View RSS Feed

Assorted Thoughts on Website Buying, Selling and Monetizing

How Flippa Was Hacked - Video

Rate this Entry
Is-Hacked has released the video of how they hacked Flippa.

From earlier reports Flippa threatened to sue them if they released this video. I suspect that was sabre rattling. Even Flippa isn't that dumb to attract the negative publicity a law suit would inevitably do.

The vulnerability was simple, you could either click Forgot Password or Register. The email Flippa sends you contains a link that is designed to authenticate your email and contains a UserID in the url. To hack Flippa, you simply change the UserID. This can be to any UserID to find their profile info/private messages or as shown in the video an Administrator UserID.
They are taking questions and answering them on that blog post above.

Submit "How Flippa Was Hacked - Video" to Digg Submit "How Flippa Was Hacked - Video" to del.icio.us Submit "How Flippa Was Hacked - Video" to StumbleUpon Submit "How Flippa Was Hacked - Video" to Google

Categories
Uncategorized

Comments

  1. hooperman's Avatar
    Now that was a schoolboy error! tke71709 was right about substituting the user id.
  2. Andy's Avatar
    Oh my gorsh! How common is this vulnerability?

    Even Flippa isn't that dumb to attract the negative publicity a law suit would inevitably do.

    "The difference between genius and stupidity is genius has it's limits" Albert Einstein

    Andy
  3. Clinton's Avatar
    Flippa's software is custom-built, isn't it?
Leave Comment Leave Comment

Trackbacks