![]() |
|
sinister.ly like flood/referrals - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge) +--- Thread: sinister.ly like flood/referrals (/Thread-sinister-ly-like-flood-referrals) |
sinister.ly like flood/referrals - fritz - 10-20-2021 I noticed today something weird : ![]() And when I check those, they're all from uid 0 : ![]() When I click on this uid 0, weirdly it shows my profile, but with a huge list of users at the end: ![]() Any idea what happened there? @Oni? RE: sinister.ly vulnerability ? - fire - 10-20-2021 the exact same thing happened to me too RE: sinister.ly vulnerability ? - Equinox - 10-20-2021 Not a vulnerability. It was a bot that liked every post, and the account was deleted. Since the account was deleted though and not banned like a user normally would be, it has no uid, so MyAlerts just reports it as uid 0, which paired with no checks for if a user is valid or not, gives you the profile. RE: sinister.ly vulnerability ? - fritz - 10-20-2021 (10-20-2021, 01:52 PM)Equinox Wrote: Not a vulnerability. It was a bot that liked every post, and the account was deleted.Well yeah I did guess that part, but it's still some kind of vulnerability (not a security one though) to be able to like most posts and pollute every users notifications. (10-20-2021, 01:52 PM)Equinox Wrote: gives you the profile.I doubt having a list of 127,305 users on that uid 0 profile page is intended though
RE: sinister.ly vulnerability ? - Equinox - 10-20-2021 (10-20-2021, 02:13 PM)fritz Wrote:(10-20-2021, 01:52 PM)Equinox Wrote: Not a vulnerability. It was a bot that liked every post, and the account was deleted.Well yeah I did guess that part, but it's still some kind of vulnerability (not a security one though) to be able to like most posts and pollute every users notifications. So… what you’re saying is the like and notifications system are functioning as intended. Yeah, sure, it’s annoying to have polluted notifications. But that’s still not a vulnerability of… any kind. And you’re correct, having a page with x-hundred-thousand users on it is unintended. So this is thread is a bug report at best. RE: sinister.ly vulnerability ? - mothered - 10-20-2021 (10-20-2021, 02:13 PM)fritz Wrote: but it's still some kind of vulnerability (not a security one though) to be able to like most posts and pollute every users notifications.It's not a vulnerability. There's no flood control on Likes, so the user was able to hit one after the other without time restrictions. RE: sinister.ly vulnerability ? - fritz - 10-20-2021 I know English isn't my first language but still, a vulnerability is "Susceptibility to attack or injury; the state or condition of being weak or poorly defended." As @mothered pointed out "There's no flood control on Likes", so yeah it's what I'd call poorly/not defended! ^^ (10-20-2021, 03:09 PM)Equinox Wrote: And you’re correct, having a page with x-hundred-thousand users on it is unintended.We agree on that! (10-20-2021, 03:09 PM)Equinox Wrote: So this is thread is a bug report at best.Nope, the UID 0 issue wasn't the main point of this thread RE: sinister.ly vulnerability ? - Oni - 10-21-2021 (10-20-2021, 01:52 PM)Equinox Wrote: Not a vulnerability. It was a bot that liked every post, and the account was deleted. Confirming that this is the case. People are freaking out like this hasn't happened before. RE: sinister.ly vulnerability ? - fritz - 10-21-2021 (10-21-2021, 12:14 AM)Oni Wrote: Confirming that this is the case. People are freaking out like this hasn't happened before.Has it? And still no flood protection on likes? Seeing that annoying flood protection on search I'm surprised
RE: sinister.ly vulnerability ? - Oni - 10-21-2021 (10-21-2021, 12:29 AM)fritz Wrote:(10-21-2021, 12:14 AM)Oni Wrote: Confirming that this is the case. People are freaking out like this hasn't happened before.Has it? And still no flood protection on likes? While we have many custom plugins, this one is not. I might modify it, but that is the stock functionality of the plugin. |