{"id":4549,"date":"2012-11-30T22:50:05","date_gmt":"2012-11-30T21:50:05","guid":{"rendered":"http:\/\/daniel.haxx.se\/blog\/?p=4549"},"modified":"2012-11-30T22:50:05","modified_gmt":"2012-11-30T21:50:05","slug":"haking","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2012\/11\/30\/haking\/","title":{"rendered":"&#8220;haking&#8221;"},"content":{"rendered":"<p>(This is an authentic email we received at <a href=\"http:\/\/www.haxx.se\/\">Haxx<\/a> the other day. Names, emails and URLs are replaced in this excerpt to save the innocent)<\/p>\n<blockquote><p>Date: Thu, 29 Nov 2012 14:59:25<br \/>\nSubject: haking<\/p>\n<p>hello, can you tell me how to hack into web site:<br \/>\n[FIRST URL]<br \/>\nso it is showing:<\/p>\n<p>[OTHER URL]<br \/>\nwhen you click on a link in google results?<\/p>\n<p>for example if you click on a google result:<br \/>\n[URL to a google.rs search for something on the FIRST URL site]<\/p>\n<p>the point is i would like to protect my web site form that kind of attack so please let me know how to do that<\/p>\n<p>how did i found you? there is your address at [FIRST URL]\/coockies.txt so i think you did it, but was polite enough to leave address.. please help me.<\/p><\/blockquote>\n<p>Of course I was curious enough to check the &#8220;coockies.txt&#8221; file, and the beginning of that file looked like this:<\/p>\n<pre style=\"padding-left: 30px;\"># Netscape HTTP Cookie File\r\n# http:\/\/curlm.haxx.se\/rfc\/cookie_spec.html\r\n# This file was generated by <a href=\"http:\/\/curl.haxx.se\/libcurl\/\">libcurl<\/a>! Edit at your own risk.\r\n[FIRST URL] FALSE\t\/\tFALSE\t0\tPHPSESSID\tdfn1a5ll0hs8odpfh3p2qtlcj3<\/pre>\n<p>This tells us a few trivial things, all of which might not be obvious to the untrained eye:<\/p>\n<ul>\n<li>The file was generated by libcurl that was 7.16.0 or later, but no later than 7.18.3 as we only used the URL in that file between those releases.<\/li>\n<li>The spelling of that cookie file is so hilarious we can guess it wasn&#8217;t a native English speaker who named it. The subject of the email is similarly bad so perhaps it was a fellow countryman of Serbia? (the <a href=\"http:\/\/www.iana.org\/domains\/root\/db\/rs.html\">TLD of the google URL was .rs<\/a> after all)<\/li>\n<li>The person doing this didn&#8217;t even try to clean up the remaining junk file(s) afterwards<\/li>\n<li>The guy sending me the email is completely in the blue of what has happened or even who he&#8217;s contacting or my relation to this all.<\/li>\n<li>The world can be a harsh and cruel place and it isn&#8217;t easy to know your way around all of it&#8230;<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>(This is an authentic email we received at Haxx the other day. Names, emails and URLs are replaced in this excerpt to save the innocent) Date: Thu, 29 Nov 2012 14:59:25 Subject: haking hello, can you tell me how to hack into web site: [FIRST URL] so it is showing: [OTHER URL] when you click &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2012\/11\/30\/haking\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">&#8220;haking&#8221;<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[33,89,429,423],"class_list":["post-4549","post","type-post","status-publish","format-standard","hentry","category-blog","tag-curl-and-libcurl","tag-funny","tag-haxx","tag-mail"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/4549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=4549"}],"version-history":[{"count":5,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/4549\/revisions"}],"predecessor-version":[{"id":4554,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/4549\/revisions\/4554"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=4549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=4549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=4549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}