Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Thursday, 28 June 2012

Even More Teething Problems For Menshn

Following on from my previous post on Menshn Syn0nymph has yet again uncovered another security flaw in the website
Worryingly you can still use someone else's email address to get into Menshn. How? Register with a valid email/and receive a confirmation email which validates you own account. Open mail and click the link and you can then log in and use Menshn to your hearts content.

You can then, if you were of a mind to, edit your profile and change your email login and user name to anything you like. Logout and then login again and instead of being prompted to click on an email confirmation confirming your email change etc you will find you can continue to use Menshn as usual unprompted and without any validation. I just did this and I now have an account called //BobDiamond, using his email address to access Menshn!
So yet another reason to wait a while before you open your Menshn account.

You can contact the author on Twitter @brown_moses or by email at brownmoses@gmail.com

Wednesday, 27 June 2012

More Teething Problems For Menshn

By now I'm sure you've all heard of new social network Menshn, founded by Conservative MP Louise Mensch, as a sort of alternative to Twitter, except with many more security flaws.  Twitter user Syn0nymph has been uncovering a number of issues with the site, and has just uncovered a fresh set of issues:
Last night I flagged issues with Menshn not having email validation as I was able to register for an account using someone else's email address and by just making up a dummy email address. I am pleased to see that this issue has now been fixed.

However, I felt the process had to be tested and so I again set up an account using a dummy, non-existent email address and as expected got a screen up on Menshn telling me that I needed to validate my email address by clicking on the link which had been sent to me before I could use the site and it's features etc.

Now, as I had made the email address up, I was never going to get a link to click was I? So I assumed that I would not be able to use any Menshn features at all until I had validated the email address. I was wrong and I could. I could not get into any of the topic rooms to post anything which is good but I was able to do all of the following:

1.Use the User Search facility
2.Subscribe to other Menshners
3.Send a Menshner a DM
4.Mute a Menshner
5.See who another Menshner's subscribers were
6.Invite my friends to join via entering their email addresses

Guess Mr Bozier still has some work to do...
So it seems that Menshn still has quite a while to go before it's a fully functioning site, something that should have really been resolved before the site was released in the UK, especially as the past security issues may have left it's users vulnerable to malicious attacks.

You can contact the author on Twitter @brown_moses or by email at brownmoses@gmail.com

Monday, 14 May 2012

Did the Leveson website team ignore warnings about the risk of being hacked?

Following on from my earlier post about the Leveson Inquiry website hack I've been sent a copy of an email sent to the Leveson Inquiry website team that warns about the dangers of having open directories on the Leveson website:


As this post on the Something Awful forum shows directories were still open right up until the attack, so obviously the warning wasn't heeded
I have to admit, I noticed the wp-content folder and subfolders allowed directory listing a while ago. Didn't tell anyone, it was useful for checking when new stuff had been uploaded. They've fixed it now though.

Was the Leveson website hacked through a weakness in WordPress? - UPDATE 2

This afternoon is appears that the Leveson Inquiry website has been under attack by hackers, forum poster zlyche on Something Awful has a theory on how it may have been done:

Just putting up what information I ascertained before the site went completely down.
The server itself ran Apache 2.2.14 - out of date (Recommended is 2.2.22). Advisories

Clues as to a Wordpress backend:

  • A 'wp-content' exists, with further subdirectories holding images
  • A response from the search on the website stated "Welcome to WordPress. This is your first post. Edit or delete it, then start blogging!"
  • This comment on the website: "<!-- This site is optimized with the Yoast WordPress SEO plugin v1.0.3 - http://yoast.com/wordpress/seo/ -->"
  • This link also told us what the search backend was, and its version"<link rel="stylesheet" id="faceted-search-css" href="http://www.levesoninquiry.org.uk/wp-content/plugins/bang-faceted-search/faceted-search.css?ver=3.2.1" type="text/css" media="all">"
The nail in the coffin that this is a group going after the site for a while though:

http://pastebin.com/jfxqZQQr

This shows someone found the Wordpress login to the site. Not only that, it has a password reset feature.

Given that, it is my opinion that the most likely way the got into it was through Wordpress. Be it through a vulnerability in the search engine or weakness in the password authentication system.

Surprised that the HTTPS section was up for so long.
Looks like the group involved has been working on this since at least late Febuary according to the date on the Pastebin files, guess it time for Leveson to invest some time into investigating website hacking too.

UPDATE

Another Something Awful forum member pointed out directory listings were allowed on the Leveson Inquiry website,
I have to admit, I noticed the wp-content folder and subfolders allowed directory listing a while ago. Didn't tell anyone, it was useful for checking when new stuff had been uploaded. They've fixed it now though. 
 zlyche replies:
They allowed directory listing? Ouch. No wonder this ended up happening. Basic security seems to have gone the wayside there. Given the speed at which the site was brought back up I'd hasten to say that it was a weak password. When I state a weakness in the password authentication system this also includes the credentials of the user itself.

As said, the time the site has taken to get back up shows that the administrators do not believe it to be a vulnerability in the site itself. If it were the case, the site would not be back to its current state so soon. To that end, its likely that they simply changed the password. Emphasising this point is that the Wordpress Login area is still present.
Some pretty poor security by the Leveson website team there.

UPDATE 2

Something Awful forum member zlyche has done a bit more investigating:
I did a tiny bit more legwork. Here is the limited information so far:

Starting from the 12th the group start mentioning #OpLeveson. Later posts that evening show that the group, having confirmed their capacity to takedown the site, are re-enacting it as a show of power.

They seem to have a tendency to use DDoS-based attacks, reminiscent of most Anon approaches to websites. Given how the site looked earlier however, a removal of files seemed to have occurred. That is, a blank root directory was shown. Encouraging this over another possibility - dns poisoning - is that when the HTTP version of the site was down in this regard, the HTTPS version was still up.

Read into it what you will, however information must be obtained on when precisely the site went down. I was under the misunderstanding that this was at 14:46~, which would have been significantly earlier than AnonATeam's announcement. However I cannot find a reference to this.

It seems very likely that someone involved in the DDoS operation over the weekend was involved in this attack. Focus was already on the site by the group, and if one of them got overenthusiastic and successfully gained access it would explain events somewhat. This could be proven wrong with identical attempts at access on the other targeted websites - showing an M.O of the group rather than of a specific individual within.