Hacking Stephen Fry's Twitter Account
eng.xakep.ru
eng.xakep.ru
For those who don't know what a null byte attack is, that's where you pass in an http request that turns into a string that explicitly encodes a null byte, \0 at the end. So you insert something like subsection=/../../../../../../../../../../../../../../../../etc/passwd%00. Now the code in the application tries to append something like .txt because "how bad could a .txt file be", and it arrives in C land as "/../../../../../../../../../../../../../../../../etc/passwd\0.txt\0" and C thinks that the string ends at the first \0 and doesn't pay any attention to the .txt bit.
This is a good example of why your escaping mechanism should always be "allow only what is explicitly known to be safe" rather than "block what is known to be unsafe". Because you have no idea what unsafe things there are that you don't know about.
But that ship sailed eons ago.
There's a security hole in the postal service, too. You can read anyone's mail by stealing it from their mailbox. Doesn't mean it's a good thing to do.
Surely that's a good thing? I agree that Stephen would/will probably be offended (assuming he wasn't notified), but he'll certainly take security more seriously now.
If someone broke into my house and I found out about it on Hacker News because they set up a webcam in my living room, I suppose it would be a good thing that I found out about a security problem in my home, but I certainly wouldn't be happy about it.
Kind of scary how many of these sites are almost certainly out there, though.
This material is definitely on the black hat side of things, but it is still important to be aware of these types of attacks. Sadly, PHP include bugs and SQL injections are still very widespread.
Was the site author (not the hacker) taking a get parameter and passing it to an include? That seem odd.
I need a little more help understanding this.
sections/food.php
sections/shopping.php
sections/fryclub.php
with different content, then an index page like, <!-- common header -->
<?php include("sections/" . $_GET["section"] . ".php") ?>
<!-- common footer -->
And then when you access, http://fry.com/index.php?section=fryclub
you get the content of fryclub.php with the correct headers and footers. Or you access, http://fry.com/index.php?section=/../.[snip]./../etc/passwd%00
and get any file you like, treated like a php file.Find a file that you can write to (such as the error log), use the above trick to treat it as a php file, use it to make system calls, and the box is yours.
EDIT: Errr, at least, not this sort of story.
His injected worked by causing an error to be written to a log, and then reading that log back through the PHP include. The error that was logged contained an arbitrary string (the HTTP request, with the malicious PHP code), which was executed by the server.
:-(
Also, he tries to use his twitter account to promote good causes. Depending on his reaction to this episode, this might have been put at risk.
> "P.S. I deleted that post from his micro-blog a few minutes later, cause my delicate mental organization didn’t allow me to injure a huge army of Stephen Fry fans."
Assuming the "hack" was real (no way to prove it IMO), I rather be hacked by this person than someone else with malicious intent. No harm done, as a matter of fact this will probably help to secure whatever hole was in the system. Do you think we would give a flying-frack if the twitter account in question didn't belong to Stephen Fry or anyone famous?
I doubt it.
Do you know Stephen Fry well? Is he 'nothing'? Can you predict how he will feel about this?
>if the twitter account in question didn't belong to Stephen Fry or anyone famous?
I didn't say famous, I said good.
Btw, check out the author's disclaimer:
>Neither the editors nor the author shall not be liable for any possible damage caused by the materials of this article.
I think you are being a bit too emotional here. Its not like Fry got kidnapped from his house, hog tied and thrown out of london bridge. His twitter account got compromised by someone, who was well intentioned enough not to screw around with it. If the person didn't write about the hack, you wouldn't know about it, Fry wouldn't know about it and he would wake up the next morning and have his "eggie in the basket" and no one would care.
Saying Awwww but "Stephen Fry is a good person. :-(" adds nothing to a discussion about something that has to do with web security.
Would knowing that Stephen Fry suffers from bipolar disorder, and has threatened to quit Twitter not long ago (http://www.guardian.co.uk/technology/2009/oct/31/stephen-fry... ) change your view?
No. I would be more concerned about him quitting blogging than him quitting twitter. He is an amazing writer and speaker and using twitter is a disservice to his talent. IMO.
How many times did twitter itself got hacked? From DNS hack to brute force password cracked (was no failed password limitation) to phishing attack to twitter employees account getting compromised to XSS attack to every single twitter account (earlier this year).
Twitter account of famous people getting hacked is part of the experience of using twitter. If someone stops using twitter for this, I don't feel bad about it.
Its twitter, not the end of the world.
Some weeks ago Stephen Fry was watching some live sporting event from his sofa, wrote a tweet about it, and got a reply from the presenters ON AIR. In a program broadcast to millions.
I think your position is that you don't care about these people and their use of Twitter. Fine, but THEY care.
Besides, a tweet like this from Sarah Palin is worth more than ten press releases: http://twitter.com/SarahPalinUSA/status/6823906156
Whether he is seen as a good or bad person is immaterial. Public figures like Fry are not immune to attacks on the basis of their personal qualities. If someone's account is going to be accessed unlawfully, then Stephen Fry's is as good a target as any other. Fry is as much fair game as Britney Spears.
FWIW, the vulnerability is listed in the OWASP 2007 Top 10 as Malicious File Execution http://www.owasp.org/index.php/Top_10_2007-A3
What??? I guess you don't watch BBC TV do you.
QI (Fantastic series).
Kingdom.
Stephen Fry's America
Last chance to see
etc etc
(Most of these from the last year or 2).
He's first and foremost known as a fantastic comedian and maker of good quality TV.