create account

Deleted by moisesmcardona

View this thread on: hive.blogpeakd.comecency.com
· @moisesmcardona · (edited)
$1.34
properties (23)
authormoisesmcardona
permlinksteemapi-php-python-open-source
categorytechnology
json_metadata{"tags":["steem","steemit","contribution","opensource","dev","blog"],"app":"steemit/0.2","format":"markdown"}
created2017-11-20 02:29:00
last_update2020-02-24 12:55:45
depth0
children9
last_payout2017-11-27 02:29:00
cashout_time1969-12-31 23:59:59
total_payout_value1.180 HBD
curator_payout_value0.157 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length7
author_reputation30,544,308,668,193
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id20,934,473
net_rshares582,521,793,072
author_curate_reward""
vote details (55)
@anthonyadavisii · (edited)
$0.04
Hi @moisesmcardona, I am starting a project and am trying to figure out the best way to integrate Steem python within a web app securely. Were you ever able to look into the security concern expressed by @jamzed. We're you able to confirm that it affects your code or have you figured out a fix? Appreciate any help. You got my witness vote. :)
👍  
properties (23)
authoranthonyadavisii
permlinkre-moisesmcardona-steemapi-php-python-open-source-20180214t165738471z
categorytechnology
json_metadata{"tags":["technology"],"users":["moisesmcardona","jamzed"],"app":"steemit/0.1"}
created2018-02-14 16:57:42
last_update2018-02-14 17:12:30
depth1
children6
last_payout2018-02-21 16:57:42
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length344
author_reputation212,565,147,344,592
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,525,728
net_rshares5,357,376,106
author_curate_reward""
vote details (1)
@moisesmcardona ·
$0.05
I did took a look at @jamzed security concern. However, I was unable to reproduce it.
👍  
properties (23)
authormoisesmcardona
permlinkre-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t200000494z
categorytechnology
json_metadata{"tags":["technology"],"users":["jamzed"],"app":"steemit/0.1"}
created2018-02-14 20:00:03
last_update2018-02-14 20:00:03
depth2
children5
last_payout2018-02-21 20:00:03
cashout_time1969-12-31 23:59:59
total_payout_value0.044 HBD
curator_payout_value0.004 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length85
author_reputation30,544,308,668,193
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,560,777
net_rshares7,278,859,748
author_curate_reward""
vote details (1)
@anthonyadavisii ·
$0.04
Thanks. Will do some pen testing when I get it set up and let you know how it goes.
👍  
properties (23)
authoranthonyadavisii
permlinkre-moisesmcardona-re-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t201121607z
categorytechnology
json_metadata{"tags":["technology"],"app":"steemit/0.1"}
created2018-02-14 20:11:27
last_update2018-02-14 20:11:27
depth3
children0
last_payout2018-02-21 20:11:27
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length83
author_reputation212,565,147,344,592
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,562,793
net_rshares5,357,376,106
author_curate_reward""
vote details (1)
@jamzed ·
@moisesmcardona seriously? ;-)

`https://api.steem.place/getFollowersCount/?a=abc;uname%20-a`

![](https://steemitimages.com/DQmdZ39B1F12iQFNoAH9dWM4vTMicobL33ZCUT7DcEafrGy/image.png)
properties (22)
authorjamzed
permlinkre-moisesmcardona-re-anthonyadavisii-re-moisesmcardona-steemapi-php-python-open-source-20180214t200917543z
categorytechnology
json_metadata{"tags":["technology"],"users":["moisesmcardona"],"image":["https://steemitimages.com/DQmdZ39B1F12iQFNoAH9dWM4vTMicobL33ZCUT7DcEafrGy/image.png"],"app":"steemit/0.1"}
created2018-02-14 20:09:18
last_update2018-02-14 20:09:18
depth3
children3
last_payout2018-02-21 20:09:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length183
author_reputation2,159,179,776,915
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,562,443
net_rshares0
@ecoinstant · (edited)
I will take a look!  Have you checked out utopian.io?  This type of open source development is rewarded through an alternative steem condensor!
properties (22)
authorecoinstant
permlinkre-moisesmcardona-steemapi-php-python-open-source-20171120t023914023z
categorytechnology
json_metadata{"tags":["technology"],"app":"steemit/0.1"}
created2017-11-20 02:39:18
last_update2017-11-20 02:39:33
depth1
children0
last_payout2017-11-27 02:39:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length143
author_reputation843,606,111,585,301
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id20,935,109
net_rshares0
@jamzed ·
Hey!

I'm not PHP expert, but I think steemapi-php API has a huge security breach...

example code: https://github.com/moisesmcardona/steemapi-php-python/blob/master/steemapi-php/getFollowingCount/index.php

```
<?php
header("Content-Type: text/plain");
$account = $_GET['a'];
setlocale(LC_ALL, 'en_US.utf8');
putenv('LC_ALL=en_US.utf8');
echo(exec("python3 ../../steemapi-python/getFollowingCount.py $account"));
?>
```
&nbsp;
Using exec calls is terrible idea when Steemit's API is available thru RPC/JSON calls and what is much much more dangerous, the above example code allows to inject any Bash command to run...  

```
index.php?a=jamzed;rm -rf/
```
&nbsp;
Please consider switching to Curl instead of running Python script and also please escape all input from users :)

You can find a lot of information how to make your code more secure on [Owasp Top 10](https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project) page.
👍  
properties (23)
authorjamzed
permlinkre-moisesmcardona-steemapi-php-python-open-source-20171120t220655195z
categorytechnology
json_metadata{"tags":["technology"],"links":["https://github.com/moisesmcardona/steemapi-php-python/blob/master/steemapi-php/getFollowingCount/index.php","https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project"],"app":"steemit/0.1"}
created2017-11-20 22:06:54
last_update2017-11-20 22:06:54
depth1
children0
last_payout2017-11-27 22:06:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length934
author_reputation2,159,179,776,915
root_titleDeleted
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id21,023,891
net_rshares0
author_curate_reward""
vote details (1)