{"id":92,"date":"2007-12-04T21:13:33","date_gmt":"2007-12-04T21:13:33","guid":{"rendered":"http:\/\/quinert.com\/blog\/xml-rss2.php?itemid=59"},"modified":"2007-12-04T21:13:33","modified_gmt":"2007-12-04T21:13:33","slug":"web-testing-security-or-does-your-website-help-spammers","status":"publish","type":"post","link":"http:\/\/www.software-testing.com.au\/blog\/2007\/12\/04\/web-testing-security-or-does-your-website-help-spammers\/","title":{"rendered":"Web testing security, or Does your website help spammers?"},"content":{"rendered":"<p>Today I was trolling through my Yahoo mails, and noticed that a spam message had made it through to my inbox.  I read through my mail, expecting to just delete the spam message when I eventually got to it.  When I did, it struck me as unusual.  In addition to the message body, there was the usual link.  But it looked like this:<\/p>\n<p>http:\/\/www.google.com\/search?hl=en&#038;q=inurl:ma&#8230;&#8230;.ls&#038;btnI=I=Im+Feeling+Lucky<\/p>\n<p>I was surprised.  It was a link to a Google search.  I hovered over the link, and it wasn&#8217;t just a clever ploy to make me think I was going to Google.  It was actually a spammer exploiting Google&#8217;s functionality to redirect someone unwittingly to the spam site.<\/p>\n<p>If you want to see this in action (the link above won&#8217;t work), you can try this:<\/p>\n<p><a href=\"http:\/\/www.google.com\/search?hl=en&#038;q=inurl:quinert.com&#038;btnI=I=Im+Feeling+Lucky\">http:\/\/www.google.com\/search?hl=en&#038;q=inurl:quinert.com&#038;btnI=I=Im+Feeling+Lucky<\/a><\/p>\n<p>Now, you can probably filter this just by looking for the &#8220;Im+Feeling+Lucky&#8221; keyword, as the odds of anyone sending you a legitimate URL containing this are highly unlikely.  But it does point to an interesting kind of exploit that we might need to be aware of when we&#8217;re developing websites.  More generally, when we are testing a web-based product, when we think about security risks, we also need to think about how our website might help spammers.<\/p>\n<p>The most common function of this type that leaps to mind are &#8216;Email to a friend&#8217; type functions, where using tools like WebScarab, or hand-crafting your own html page, websites can be made to send anonymous or faked emails to anyone you like.<\/p>\n<p>What others can you think of?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I was trolling through my Yahoo mails, and noticed that a spam message had made it through to my inbox. I read through my mail, expecting to just delete the spam message when I eventually got to it. When I did, it struck me as unusual. In addition to the message body, there was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,30,40],"tags":[],"class_list":["post-92","post","type-post","status-publish","format-standard","hentry","category-bugs","category-software-testing","category-value"],"_links":{"self":[{"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/posts\/92","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/comments?post=92"}],"version-history":[{"count":0,"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/posts\/92\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/media?parent=92"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/categories?post=92"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.software-testing.com.au\/blog\/wp-json\/wp\/v2\/tags?post=92"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}