4 ms·
Show HN: Upload any file
- plugnburn 11y agoNice idea, nice design, horrible code behind it. Just a look at rtu.js made me cry. Never mix logic and presentation. Especially in such security-crucial projects. I don't know what is the server side written in but it seems horrible too: I managed to upload the same file twice and returned a link in the same directory but with different names (boomer.mid and boomer(1).mid). So it's possible to flood all the server space with the same file unlimited amount of time. This is definitely a security issue. Also, a name mustn't change over time: my (or anyone else's) next boomer.mid upload mustn't become boomer(2).mid. I haven't tried it yet but I hope server-side filetype validation is also present? Otherwise the server is going to have big troubles over time...
- plugnburn 11y agoWell, I found what the server side is written in. In fact, I found everything about your server. Why? Because you, sir, do not know a thing about server security and configuration - this is the file I managed to upload: http://updrop.it/uploads/info.php http://updrop.it/uploads/info.php I will not hack your server but someone else definitely will, so you have to either close this hole ASAP (disable PHP file uploading) or take the service down.
- devbob 11y agoHey please shoot me an email if your interested in any paid work, thanks
- DanBC 11y agoYou need to put your email address in the "about" field of your profile for other people to see it.
- plugnburn 11y agoI'm not interested in any paid work. I'm trying to say that your entire server is vulnerable to hacker attacks right now. It seems strange that you posted a vulnerable website on Hacker (!) News... Or do I need to post my message on the index page of your site for you to get how critical the vulnerability is? If so, which one? Updrop.it, torrbin.com or noteworthyfacts.com?
- devbob 11y agoNo problem, its an mvp, looks like I need to hire a dev!, thanks.
- plugnburn 11y agoSo Updrop wasn't made by you and you hired a dev to create it?
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- fiatjaf 11y agoThat's crazy. Are you going to HIRE A DEV for fixing a proof-of-concept app like this? Stop. This is where you should be learning to do things, not hiring a dev for writing such simple small apps for you. Since you're learning right now, find a framework (best if not PHP, but it can be a PHP framework) and follow the tutorial. You'll learn some "backend", and you'll learn it with best practices and with things in the right place.
- tacone 11y agoWorth of mentioning: during the earliest years of Facebook, some guy managed to hack in and expose some source code. When they did, everybody was like "oh, how can such crappy code power a successful service like that?" Security is very important, but totally unrelated to good business sense. :)
- plugnburn 11y agoIt's related to the intentions this guy had in his head. If someone would find this vulnerability in Updrop after plenty of files were uploaded and the service became popular, compromising the security with any evil intention would bring a disaster. Now that PHP file uploading is already closed both at the client and server sides, it became relatively safe to operate. Although, until filename(1), (2) etc issue is fixed, this service isn't worth any serious consideration anyway. Too many newbie mistakes here. Update: this seems to be fixed too for now (not a perfect variant, as the original name is lost forever, but a plausible solution that's much better than it was). Nice!
- devbob 11y agoHey, I appreciate your vigilance, thanks