Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Accidentially comprimised bebo's Music
EH-Net
May 25, 2013, 02:43:25 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Accidentially comprimised bebo's Music  (Read 4545 times)
0 Members and 1 Guest are viewing this topic.
xorf
Newbie
*
Offline Offline

Posts: 4


View Profile
« on: October 16, 2007, 05:19:18 AM »

I was bored, and i was doing some leeching attacks on my own community website, i wanted to test out the new java script and htaccess that i put in place so the divx player could not be embedded on another site and for the videos to be leeched.  Everything worked out well, even with attacks against tamper data.

But in the process i found a dangerous exploit in the community website 

by using tamper data when loading any of the songs on bebo, it should up the sub domain in which the mp3's are loading from, and just be removing a few characters from the end of the absolute url, i was able to get the mp3. I informed  (owner of) but I got no response. 

What other steps would be advisable to take?

Maybe  doesn't believe me or maybe he is just worried now that his "Music" side to has been completely compromised.
« Last Edit: October 16, 2007, 12:25:41 PM by xorf » Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #1 on: October 16, 2007, 09:06:54 AM »

How long did you give them to respond? Generally you want to give the person/company ample time to fix the issue before posting in a public forum. For a site like that, I would say 30 days at least. For a vendor software bug, you should way 60-120 days to allow them to fix it, otherwise its not responsible disclosure. After that, a popular way to take it public is the Full-Disclosure mailing list.

From what your saying, it sounds like its only a misconfiguration of his webserver, allowing users to traverse directories and obtain files illegally. Is that correct?

In the future, you may want to not use the actually domain name either.
Logged
xorf
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #2 on: October 16, 2007, 12:16:56 PM »

Firstly, it would have been nice to point me in the direction of an IT law that explains it. Instead of giving a lecture. I'm not a hacker black/white in any means, i'm just an I.T student who likes web security. This site is based upon ethics, isn't it not?


about a month now.

The audio is controlled by a flash object which in turns streams the mp3 from a directory within a sub domain. this call is controlled by a java script. And from what i can tell there seems to be no fault. It does what it is suppose to do. I'm not prepared to enter the script here or anywhere. I have no right to.

Quote
From what your saying, it sounds like its only a misconfiguration of his webserver, allowing users to traverse directories and obtain files illegally. Is that correct?
  If it was a misconfiguration, then the flash mp3 player wouldn't be able to be embedded on another website, but it. And from research it always was.

I was going to tell him to write the following .htaccess  But as im not to fimilar with Resin server and from what you just said. Im staying away from the topic.


RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?websiteaddresshere(.com(/)?.*$ [NC]
RewriteRule .*\.(mp3|MP3)$ [F,NC]

 
« Last Edit: October 16, 2007, 12:26:05 PM by xorf » Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.053 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.