news.volyx.in

Rook to XSS: How I hacked chess.com with a rookie exploit (skii.dev)

430 points by el_duderino · 936 days ago · 131 comments on HN

Article summary

The article describes how the author, a cybersecurity enthusiast, discovered and exploited vulnerabilities on chess.com, including an OSRF vulnerability and a stored XSS vulnerability. The author used their knowledge of cybersecurity to find and report these vulnerabilities, which were then fixed by the chess.com security team. The vulnerabilities were caused by a combination of factors, including the re-uploading of images and the use of a rich text editor. The author's findings were reported under a bug bounty program and were rewarded with a bonus.

Main themes

  • cybersecurity vulnerabilities
  • chess.com vs lichess.org
  • bug bounty programs
  • open-source chess community
  • business models and ethics
  • WebAssembly and technology
  • ideological differences and rivalries

What commenters say

  • Some users have experienced issues with their chess.com accounts, including unauthorized moves being made in their games.
  • The author's exploit was impressive and demonstrated a high level of dedication and skill.
  • There is a rivalry between chess.com and lichess.org, with some users preferring one over the other due to differences in features and business models.
  • Lichess.org is a non-profit organization that has contributed to the open-source chess community, while chess.com is a for-profit company that has been accused of paying streamers to exclusively play on their platform.
  • Some users feel that chess.com's business practices are harmful to the chess community, while others see them as a necessary part of the market.
  • The use of WebAssembly and other technologies has helped lichess.org to reduce server costs and improve performance.
  • The debate between chess.com and lichess.org is also influenced by ideological differences, with some users preferring the non-profit and open-source approach of lichess.org.