Slashdot Mirror


Hacker Finds Bug to Edit or Delete Any Medium Post (vice.com)

Joseph Cox, reporting for Motherboard: Medium has become the go-to home for extended blog posts from researchers, CEOs, and even the President of the United States. Now, one hacker has found a way to edit or delete any post on the publishing platform. "I tried to think of different possibilities or testing cases on how can I delete a story of any user. And fortunately, I found a severe bug," Philippines-based freelance penetration test and bug bounty hunter Allan Jay Dumanhug told Motherboard in an email. The trick, Dumanhug explained in a blog post published at the end of last month, centres around Medium's "Publications" feature. Users can create their own publications -- perhaps a page dedicated to infosec news, for example -- and then request to add other users' posts to it. Each post on Medium is given its own unique, 12-character identifier code. The person who authored the post has to approve that request, otherwise their story doesn't go anywhere. But Dumanhug found that while adding his own story to his own publication, he could intercept the HTTP request and simply change the identifier to that of another post.

5 of 39 comments (clear)

  1. Where they got their name from by JustNiz · · Score: 4, Funny

    clearly the name Medium refers to their level of security.

  2. See, this is why we hate black-hat hackers. by jeffb+(2.718) · · Score: 5, Funny

    If a white-hat hacker had found this exploit, he would've gone ahead and deleted all Medium posts. And there would have been much rejoicing.

  3. Re:Astroturf much? by slashdice · · Score: 4, Insightful

    According to netcraft, more people are aware medium exists than are aware slashdot [still] exists.

    --
    Copyright (c) 1990 - 2014 Dice. All rights reserved. Use of this comment is subject to certain Terms and Conditions.
  4. Next level! by Anonymous Coward · · Score: 5, Funny

    "he could intercept the HTTP request and simply change the identifier to that of another post."

    Stand back guys, we got a pro here.

  5. Had to be said... by sysrammer · · Score: 4, Funny

    It's a rare Medium that's done well.

    --
    His ignorance covered the whole earth like a blanket, and there was hardly a hole in it anywhere. - Mark Twain