Greetings and possible spam attack
QuoteNov 04, 2009 13:070 likesLike
 

Hi,

I cannot think of a solid usecase but I think that sending greetings is a probable spam-prone area. I noticed to send a greeting you just need to login to your account and type this in the browser:

http://demozzz.com/dolphin7b/greet.php?sendto=<user_id>&from=<the_spammer_id>&ConfCode=

No authorization or captcha code is required.

So a spammer can create an account, login  and just use a script and have this url in it:

http://demozzz.com/dolphin7b/greet.php?sendto=<user_id>&from=<the_spammer_id>&ConfCode=

And then all he needs to do is to increment the user_id count and fire the request again to send greetings to a different user. So imagine how easy it would be to SPAM the whole community forget about server load issues.

What do you say guys???

Mick

QuoteNov 05, 2009 01:320 likesLike
 

Ticket for 7.1 was added: http://www.boonex.com/trac/dolphin/ticket/1428

Rules: http://www.boonex.com/unity/txt/terms