9 ms·
Ask HN: Has Hacker News been hacked/cracked?
It seems like you can change the about field under PG's account http://news.ycombinator.org/user?id=pg using this appjet app
http://notabank.appjet.net/
- chanux 18y agoOf course it was hacked... By the creator of it :). That's why other hackers find it interesting. For the question whether it's cracked... I dunno but nothing is perfect.
- chanux 18y agoLooks like the hackers don't understand that Hacker News is a nice hack altogether.
- markokocic 18y agoNice and insucre one. Anyways, the fact it is hacked drove some nice traffic to HN from reddit :)
- pmikal 18y agoCertainly seems like it.
- GeoJawDguJin 18y agoThere are a lot of bogus links showing up on the front page with obviously falsified vote counts (numbers starting with the digits "1337"). I'd say, yeah, it's been seriously compromised.
- jwb119 18y agoRe: 1337 http://en.wikipedia.org/wiki/Leet http://en.wikipedia.org/wiki/Leet
- erlanger 18y agoWe know.
- The_Sponge 18y agoYes, that's the joke.
- unalone 18y agoYes, it has been. Looks like the site had some major vulnerabilities. I emailed PG, if he didn't know already, and slowly some of the things are being fixed back. PG's account is still vulnerable as of this posting. EDIT: No it's not.
- deleted 18y ago[deleted]
- pelle 18y agoI caught it here: http://skitch.com/pelle/beksu/hacker-news-hacked http://skitch.com/pelle/beksu/hacker-news-hacked
- deleted 18y ago[deleted]
- Spyckie 18y agohttp://source.notabank.appjet.net/ http://source.notabank.appjet.net/
- kqr2 18y agoJust in case the original app gets taken down, I copied the source to pastebin: http://pastebin.com/f1a67398f http://pastebin.com/f1a67398f
- markbao 18y agoWhoever did this, please post a Tell HN or otherwise an article on how you did it. I'm sure others are curious (and would make a good starting point for patching Arc) From the source, it looks like there was a vulnerability in which the fnid (I'm guessing a string that authenticates a user to edit an item?) was searched for on PG's profile page (using the regex /<input type=hidden name="fnid" value="([^"]+)">/. Then a POST request was made on the standard profile saving resource news.ycombinator.com/x, with the fnid which authenticated the user's permission to edit the page, along with the about text, as parameters. Edit: PG says the fnid just points to a closure on the system. See above. Which means... all you needed was a randomly generated fnid, and that's all that you needed to edit anyone's page. Apparently? Clever, or just poor authentication design. But that's only one half of the exploit. How were the points done? I'm going to rule out millions of accounts created.
- unalone 18y agoI'm going to disagree. Chances are it was XSS or - shudder - simple injection. It was a basic vulnerability and it got fixed. We don't need to know the details - though I'd like if whoever did this got banned for a while for being an obnoxious jerk. (When you think about it, this was pretty simplistic. All anybody did was edit text fields on the site. That hints it was injection.
- deleted 18y ago[deleted]
- IHackedHN 18y agoThe points were editable through similar means. Pages like http://news.ycombinator.com/edit?id=519433 http://news.ycombinator.com/edit?id=519433 contained a form that allowed all of a story's details -- including title, url, and score -- to be edited. Just like with profiles, the story editing forms didn't have fields for non-admins, but just like with profiles, it was possible to submit a request with the fnid from the form regardless of admin status.
- pg 18y agoYes. I made an unbelievably stupid mistake in the code that generates forms with labelled fields. It was basically functional programming taken a little too far: I generated the same form whether the fields were editable or not, and then later if there were no editable fields I just omitted the submit button. So anyone looking at the source of one of these pages could find a fnid that would work to modify the object displayed on it. (There's still a fnid, but it no longer does anything.)
- unalone 18y agoThat would suggest, then, that the comment points and submission points are also controllable within some form, since they were tampered with also. Is that the case? (I'm not asking because I don't believe you - I'm just wondering how those numeric fields were altered.)
- suhail 18y agoAlmost sounds like SQL Injection, perhaps no escaping on fnid?
- markbao 18y agoEdit: I'm wrong, see below. If I'm not mistaken, that had nothing to do with SQL injection. The fnid basically was the authenticator that allowed a person to edit a page, regardless of who was logged in. What about other HN-powered Arc sites? Are they vulnerable as well? I won't name names, because I'm guessing they are indeed vulnerable. Edit: Yes, they are.
- joshuaxls 18y agoYes, it was hacked. Here's the original post from a lesser hack earlier today with pg's response containing the "not a bank" quote: http://news.ycombinator.org/item?id=518752 http://news.ycombinator.org/item?id=518752
- nx 18y agoOkay, trust doesn't work as well as correct security measures. That's sad, but true.
- sho 18y agoDodged a bullet there I'd say. At least your "hacker" seems to be a reasonable guy. Seems like he could have done a lot more damage. I hope your backups are up to date and verified recoverable; a more malicious intruder might not be so kind. While I appreciate and admire the sentiment that this is a "community of trust", security still must be taken seriously. There are plenty of guys out there with the ability to pull such tricks; they may not care about trust, and the website is accessible to anyone, good or bad.