[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <9942a73c0702251712j33dbf441n68fdfc58d7c316a9@mail.gmail.com>
Date: Mon, 26 Feb 2007 02:12:15 +0100
From: "John Duhuh" <john.duhuh@...glemail.com>
To: full-disclosure@...ts.grok.org.uk
Subject: flickr not truly private
flickr say you can mark your photos private. when you look at the web
interface maybe. just give the direct address of a picture to one with no
access he grabs it no problem.
google images tips left as an exercise.
for the brute forcers it looks like feasible, maybe difficult.
targetting someone is easier with an estimation of the time of upload, as
first part of the filename is incremental.
for the rest maybe they did the job right, maybe not.
apologies if this is lame or already known.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists