DISQUS

A Weird Soul: Brijj.com bug

  • Gaurav Sharma · 1 year ago
    LinkedIn API?
  • Gaurav · 1 year ago
    No, just a XSS vulnerability on Brijj. Click the image to see the URL.
  • Gaurav Sharma · 1 year ago
    i wudn't be trusting this site with my email credentials ( http://brijj.com/aboutus/TakeATourPage2 ). A 1 year old indian website.. hmmm :-s
  • Gaurav · 1 year ago
    I apparently did that.

    They don't encrypt your password either. I did the 'forgot my password' thing and they emailed me my existing password in plain text. Yikes! Info Edge, a publicly traded company, needs to improve their coding quality.
  • Gaurav Sharma · 1 year ago
    It all boils down to the Tech Lead / Programmers. They certainly don't seem to have any coding standards. 'Lack of experience' I assume. Moreover, quantity is rated higher than quality (in India). Pity.
    I suggest you change your passwords NOW ;-)
  • Kapil · 1 year ago
    Interesting find. looks like some authentication issue with the Linkedin API
  • Gaurav · 1 year ago
    Kapil, this has nothing to do with LinkedIn API or even LinkedIn. I guess I chose a bad example for the iframe.

    See the URL in the screenshot - http://www.flickr.com/photos/gsharma/2740079054...
  • Gaurav · 1 year ago
    I just found out that you were Technical Architect on Brijj.com and it uses Symfony. I haven't dug deep into Symfony, but I'd imagine their basic auth module/plugin will hash passwords before saving them.

    I wonder if Brijj.com isn't fully using Symfony to its potential?
  • Gaurav Sharma · 1 year ago
    Tech Architect? You're referring to Kapil, rite? :)
  • Gaurav · 1 year ago
    Yes, it was for Kapil.