Thursday, January 08, 2009   
  Search   
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  News & Feedback  Latest News  ImageShack Flaw Exposes the IP Addresses of Uploaders
Previous Previous
 
Next Next
New Post 9/29/2008 11:49 PM
User is offline Jenil
128 posts
www.jenilvasani.blogspot.com
Senior Member


ImageShack Flaw Exposes the IP Addresses of Uploaders 
Modified By Jenil  on 9/29/2008 11:50:03 PM)

 

 

   Christoper Boyd, Director of Malware Research for FaceTime Security Labs and Microsoft Security MVP, has come across a security flaw on the popular free image hosting service ImageShack through which anyone could have downloaded the log file associated with any image. Such a log file contains the IP address which was used to upload a particular image.

The file/directory permission related vulnerability was easily exploitable through URL manipulation, a user only needing to change the file extension from .jpg to something else in an ImageShack direct URL. Not being able to parse the Content-Type the browser offered this new file for download. Upon opening it in any text editor, the IP address of the uploader would have been revealed.

Being able to see the IP of anyone who uploaded an image on the website poses a very serious privacy issue. “Considering they have 2+ million uploads a day, that's an awful lot of people to choose from,” notes Christopher Boyd. He also gives several examples of what one might do with this piece of information. They range from scaring people on forums by revealing their IP to running exploits against their computers. 

Sorce 

 

 
New Post 9/29/2008 11:59 PM
User is offline Rahul Manekari
1216 posts
www.manekari.blogspot.com
MW Addict




Re: ImageShack Flaw Exposes the IP Addresses of Uploaders 

wow... whata big problem ..

our system is open to Hackerz...

 


Rahul Manekari
Be Live...with Me...!!! Click here
 
New Post 9/30/2008 7:46 AM
User is offline Ramesh Kumar
2866 posts
www.itsmyWindows.com
Forum Guru








Re: ImageShack Flaw Exposes the IP Addresses of Uploaders 

 Rahul Manekari wrote

wow... whata big problem ..

our system is open to Hackerz...

 

Thanks for ALERT . Im using Photobucket


it's my Windows
 
Previous Previous
 
Next Next
  Microsoft Windows Forums  News & Feedback  Latest News  ImageShack Flaw Exposes the IP Addresses of Uploaders


   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account