Yesterday, a friend mentioned that some program had been accessing most of his (s9y) blog, and apparently even manged to access password protected entries.

Now I’m not a s9y user myself, but somehow I felt like digging into this. I wouldn’t consider myself a web security expert, actually. I’m more interested in data mining and such algorithms these days.

It took me 10 minutes to find the problem (despite not having used PHP much in years; I don’t trust that programming language; including some searching if it was maybe already reported somewhere). By sending an appropriate POST request, you could override the password used, and that way disabling it.

Granted: “locating” a security issue you know it exists is a lot easier than actually discovering new ones…

Official announcement in the s9y blog, including a fix for the problem.

Memo to the guys who wrote that bot that was accessing the blog of my friend: You messed with the wrong people, guys. We know how to detect your scan, and we’ll spoil the fun for you by helping in fixing the bug!