Deleted
author | moisesmcardona |
---|---|
permlink | steemapi-php-python-open-source |
category | technology |
json_metadata | {"tags":["steem","steemit","contribution","opensource","dev","blog"],"app":"steemit/0.2","format":"markdown"} |
created | 2017-11-20 02:29:00 |
last_update | 2020-02-24 12:55:45 |
depth | 0 |
children | 9 |
last_payout | 2017-11-27 02:29:00 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 1.180 HBD |
curator_payout_value | 0.157 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 7 |
author_reputation | 30,544,308,668,193 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 20,934,473 |
net_rshares | 582,521,793,072 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
fractalnode | 0 | 5,332,950,425 | 15% | ||
ubg | 0 | 220,344,563 | 1% | ||
sc-steemit | 0 | 12,253,039,690 | 15% | ||
moisesmcardona | 0 | 104,529,237,547 | 100% | ||
barton26 | 0 | 6,191,348,815 | 100% | ||
frankches | 0 | 6,475,241,859 | 100% | ||
criptomonedastv | 0 | 23,412,985,532 | 100% | ||
anthonyadavisii | 0 | 0 | 100% | ||
sodom | 0 | 2,000,280,221 | 100% | ||
aismor | 0 | 899,308,586 | 100% | ||
jackelinlopez | 0 | 759,933,472 | 10% | ||
ecoinstant | 0 | 36,330,553,447 | 100% | ||
fabiyamada | 0 | 13,105,104,462 | 100% | ||
techtek | 0 | 14,753,326,799 | 50% | ||
kusatsuri | 0 | 396,117,812 | 100% | ||
doritm | 0 | 619,520,000 | 100% | ||
fivestargroup | 0 | 138,588,305 | 0.02% | ||
mireevse | 0 | 454,405,891 | 100% | ||
nnnarvaez | 0 | 165,075,485,297 | 100% | ||
bebeth | 0 | 122,719,180,689 | 100% | ||
gusjaramillo | 0 | 617,220,000 | 100% | ||
canachof | 0 | 617,220,000 | 100% | ||
vanerossetti2 | 0 | 618,537,701 | 100% | ||
pla1971 | 0 | 1,161,940,789 | 100% | ||
issapaz | 0 | 614,133,900 | 100% | ||
reveur | 0 | 28,351,466,616 | 100% | ||
walo | 0 | 860,547,796 | 100% | ||
restlessmike | 0 | 617,220,000 | 100% | ||
calliope | 0 | 1,160,621,750 | 100% | ||
gregan | 0 | 3,633,424,814 | 100% | ||
wabs | 0 | 617,220,000 | 100% | ||
juliococo | 0 | 779,661,428 | 100% | ||
guaraira | 0 | 614,133,900 | 100% | ||
pontias | 0 | 608,123,780 | 100% | ||
cleiverurdaneta | 0 | 622,524,540 | 100% | ||
juancho389 | 0 | 617,384,534 | 100% | ||
jvigil | 0 | 1,155,622,952 | 100% | ||
aerofer | 0 | 1,154,803,570 | 100% | ||
erdavid | 0 | 2,988,662,298 | 100% | ||
pilas | 0 | 633,001,420 | 100% | ||
juanmi96 | 0 | 1,348,008,577 | 100% | ||
pararova | 0 | 608,772,683 | 100% | ||
pepegrillo | 0 | 614,256,762 | 100% | ||
kamyee | 0 | 614,133,900 | 100% | ||
argelida1 | 0 | 614,133,900 | 100% | ||
caroastrologica | 0 | 614,133,900 | 100% | ||
margarita97 | 0 | 621,112,599 | 100% | ||
hectorr | 0 | 614,133,900 | 100% | ||
namra | 0 | 775,427,304 | 100% | ||
peggymarin | 0 | 614,133,900 | 100% | ||
dolartoday | 0 | 614,153,800 | 100% | ||
eviledx | 0 | 369,126,494 | 100% | ||
steemusa | 0 | 8,728,810,320 | 15% | ||
aba-kevin | 0 | 941,114,005 | 100% | ||
danieelab | 0 | 1,119,915,828 | 100% |
Hi @moisesmcardona, I am starting a project and am trying to figure out the best way to integrate Steem python within a web app securely. Were you ever able to look into the security concern expressed by @jamzed. We're you able to confirm that it affects your code or have you figured out a fix? Appreciate any help. You got my witness vote. :)
author | anthonyadavisii |
---|---|
permlink | re-moisesmcardona-steemapi-php-python-open-source-20180214t165738471z |
category | technology |
json_metadata | {"tags":["technology"],"users":["moisesmcardona","jamzed"],"app":"steemit/0.1"} |
created | 2018-02-14 16:57:42 |
last_update | 2018-02-14 17:12:30 |
depth | 1 |
children | 6 |
last_payout | 2018-02-21 16:57:42 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 344 |
author_reputation | 212,565,147,344,592 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 37,525,728 |
net_rshares | 5,357,376,106 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
moisesmcardona | 0 | 5,357,376,106 | 7% |
I did took a look at @jamzed security concern. However, I was unable to reproduce it.
author | moisesmcardona |
---|---|
permlink | re-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t200000494z |
category | technology |
json_metadata | {"tags":["technology"],"users":["jamzed"],"app":"steemit/0.1"} |
created | 2018-02-14 20:00:03 |
last_update | 2018-02-14 20:00:03 |
depth | 2 |
children | 5 |
last_payout | 2018-02-21 20:00:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.044 HBD |
curator_payout_value | 0.004 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 85 |
author_reputation | 30,544,308,668,193 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 37,560,777 |
net_rshares | 7,278,859,748 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
anthonyadavisii | 0 | 7,278,859,748 | 33% |
Thanks. Will do some pen testing when I get it set up and let you know how it goes.
author | anthonyadavisii |
---|---|
permlink | re-moisesmcardona-re-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t201121607z |
category | technology |
json_metadata | {"tags":["technology"],"app":"steemit/0.1"} |
created | 2018-02-14 20:11:27 |
last_update | 2018-02-14 20:11:27 |
depth | 3 |
children | 0 |
last_payout | 2018-02-21 20:11:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 83 |
author_reputation | 212,565,147,344,592 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 37,562,793 |
net_rshares | 5,357,376,106 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
moisesmcardona | 0 | 5,357,376,106 | 7% |
@moisesmcardona seriously? ;-) `https://api.steem.place/getFollowersCount/?a=abc;uname%20-a` 
author | jamzed |
---|---|
permlink | re-moisesmcardona-re-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t200917543z |
category | technology |
json_metadata | {"tags":["technology"],"users":["moisesmcardona"],"image":["https://steemitimages.com/DQmdZ39B1F12iQFNoAH9dWM4vTMicobL33ZCUT7DcEafrGy/image.png"],"app":"steemit/0.1"} |
created | 2018-02-14 20:09:18 |
last_update | 2018-02-14 20:09:18 |
depth | 3 |
children | 3 |
last_payout | 2018-02-21 20:09:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 183 |
author_reputation | 2,159,179,776,915 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 37,562,443 |
net_rshares | 0 |
I will take a look! Have you checked out utopian.io? This type of open source development is rewarded through an alternative steem condensor!
author | ecoinstant |
---|---|
permlink | re-moisesmcardona-steemapi-php-python-open-source-20171120t023914023z |
category | technology |
json_metadata | {"tags":["technology"],"app":"steemit/0.1"} |
created | 2017-11-20 02:39:18 |
last_update | 2017-11-20 02:39:33 |
depth | 1 |
children | 0 |
last_payout | 2017-11-27 02:39:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 143 |
author_reputation | 843,606,111,585,301 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 20,935,109 |
net_rshares | 0 |
Hey! I'm not PHP expert, but I think steemapi-php API has a huge security breach... example code: https://github.com/moisesmcardona/steemapi-php-python/blob/master/steemapi-php/getFollowingCount/index.php ``` <?php header("Content-Type: text/plain"); $account = $_GET['a']; setlocale(LC_ALL, 'en_US.utf8'); putenv('LC_ALL=en_US.utf8'); echo(exec("python3 ../../steemapi-python/getFollowingCount.py $account")); ?> ``` Using exec calls is terrible idea when Steemit's API is available thru RPC/JSON calls and what is much much more dangerous, the above example code allows to inject any Bash command to run... ``` index.php?a=jamzed;rm -rf/ ``` Please consider switching to Curl instead of running Python script and also please escape all input from users :) You can find a lot of information how to make your code more secure on [Owasp Top 10](https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project) page.
author | jamzed |
---|---|
permlink | re-moisesmcardona-steemapi-php-python-open-source-20171120t220655195z |
category | technology |
json_metadata | {"tags":["technology"],"links":["https://github.com/moisesmcardona/steemapi-php-python/blob/master/steemapi-php/getFollowingCount/index.php","https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project"],"app":"steemit/0.1"} |
created | 2017-11-20 22:06:54 |
last_update | 2017-11-20 22:06:54 |
depth | 1 |
children | 0 |
last_payout | 2017-11-27 22:06:54 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 934 |
author_reputation | 2,159,179,776,915 |
root_title | Deleted |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 21,023,891 |
net_rshares | 0 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
gokulnk | 0 | 0 | 100% |