    On December 3, 2012, the Gay Nigger Association of America, both legally and effectively, exploited a XSS vulnerability in popular web-blog service tumblr resulting in the complete ruin of thousands of blogs. Utilising nothing but a few lines of javascript, an estimated 14,000 users reblogged the following post:

    Gnaa tumblr.jpg

    This caused such an outrage that uncounted numbers of news sources ArchiveToday-favicon.pngpicked up the ArchiveToday-favicon.pngstory. While hundreds of users took to other social networks to cry about the personal violation they had endured, the mainstream media was forced to largely ignore this in favor of awkwardly explaining what GNAA stands for. Showing an impressive lack of understanding of the internet, despite it being the basis of almost all of this year's hot shit news stories in one form or another, news sources have settled on describing GNAA as a "racist anti-blogging group", yet another example of straight old whitey trying to spread misinformation about the proud homosexual gentlemen of colour.

    Tumblr is Vuln

    Friendly tumblr staff member Christopher Price

    For those of you without a degree in CSIII, a XSS, or cross-site scripting attack is made possible by a website not properly sanitizing input and thus allowing scripts to be executed on the page of a website. This is one of the oldest methods of web penetration, and should be extinct in 2012. Clearly the hard working development team at Tumblr don't feel the need to patch these obvious and frankly retarded vulnerabilities, instead focussing their attention on being very pleased that Tumblr panels are still a thing.

    There were numerous XSS vulnerabilities identified on the site, including the video post field, which was exploited this time by the GNAA, the image post field, and every single mobile post field.

    Somebody Call the e-Police

    Tumblr was made aware of the issue two weeks prior to the exploit via direct communication. Clearly the Tumblr staff email was down, as the GNAA did not receive a response after helpfully attempting to assist them in securing their services. As such, there was no option but to demonstrate the vulnerability, because the friendly staff at Tumblr would surely want people to know about the problem as soon as possible so that they could promptly fix the issue.

    No accounts or sensitive data were unduly compromised by the uncovering of this security hole, as the "reblog" function was merely utilized. It is best to think of it as a site feature, rather than one of the most popular blogging platforms on the internet showing a startling disregard for the security of its users. It is easier that way. Naturally, the inability of the average Tumblr user to make the distinction between the two has led to many hilarious threats of lolsuits. Good luck with that.

    Twitter-favicon.png Gary_Niger hey you gave everyone on tumbler a virus I could and should sue you! I would have supported you if you would have not done this!


    —This bitch knows the score.

    What did Tumblr do to Deserve This?

    Tumblr does no more than provide a shield of relevance to bloggers of the worst variety. Bronies sharing pornographic images of animals from children's cartoons, Hot-Topic shoppers showing off their latest Invader Zim piercings, and New York hipsters spending 20% of their free time posting their lunches to Instagram can all be found carelessly grazing on tumblr, waiting for the next biggest happening to reblog and share with all (omg) 200 followers. Disgusting. Not only does this filth exist in the stores, schools, and places of work of the world, but is continuing to populate the gene pool, giving birth to even more abominations of mankind.

    Is this truly the future that great visionaries of the past dreamed for?

    Lulzy quotes

    File:Tumblr GNAA.png
    Tumblr are aware though so it's coo.
    Only a few thousand blogs.
    These domestic terrorists ought to be found and executed. They are as dangerous as AQ and we ought to stop treating them as a mild pain in the rump.


    You mean a masterful destruction of private property. Hopefully, you'll be as amused when someone hacks your paypal/bank account.




