<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Cracking Trivia Crack</title>
	<atom:link href="http://jodoglevy.com/jobloglevy/cracking-trivia-crack/feed/" rel="self" type="application/rss+xml" />
	<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/</link>
	<description>The Personal Blog of Joe Levy</description>
	<lastBuildDate>Tue, 03 Mar 2015 06:13:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.1.1</generator>
	<item>
		<title>By: robert</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-8340</link>
		<dc:creator><![CDATA[robert]]></dc:creator>
		<pubDate>Tue, 03 Mar 2015 06:13:59 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-8340</guid>
		<description><![CDATA[I was also hoping for an app version of this.  Any chance of that being a possibility?]]></description>
		<content:encoded><![CDATA[<p>I was also hoping for an app version of this.  Any chance of that being a possibility?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anna</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-5679</link>
		<dc:creator><![CDATA[Anna]]></dc:creator>
		<pubDate>Sun, 25 Jan 2015 11:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-5679</guid>
		<description><![CDATA[So I have to be using Chrome Browser in order to be able to download the Trivia Cracker? It&#039;s not an app that&#039;s available from play store to be used with the game app?]]></description>
		<content:encoded><![CDATA[<p>So I have to be using Chrome Browser in order to be able to download the Trivia Cracker? It&#8217;s not an app that&#8217;s available from play store to be used with the game app?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jared</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-5386</link>
		<dc:creator><![CDATA[Jared]]></dc:creator>
		<pubDate>Thu, 22 Jan 2015 23:55:50 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-5386</guid>
		<description><![CDATA[Interesting! I actually found and exploited this glitch myself, though it was time consuming to sift through the responses manually. Thanks for this extension :)]]></description>
		<content:encoded><![CDATA[<p>Interesting! I actually found and exploited this glitch myself, though it was time consuming to sift through the responses manually. Thanks for this extension <img src="http://jodoglevy.com/jobloglevy/wp-includes/images/smilies/icon_smile.gif" alt=":)" class="wp-smiley" /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shandizzle</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4859</link>
		<dc:creator><![CDATA[Shandizzle]]></dc:creator>
		<pubDate>Sun, 18 Jan 2015 13:04:51 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4859</guid>
		<description><![CDATA[This may be the greatest response ever.]]></description>
		<content:encoded><![CDATA[<p>This may be the greatest response ever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jodoglevy</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4629</link>
		<dc:creator><![CDATA[jodoglevy]]></dc:creator>
		<pubDate>Thu, 15 Jan 2015 22:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4629</guid>
		<description><![CDATA[Hi Curtis,

Fun idea. How much time do you have? I have a pretty good idea of how to do this with the online version of the game on Facebook, that might work. Only issue is she would have to access the game on Facebook, and using the Chrome browser started in a special way (so probably from your laptop, unless you have access to hers to set this up). Also, only one answer can be correct, not two, so there would only be one &quot;yes&quot; option.

Find my email on http://jodoglevy.com/ . Always happy to help out an aspiring engineer.]]></description>
		<content:encoded><![CDATA[<p>Hi Curtis,</p>
<p>Fun idea. How much time do you have? I have a pretty good idea of how to do this with the online version of the game on Facebook, that might work. Only issue is she would have to access the game on Facebook, and using the Chrome browser started in a special way (so probably from your laptop, unless you have access to hers to set this up). Also, only one answer can be correct, not two, so there would only be one &#8220;yes&#8221; option.</p>
<p>Find my email on <a href="http://jodoglevy.com/" rel="nofollow">http://jodoglevy.com/</a> . Always happy to help out an aspiring engineer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Curtis</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4621</link>
		<dc:creator><![CDATA[Curtis]]></dc:creator>
		<pubDate>Thu, 15 Jan 2015 20:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4621</guid>
		<description><![CDATA[Hey Joe, awesome article about the behind-the-scenes vulnerabilities of Trivia Crack! Would it be possible to insert your own questions this way? I&#039;m a senior in high school hoping to eventually get my master&#039;s in Cyber Security, and I&#039;m pretty well known at school for my reputation as a geek. I want to ask a girl at school to go to prom with me using Trivia Crack (She would spin the wheel, and the question would be &quot;Will you go to prom with me?&quot; The answers would include two &quot;Yes&quot; options and two &quot;No&quot; options. When she presses yes, it would show up as correct.) I know this wouldn&#039;t work on an online version of the game, but would it work as an offline mode (I could download the source code and edit it)? I also have a jailbroken iPhone, a rooted Android phone, a Mac Pro, and a PC, so devices aren&#039;t a problem. Thank you in advance!]]></description>
		<content:encoded><![CDATA[<p>Hey Joe, awesome article about the behind-the-scenes vulnerabilities of Trivia Crack! Would it be possible to insert your own questions this way? I&#8217;m a senior in high school hoping to eventually get my master&#8217;s in Cyber Security, and I&#8217;m pretty well known at school for my reputation as a geek. I want to ask a girl at school to go to prom with me using Trivia Crack (She would spin the wheel, and the question would be &#8220;Will you go to prom with me?&#8221; The answers would include two &#8220;Yes&#8221; options and two &#8220;No&#8221; options. When she presses yes, it would show up as correct.) I know this wouldn&#8217;t work on an online version of the game, but would it work as an offline mode (I could download the source code and edit it)? I also have a jailbroken iPhone, a rooted Android phone, a Mac Pro, and a PC, so devices aren&#8217;t a problem. Thank you in advance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jodoglevy</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4509</link>
		<dc:creator><![CDATA[jodoglevy]]></dc:creator>
		<pubDate>Wed, 14 Jan 2015 18:34:12 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4509</guid>
		<description><![CDATA[Interesting idea Harris. I don&#039;t think that is the case though because that 99999 value is never sent to the server, it is only received by the client. The 99999 value lets you get past client side checks for things like &quot;does this user have enough lives left to allow them to start a new game,&quot; but then once a user clicks the new game button, the client tells the server &quot;this user wants to start a new game,&quot; and the server, which knows the real # of lives one has left, also validates one has enough lives left to start a new game, and responds to the client &quot;sorry, not enough lives.&quot; 

So I think its just simply server side validation, rather than a byte overflow.]]></description>
		<content:encoded><![CDATA[<p>Interesting idea Harris. I don&#8217;t think that is the case though because that 99999 value is never sent to the server, it is only received by the client. The 99999 value lets you get past client side checks for things like &#8220;does this user have enough lives left to allow them to start a new game,&#8221; but then once a user clicks the new game button, the client tells the server &#8220;this user wants to start a new game,&#8221; and the server, which knows the real # of lives one has left, also validates one has enough lives left to start a new game, and responds to the client &#8220;sorry, not enough lives.&#8221; </p>
<p>So I think its just simply server side validation, rather than a byte overflow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harris</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4426</link>
		<dc:creator><![CDATA[Harris]]></dc:creator>
		<pubDate>Tue, 13 Jan 2015 05:53:06 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4426</guid>
		<description><![CDATA[Perhaps this is an amateur guess, but could they be using a byte or some small variable type to store these, and you&#039;re overflowing to numbers &lt;1?]]></description>
		<content:encoded><![CDATA[<p>Perhaps this is an amateur guess, but could they be using a byte or some small variable type to store these, and you&#8217;re overflowing to numbers &lt;1?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jodoglevy</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4402</link>
		<dc:creator><![CDATA[jodoglevy]]></dc:creator>
		<pubDate>Tue, 13 Jan 2015 01:53:04 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4402</guid>
		<description><![CDATA[I actually attempted this and was able to manipulate the responses from the Trivia Crack server in real time to contain 99999 for the lives, coins, and spins. The Trivia Crack client accepted these values and showed them in the UI, but when you use a life, coin, or spin, it tells the server you are using one and the server responds with an error saying you don&#039;t have any left, at which point the client rejects your attempt.

So while Trivia Crack doesn&#039;t validate answers server side, it turns out they do validate lives, coins, and spins!]]></description>
		<content:encoded><![CDATA[<p>I actually attempted this and was able to manipulate the responses from the Trivia Crack server in real time to contain 99999 for the lives, coins, and spins. The Trivia Crack client accepted these values and showed them in the UI, but when you use a life, coin, or spin, it tells the server you are using one and the server responds with an error saying you don&#8217;t have any left, at which point the client rejects your attempt.</p>
<p>So while Trivia Crack doesn&#8217;t validate answers server side, it turns out they do validate lives, coins, and spins!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://jodoglevy.com/jobloglevy/cracking-trivia-crack/#comment-4400</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Tue, 13 Jan 2015 01:10:17 +0000</pubDate>
		<guid isPermaLink="false">http://jodoglevy.com/jobloglevy/?p=169#comment-4400</guid>
		<description><![CDATA[I agree, however if you look at his extension description it says that he will soon be adding infinite lives, powerups and etc.]]></description>
		<content:encoded><![CDATA[<p>I agree, however if you look at his extension description it says that he will soon be adding infinite lives, powerups and etc.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
