User21 – Yuval Atzmon

Yet Another Technology Explorer
  • Home
  • About
    • Contact
  • Contact

FriendFeed Images on Amazon S3 – Potential Exploits

Yuval Atzmon | October 1, 2008 | 2:10 AM

It’s been a while, I know. Been busy, still alive, thanks for asking.

Here’s a little test I performed. About two months ago I deleted an entry which had an image attached to it. I noted the URL of the uploaded image (the location where FF stored it on Amazon S3 storage service).

I checked this URL a few hours later, the next day, next week and so on, assuming there’s some sort of garbage collection process that would delete this resource, but the image is still there at the time of writing. I have repeated this test more than once.

This raises a few concerns:

  1. Potential exploit #1 – someone who wants to save on their site’s bandwidth costs can store images on FF at no cost.
  2. Potential exploit #2 – storing files on Amazon S3 costs FF money (currently $0.15 a month per 1GB), so if someone wants to increase FF’s monthly bill they can just dump a lot of large photos there. Not to mention bandwidth costs (think Digg homepage kind of traffic).
  3. An entry you delete might not really be deleted – if FF doesn’t bother deleting these binary resources, one may assume the text is kept as well, which is a bit of a problem if you shared something by mistake and wouldn’t want it popping up in the future.

Of course this could all just be a bug and these images should have been deleted in the first place. I’m just speculating here.

Comments
2 Comments »
Categories
friendfeed
Tags
exploits, friendfeed
Comments rss Comments rss
Trackback Trackback

About This Blog

User21 is an internet technology oriented blog written by Yuval Atzmon, a consultant and project manager. If you find other people with the name Yuval Atzmon, they are not me. [More]

Categories

  • dev
  • friendfeed
  • mscrm
  • Off topic
  • Uncategorized

Popular Posts

  • FriendFeed's Top 250 Most Followed Users
  • FriendFeed Has ~75,000 Active Users (Personal Research)

Follow Me

Follow me on Twitter
Subscribe to me on FriendFeed
View Yuval Atzmon's profile on LinkedIn
rss Comments rss design by jide