Want a better experience in Fortnite? They usually involve the player holding a weapon in front of them and attempting to shoot other players or characters. Being a sub-domain of the main epicgames.com domain, this would again prove to be most important for the last stage of our attack. Know what your (potential) clients are thinking, and what they are interested in. For more information, please see our epicIPIP Malus Created by Epic Games, an American video game developer, Fortnite is the game responsible for almost half of their $5bn-$8bn estimated value. Va Resolver. Save my name, email, and website in this browser for the next time I comment. The redirectedUrl parameter is used for redirection as the SSO login completes. Once clicked, with no need even for them to enter any login credentials, their Fortnite username and password could immediately be captured the attacker. IP Tracker Whois Lookup Epic-games.com Who owns Epic-games.com? Also by using tools such as Octosniff and Lanc PCPS to generate a database. With such a meteoric rise in fortune, it is no surprise then that the game had already attracted the attention from cyber criminals who set out to con unsuspecting players. Measure your prospects and customers across complex funnels. In our case, the redirection goes to ut2004stats.epicgames.com with the XSS payload and the Facebook user oAuth token. Just like shown in the. We guessed that this web page is used for presenting tournament statistics sorted by map name/id. Frequently you have to reboot your router for the changes to take effect. If you are having any issues, shoot us an email, Contact MPGH Support. Hope it works for you and for the ones you are going to share this link with after you are successful. By continuing to visit this website you agree to our use of cookies. An IP/DNS/Gamertag Resolver is a server or database on the Internet that converts domain names and Gamertags into IP addresses, and vice versa. With the ability to control the redirctedUrl parameter, we could redirect the victim to ut2004stats.epicgames.com, site that contained the XSS payload: http://ut2004stats.epicgames.com/index.php?stats=maps&SearchName=>