Digg, Delicious, Netscape & Technorati Hacked
March 31st, 2007or “A Javascript To Rule Them All“
LMAO I didn’t look at the date, excuse me but this is no April Joke
Hello visitor! I am very proud to present you the work I’ve done during the last few months: The Creation of a new XSS Worm affecting the popular Social Bookmarking and Blogging platforms del.icio.us, Digg, the “new” Netscape and our friends at Technorati.
Probably you know the phenomenon called “Digg Effect”: Tons of traffic caused by a high ranking on a Social Bookmarking Platform, and because of that a shitload of visitors bringing your servers down, the fear of all sysadmins.
With this Script I’m trying to take this to another dimension: Automatically Adding Links, Making new friends and a lot of more Stuff will be done while you’re reading this Post. No, Please don’t leave! Believe me:
I WONT HARM YOU
I WONT STEAL ANY INFORMATION
THIS IS JUST AN EXPERIMENT
TO RAISE WEB 2.0 PROGRAMMERS’ SECURITY AWARENESS!
Why is this just an experiment?
I found hundrets of vulnerabilities in well-known homepages, and this time I took the time to connect some of them in order to get the maximum of fun, plus I really improved my JavaScript skills during this task.
How can I be sure you don’t steal any information from your visitors?
You can be sure of that because I promised it to you, but it would be very easy to get your EMail addresses, your Name, your Cookies and whatever else you’ve ever saved on a homepage containing Cross-Site Scripting (XSS) Vulnerabilities (if I were one of the “Bad Guys”!).
What is your aim?
My aim is to make the Creators of popular homepages aware of their security problems and the technique of proper patching (shouts to the del.icio.us fellow who closed the half of a XSS vuln
). XSS is very dangerous for Web 2.0, and most of the companies don’t care about us whitehats notifying them about vulnerabilities. They just don’t reply, so I discovered the “art” of Full Disclosure.
What can be done using such Combined XSS & CSRF Attacks against Web 2.0 platforms?
- Account and Data theft
- Manipulation of Rankings (like I’m doing right now), followed by on site advertising -> Money
- Destroying a Company’s good reputation (That’s really not my intention, if you feel pissed, drop me a line)
- SPAM via “Tell-a-friend” features and open Mail Scripts/Relays which are existing everywhere (Digg, Delicious, Netscape, Yahoo, bla blub), if I would have used this in my sweet Script, it would be able to spread allover the Digg/Delicious/Netscape communities. You can get all the user information - powered by Javascript (I hope you get the point)
- Other freaky things the bad guys like, but I think I have noticed enough
Where the hell is the script you’re talking about all the time?
Somewhere in the homepage you are currently looking at, not that easy to find, but I think you’ll discover it anyway
And, finally:
Dear Digg / Delicious / Technorati / Netscape Staff!
I Love you. You provide great Social Community platforms which are really entertaining and helpful for us bloggers (Technorati! *hug*).
These few security issues I talked about are not that bad, and I’m sure you’ll fix them ASAP after you were notified. Probably you are going spend more time in QA, but thats nothing I need to tell you.
Best Regards,
- benjamin “beNi” flesch (mybeNi websecurity)
PS: Sorry, I did it all for the pagerank![]()
Now, let the show begin!
Update: Here’s the Digg Link:
http://digg.com/offbeat_news/Digg_Delicious_Netscape_And_Technorati_Hacked
wow I already got a couple of friends
Technorati & Delicious work, too. Only Netscape sucks
Did you Like this Post? Try these ones! :)
Wordpress 2.3 Beta Testing Started on September 2nd, 2007
Re: *****SPAM***** Link Exchange [Advertisement] - A SEO is Spamming me, fuck off! on August 22nd, 2007
Debian Traffic Shaping Script on October 19th, 2007
"Your ActiveX Security Settings Do Not Allow Web Sites" on August 20th, 2007
SEO Title Tag Wordpress Plugin Vulnerability: Cross-Site Scripting in my own Homepage on August 16th, 2007


March 31st, 2007 at 09:34
So how did you do it?
March 31st, 2007 at 09:51
XSS + CSRF are great
and sorry, its no 1st April joke
March 31st, 2007 at 11:13
Impressive. Actually I expected something like this to happen. If you hadn’t done it, it would have been me.
I’ll keep an eye one you
March 31st, 2007 at 11:23
found it with one click =oP, I love the Web Developer extension =o)
about:neterror?e=netReset&u=….
http://del.icio.us/for/‘%22%3E%3C…
http://www.technorati.com/faves/mybeNi?remove=…
April 1st, 2007 at 04:07
It has been fixed (creplyto=)
BTW… Nice “hacks” folder
Really impressive, how did you find them?
April 1st, 2007 at 04:56
cool. Nice one.
April 1st, 2007 at 06:41
I hope it wont be April fool layout. The companies have to pay attention to our research. Even I have undertaken lot of vulnerabilities of premium companies , Yeah so the best solution is Full Disclosure.
Good .
April 1st, 2007 at 08:22
bussin3ss: damn, it took me 3 hours after submitting to get the “final” script workings… that destroyed a lot of votes
perhaps next time I’ll achieve it.
Yes, I love my “hacks” folder, and now I need to get up and make jokes (April muhahaha)
April 1st, 2007 at 02:09
Just one word: NoScript
Latest dev version with anti-XSS countermeasures:
http://noscript.net/getit#devel
April 1st, 2007 at 05:34
where is the code on this page! tis evading me…
October 13th, 2009 at 04:34
[…] Almost a year and a half ago we learned about an undisclosed XSS hole in Digg.com thanks to Beni. He is an outstanding security researcher and author of pretty sick stuff like this Digg, Delicious, Netscape and Technorati XSS Worm. […]