MyBlogLog Bug

Enter your email address to Subscribe:
Delivered by FeedBurner

I received a request from BlogMeme to become co-author of the community. I was thinking that it’s a clean invitation ( I mean an invitation with no negative intention like spamming, etc). But, ShoeMoney revealed that it’s a MyBlogLog exploit.

If you look at my profile on MyBlogLog You will see 2 sites that I did not add.

I wonder if Yahoo could be possibly liable here because basically Yahoo is saying that I said I own these sites… yet I did not…

Check out Jason Calacanis community. Evidently in addition to calacanis.com he also owns and authors seoadwords.com …. right….

So what else can people do with cross site xploits on mybloglog? Oh I think we are just seeing the tip.

The exploiter on this explains:

Choose ad a Co-Author, type in the MyBlogLog member name. (for example: Shoemoney). This sends out a e-mail to the user account with a link add yourself as a co-author. Now most people won’t open them, or they get picked up as spam.

Now exam the link:
http://www.mybloglog.com/buzz/add_author_conf.php?sid=&mid=
SID = Site ID, which is the community you author
MID = Member ID, which is the member the e-mail went to

Now, if you open that url, it will automatically add the author, no clicking, no form etc.

If you send author requests to a bunch of people. For example, yourself. Then find their memberID, your own SiteID, and insert them into the url, open in a browser. Bam, you have new authors on the community.

I am thinking if I will use this exploit… :-)

Rate this:
2.8
Automatically receive updates via email.
Enter your email address to Subscribe:
Delivered by FeedBurner
Posted by User ImageSELaplana, 19 February 2007 at Internet, Security (No. of Views: 1816)

Comments

2 Responses to “MyBlogLog Bug”

  1. No MyBlogLog Account
    1
    no imageEric Marcoullier (Check me out!) Says:

    Dude, don’t even joke about using exploits. No good karma will come of it. In the meantime, we have not only turned off the exploit, we’ve also blogged about the entire experience and what we’re doing in the future. I hope you’ll have a look. http://mybloglogb.typepad.com/my_weblog/2007/02/weekend_spamtac.html

  2. No MyBlogLog Account
    2
    Eric Reaction On MyBlogLog Bug » SELaplana Says:

    [...] MyBlogLog Bug [...]

Leave a Reply

Search Lyrics by Artists: 0-9 - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z