Check your old code: if it’s old enough even the most innocuous cruft can be a problem

Over on my personal site I keep write-ups and photo galleries of all the canoe trips I’ve done. It helps me (and possibly others) plan for the next one and avoid past mistakes etc etc.

Time was when I also used it to teach myself things. Like CSS and PHP and the Javascript DOM. I figured these reports would be evergreen and wouldn’t need much maintenance as they were more or less static. Nope. I’ve updated them over the years, changing DOCTYPEs, getting rid of old MSIE/Netscape CSS work-arounds (yes, they are that old), but I didn’t anticipate what happened last week.

I got an email from a security researcher the other day telling me that one of the PHP scripts on one of these old trip reports could be used to inject malicious code into the browser window.

I do get a lot of unsolicited emails about all sorts of problems with my sites — my domain’s expiring, I’m not ranking on the first page of Google, I have million dollars coming to me from an octogenerian in Nigeria who has throat cancer etc etc.

But this one actually was legit. He was building sweat equity as part of Open Bug Bounty and had found something on my site amongst these sometimes 20 year old, hand-coded trip reports.

It was the sort of thing that would allow a remote attacker to enlist my site in building phishing links or credential/info stealing pages. So there was no leaving it around.

The fix was relatively simple. And now that I’ve deployed it across all those reports, I think they are safe again.

Thanks to Security Researcher Imtiaz Ahmed for being clear and polite in pointing out my lassitude. Here’s his OpenBugBounty profile.

Leave a Reply

Your email address will not be published. Required fields are marked *