Potential DevForum Login Vulnerability

They’re already busy with it, as I see a lot of secret hidden stuff roblox is working on.
(And it all points to twofactorverification huehuehue)
(You’ll actually have to enter a code you receive somewhere else)

At this point, 2 step auth needs to be Top-priority, as well as fixing these security issues.

1 Like

just a thought, but maybe one of us could setup as a bait account, and try to find out how he/she does it? If it’s truly related with the sso, then they should be able to access any account. As to why they don’t aim for an administrative account, it would compromise their exploit as roblox would make it top priority to fix. So instead, they’re targeting famous/semifamous accounts. If you know your ULimiteds ids, try and keep track of what accounts they split off to. Eventually, they’ll end up on the targets main.

Doubt that would work, the people getting compromised are pretty specific.

Some admin accounts also have 2 Layer Authentication. (One admin had to use his phone for a code during The Next Level, I think it was Tone.)

I’m aware this, but I think thats only required for accessing the admin panel, not to login under the account.

It’s used for login I’m pretty sure, as Tone was logging in during the livestream, I don’t think they would show him logging into any sort of admin panel.

Vetex got a few password reset emails, but I told him not to click any and check if he’s still logged into the site, and he was. I’m suspecting these are fake emails.

1 Like