Live data from Hacker News

Tumblr security hole (the gaping kind)

news.ycombinator.com

31–40 of 85 posts

Re: Tumblr security hole (the gaping kind)

#32
I didn't know what Tumbler is and I created an account just to confirm the hack (the security hole is still there). But this got me thinking about another post at HN on how to market your site - I guess a blatant (fake?) security hole is one way to do it.

Re: Tumblr security hole (the gaping kind)

#33

Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.

I just shot them a mail to let them know.

Ironically they don't obey one of the primary rules of usability for websites: have a link to contact info on the front page.

Re: Tumblr security hole (the gaping kind)

#36
post #3

If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....

I can believe they stuck their admin at /admin, but it's hard to believe they didn't create an admin bit as part of the users table and check it to access /admin. That takes about 2 minutes if you do it when you create the system. Oh well, everyone overlooks something that seems obvious to someone else, I guess.

Elevation of privilege FTL.
Post reply on HN