Flickr: Invitations disclosure (resend feature)
hackerone.com
Flickr: Invitations disclosure (resend feature)
1–10 of 93 posts
Re: Flickr: Invitations disclosure (resend feature)
#2As d4d1a179c0f3 mentions, this kind of information could be useful for setting up more targeted phishing attacks. "Hi John, remember the Flickr invite for holiday photos I sent you two weeks ago? I moved my albums to new site, please go to blackhat.org/malwaredl.."
Re: Flickr: Invitations disclosure (resend feature)
#3Re: Flickr: Invitations disclosure (resend feature)
#4The party would have a list of of flickr users / email combinations.
The best way to fix this if they want to have the urls work for some backward compatible reason is probably severe rate limiting after x requests if they do not want to expire these requests -- right? Otherwise, something the size of UUID will make the search space too large.
Re: Flickr: Invitations disclosure (resend feature)
#5Welp, the verdict is schofield is being dense. Of course user relationship pairs are potentially sensitive. Therefore enabling attackers to discover them by enumerating your tiny key space is an issue.
Either schofield needs to wisen up or Yahoo needs to put someone better in charge of their security issues.
Re: Flickr: Invitations disclosure (resend feature)
#6Right from the get-go, schofield showed incompetence when they declared they couldn't reproduce the bug, even though it was explained to them plainly and thoroughly!
How do these inept developers get hired?
Re: Flickr: Invitations disclosure (resend feature)
#7Well thats messed up... At least now I know how spammers get my email :D
Re: Flickr: Invitations disclosure (resend feature)
#8The response surprises me.
Re: Flickr: Invitations disclosure (resend feature)
#9The response to this bug is atrocious and shameful. The developer that responded to this did the same as putting on a blindfold and declaring that because they could no longer see the bug, it must not exist. Right from the get-go, schofield showed incompetence when they declared they couldn't reproduce the bug, even though it was explained to them plainly and thoroughly! How do these inept developers get hired?
Given that Yahoo operates in a number of European countries, and have offices and legal entities in many of them, this potentially means they are legally liable for data protection breaches if they don't plug this hole.
Re: Flickr: Invitations disclosure (resend feature)
#10A simple fix seems to be to use longer random id for the invitation. As d4d1a179c0f3 mentions, this kind of information could be useful for setting up more targeted phishing attacks. "Hi John, remember the Flickr invite for holiday photos I sent you two weeks ago? I moved my albums to new site, please go to blackhat.org/malwaredl.."