|
|
|
|
|
by steakejjs
4257 days ago
|
|
You've got to be kidding me. Despite the policy difficulties of running a site like this (when is someone dead?, how long until release of secrets?, how to deal with lack of access to emails? etc), This site is completely insecure. https://www.deathswitch.com/members/myaccount.php
is vulnerable to a CSRF hijack through the update email page. This literally took 20 seconds to find...who knows what would happen if I dedicated an entire minute. In fact, there are no CSRF tokens on the entire site at all. There are big problems in these services and the policies that run them. Technical solutions might not be the best to use here. Perhaps a legal solution is the best route... edit: I gave it 20 more seconds. Stored XSS. If I paid the money for premium service which allows file upload I'll bet I can RCE too. This is just not the type of person I want protecting my secrets. |
|
Not that there's anything wrong with (what's likely) shared hosting, but it doesn't paint the best picture.
To the author: Your idea is good, but it was executed poor, and it's not a <need> by any means. If it is, the logistics of it are too damn difficult to warrant your service (or any service that does this, for that matter).