ZeroTixDev / Darrows

pvp io game that uses bow and arrows - sequel to death arrows
1 stars 4 forks source link

Chat message spoofing. #27

Open 10maurycy10 opened 2 years ago

10maurycy10 commented 2 years ago

Using unicode characters such as the zero-width-space, it is possable to have a name that is visualy identical to that of someone in game.

A working exploit can be found at inject.js in https://github.com/10maurycy10/DarrowsTroll