Skip to contentExploitQuest

Lesson 1 of 4 in The Bug Between Two Features · 7 min left in this chapter

Neither Half Is a Bug

Avatar-by-URL is a convenience. Recent visitors is engagement. Together they tell a stranger where you live.

3 min read

Not yet reviewed

This one is from a real forum, and it is the clearest example anywhere of a bug that is not in any single piece of code. Both features worked exactly as their authors intended. Neither one, on its own, is a vulnerability.

Feature one — set your avatar by URL

Instead of uploading a picture you paste a link, and the forum renders it straight into the page. It saves storage and it is a five-line feature.

What the page contains

<img src="https://somewhere.example/pic.png">

What that means

Every browser that loads this profile makes a request
to somewhere.example, carrying its IP address, its user
agent, and the time - to a server the forum does not control.

Nothing here is a flaw. It is what an img tag does, and it is what the feature was for.

Feature two — recent visitors

A panel on your profile listing the last few members who looked at it, by name. It is an engagement feature and it exists on plenty of sites.

Both at once

Set your avatar to a URL on a server you control. Wait. Your server's log now holds an IP and a timestamp for every person who viewed your profile, and your profile page tells you their names and when they visited.

your-server.log   14:02:11  198.51.100.44  Firefox/126.0
forum panel       14:02     rowan_hale viewed your profile
  1. Line 1Your server saw an address, and nothing about who it belongs to.
  2. Line 2The forum told you a name, and nothing about where they are.
  3. Line 2Line them up on the timestamp and you have both. That is the whole attack, and it is arithmetic rather than exploitation.

Note

Nobody clicked a link. Nobody was phished. The target visited a profile on a site they trusted, which is the thing profiles are for. Every component behaved correctly.

Wrenlearner

So whose bug is it? The avatar feature is fine and the visitors panel is fine.

Rookmentor

Nobody's, which is exactly why it survived. A code review sees one feature at a time, and each one passes. It takes somebody holding both in their head at once, and usually that somebody is an attacker.

Magpieadversary

I am not looking for a flaw. I am reading your feature list for two things that answer different halves of the same question.

What it is actually for

This is not a route to a database or a shell. Nothing is compromised. The harm is narrower and worse: a specific person who was careful about their real name is now locatable by somebody who wanted to find them, and an IP address plus a rough time is enough to start.

Take care

The people most exposed by this are the ones for whom being found matters most, and they are usually the ones who were most careful about everything else. That is the pattern with correlation attacks generally: they defeat the person who did the work, because the person who did not was already findable.

Which single change would have prevented this, without removing either feature?

That fix is correct, and it introduces two worse problems. First, though — what did this look like from the forum's side?