3 ms·
That is a massive hole. Very nice find. I hope you notified the ad network of this before you posted it though, responsible disclosure of these things is import
by loopdoend 15y ago
That is a massive hole. Very nice find. I hope you notified the ad network of this before you posted it though, responsible disclosure of these things is important because this hole can now be used by anyone to do pretty much anything. The most obvious thing that comes to mind is a spammer using this to redirect traffic through a third party domain which is whitelisted.
- kemayo 15y agoThey were a bit lacking in an obvious right person to email[1], but I did send a quick "hey there's a problem" note. I almost didn't when I saw that their main "contact us" page was a "opt in for us to email you" form, but then I found some actual email addresses rather further down. [1]: http://www.eyewonder.com/contact.php http://www.eyewonder.com/contact.php
- GICodeWarrior 15y agoI just sent an email to sitesupport@, websites@ (both from whois), abuse@, noc@, webmaster@, security@ (from RFC2142). Generally you should attempt to receive a response before posting vulnerabilities though...
- kemayo 15y agoPast experience dealing with ad networks about this issue has led me to believe that they really don't care. Multiple networks, multiple framebusting scripts they want you to host, all with blatant security holes that they don't want to fix after you (as a client) point them out. Or maybe it's that the people in the organization who might care are completely insulated from the channels available to people who are dealing with the network as a client. Hard to say.