, and then sells or stores the NFT. The NFT doesn’t really do anything.
    >
    >Some new NFTs are being used to harvest viewers’ IP addresses, though, in a demonstration of how NFT marketplaces like OpenSea allow vendors, or attackers, to load custom code when someone simply views an NFT listing.
    >
    >“We've been researching a lot of problems in the NFT space (with more of a focus on fraud) and one of the things we were playing around with was different XSS attacks on websites that display NFTs which is when I realized we could get OpenSea to load HTML pages,” Nick Bax, head of research at NFT organization Convex Labs, told Motherboard in an online chat. XSS refers to cross site scripting attacks, one of several different kinds of attack that someone could use an NFT for.
    >...

    Just say No to NFT's.
    In conversation Thursday, 27-Jan-2022 10:56:54 EST from nu.federati.net permalink

    Attachments

    1. Invalid filename.
      This NFT on OpenSea Will Steal Your IP Address
      The NFT shows how viewers of NFTs on marketplaces like OpenSea may unexpectedly expose their data.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.