Things I Learn From Spammers

Thanks to the diligence of comment spammers I have learned something interesting.

I’m not sure if ny.com is affiliated with the New York City in any way - it looks like a big commercial link site for NY related content. This may or may not be sanctioned by the city itself. What I do know, is that they have an interesting script in their cgi-bin which will load any URL passed via GET in the page’s lower frame. Let me illustrate this - please check out the link below:

http://www.ny.com/cgibin/frame.cgi?url=http://google.com

I’m loading Google page within the NY page’s frame. I already sent them an email about this, so perhaps they will be fixing it soon. In case this is gone tomorrow, here is a screenshot of how it looked:

NY.com Security Issues
click to enlarge

Allot of the comment spam that is getting caught in my filters lately uses this technique to push their free ringtone downloads and other garbage. If they were smarter, they would of course obfuscate the address to make it look like this:

http://www.ny.com/cgibin/frame.cgi?url= %68%74%74%70%3A%2F%2F1208930147

It still works, but the URL is obfuscated so it may not be entirely obvious that the script is loading an external page just by looking at the URL. Now, just imagine how many nasty things can you do with this little trick. Can you say cross-site scripting?

Related Posts:

  • Comment Spammers Suck!
  • Windows user complains about OS X usability.
  • What is this “address bar” you speak of?
  • Two types of Lusers
  • BBC is Spamming Wikipedia
  • Damn Comment Spammers
  • Awww… Mac users are cute!
  • Who reads EULAs?
  • Not Good With Computers
  • Learn your browser people!

  • 2 Responses to “Things I Learn From Spammers”

    1. Gravatar clamb CANADA Says:

      As a note … your link to
      http://www.ny.com/cgibin/frame.cgi?url=http://google.com
      is still available. Surprised?

      Posted using Mozilla Firefox Mozilla Firefox 1.5.0.11 on Windows Windows XP
    2. Gravatar Luke Maciak UNITED STATES Says:

      Heh.. They still haven’t fixed it. It’s been over a year now! LOL

      Posted using Mozilla Firefox Mozilla Firefox 2.0.0.6 on Ubuntu Linux Ubuntu Linux

    Leave a Reply

    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <pre lang=""> <em> <i> <strike> <strong>

    [Quote selected]