<h4><center>Defacement / Phishing</center></h4> <div class="pull-right"><br>https://images.hive.blog/DQmW5YXngzAsNPEhQ5MtVgsttwXvVQgKVM37RsjHgGrVPHT/image.png</div> <br /><br /><br /> You can see from the screenshot below that I was able to replace the content of the target website with my own content. <br><br>This vulnerability could be exploited by malicious users for phishing campaigns as the link shared with the potential victims has a trusted domain in it! <center>https://images.hive.blog/DQmUtLMVSGDGi5TKYTAd9Yx68GBGuAamFWPaMxQxRnLEj2z/image.png</center> <br>The mantainer (one of the top 30 witnesses) has now been notified in multiple ways. Stay tuned for updates! Will tell you a bit more about it after it gets fixed 😎 👍 ----- UPDATE 1: The vulnerability reported above has now been fixed by @jesta. The problem though is worse than I though and I've found another similar vulnerability that allows me to store code in the site and execute it when the user visits that page: <center>https://images.hive.blog/DQmXXPyy1ubuwq9YcmY2Y7n7uJaSs2PVTZRmLMeiN8XibXZ/image.png</center> ----- ----- The issue has not been patched but the site is now less uselful since if you use any html tag in your post, when you try to inspect it in hive-db.com it will now just display "Content not available".  The maintainer said that at the moment he cannot fix it in a better way as he is not actively maintaining this old project (back in the Steemit days it was called https://steemdb.com). When i have a chance I will test it a bit more for vulnerabilities but after an initial check it seems safe now. ----- ----- <div class="pull-right"> <sub><b>My side project: @keys-defender</b></sub> <div> - <sub><a href="https://hive.blog/steem/@gaottantacinque/the-keys-defender-bot-is-live-in-beta-mode">Keys protection</a><sub>(scan of transfers/posts/comments/others, auto-transfer to savings, auto-reset of keys)</sub></sub> <br><i>-</i> <sub><a href="https://hive.blog/hive/@keys-defender/new-feature-phishing-detection-and-auto-reply">Phishing protection</a></sub> <br><i>-</i> <sub><a href="https://hive.blog/hivedev/@keys-defender/new-feature-added-to-keys-defender-plagiarism-detection">Re-posting detection</a></sub> <br><i>-</i> <sub><a href="https://hive.blog/hive-139531/@keys-defender/new-feature-code-injections-attempts-detection-xss-sql-injections-csrf">Code injections detection</a></sub> </div> </div> <div class="pull-left"> <sub><b>My security disclosures (from most recent) on Hive:</b></sub> <br>- <sub><a href="https://hive.blog/hive/@gaottantacinque/xss-found-in-one-of-drako-s-websites-will-add-details-after-it-s-patched">XSS vulnerabilities in scribe.hivekings.com</a></sub> <br>- <sub><a href="https://hive.blog/hive/@gaottantacinque/hiveblockexplorer-com-is-vulnerable-to-stored-xss">XSS vulnerabilities in hiveblockexplorer.com</a></sub> <br>- <sub><a href="https://hive.blog/steemit/@gaottantacinque/steemit-got-hacked">Malicious ads redirecting all Steemit iOS users to a phishing site</a></sub> <br>- <sub><a href="https://hive.blog/security/@gaottantacinque/steemit-chat-is-unsafe">Reverse tabnabbing and clickjacking in steem.chat and steeemit registration page</a></sub> </div>
author | gaottantacinque |
---|---|
permlink | defacement-phishing-vulnerability-in-one-of-the-most-used-hive-tools |
category | hive-139531 |
json_metadata | {"tags":["hivedev","security","phishing","abuse","neoxian","palnet"],"app":"hiveblog/0.1","format":"markdown","image":["https://images.hive.blog/DQmW5YXngzAsNPEhQ5MtVgsttwXvVQgKVM37RsjHgGrVPHT/image.png","https://images.hive.blog/DQmUtLMVSGDGi5TKYTAd9Yx68GBGuAamFWPaMxQxRnLEj2z/image.png","https://images.hive.blog/DQmXXPyy1ubuwq9YcmY2Y7n7uJaSs2PVTZRmLMeiN8XibXZ/image.png","https://images.hive.blog/DQmPFU7ewT7DqB1qh9aTpmdHtHThhwNibN1MuzxNN2DsUqT/image.png"],"links":["https://steemdb.com"],"users":["jesta","keys-defender"]} |
created | 2020-09-22 22:01:27 |
last_update | 2022-07-30 15:27:15 |
depth | 0 |
children | 7 |
last_payout | 2020-09-29 22:01:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 2.764 HBD |
curator_payout_value | 2.726 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 3,329 |
author_reputation | 13,592,747,127,375 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,767,645 |
net_rshares | 21,314,105,309,816 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
pfunk | 0 | 4,208,958,000,609 | 50% | ||
klye | 0 | 134,837,336,922 | 100% | ||
ausbitbank | 0 | 2,418,888,668,211 | 100% | ||
donatello | 0 | 1,304,313,130 | 2% | ||
logic | 0 | 241,992,620,696 | 100% | ||
seckorama | 0 | 25,798,958,480 | 30% | ||
steemcleaners | 0 | 2,728,479,237,159 | 100% | ||
dylanhobalart | 0 | 56,005,322,130 | 21% | ||
rishi556 | 0 | 32,001,693,440 | 100% | ||
vannour | 0 | 24,527,807,004 | 25% | ||
steemworld | 0 | 1,004,300,380 | 25% | ||
keuudeip | 0 | 2,084,504,935 | 12.5% | ||
anthonyadavisii | 0 | 250,349,621,119 | 100% | ||
pedir-museum | 0 | 629,938,353 | 25% | ||
travelnepal | 0 | 1,286,786,781 | 10% | ||
borislavzlatanov | 0 | 130,745,425,455 | 100% | ||
zaragast | 0 | 74,755,223,781 | 45% | ||
thenightflier | 0 | 158,786,597,696 | 45% | ||
drakos | 0 | 1,411,048,270,921 | 100% | ||
sannur | 0 | 1,803,007,107 | 100% | ||
tykee | 0 | 2,687,258,724 | 25% | ||
steempostitalia | 0 | 211,083,059,945 | 45% | ||
spiceboyz | 0 | 35,293,644,119 | 20% | ||
spaminator | 0 | 2,297,714,738,822 | 100% | ||
tipu | 0 | 2,224,271,978,679 | 6% | ||
alinakot | 0 | 68,487,417,433 | 45% | ||
heidi71 | 0 | 35,589,644,820 | 45% | ||
steemseph | 0 | 74,837,414,563 | 100% | ||
gianluccio | 0 | 15,016,692,035 | 10% | ||
ciuoto | 0 | 2,999,775,079 | 10% | ||
marcolino76 | 0 | 11,935,029,861 | 30% | ||
kamchore | 0 | 80,673,008,333 | 50% | ||
straykat | 0 | 5,087,594,467 | 10% | ||
jim888 | 0 | 400,114,392,751 | 22% | ||
bartheek | 0 | 8,657,895,583 | 3% | ||
alequandro | 0 | 5,340,505,989 | 10% | ||
mirkon86 | 0 | 537,692,423 | 20% | ||
bala41288 | 0 | 16,363,555,389 | 5% | ||
leslierevales | 0 | 587,708,554 | 10% | ||
knfitaly | 0 | 250,603,317,777 | 34.84% | ||
pab.ink | 0 | 6,558,856,242 | 10% | ||
piumadoro | 0 | 4,765,965,709 | 20% | ||
happy-soul | 0 | 10,544,704,677 | 3% | ||
condeas | 0 | 1,307,824,694,809 | 60% | ||
mad-runner | 0 | 26,760,697,807 | 14% | ||
sbarandelli | 0 | 4,647,393,049 | 20% | ||
vittoriozuccala | 0 | 6,191,766,394 | 10% | ||
lycos | 0 | 768,069,386 | 10% | ||
spaghettiscience | 0 | 28,056,716,357 | 20% | ||
payroll | 0 | 76,127,757,689 | 2% | ||
oscurity | 0 | 5,253,859,192 | 16% | ||
saboin | 0 | 227,793,434,647 | 25% | ||
bafi | 0 | 1,410,686,162 | 20% | ||
phage93 | 0 | 8,740,631,003 | 20% | ||
enforcer48 | 0 | 123,110,667,303 | 15% | ||
giuseppemasala | 0 | 3,267,904,448 | 20% | ||
acquarius30 | 0 | 1,703,984,526 | 20% | ||
gaottantacinque | 0 | 8,043,569,931 | 100% | ||
aulia1993 | 0 | 72,457,764,807 | 25% | ||
longer | 0 | 699,026,015 | 1.5% | ||
nattybongo | 0 | 7,718,439,622 | 2% | ||
armandosodano | 0 | 61,079,252,851 | 14% | ||
gerdtrudroepke | 0 | 40,373,530,010 | 60% | ||
ilnegro | 0 | 37,869,547,852 | 10% | ||
gasaeightyfive | 0 | 0 | 100% | ||
tommasobusiello | 0 | 4,365,803,723 | 16% | ||
coccodema | 0 | 2,815,827,177 | 20% | ||
marcocasario | 0 | 163,754,233,736 | 100% | ||
laissez-faire | 0 | 53,877,084 | 100% | ||
cribbio | 0 | 0 | 100% | ||
javier.dejuan | 0 | 716,168,575 | 10% | ||
elyon | 0 | 800,846,436 | 10% | ||
ibc | 0 | 39,545,018,447 | 60% | ||
itegoarcanadei | 0 | 562,719,232 | 20% | ||
linuxbot | 0 | 763,852,492 | 100% | ||
middleearth | 0 | 790,779,865 | 20% | ||
adinapoli | 0 | 2,563,304,551 | 10% | ||
akireuna | 0 | 1,237,945,205 | 20% | ||
discovery-it | 0 | 169,659,953,019 | 20% | ||
jaguar.force | 0 | 14,748,372,331 | 100% | ||
kork75 | 0 | 1,369,155,283 | 10% | ||
jacuzzi | 0 | 872,914,119 | 3% | ||
loliver | 0 | 19,082,598,563 | 100% | ||
lallo | 0 | 3,414,833,160 | 20% | ||
cooperfelix | 0 | 1,254,966,150 | 14% | ||
abbenay | 0 | 10,977,392,196 | 50% | ||
david.steem | 0 | 546,648,739 | 18% | ||
kryptogames | 0 | 27,495,907,454 | 6% | ||
titti | 0 | 7,518,242,223 | 20% | ||
maryincryptoland | 0 | 4,520,055,854 | 20% | ||
stregamorgana | 0 | 1,404,768,078 | 20% | ||
meeplecomposer | 0 | 1,557,413,214 | 12% | ||
libertycrypto27 | 0 | 37,498,790,949 | 20% | ||
tinyhousecryptos | 0 | 528,241,431 | 5% | ||
claudietto | 0 | 1,716,531,753 | 10% | ||
omodei | 0 | 2,302,830,491 | 20% | ||
cryptogambit | 0 | 1,444,869,138 | 7.5% | ||
astil.codex | 0 | 292,262,031 | 100% | ||
ilias.fragment | 0 | 315,730,954 | 70% | ||
capitanonema | 0 | 2,476,480,140 | 20% | ||
dappstats | 0 | 3,632,653,297 | 15% | ||
axel-blaze | 0 | 308,300,308,975 | 20% | ||
discovery-blog | 0 | 2,415,410,617 | 20% | ||
zacknorman97 | 0 | 16,082,584,882 | 20% | ||
riccc96 | 0 | 4,038,747,913 | 10% | ||
delilhavores | 0 | 4,119,316,486 | 20% | ||
hjmarseille | 0 | 2,658,897,131 | 18% | ||
im-ridd | 0 | 5,876,823,629 | 20% | ||
disagio.gang | 0 | 5,345,377,752 | 20% | ||
mengene | 0 | 808,525,537 | 10% | ||
keys-defender | 0 | 30,695,734,127 | 100% | ||
romytokic | 0 | 607,547,206 | 10% | ||
stuntman.mike | 0 | 42,659,696,190 | 90% | ||
hivewatchers | 0 | 435,183,763,178 | 100% | ||
hivewatcher | 0 | 41,194,753,118 | 100% | ||
gitplait | 0 | 40,031,151,663 | 50% | ||
peterpanpan | 0 | 19,809,713,396 | 20% | ||
meppij | 0 | 76,037,027,886 | 20% | ||
matteus57 | 0 | 756,657,077 | 20% | ||
hextech | 0 | 7,078,592,406 | 66% | ||
wlslink | 0 | 4,052,396,299 | 100% | ||
raven.icu | 0 | 2,560,405,499 | 100% | ||
flewsplash | 0 | 3,375,972,429 | 20% | ||
spirall | 0 | 2,875,039,187 | 10% |
<div class="pull-left">https://cdn.steemitimages.com/DQmTAn3c753LR7bHCLPo96g9UvRMaPFwaMYn8VQZa85xczC/discovery_logo_colore%20-%20Copia.png</div><br> This post was shared and voted inside the discord by the curators team of <a href="https://discord.gg/cMMp943"> discovery-it</a> <br>Join our community! <a href = "https://hive.blog/trending/hive-193212"> hive-193212</a><br>Discovery-it is also a Witness, vote for us <a href = "https://hivesigner.com/sign/account-witness-vote?witness=discovery-it&approve=true"> here</a> <br>Delegate to us for passive income. Check our <a href = "https://hive.blog/hive-193212/@discovery-it/delegations-program-80-fee-back"> 80% fee-back Program</a> <hr>
author | discovery-it |
---|---|
permlink | re-gaottantacinque-wog4ct749u |
category | hive-139531 |
json_metadata | "" |
created | 2020-09-22 22:32:24 |
last_update | 2020-09-22 22:32:24 |
depth | 1 |
children | 0 |
last_payout | 2020-09-29 22:32:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 689 |
author_reputation | 67,591,587,602,825 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,768,006 |
net_rshares | 0 |
Congratulations @gaottantacinque! You have completed the following achievement on the Hive blockchain and have been rewarded with new badge(s) : <table><tr><td><img src="https://images.hive.blog/60x70/http://hivebuzz.me/@gaottantacinque/upvoted.png?202009222241"></td><td>You received more than 4500 upvotes. Your next target is to reach 4750 upvotes.</td></tr> </table> <sub>_You can view your badges on [your board](https://hivebuzz.me/@gaottantacinque) and compare yourself to others in the [Ranking](https://hivebuzz.me/ranking)_</sub> <sub>_If you no longer want to receive notifications, reply to this comment with the word_ `STOP`</sub> **Do not miss the last post from @hivebuzz:** <table><tr><td><a href="/hive-192847/@hivebuzz/update-for-regular-authors"><img src="https://images.hive.blog/64x128/https://i.imgur.com/Bkdl8Vk.png"></a></td><td><a href="/hive-192847/@hivebuzz/update-for-regular-authors">Update for regular authors</a></td></tr></table>
author | hivebuzz |
---|---|
permlink | hivebuzz-notify-gaottantacinque-20200922t230008000z |
category | hive-139531 |
json_metadata | {"image":["http://hivebuzz.me/notify.t6.png"]} |
created | 2020-09-22 23:00:06 |
last_update | 2020-09-22 23:00:06 |
depth | 1 |
children | 0 |
last_payout | 2020-09-29 23:00:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 966 |
author_reputation | 369,407,645,254,453 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,768,405 |
net_rshares | 0 |
Damn good work here!
author | klye |
---|---|
permlink | re-gaottantacinque-qh3w3r |
category | hive-139531 |
json_metadata | {"tags":["hive-139531"],"app":"peakd/2020.09.4"} |
created | 2020-09-23 10:07:03 |
last_update | 2020-09-23 10:07:03 |
depth | 1 |
children | 1 |
last_payout | 2020-09-30 10:07:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.013 HBD |
curator_payout_value | 0.013 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 20 |
author_reputation | 412,341,527,771,769 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,774,825 |
net_rshares | 181,044,733,420 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
gaottantacinque | 0 | 8,043,569,931 | 100% | ||
dustsweeper | 0 | 173,001,163,489 | 17.48% |
Thanks! 😎
author | gaottantacinque |
---|---|
permlink | qh40jq |
category | hive-139531 |
json_metadata | {"app":"hiveblog/0.1"} |
created | 2020-09-23 11:43:03 |
last_update | 2020-09-23 11:43:03 |
depth | 2 |
children | 0 |
last_payout | 2020-09-30 11:43:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.010 HBD |
curator_payout_value | 0.010 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 9 |
author_reputation | 13,592,747,127,375 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,775,954 |
net_rshares | 145,039,579,117 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
klye | 0 | 136,714,871,619 | 100% | ||
gaottantacinque | 0 | 8,324,707,498 | 100% |
@tipu curate
author | logic |
---|---|
permlink | qh2z9s |
category | hive-139531 |
json_metadata | {"users":["tipu"],"app":"hiveblog/0.1"} |
created | 2020-09-22 22:17:51 |
last_update | 2020-09-22 22:17:51 |
depth | 1 |
children | 1 |
last_payout | 2020-09-29 22:17:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 12 |
author_reputation | 92,052,875,413,650 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 0.000 HBD |
percent_hbd | 10,000 |
post_id | 99,767,859 |
net_rshares | 7,723,672,704 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
gaottantacinque | 0 | 7,723,672,704 | 100% |
<a href="https://tipu.online/hive_curator?logic" target="_blank">Upvoted 👌</a> (Mana: 0/6) <a href="https://peakd.com/hive/@reward.app/reward-app-quick-gude" target="_blank">Liquid rewards</a>.
author | tipu |
---|---|
permlink | re-qh2z9s-20200922t221802 |
category | hive-139531 |
json_metadata | "" |
created | 2020-09-22 22:18:06 |
last_update | 2020-09-22 22:18:06 |
depth | 2 |
children | 0 |
last_payout | 2020-09-29 22:18:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 202 |
author_reputation | 55,930,979,039,115 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,767,863 |
net_rshares | 0 |
loool !discovery 20
author | phage93 |
---|---|
permlink | qh2zxc |
category | hive-139531 |
json_metadata | {"app":"hiveblog/0.1"} |
created | 2020-09-22 22:32:03 |
last_update | 2020-09-22 22:32:03 |
depth | 1 |
children | 0 |
last_payout | 2020-09-29 22:32:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 19 |
author_reputation | 80,382,904,001,177 |
root_title | "Defacement / Phishing vulnerability in hive-db.com" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 99,768,004 |
net_rshares | 7,882,204,381 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
gaottantacinque | 0 | 7,882,204,381 | 100% |