zlacker

[return to "Show HN: Non.io, a Reddit-like platform Ive been working on for the last 4 years"]
1. update+BA1[view] [source] 2023-06-12 23:20:39
>>jjcm+(OP)
Looks like the website has been overwhelmed with spam, and, possibly hacked/exploited [1]. It looks like someone has been able to create directories & upload scripts [2]?

I do bug bounty in my spare time so this was an interesting live find.

[1] https://non.io/expoity

[2] https://html.non.io/upload-demo.html

◧◩
2. jjcm+cC1[view] [source] 2023-06-12 23:29:52
>>update+BA1
Scripts are permitted in html uploads (all content is iframed and served from a separate domain), though I will go through and remove blank directories for now.

I’ll likely add checks for an index.html for any upload and turn off indexing in the future to prevent these.

[go to top]