NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


ImageShack Flaw Exposes the IP Addresses of Uploaders

A security issue allows access to upload information files associated with images

By Lucian Constantin, Web News Editor

29th of September 2008, 14:16 GMT

Adjust text size:


ImageShack URL manipulation discloses uploaders' IPs
Enlarge picture
Christopher Boyd, Director of Malware Research for FaceTime Security Labs and Microsoft Security MVP, has come across a security flaw on the popular free image hosting service ImageShack through which anyone could have downloaded the log file associated with any image. Such a log file contains the IP address which was used to upload a particular image.

The file/directory permission related vulnerability was easily exploitable through URL manipulation, a user only needing to change the file extension from .jpg to something else in an ImageShack direct URL. Not being able to parse the Content-Type the browser offered this new file for download. Upon opening it in any text editor, the IP address of the uploader would have been revealed.

Being able to see the IP of anyone who uploaded an image on the website poses a very serious privacy issue. “Considering they have 2+ million uploads a day, that's an awful lot of people to choose from,” notes Christopher Boyd. He also gives several examples of what one might do with this piece of information. They range from scaring people on forums by revealing their IP to running exploits against their computers.

He also mentions the possibility of ratting out on employees for uploading files to ImageShack while at work, using such websites from company offices being usually prohibited. “It may sound a touch OTT, but never underestimate someone’s capacity to cause trouble over the silliest things,” says Mr. Boyd on his blog.

ImageShack has acted promptly and addressed the issue in less than one hour. The ImageShack reply expressed their confidence that “this security gap no longer exists”. This looks to be the case as trying to exploit it now will return a 403 – Forbidden error, which most likely means that directory/file permissions on the Web server have been corrected. “I can't remember the last time we found something that was patched at such speed, and full credit to them,” notes Boyd.

Apparently, a very similar information disclosure incident occurred on the ImageShack website back in 2006. A permission issue allowed users to download the entire post logs for each of the 520 different ImageShack servers by accessing a URL of the type http://img##.imageshack.us/logs/postlog (where ## represent digits forming the server number). The logs contained names of the uploaded images, their respective uploader's IP, date of upload and the upload hash, which could have been used to search the log for all images uploaded by the same person.

TAGS:

ImageShack | IP Address | Upload | Data Leak | Information Disclosure
Read by 1,809 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Yet Another Data Leak from the UK Ministry of Defence

Maserati Hacker Arrested

Important Scottish Newspaper Leaks Private Data

Bank Account Information up for Sale

Prison Staff Unencrypted Information Lost

Personal Information of UK's Most Dangerous Criminals Lost

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM