20 Feb
Posted by Harper as General, Technology at 11:58 PM
Tags: 37signals, bot, campfire, campfirenow, chat, exploit, flood, hacks, perl
Oh yea. I forgot to mention that i released a new version of my campfirenow.com bot framework. It is quite a bit better and a lot more robust – however i imagine that 37signals has changed things to stop it.
Check out the source: here
I also released a proof of concept flood. its real annoying and stupid. don’t use it. i just wanted to see if i could make it.
Flood source: here
A couple things:
I really think that campfire should have some sort of authentication scheme to make sure that the message originator is the right user. It wouldn’t stop bots and what not, but it would stop the tinyurl hack that is always hilarious. I think that have super AJAXy sites and insuring simple app security is often more difficult – but in my opinion, more important because the feel of the application is more similar to the desktop applications and so the user may be caught off guard if a security breach rares its head. But as Jason Fried said: it just doesn’t matter.
I wonder if gtalk could be similarly exploited. I doubt it since it is based on the jabber client and xmpp. I wonder why 37s didn’t use xmpp or something.
awesome
Hi. My name is Harper. I am an engineer involved in social networks and the open source software. I am very happily employed as the CTO of the awesome skinnyCorp/Threadless in Chicago, IL. We make some really cool stuff. This is obviously my blog. I write about everything from being a professional yoyoer to hacking the newest Internet appliance. Be sure and check out my homepage at harperreed.org. If you are so interested, my resume is located here. I love getting emails and what not so feel free to contact me through here.
Be sure and take a gander at my photos.
If you want to contact me click here to start a chat.
One Response
jake
February 21st, 2006 at 1:07 am
1you cheeky little monkey