Skip to content
This repository has been archived by the owner on Apr 7, 2022. It is now read-only.

[HUGE BREAKTHROUGH!] Employee Panel Bypass? #348

Closed
ghost opened this issue Oct 25, 2020 · 46 comments
Closed

[HUGE BREAKTHROUGH!] Employee Panel Bypass? #348

ghost opened this issue Oct 25, 2020 · 46 comments
Assignees
Labels
Priority: High High priority Research Research further into this issue.

Comments

@ghost
Copy link

ghost commented Oct 25, 2020

Working on accessing Prodigy employee panel.

Original post:

https://prnt.sc/v6jvlb

@ghost
Copy link
Author

ghost commented Oct 25, 2020

I AM VERY EXCITED LEMME EXPIREMENT

@ArcerionDev
Copy link
Contributor

this may actually be something

@ArcerionDev
Copy link
Contributor

however, it will be hard to forge the requests in-game

@ghost
Copy link
Author

ghost commented Oct 25, 2020

also remember /oauth2/userinfo

there's a employee thing

we should use tampermonkey or something to change it to "employee": "true"

also prodigy is still "temporarily offline" for me and i gtg so i cant do more rn

@ghost ghost added the Research Research further into this issue. label Oct 25, 2020
@ArcerionDev
Copy link
Contributor

alright, we can work on it

@ghost ghost changed the title OK SO Employee Bypass? Oct 25, 2020
@ghost ghost changed the title Employee Bypass? Employee Panel Bypass? Oct 25, 2020
@ghost
Copy link
Author

ghost commented Oct 25, 2020

im back kidssss

@ghost
Copy link
Author

ghost commented Oct 25, 2020

also we should totally bruteforce this https://sso.prodigygame.com/employee/login

we have a lot of prodigy employee emails

@ghost
Copy link
Author

ghost commented Oct 25, 2020

bruh so the penis captcha thing doesnt work on employee login but it does on student/parent login

prodigy gives their employees more security on just a basic login screen than they do their actual customers lmfao

@ghost
Copy link
Author

ghost commented Oct 25, 2020

also this domain contains resources for prodigy's customer support: https://cs.prodigygame.com/

maybe bruteforce URLs for something interesting??

@ghost
Copy link
Author

ghost commented Oct 25, 2020

https://cs.prodigygame.com/index.php doesnt exist so the home is an html file

@ghost
Copy link
Author

ghost commented Oct 25, 2020

ok so when you send prodigy an email to support there's this thing where it says like "Press yes if these links solved your issue and we will close the ticket"

"Yes" links to this: https://www.prodigygame.com/actions/resolveZendeskTicket.php?ticketID=923925

the ticket ID is just my "test" ticket

but theoretically we could close every ticket on the zendesk by just going up a number each time

@ghost
Copy link
Author

ghost commented Oct 25, 2020

im getting off-topic rn tho ik

@ghost
Copy link
Author

ghost commented Oct 25, 2020

yep it works i solved my ticket by ID

https://imgur.com/r7loXV4.png

(ik a way to create an account on any zendesk support page even if the support center in question disallows it but that's a story for another day)

@rusprice
Copy link
Contributor

Major breakthrough!!!

@ghost
Copy link
Author

ghost commented Oct 25, 2020

i theoritically just marked like 20 tickets as resolved but no way to tell if it worked

@ghost
Copy link
Author

ghost commented Oct 25, 2020

Major breakthrough!!!

yep

@rusprice
Copy link
Contributor

Use the dev tools and inspect the data sent when you go to that page, make sure no cookies are sent for verification or anything.

@ghost
Copy link
Author

ghost commented Oct 25, 2020

Use the dev tools and inspect the data sent when you go to that page, make sure no cookies are sent for verification or anything.

kk

@rusprice
Copy link
Contributor

I just checked, and nope!!

@ghost
Copy link
Author

ghost commented Oct 25, 2020

absolutely nothing!

@rusprice rusprice reopened this Oct 25, 2020
@ghost
Copy link
Author

ghost commented Oct 25, 2020

I just checked, and nope!!

why did you close lmao? misclick?

@rusprice
Copy link
Contributor

Yup.

@ghost
Copy link
Author

ghost commented Oct 25, 2020

brb

@rusprice rusprice changed the title Employee Panel Bypass? [HUGE BREAKTHROUGH!] Employee Panel Bypass? Oct 25, 2020
@ghost ghost assigned rusprice and unassigned MelnCat Oct 25, 2020
@ghost
Copy link
Author

ghost commented Oct 25, 2020

back, and will hasnt been active on github lately so i unassigned him. if he actually comments here i'll re-assign him

@ghost
Copy link
Author

ghost commented Oct 25, 2020

hmm so what if we just find a prodigy employee who's email is in a data breach exposing plain-text passwords (there are quite a few) and like use that to login to the employee dashboard?

@rusprice
Copy link
Contributor

Possibly?

@ghost
Copy link
Author

ghost commented Oct 25, 2020

ye hmmm

@ghost
Copy link
Author

ghost commented Oct 25, 2020

Ok so Co-CEO email
Screenshot_2020-10-25_121110.png

@ghost
Copy link
Author

ghost commented Oct 25, 2020

a dev

Screenshot_2020-10-25_121349.png

@rusprice
Copy link
Contributor

Found a list of all the help center API endpoints.

@rusprice
Copy link
Contributor

Get all tickets - https://prodigygame.zendesk.com/api/v2/tickets.json

@rusprice
Copy link
Contributor

This endpoint is for agents only

@rusprice
Copy link
Contributor

Here's the entire API documentation for zendesk support pages, https://developer.zendesk.com/rest_api/docs/support/tickets#list-tickets. The API base URL for Prodigy is https://prodigygame.zendesk.com/api/v2/

@ghost
Copy link
Author

ghost commented Oct 25, 2020

More devs
Screenshot_2020-10-25_121819.png
Screenshot_2020-10-25_121824.png

@ghost
Copy link
Author

ghost commented Oct 25, 2020

ok that's everything RocketReach lets me search, feel free to plug the emails into HaveIBeenPwned

@rusprice
Copy link
Contributor

I posted a comment, look at it.

@ghost
Copy link
Author

ghost commented Oct 25, 2020

oooh ok

@ghost
Copy link
Author

ghost commented Oct 25, 2020

fuck i just realized i lost my canva combolist and one of the prodigy employees is in that breach

@ghost
Copy link
Author

ghost commented Oct 25, 2020

Nathaniel Groce's Gmail is in a bunch of breaches, which looks pretty useful to me ngl. A lot of the breaches had weak hashing so we might get some passwords from this. Now for the hard part: Finding the breaches.

@ghost
Copy link
Author

ghost commented Oct 25, 2020

YESS HES ON NEOPETS BREACH WHICH EXPOSED PLAIN TEXT PASSWORDS

@ghost
Copy link
Author

ghost commented Oct 25, 2020

oooh he's on wattpad too

@ghost
Copy link
Author

ghost commented Oct 25, 2020

Cracked.to or RaidForums are both good places to look for breach combolists. I suggest using a VPN, though.

@ghost
Copy link
Author

ghost commented Oct 25, 2020

kk so im thinking that if prodigy finds this they'll fix the issues and we're screwed. should we take this to Telegram or something similar?

@ghost
Copy link
Author

ghost commented Oct 25, 2020

https://t.me/joinchat/AAAAAFSe3mFvwKnySnBd2w join then add me as a contact and I'll create a "secret" (aka end-to-end encrypted) group dm for the employee hack

@ghost
Copy link
Author

ghost commented Oct 25, 2020

@ArcerionDev ArcerionDev added the Priority: High High priority label Oct 25, 2020
@rusprice
Copy link
Contributor

rusprice commented Nov 4, 2020

I'm going to close this, this is just an API endpoint that doesn't give away employee panel access.

@rusprice rusprice closed this as completed Nov 4, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Priority: High High priority Research Research further into this issue.
Projects
None yet
Development

No branches or pull requests

4 participants