3 ms·
Thanks for the feedback. I agree that not all coding tasks are appropriate for Bountify, and that there'll always be potential pitfalls whenever you outsource b
by bevan 14y ago
Thanks for the feedback. I agree that not all coding tasks are appropriate for Bountify, and that there'll always be potential pitfalls whenever you outsource bits of work. But I'm hopeful coders will recognize those pitfalls and learn to use the tool effectively. Let me know if you have any ideas on how to mitigate those risks you mentioned.
By the way, if there's a security hole in the accepted solution to https://bountify.co/B https://bountify.co/B, you should post a better one or even just mention it- I might tip you for it! :)
- mseebach 14y agoThat's another problem - I'll help you for free because I'm nice and this is HN, but if I'm to consider money as a motivator, $5 (or a tip which must be assumed to be less) is downright offensive. The problem is this PHP: <?php echo @file_get_contents($_GET['url']);?> It does nothing to validate the request, and will trivially proxy any request to not just any webpage in the world, but any file readable to your webserver. What you want is something like: <?php $zip = $_GET['zip']; if (preg_match("/^(^\d{5}$)|(^\d{5}-\d{4}$)$/", $zip)) { echo @file_get_contents("http://www.webservicex.net/uszip.asmx/GetInfoByZIP?USZip=".$zip); } ?> Not tested, but that's the general idea.
- bevan 14y agoThanks for the explanation, no offense intended. My point was that there's a mechanism (imperfect though it may be) to help catch flawed solutions. BTW, the winning solution doesn't appear to have the security flaw you pointed out.