Benjamin Flesch = definitely rocks.”> Digg, Delicious, Netscape & Technorati Hacked ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

Digg, Delicious, Netscape & Technorati Hacked

March 31st, 2007

orA Javascript To Rule Them All

LMAO I didn’t look at the date, excuse me but this is no April Joke ;-)

Hello visitor! I am very proud to present you the work I’ve done during the last few months: The Creation of a new XSS Worm affecting the popular Social Bookmarking and Blogging platforms del.icio.us, Digg, the “new” Netscape and our friends at Technorati.

Probably you know the phenomenon called “Digg Effect”: Tons of traffic caused by a high ranking on a Social Bookmarking Platform, and because of that a shitload of visitors bringing your servers down, the fear of all sysadmins.

With this Script I’m trying to take this to another dimension: Automatically Adding Links, Making new friends and a lot of more Stuff will be done while you’re reading this Post. No, Please don’t leave! Believe me:

I WONT HARM YOU
I WONT STEAL ANY INFORMATION
THIS IS JUST AN EXPERIMENT
TO RAISE WEB 2.0 PROGRAMMERS’ SECURITY AWARENESS!

Why is this just an experiment?
I found hundrets of vulnerabilities in well-known homepages, and this time I took the time to connect some of them in order to get the maximum of fun, plus I really improved my JavaScript skills during this task.

How can I be sure you don’t steal any information from your visitors?
You can be sure of that because I promised it to you, but it would be very easy to get your EMail addresses, your Name, your Cookies and whatever else you’ve ever saved on a homepage containing Cross-Site Scripting (XSS) Vulnerabilities (if I were one of the “Bad Guys”!).

What is your aim?
My aim is to make the Creators of popular homepages aware of their security problems and the technique of proper patching (shouts to the del.icio.us fellow who closed the half of a XSS vuln ;-) ). XSS is very dangerous for Web 2.0, and most of the companies don’t care about us whitehats notifying them about vulnerabilities. They just don’t reply, so I discovered the “art” of Full Disclosure.

What can be done using such Combined XSS & CSRF Attacks against Web 2.0 platforms?

  • Account and Data theft
  • Manipulation of Rankings (like I’m doing right now), followed by on site advertising -> Money
  • Destroying a Company’s good reputation (That’s really not my intention, if you feel pissed, drop me a line)
  • SPAM via “Tell-a-friend” features and open Mail Scripts/Relays which are existing everywhere (Digg, Delicious, Netscape, Yahoo, bla blub), if I would have used this in my sweet Script, it would be able to spread allover the Digg/Delicious/Netscape communities. You can get all the user information - powered by Javascript (I hope you get the point)
  • Other freaky things the bad guys like, but I think I have noticed enough ;-)

Where the hell is the script you’re talking about all the time?
Somewhere in the homepage you are currently looking at, not that easy to find, but I think you’ll discover it anyway ;-)

And, finally:

Dear Digg / Delicious / Technorati / Netscape Staff!

I Love you. You provide great Social Community platforms which are really entertaining and helpful for us bloggers (Technorati! *hug*).
These few security issues I talked about are not that bad, and I’m sure you’ll fix them ASAP after you were notified. Probably you are going spend more time in QA, but thats nothing I need to tell you.

Best Regards,
- benjamin “beNi” flesch (mybeNi websecurity)

PS: Sorry, I did it all for the pagerank :)

Now, let the show begin!

Update: Here’s the Digg Link: http://digg.com/offbeat_news/Digg_Delicious_Netscape_And_Technorati_Hacked
wow I already got a couple of friends ;-) Technorati & Delicious work, too. Only Netscape sucks :(




11 Responses to “Digg, Delicious, Netscape & Technorati Hacked”:

  1. Bob Says:

    So how did you do it?


  2. beNi Says:

    XSS + CSRF are great ;-)

    and sorry, its no 1st April joke


  3. christ1an Says:

    Impressive. Actually I expected something like this to happen. If you hadn’t done it, it would have been me.

    I’ll keep an eye one you ;)


  4. CrYpTiC_MauleR Says:

    found it with one click =oP, I love the Web Developer extension =o)

    about:neterror?e=netReset&u=….
    http://del.icio.us/for/‘%22%3E%3C…
    http://www.technorati.com/faves/mybeNi?remove=…


  5. busin3ss Says:

    It has been fixed (creplyto=)

    BTW… Nice “hacks” folder :)

    Really impressive, how did you find them?


  6. hackathology Says:

    cool. Nice one.


  7. Zeroknock Says:

    I hope it wont be April fool layout. The companies have to pay attention to our research. Even I have undertaken lot of vulnerabilities of premium companies , Yeah so the best solution is Full Disclosure.

    Good .


  8. beNi Says:

    bussin3ss: damn, it took me 3 hours after submitting to get the “final” script workings… that destroyed a lot of votes :-( perhaps next time I’ll achieve it.
    Yes, I love my “hacks” folder, and now I need to get up and make jokes (April muhahaha)


  9. NoScript Says:

    Just one word: NoScript :)

    Latest dev version with anti-XSS countermeasures:
    http://noscript.net/getit#devel


  10. Chris Says:

    where is the code on this page! tis evading me…


  11. How We Gamed Digg for Fun and Profit! | I Can Has Rankings? Says:

    […] Almost a year and a half ago we learned about an undisclosed XSS hole in Digg.com thanks to Beni. He is an outstanding security researcher and author of pretty sick stuff like this Digg, Delicious, Netscape and Technorati XSS Worm. […]


Leave a Reply


Google Traffic (7 days)

550
500
450
400
350
300
250
200
150
100
50
473
476
460
510
536
515
477
38.107.191.88