Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…
How I "hacked" Dustin Curtis's Posterous.
101–110 of 123 posts
Re: How I "hacked" Dustin Curtis's Posterous.
#102> and they should not let you disable submission checking I realize the security implications of all of the latest Posterous musings. But the fact is if Posterous didn't allow you to disable this I'd stop using their service. Posterous knows this. My use case for Posterous is my phone. It has a nice 8 megapixel camera, and with literally two clicks I can have a picture sent to my Posterous blog. Is it secure? Not at…
Re: How I "hacked" Dustin Curtis's Posterous.
#103Re: How I "hacked" Dustin Curtis's Posterous.
#104We were using posterous fairly often a while back, until my friend got into an argument with the posterous founder. He (my friend) had a few beers and then wrote a stupid message, basically saying that the posterous idea in general was bad (using different words :> ).
Then posterous founder replied saying he was banning my friend. We never found out if he actually followed through- because all of us (~15 guys) stopped using it completely the next day.
We, as users, have many options when choosing where to host our data, and we want services that are useful, secure, ethical, and beautiful.
http://charisma.posterous.com/
This one is not ready for us.
Re: How I "hacked" Dustin Curtis's Posterous.
#105Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…
Yey I'm not getting prosecuted. Good times.
A year or two later, I was interviewing at a company whose product has a similar feature (post todos more or less), and decided to see if I could post to my friends todo list. I was thinking that if I could, I'd post to the guy who was interviewing me's list "Hire Andrew--he exposed a hole." It didn't work on my friends account, and I got an email a couple of minutes later. "I see you were doing some fuzzing, were you able to get any messages through?" I wasn't able to (though I didn't try too hard), and I didn't get the job either. (I ended up with a better job, so it all worked out).
Re: How I "hacked" Dustin Curtis's Posterous.
#106Earlier quoted context omitted.
True, but opening an unlocked door is hardly breaking into a house, yet you'd still get in trouble for it.
Locked or not it's still trespass, which is illegal, in most places.
Re: How I "hacked" Dustin Curtis's Posterous.
#107Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…
Odd, the other Posterous threads are getting buried so quickly. When a new comment is posted in any thread it appears at the top, except for these Posterous threads. Is this damage control on the part of YC? The only other person so far to comment under the co-founder on this thread (at time of writing) is jseeba, who has had very little activity and one of the few comments he's ever made was in a thread called "Ask…
Re: How I "hacked" Dustin Curtis's Posterous.
#108Earlier quoted context omitted.
Yey I'm not getting prosecuted. Good times.
A couple of years ago, I emailed Garry Tan about this very issue after successfully posting to a friend's Posterous. They were only thankful for the heads up and investigated. A year or two later, I was interviewing at a company whose product has a similar feature (post todos more or less), and decided to see if I could post to my friends todo list. I was thinking that if I could, I'd post to the guy who was intervie…
Re: How I "hacked" Dustin Curtis's Posterous.
#109Hey guys. I'm the cofounder of Posterous. Yes, someone did figure out how to post to Dustin's site today. This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing. For the vast majority of users who use gmail, hotmail or…
That would probably improve your security too.
Re: How I "hacked" Dustin Curtis's Posterous.
#110Earlier quoted context omitted.
A couple of years ago, I emailed Garry Tan about this very issue after successfully posting to a friend's Posterous. They were only thankful for the heads up and investigated. A year or two later, I was interviewing at a company whose product has a similar feature (post todos more or less), and decided to see if I could post to my friends todo list. I was thinking that if I could, I'd post to the guy who was intervie…
Well, apparently all you need to break Posterous' security is an SMTP server from 1and1.co.uk