ブックマーク / chr13.com (2)

  • Using Facebook Notes to DDoS any website | A Programmer's Blog

    [Update] Facebook Notes allows users to include <img> tags. Whenever a <img> tag is used, Facebook crawls the image from the external server and caches it. Facebook will only cache the image once however using random get parameters the cache can be by-passed and the feature can be abused to cause a huge HTTP GET flood. Steps to re-create the bug as reported to Facebook Bug Bounty on March 03, 2014

    Using Facebook Notes to DDoS any website | A Programmer's Blog
    tmatsuu
    tmatsuu 2014/04/27
    Facebookノートを使ってDDoS攻撃を実現する方法。確かGoogle Spreadsheetでも同じことはできるんだけど、あっちは仕様ですとの回答だったと思う。
  • Using Google to DDoS any website - A Programmer's Blog

    [Update] Facebook Notes allows users to include <img> tags. Whenever a <img> tag is used, Facebook crawls the image from the external server and caches it. Facebook will only cache the image once however using random get parameters the cache can be by-passed and the feature can be abused to cause a huge HTTP GET flood. Steps to re-create the bug as reported to Facebook Bug Bounty on March 03, 2014

    Using Google to DDoS any website - A Programmer's Blog
    tmatsuu
    tmatsuu 2014/03/12
    Googleスプレッドシートに=image("画像のURL")を並べるだけでGoogleからお手軽DoS攻撃が可能らしい。Googleに報告したものの、脆弱性じゃないと判断されたとか。うん、まぁ、はい。
  • 1