AspireOne / umimto

A cheat for umimeto.org | Chrome Plugin
0 stars 0 forks source link

Hello #1

Closed EvilBytecode closed 8 months ago

EvilBytecode commented 8 months ago

Does this still work? i heard they implemented something with proxy and not sure if this works anymore, im lazy 2 test it anyways.. 💀 lmk if y have free time

AspireOne commented 8 months ago

Hey, where on earth did you stumble on this? 🤣

Well, last time I tested it was about the time of the last commit, so I doubt it still works by now. But at the same time, I would be pretty surprised if they did implement somehing with proxy / something that cannot be bypassed, judging simply by how fucking terribly they had it made in the past :D

Did you know that not even more than two years ago, they just put the answer into the HTML tag? e.g.

<radio>
<option id="a" correct="true">
<option id="b">
<option id="b">
</radio>

That was pretty funny. And then when they switched to having it JS-based, there was a comment above some code in the JS file along the lines of

// i made it this way because the fuckers kept looking at the HTML and figuring out the correct answer

Their website was(/is?) full of holes all around - one of my classmates did a little XSS gymnastics, inserted some arbitrary html into his profile description or something, and next thing you know, when you open his profile, the screen is filled with disco-colors, spinning images of cats, NSFW sounds and whatnot :D

Another time, we figured out how they sent progress info to their servers (no timestamp validation, no HMAC, no nothing, you just send it in plain text, specify the answer and the question, and boom), and generated ourselves 10K green shields.


Fun times. Sorry, just a storytime I thought you might find interesting, looking at your profile.

So to sum it up, it most likely does not work by now, but I doubt that they patched it correctly this time. If you have the time, it can be a fun thing to do, and you also might learn a thing or two by googling around and figuring out how it's done.

Otherwise your best bet is honestly to just do the assignments (with the benefit of actually learning it), or just copy-pasting the question to ChatGPT or Claude.ai.

If you ever manage to workaround their current sheningans, please do let me know, I would love to hear it :D

EvilBytecode commented 8 months ago

Im not really a webdev I Just Made activity botter yesterday I dont think ill find workaround..