11 ms·
Project Euler Humble Return
- dyoo1979 11y agoIt would be nice if source were provided, so that we can do a whitebox analysis. I don't have confidence that there is one single point of failure here, given that the site has already been compromised multiple times.
- mmanfrin 11y agoEspecially since PE is such a technically simple site. It's login/logout, listing of problems, and confirmation/logging of problem success. It's simpler than the apps that beginning web framework tutorials show how to make.
- giancarlostoro 11y agoWe see lots of projects on HN that get open sourced. It's surprising nobody has made one yet. I've even seen clones to HackerNews open sourced here.
- kiba 11y agoI checked the license. It appears that the content is licensed under creative common attribution non-commercial. I haven't found any indication that the website behind Project Euler is open source or follow open source development processes.
- mathetic 11y agoSo?
- Retr0spectrum 11y agoSo, it's much harder for the community to find and report security bugs.
- zajd 11y agoIt's a shame the maintainer of the site is going to let it fall into obscurity instead of just adopting more modern development practices. edit. Such as allowing people to audit the source of the site as opposed to requesting pentesting.
- ajkjk 11y agoIt's a shame to not be more sympathetic to people with less experience or less time on their hands, especially when they run a widely appreciated site.
- smoyer 11y agoI didn't down-vote you (yet), but I don't understand how asking for security help is the same as letting the site fall into obscurity. What modern development practices would you suggest? Comments like this (sometimes) go half-way. If there's a point behind it, enumerate the ways you think would improve his practices.
- zajd 11y agoIt's less that he's asking for help and more that this has happened multiple times and it's quite clear he should be allowing someone to audit the source code, not just search blindly for attack vectors. It's clear there are issues, it's time to invite some help.
- smoyer 11y agoThen I agree ... having a community of people who can help with the source code is a valid suggestion.
- deleted 11y ago[deleted]
- jimmyhmiller 11y agoMaybe I'm a bit confused, but it doesn't seem by your announcement that you are opening up the source, just inviting people to try and hack. Having the source open would make it much easier to spot security problems.
- logicrime 11y agoHaven't they been wrecked once before this most recent incident? I find it concerning that folks are so eager to rush back into a warzone when they know it's not safe. Piling onto a recovering website after a cyberattack is akin to running back into a field where landmines were found. Maybe somebody was able to remove a landmine or two, but wouldn't it be wiser to just walk around it?
- lukev 11y agoExcept that as long as you use a unique password, and don't give any details that you don't mind falling into the wrong hands, there is absolutely no risk. Unlike, for example, actual mines.
- ghshephard 11y agoThere is a lot of risk going to a compromised website. You are basically inputting potential malware onto your computer, and, if there are zero-days present on your system, handing control of your computer over to a malware author.
- teach 11y agoYes, I'm pretty worried about browsing a website with no ads using Chrome on my Linux machine with uBlock origin and Flash disabled. I think I take greater risks going for a walk in the evening.
- ghshephard 11y agoA random website? Absolutely, 99.999% of the Web is safe. But we're talking about a site which is specifically compromised with malware. With that said - "Linux" is safe by being such a tiny population of the community that browser malware generally isn't written for it. In general, I take it as a given that people have deleted/disabled flash and java plugins a long, long time ago.
- 11y ago
- aesthetics1 11y agoCue thousands of determined hackers descending on Project Euler! It would be great if the community could find the exploit and save the site.
- Zikes 11y agoFinding an exploit doesn't necessarily mean they've found the exploit, unfortunately.
- deleted 11y ago[deleted]
- kelukelugames 11y agoI can't wait for someone to figure out the exploit. Very excited. Go crowdsourcing!
- goldenkey 11y agoWhy is project euler not on github? Yeah..no one's gonna help unless you open-source your project buddy.
- dang 11y agoThat's not nice. It's also plainly false. Lots of people love Project Euler.
- revskill 11y agoHow to down-vote a comment ?
- civilian 11y agoYou click the "down" arrow that's below the up arrow. You also need a bunch of karma, like 500 or a 1000.
- elektromekatron 11y agoWhy is X not on Github is the programmer version of folk getting offended when you don't use Y social network. Also: Github Presence != Open Source Open Source != requirement in asking for help/advice
- fao_ 11y agoOf course, but perhaps the point that most people who try and coerce others into using GH are making, is that the community would be more able and more ready to help them fix vulnerabilities quicker if they had access to the (non-sensitive parts of the) source code. As such we can only trust that the people running the site are taking due notice and patching it correctly -- which, (I hate to say) given Project Euler's track record in the last year or so...
- sfrank2147 11y agoDoes anyone know how Project Euler was storing the passwords?
- krapp 11y agoUsernames cannot contain more than 32 characters and they may only contain upper/lower case alphanumeric characters (A-Z, a-z, 0-9), dot (.), hyphen (-), and underscore (_). Passwords must contain between 8 and 32 characters. My money is on "ineptly."
- uxcn 11y agoIt used to be a salted MD5 hash, but it may have changed.
- krapp 11y agoI would have assumed of course that the size limits were because the passwords were being stored in plaintext in fixed-length fields, but I guess they wanted to make sure they were 'complicated' enough? I guess salted md5 is literally better than nothing. The character limits for usernames, though... smells like a SQL injection issue. Which is an obvious and completely naive thing to assert but they're using PHP so my immediate thought is that they're passing raw userdata into the database as strings.
- uxcn 11y agomy immediate thought is that they're passing raw userdata into the database as strings That was my first thought too. I'd guess that it's a vulnerability somewhere in the code for handling the forums. I would be willing to bet that they could get rid of a lot of the attack surface just by using standard services for certain things.
- krapp 11y agoProbably. If they're not using PDO then that needs to be their first priority, dead stop. After that, maybe looking at their captcha script, because those sometimes have issues if they're not well designed. I don't know where theirs comes from but it doesn't seem to use much obfuscation so it's probably old. After that, Twig. Although judging by a screenshot of the recent hack[0] posted here[1] escaping (and XSS) may not be an issue. [0]https://i.imgur.com/pl22srz.png https://i.imgur.com/pl22srz.png [1]https://news.ycombinator.com/item?id=9990221 https://news.ycombinator.com/item?id=9990221
- klekticist 11y agoDespite the whole situation being rather embarrassing, it seems like they're handling this quite well. Whitehat to the rescue!
- brokentone 11y agoThe ultimate project euler challenge!
- edem 11y agoI don't get it why someone would hack project euler.
- austenallred 11y agohttp://www.hackthissite.org/ http://www.hackthissite.org/ lists "hack project euler" as the final challenge
- elektromekatron 11y agoFor some reason, I have little desire to follow that link.
- phragg 11y agoDo you know who Jeremy Hammond is?
- tedunangst 11y agoYes.
- kachnuv_ocasek 11y agoIs that the guy from Top Gear?
- deleted 11y ago[deleted]
- stevesteve 11y agoWhere does it show this?
- fao_ 11y ago...Hack This Site is a free, safe and legal training ground... It's rather amusing how they claim they're 'legal', then.
- elchief 11y ago
- adamzubi700 11y agohttp://googler700.blogspot.com/ http://googler700.blogspot.com/
- mindcrime 11y agoOK, well, here's an initial observation: 1. Your login page leaks information, as it returns "username not found" if you enter an invalid username. This is a bad idea. Better to simply say "login failed" in any case. Now, thanks to a few minutes of playing around, I have a fairly good idea that "admin" is a valid username on projecteuler.net. For the sake of argument, let's assume that's a real account, and actually has some administrative access... that's a bad idea. "Security through obscurity" is oft derided, but no sense making it easy for the bad guys. Make your admin username "flummoxedrabbit" or something that nobody bothers trying. As it is, I'm hoping this "admin" account is a dummy or a honeypot or something, but if it isn't, I definitely encourage you to change that and quit leaking username validity information. 2. From the limited testing I did, it doesn't appear that you limit the number of failed login attempts. Or if you do, the login limit is awfully high. I tried logging in 10 times and as far as I can tell, I could have kept going. If there really is no limit, it's probably not that hard to brute force your password. There are plenty of scripts and browser plugins to sit there and try to login repeatedly, trying to brute force forms like that. 3. In addition to limiting the number of login attempts, it's possibly a good idea to add a steadily increasing delay before accepting another login try from the same IP address, after each failed login. This will slow down at least some attempts to brute force your password. 4. You could consider some sort of Multi-Factor Authentication setup. 5. You could also consider adding code to do something similar to what fail2ban does, and automatically block connections from an IP where more than X failed logins originate in some period of time.
- function_seven 11y agoRegarding #1, telling the user that their login failed doesn't eliminate their ability to enumerate existing usernames. All they have to do instead is attempt to register a new account with the username they're testing. At some point, the site will have to tell them that the username already exists. #2-#5 are all good points, though, and would help prevent username enumeration as well.
- mindcrime 11y agoRegarding #1, telling the user that their login failed doesn't eliminate their ability to enumerate existing usernames. All they have to do instead is attempt to register a new account with the username they're testing. At some point, the site will have to tell them that the username already exists. Agreed, but I would lean towards giving the bad guys as few tools as possible. If you require a captcha to register, and if you limit the number of registration attempts, you can also cut down on that channel. That's not to say that this stuff is the be all / end all of course. It would probably be better to eliminate username/password combos altogether and do everything with keypairs, but until that day comes...
- daguava 11y agoYou can list what problems you've solved by showing an image generated for you. Ex) https://projecteuler.net/profile/daguava.png https://projecteuler.net/profile/daguava.png But you can also use this to quickly test the status of accounts. For example, I was able to find Euler is an admin account by trying https://projecteuler.net/profile/euler.png https://projecteuler.net/profile/euler.png It tells you it's admin in the image, why? Edit: Wonder if they're exposing some vulnerability with the HTTP 300 Multiple Files they're returning. If you try something like this: https://projecteuler.net/profile/.wat https://projecteuler.net/profile/.wat the page confirms a .htaccess file exists at https://projecteuler.net/profile/.htaccess https://projecteuler.net/profile/.htaccess we also find one at https://projecteuler.net/.htaccess https://projecteuler.net/.htaccess While currently inaccessible, this is significant information leak All directories allow this, so you can do some digging to find what files exist. Edit 2:while logged in, you can enumerate all usernames with a skill level attached by using URLs like https://projecteuler.net/level=1 https://projecteuler.net/level=1 If you try changing the level to a period, the page conveniently tells you there are over 118k users in total (listing the first 10k), and MAY even show accounts without levels, but I'm not sure. Combine this with the profile image URLs above and you may be able to find more admin account usernames if they have levels associated with them.
- mhink 11y agoSo basically, by telling us this, you're completely contravening the request they made that security vulnerabilities be disclosed privately? Kind of a jerk move.
- daguava 11y agoWhile I am kind of a jerk, I haven't made a vulnerability of it yet, just an info leak that may help someone here complete the puzzle.
- colechristensen 11y agoIf this was an essential security library instead of a fun website, this would have been an incredibly irresponsible disclosures. Bug bounty programs searching for security vulnerabilities rarely need completed proof of concept exploits – crashes are enough. You've laid down all of the pieces for someone competent to potentially do some real damage without much work at all, and that's exactly why the request was made not to disclose any further vulnerabilities.
- hamza001 11y agohttp://googler700.blogspot.com/ http://googler700.blogspot.com/
- aikah 11y agoOpen source that site. Vet a few devs to have access to the source to begin with then opensource it. Or even better, let the community rewrite the source from scratch. How hard can it be? and there are often a lot of people willing to contribute to open-source projects.
- tsukikage 11y ago"How hard can it be?" <--- yeah, that's how you end up with vulnerable sites.
- jdiez17 11y agoNot if you make security your number one goal from the beginning. But "letting the community rewrite the site" would be very complicated, especially on a niche website such as Project Euler, where a lot of its users are opinionated and would probably take a long time to reach consensus on anything.
- hn9780470248775 11y agoIf security were really your "number one goal", then you would not create a site at all.
- jeeva 11y agoNumber two after availability, then.
- trengrj 11y agoPart of me learning to code was by going through the challenges on Project Euler and I always get a sense of nostalgia when reading about it. It is a pity it keeps getting hacked. I think that the site owners are more interested in algorithms and mathematics than mundane engineering. It would probably be a good idea to open source the site.
- codyb 11y agoI can't imagine the rationale for hacking projecteuler in the first place. Always a favorite place of mine as well and I still bring newbies to the scene there when I attempt to show them the basics of programming. I guess there's just an asshole for everything when you have hundreds of millions of people online these days. Sucks a bit doesn't it?
- Houshalter 11y agoI am unable to login to my account, so I'm not able to test this. But if I remember correctly this site used a poor captcha. There has been a lot of advancement at captcha breaking software in recent years. If they used some kind of custom captcha to prevent password guessing, then it's not extremely secure.