How I hacked Friendster with CoComment
Update: Just received an email from Stephanie Booth of CoComment acknowledging the bug. She indicated that the CoComment team is working on a fix - kudos to them for the quick follow-up! (I'm guessing they made the quick discovery with CoComment on this Techcrunch conversation - bravo, definitely a worthy app despite the bug)
I just stumbled upon an interesting loophole with Friendster using CoComment which allows me to see a list of sent messages belonging to other users, presumably those that are also registered with CoComment, and are keeping track of their sent messages using the form on the default Friendster Send Message page (http://www.friendster.com/sendmessage.php)
Here's how it happened:
- I received a private message in Friendster from a friend.
- I clicked on reply, and chose to keep track of the conversation with CoComment.
- Moments later, I receive a notification from CoComment that the conversation has been updated.
- I log on to my CoComment conversations page, and notice that it's a message sent by mrblinky, who happens to be another user that has signed up with CoComment and has chosen to keep track of his/her Friendster messages
The following screenshot shows my sent message amongst 97 other sent messages that do NOT belong to me:

The screenshots below shows the message in my Friendster inbox which I replied to. The reply form is hosted on http://www.friendster.com/sendmessage.php:


Relevant links:
- Articles on CoComment by Techcrunch
- Techcrunch > CoComment: Tracking Your Blog Comments
- Friendster
- CoComment
Labels: hacking

9 Comments:
Praveen, thanks a lot for pointing this out! Actually, I found your post because I use Technorati to see what the blogosphere is saying about us.
We've removed the offending conversation thread and ensured that future private messages on Friendster would not be captured.
Thanks again!
Stephanie, thanks for the follow up. Good to know that the bug has been squashed. Glad to be of help. All the best and keep up the great work over there!
its the bug still there or had it been fixed?
@daniboi: I believe this bug has been squashed.
bug?? do u really think so? in my opinion this is purposely done by someone to eavesdrop.. unlikely to be a bug.
Anonymous: I can assure you it was a bug. It wasn't a "design" so that somebody could eavesdrop. You've probably watched too much X-Files or conspiracy theory thingies ;-)
download sini password FS..enjoy
a) http://hotfile.com/dl/7804927/fe67243/Password_Friendster.rar.html
...please where can I buy a unicorn?
i'm gonna make my own blog
Post a Comment
<< Home