3 ms·
If I think like an attacker I would say a preview would be an even juicier target. I can basically run something on thousands of peoples computers with zero in
by sumtechguy 2y ago
If I think like an attacker I would say a preview would be an even juicier target. I can basically run something on thousands of peoples computers with zero input from them.
- ehutch79 2y agoTheir site isn't going down from an attack. It's running out of resources for normal operations. It's not even a large amount of traffic. not really.
- BlueTemplar 2y agoWhy would it be about running something, rather than just a paragraph of text and a picture ?
- sumtechguy 2y agoThe thing is you are allowing your client to do things without you saying to do it. That means you trust whoever is sending that link. To render you have to run a bit of JS and grab some other URLs. 'running' is probably not a great term for it. In this case if I were an attacker I can basically cause your mastodon client render without the users doing anything. I would call it a possible attack vector. Instead of the originating client rendering it and sending a picture along with the URL, it is telling the other side 'hey here is a URL' then the client own its own going to get a new snapshot. Some sort of render needs to happen for that picture to be created. In the second case that means if I were a sneaky sort I could send a link out to a group and I know an exploit in the mastadon render code I could cause interesting things to happen. I could also use this to attack sites. If I get into a large enough group I could basically spam the group with a bunch of URLs and cause a DDoS to any victim site I want.