LiveJournal XSS Security Challenge 66
Jamesday writes "LiveJournal is offering a free permanent account and possibly other prizes to those who find new vulnerabilities in its XSS Security Challenge. LiveJournal has recently been attacked via a Firefox XSS exploit."
Well.. (Score:1)
Re:Well.. (Score:1)
-SixApart CEO
Re:Well.. (Score:1)
Poor guys at livejournal.. We did slashdot their VM test box.
That's what they get for giving it too little memory. Hey! At least the icon comes through!
I have no time for this (Score:5, Funny)
Re:I have no time for this (Score:1)
I was until Tom took down LOGIN for fucking repairs.
The fucking login!!! And there are MILLIONS OF PEOPLE who use that site.
Since things that suck are coming into fashion I'm wondering when Windows ME is going to make it's big comeback...
Re:I have no time for this (Score:2)
Y'know... (Score:5, Interesting)
But still, good to see them taking it seriously. Now, instead of Bantown getting an eternal newspost declaring their victory, they'll just get permanent accounts.
Re:Y'know... (Score:1, Flamebait)
Oh, but we can trust users, can't we? And what's with a little harmless hacking? Good for the spirit, good for the soul!
Making software bulletproof is probably impossible. If one coder can think something up, another can devise a way to break it or exploit it. LiveJournal is going to run thei
Re:Y'know... (Score:4, Insightful)
I don't think people realize how complex a blogging site can be. Attempting to secure a blogging site is a real task. Live journal actually has a revenue stream and paid programmers so there is less excuse for them not to try, but succeeding is another matter. In reality, if they cut of rich content posting then their users will move on to another service or simply find a OSS product they can run themselves. Then we'll have automated attacks on those scripts. I've written a blogging site in java, and its not even close to secure. I'm in the process of rewriting the whole thing in a language I'm more familiar with. Its not an easy task.
Re:Y'know... (Score:2)
There is a vast difference between making a site "bulletproof" and making it work "correctly." Make no mistake, any software undertaking is not easy, but when a piece of software has to interact with the outside environment, the correct procedure is
Re:Y'know... (Score:2, Informative)
No, it's not. (Score:2)
Tell that to Dan Bernstein [wikipedia.org] or Donald Knuth [wikipedia.org].
Re:Y'know... (Score:2, Informative)
Firefox dev's have in the past explicitly ruled out supporting HTTPONLY pretty much just because Microsoft invented it. The result is Firefox users are much more vulnerable to XSS attacks that IE users.
Re:Y'know... (Score:1)
Re:Y'know... (Score:2)
Stuff happens.
Other possible prizes: (Score:2, Interesting)
Re:Other possible prizes: (Score:1)
Re:Other possible prizes: (Score:1)
Re:Other possible prizes: (Score:5, Insightful)
Re:Other possible prizes: (Score:3, Interesting)
Re:Other possible prizes: (Score:2)
The ISP Service may not be used to breach or attempt to breach the security, the computer, the software or the data of any person or entity, including Operator, to circumvent the user authentication features or security of any host, network or account, to use or distribute tools designed to compromise security, or to interfere with another?s use of the ISP Service through the posting or transmitting of a virus or other harmful item to deliberately overload or fl
Re:Other possible prizes: (Score:1, Informative)
Re:Other possible prizes: (Score:2)
I see that this is your first time on Slashdot. Don't worry, it takes some time to get used to how we do things here but eventually it will all make sense.
Re:Other possible prizes: (Score:2)
Why only XSS? (Score:3, Insightful)
Besides, I think putting up a bounty makes it more "legal" and will bring out more of the more-experienced White Hats into the game and make LJ that much safer...
possible other prizes (Score:5, Funny)
Rumours are the other prizes include books on forming lasting interpersonal relationships, 7-day trips to Club Med, and the book 'Romance for Dummies.'
Re:possible other prizes (Score:2, Funny)
7-day trips to Club Med
Actually, 7-day trips for two to Club Med, but in the event that you're going alone, doing the Han Solo thing, that'll be a 14-day trip for one. With a fully loaded mini-bar in your room if you ever get tired of 'shaking hands with the wookie'.
Re:possible other prizes (Score:3, Funny)
Y'know, those that live in Slash houses shouldn't cast stones...
OOOh! A shiny thing! (Score:5, Funny)
hacker demographic? (Score:5, Funny)
the above comment is an unfair stereotype and should be viewed with extreme suspicion
Excellent idea (Score:5, Funny)
Re:Excellent idea (Score:1)
Free "lifetime" account* (Score:3, Insightful)
Re:Free "lifetime" account* (Score:3, Funny)
Sheesh, these guys are much tougher than I thought. At least I only get bad karma here.
Justin.
LJ bullshit (Score:2)
Re:LJ bullshit (Score:1)
Compromise means that to get what you want, you don't always get it on all of your own terms. Meta wanted his way, his terms... unfortunately for him, it's not his website!
The whole case was one
Re:LJ bullshit (Score:2)
Re:LJ bullshit (Score:2)
"In 1989 the PRC violently suppressed a peaceful student protest in Tiananmen Square killing hundreds"
90-odd letters. Not bad.
J.
Re:LJ bullshit (Score:2)
TRANSLATION: (Score:3, Funny)
Marketing gimmic? (Score:2, Interesting)
STEP 1: Go to http://www.test.dev.livejournal.org/ [livejournal.org] . Make an account. Probably need to change it to paid so you can make styles/etc.
So to be able to help them test their security, you have to pay them? Or am I missing something?
Re:Marketing gimmic? (Score:2, Troll)
Re:Marketing gimmic? (Score:3, Informative)
BTW, the only reason I haven't figured out a way do something *really* nasty is that they seem to have totally disabled inline style markup on comments. (I've spotted some smaller holes, but if it wasn't for that
Re:Marketing gimmic? (Score:2)
Somebody please pull a Tyler Durden on livejournal (Score:3, Funny)
Re:Somebody please pull a Tyler Durden on livejour (Score:3, Funny)
Last time one of those went off, LiveJournal's servers melted down, the attempted suicides rate spiked for a week, low lying areas were flooded from the deluge of tears....
I could go on, but I think you get the idea.
The Cross Site Scripting FAQ (Score:1, Informative)
The Cross Site Scripting FAQ [cgisecurity.com]
Firefox? (Score:1)
Re:OT: Secure LiveJournal RSS feeds? (Score:2)
Digest auth (which I assume from the URL is what LJ is using here) uses a one-time nonce as a challenge, so capturing your response would not benefit an attacker since the same response cannot be replayed. Also, the MD5 hash you're seeing your client send is based not only on your password and the nonce but also on the HTTP method being used and the URI being requested. Digest auth does have its flaws, but I think it's secure enough for this purpose.
Re:Personal Contact Info For LJ Hackers (Score:3, Insightful)
Maybe you should stop blaming the actions of everyone who idles in that channel on a small minority of their non-livejournal-using denizens.
Re:Personal Contact Info For LJ Hackers (Score:2, Informative)
It is true, I am the a+++ #1 mayor of Bantown! However Bantown is an independent citystate and not responsible for the actions of its citizens! That would be like the city of San Francisco being responsible because one of its citizens plans and carries on activities such as conspiracy and instigating riots! I am sorry that someone on the internet was mean to you! However carrying on some immature internet grudge against people and then trying to get other people in on it is a little high schoolish don