20 ms·
How we broke PHP, hacked Pornhub and earned $20k
- watbe 10y agoThis is an elaborate hack and a very detailed writeup. Thanks for sharing.
- Phithagoras 10y agoAppears to be experiencing the hug of death. May be quite slow
- KngFant 10y agoYes, thats sad. There is more discussion about this here: https://www.reddit.com/r/netsec/comments/4u86a4/how_we_broke_php_hacked_pornhub_and_earned_20000/ https://www.reddit.com/r/netsec/comments/4u86a4/how_we_broke...
- expression 10y agoI guess the site is served using PHP.
- cocotino 10y agoThat's funny because in my experience php is one of the fastest languages.
- expression 10y agoMust be a funny comparison group you have there.
- cocotino 10y agoI'm certainly positive it's faster than Ruby, Python and Java.
- geon 10y agoRuby and python aren't exactly known to be fast. In my experience php is fast enough until you start generating lots of garbage. It seems it wasn't really designed to garbage collect at all, but to rely on the per-request cleanup.
- cyphar 10y ago> until you start generating lots of garbage We should really stop pretending that the garbage collector is the problem with langauges. The collector isn't the problem, your garbage is the problem. [Not that I'm a proponent of PHP, though it does make popping shells far more fun.]
- geon 10y agoThe code becomes kind of weird when you have to second guess the language. Now, the approach PHP takes is fine for the original vision of the language. It even works great. But languages designed for long running processes often have some sort of mechanism for dealing with that situation explicitly. Like the `NSAutoreleasePool` in Objective C. In C++ you might build your own custom slab allocator. I'd say the garbage collector is one of the problems with PHP. Then again, if you run into it, PHP might not be the right tool for that particular job.
- smt88 10y agoIt depends on the code base and use case. For the vast majority of coders, the time/cost savings will be in the usability of the language itself rather than the hardware required to run the code.
- percept 10y agoFWIW, it places well across TechEmpower benchmarks: http://www.techempower.com/benchmarks/ http://www.techempower.com/benchmarks/
- jake_morrison 10y agoRaw PHP is reasonably fast. The performance issue comes with loading source files on every request: http://talks.php.net/show/froscon08 http://talks.php.net/show/froscon08 This means that there is a conflict between performance and having a well structured object oriented framework. Demand loaded classes and byte code help a lot with that: http://www.yiiframework.com/performance/ http://www.yiiframework.com/performance/ Best would be a model where a persistent process handles multiple requests concurrently, but that is not normal for PHP. So you need to make sure that all the libraries you are using are not leaking, have a nice db connection pool, and write a PHP framework that handles concurrency. Might as well use a better language at that point :-)
- toast0 10y ago> This means that there is a conflict between performance and having a well structured object oriented framework. What do you need a 'well structured object oriented framework' for? You're going to build up a huge object graph in memory, to output some HTML, and then throw away all the objects at the end of the request. Nobody is going to see your beautiful object tree, so don't bother. A blog entry page should be super simple. header, title, content, comments, recent comments, footer. Header and footer are dead simple echos of the boilerplate, maybe replace in the html title or something. Read the title and content from disk[1]. Have another data file for all your articles for the index page. I prefer not to have comments on my blog, but if you must, you can put them in a database; limit to something like 100 or 1000 comments per article (because really) and limit threading, and it's going to be pretty quick to query them (make sure your webserver is doing reads from a database in the same metro area, if not on the same box). Recent comments is across all blog entries; I would probably add a index on the time in the comments table and just select 2 from there; you could union that into the earlier comments query if you don't want to make two round trips to the database. You don't need to do this with concurrency, each page load has barely anything to wait for, so more threads doesn't help throughput. Run enough php workers (php-fpm, or apache children if you're using apache_mod_php) to keep your cpu busy, and you're golden. [1] There's four articles on this blog -- it doesn't need a database. PS run php as a user that can't write anywhere on the disk, and push the blog entries and the summary datafile with another user. Edit to add: If you skip comments (or outsource to disqus or some other comments w/ javascript platform), you can make the whole site just static html, and leave PHP at home. OTOH, these guys are running Wordpress, because they like frequent security updates?
- aw3c2 10y agohttp://web.archive.org/web/20160723130827/https://www.evonide.com/how-we-broke-php-hacked-pornhub-and-earned-20000-dollar/ http://web.archive.org/web/20160723130827/https://www.evonid...
- danso 10y agoOT: Is there a site that curates these kinds of interestingly detailed hacks? Like Dan Luu does for debugging stories? (https://github.com/danluu/debugging-stories https://github.com/danluu/debugging-stories)
- ssclafani 10y agoThe r/netsec subreddit: https://www.reddit.com/r/netsec/top/?sort=top&t=all https://www.reddit.com/r/netsec/top/?sort=top&t=all
- zaroth 10y agoInterestingly, I've noticed just about every well upvoted story on /r/netsec will hit the HN front page 2-3 days later.
- sbierwagen 10y agoArbitrage opportunity there: submit them to HN yourself.
- danso 10y agoI've been guilty of doing that before. Also, from top r/reverseengineering, though that subreddit is a little less traveled so doesn't get as many comments, so it's interesting to read what HNers think.
- __david__ 10y agoSome sort of "hack news", maybe. :-)
- cloudjacker 10y agowow From a legal perspective how do companies and hackerone create a binding exemption from laws used to prosecute hackers?
- ihsw 10y ago> binding exception Two words -- honor code. Rock the boat and you will find yourself in an unpleasant situation, so instead everybody does good work and nobody asks too many questions.
- AYBABTME 10y agoHonor codes for stuff that traditionally involve corporations going after individuals for criminal charges. I feel that's a bit of a crazy proposition.
- jessaustin 10y agoMost people would probably expect Pornhub to be more honorable than e.g. AT&T...
- mdholloway 10y agoCrazy indeed, but it happens to be the case. http://blog.erratasec.com/2015/05/how-to-fix-cfaa.html http://blog.erratasec.com/2015/05/how-to-fix-cfaa.html
- smt88 10y agoWhen people say "honor code" around me, it usually means, "Do something honorable, even though it's against your self interest." For both white hats and Pornhub, the legal/authorized bounty system is in their interest. White hats are making less money than some black hats, but they're not constantly terrified of being prosecuted under intense anti-hacking laws. Pornhub is spending a lot less than they would if they were hacked by black hats. Both parties win.
- celticninja 10y agoPornhub have active bug bounties. In general you have to sign up to abide by the rules, which generally say how far you can take an exploit, ie prove it works but don't fuck with the actual data just to show you can. Your exploit would show that you could and that's what they want you to do.
- krapp 10y agoThe takeway: You should never use user input on unserialize. Assuming that using an up-to-date PHP version is enough to protect unserialize in such scenarios is a bad idea. Avoid it or use less complex serialization methods like JSON.
- CiPHPerCoder 10y agoEven JSON isn't great. It's still a hash-collision DoS attack vector. https://paragonie.com/blog/2016/04/securely-implementing-de-serialization-in-php https://paragonie.com/blog/2016/04/securely-implementing-de-...
- nickpsecurity 10y agoDude, that's horrific. I figured some secure coders wouldve at least implemented a better JSON one by now since it's relatively simple. Or are they already available but dev's often rely on these broken ones?
- justinlardinois 10y agoHash functions designed for hash tables are generally not hard to find collisions for, so there's not much that can be done. You could shoehorn in a secure hash function, but that would hurt performance.
- perlgeek 10y agoYou can randomize some parameters of the hashing function when you detect too many collisions. Which makes a DOS much harder. The Perl interpreter has been doing that for ages.
- nickpsecurity 10y agoI was thinking more on lines of (a) does JSON handling need hash tables and (b) if do, do they have to be open addressing or something vulnerable to DOS? A No on either can lead to an implementation with better DOS resistance.
- ndesaulniers 10y ago> Using a locally compiled version of PHP we scanned for good candidates for stack pivoting gadgets Surprised that worked. Guess they got lucky and either got the comiler+optization flags the same as the PHP binary used, or the release process can create higly similar builds.
- chatmasta 10y agoThey mention that PH had a custom compiled PHP and that's why they couldn't get the address of the function they wanted to call for evaluating code. My understanding is that ROP gadgets are a separate issue. Basically you want to find a function that compiles to assembly instructions resembling the ones you need to move the stack pointer to your desired location. Testing this locally shouldn't be a problem, because functions across builds will compile to the same assembly instructions (even if their headers have different load addresses). Again, that's my understanding - I have a very vague grasp of this stuff.
- fencepost 10y agoSo does Pornhub's bug bounty program include some number of years of free paid membership along with financial bounties? Kind of a "treat us right and we'll let you treat yourself right" kind of thing?
- seanp2k2 10y agoIf you know enough to be able to pull off hacks like this, you surely know enough to get more of this kind of thing than you'd have time to watch in 10 lifetimes. I doubt that such a "reward" would be very appealing to those who participate in the bug bounty program, and it'd honestly be a sleazy business proposition, which would harm the professionalism of operating a successful bug bounty program. And yes, I'm completely serious.
- fencepost 10y agoI'm glad you were serious, because frankly I wasn't. I'm sure there's more than enough "free" porn out there for just about anyone's taste, so I doubt that free accounts would be a significant incentive anyway. But meh, sometimes jokes fall flat.
- ckdarby 10y agoThat moment when the company you work at is on the front page of Hacker News xD
- nitrix 10y agoI feel you and I know each others ;)
- brettz 10y agoNah
- khoury 10y agoSeriously, please do an AMA. As a developer, I am very curious about how it feels like working for a company like that :)
- ymse 10y agoSome other Pornhubbers did one 2,5 years ago: https://www.reddit.com/r/IAmA/comments/1un3wn/we_are_the_pornhub_team_ask_us_anything/ https://www.reddit.com/r/IAmA/comments/1un3wn/we_are_the_por...
- ckdarby 10y agoIn terms of working at the company, aside from the adult content on people's screen, discussions of adult content, etc it is honestly no different than working at any large company.
- tjallingt 10y agoI have some questions about two things in the exploit code that puzzled me: my $php_code = 'eval(\' header("X-Accel-Buffering: no"); header("Content-Encoding: none"); header("Connection: close"); error_reporting(0); echo file_get_contents("/etc/passwd"); ob_end_flush(); ob_flush(); flush(); \');'; 1. they seem to be using php to code the exploit (solely based on the $ before the variable name) but i've never seen the 'my' keyword before, what exactly is this language? 2. if i understand the exploit correctly they got remote code execution by finding the pointer to 'zend_eval_string' and then feeding the above code into it. doesn't that mean the use of 'eval' in the code that is being executed is unnecessary?
- anglebracket 10y ago>i've never seen the 'my' keyword before, what exactly is this language? It's Perl: http://perldoc.perl.org/functions/my.html http://perldoc.perl.org/functions/my.html
- Xeago 10y agoLooks like perl, seeing the `my`.
- joeldg 10y agoThey could have sold those 0-day's and made 10x the money
- aprdm 10y agoReally good write up. Some people are really smart, I wouldn't ever be able to do that kind of stuff even after being programming for years.
- i_am_cam 10y agoAs well as being good, they'll also be very experienced. What you're seeing in that post is specialised knowledge, likely built up over many years. We can't all know everything, as much as we'd like to!
- given 10y agoToo bad they didn't just go ahead and: > Dump the complete database of pornhub.com including all sensitive user information. And of course leak the data to expose everyone that participates in this nasty business. It is such a sad thing that people are even proud to work at companies like this where humans are not worth more than a big dick or boobs. And then you get around and say that child porn is so horrible. No, all porn is horrible and destroys our families and integrity. How can there be any dignity left if these things are held to be something good?
- Annatar 10y agoRighteous much? The most insidious prison one could ever be put into is the arbitrary restriction in one's own mind. Luckily for the rest of us, we are in the 21st century and most people are educated enough to not believe in nonsense like witches any more. Pornography is heading in the same direction, people are finally starting to realize that sexuality is part of one's natural self. When you consider that each of us was born with a dick or tits, there is nothing wrong by accepting that and getting turned on by appreciating the aesthetics of it. It has been done since antiquity and even before that, and then we regressed into the dark ages of morality. At the very least, it is biology. Science? Yes please!