SECURITY ISSUE!! Do you have a blog using top commenters plugin?

Discussion in 'Link Development' started by pixeladd, Sep 21, 2008.

  1. #1
    Theres is a major security issue with this plugin

    the plugin uses the name of the commenter to enable the link

    go to any blog with the plugin and put the top commenters name as your name when you comment then use your link and email

    the top commenter will then have your link

    im ashamed to say ive been using this for months to get thousands of links but feel i should come clean now

    Anyone who doesnt understand send me thier blog link if they have the plugin and il show them
     
    pixeladd, Sep 21, 2008 IP
  2. !Unreal

    !Unreal Well-Known Member

    Messages:
    1,671
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    165
    #2
    not so much of a security issue; it doesn't pose a danger to anyone does it?

    Any way, cool tip ;)
     
    !Unreal, Sep 21, 2008 IP
  3. pixeladd

    pixeladd Banned

    Messages:
    2,238
    Likes Received:
    93
    Best Answers:
    0
    Trophy Points:
    0
    #3
    well it is a slight security issue i believe as it clearly compromises the site

    lol i should have put this in an ebook and sold it instead of trying to be helpful
     
    pixeladd, Sep 21, 2008 IP
  4. PoemofQuotes

    PoemofQuotes Peon

    Messages:
    637
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I don't know what top commentator plugin you are talking about, but the ones I have seen the site owner gets to set how it associates comments with their author. You can choose email, name, url, etc. and most of the time, if someone comments using the same email but not url, it still shows up as the previous url.
     
    PoemofQuotes, Sep 21, 2008 IP
  5. whirlybird20

    whirlybird20 Guest

    Messages:
    462
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I have set mine to determine the top commenter by email, but I think the default option is name.
     
    whirlybird20, Sep 21, 2008 IP
  6. Dodger

    Dodger Peon

    Messages:
    1,494
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Kewl. Now we can go through all of the 'SEO Freddy' names and point them at a casino site.

    While not a security issue, it is a nasty little loophole in the plugin. You can bring a blog ranking down by linking to some very bad neighborhoods.
     
    Dodger, Sep 21, 2008 IP
  7. Dodger

    Dodger Peon

    Messages:
    1,494
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Apparantly there are different varities of the Show Top Commentator plugin. The original (non-widgetized) version is here:

    http://www.pfadvice.com/wordpress-plugins/show-top-commentators/

    There are at least 4 widgetized versions. Any of which, may not be up to date with the original.


    Per the STC Change Log:

    So I think PixelAdd may have stumbled upon either a widgetized plugin variety that has never been updated or they just are plain lazy and have not updated yet.
     
    Dodger, Sep 22, 2008 IP
  8. pixeladd

    pixeladd Banned

    Messages:
    2,238
    Likes Received:
    93
    Best Answers:
    0
    Trophy Points:
    0
    #8
    yeh thats the way to fix it

    i have found over 2000 blogs with the security bug so thats alot of backlinks
     
    pixeladd, Sep 22, 2008 IP
  9. Gallito

    Gallito Peon

    Messages:
    1,939
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Well there is a security issue if they are using it anyway, just because that plugin isn't compatible with new versions of WP.
     
    Gallito, Sep 22, 2008 IP