Hacker News new | past | comments | ask | show | jobs | submit login
Show HN:I personally created a web service in japan. Please review if you like. (note.com)
21 points by mTano on April 21, 2021 | hide | past | favorite | 36 comments



So apparently this is a thumbnail manager located at http://url-wiki.com/

That url gives me a blank page with the letters “wtf”


It looks like the site had some hideously insecure file upload function which someone's taken advantage of to nuke the site.

If I go to the archived version [0] of the site and click the + button I end up at [1]

[0] https://web.archive.org/web/20210329151816/http://url-wiki.c...

[1] https://web.archive.org/web/20210329151816mp_/http://url-wik...

Edit: on closer inspection you can overwrite the whole index page just by passing in URL-encoded HTML in one of the form fields.

Edit 2: It's even worse than I thought. Arbitrary file upload. Flagging this post for its own good.


Thank you very much for pointing out. I didn't realize there was a security hole. I would like to study a little more about the input form. For the top page, JavaScript has been completely removed.


You need to remove the vulnerable PHP script too


I would like to improve the security hole for PHP scripts as well. Thank you for giving us a very detailed point.


Thank you very much for your comment. The top page has been modified to "wtf" characters for malicious users. Now that all the input forms and JavaScript have been removed, you can browse correctly.


That domain name is amazing! Worth millions I’m assuming.

Would you be able to provide an English description of what it does as many of us don’t speak Japanese?


note.com isn't the site, it's url-wiki.com. If you translate it with Google Translate you get the gist of it.


Thank you for your comment. The site I searched for was "http://url-wiki.com", not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


hank you very much for your comment.Millions of values ... Thank you very much for your kind words. To put it simply, "thumbnail URLs to manage", "collect more and more", "three types of collections (private collection, group collection, public collection)", "share and edit URLs with everyone" Is possible. (It will be smooth if you can translate the article of the linked URL into English by "right-click-> translate" of your browser)


So what is http://url-wiki.com/ actually doing apart from displaying "wtf"? Any Github link? Docs?

This is really confusing to link your post to a sort of bookmark manager


Thank you very much for your comment. The top page was modified to the word "wtf" by a malicious user. Currently, all JavaScript input forms have been removed from the top page, so I think that it can be viewed normally. I haven't studied enough.


Thank you for your comment. The site I searched for was "http://url-wiki.com", not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


NSFW warning: The current home page has porn hub as a bookmark, which displays a bookmarked image that is likely not SFW (depending on your workplace).


Thank you very much for your comment. We scrutinized the user's items and frozen users with porn related items. In the future, I would like to consider the reporting function and improve it so that it can be frozen efficiently.


I'm sorry, it seems that the top page has been changed to wtf characters by a malicious user, so I will reissue it.


I think you need to take the site offline and go learn about sanitising inputs. Your site is fundamentally insecure at the moment.


Thank you very much for your comment. I felt that I hadn't studied enough about input forms and JavaScript. Learn about injection attacks.


I don’t understand Japanese but what impressed/question me the most is how you managed to buy such a generic domain name. Good job.


So it looks like note.com is actually a blog site.

So they've linked their blog talking about making it.

http://url-wiki.com/

Is their web site. From what I understand it's a bookmark tool that lets you have lists of bookmarks which are shown as thumbnails


Thank you for your comment. The created site is "http://url-wiki.com". It's not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


Isn't their website url-wiki.com?

I would assume that note.com is not their creation but rather the blog platform on which they presented their work.


Thank you for your comment. The created site is "http://url-wiki.com". It's not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


Thank you very much for your comment.I am very happy that you were interested in it. I was very worried about deciding the domain name. Sharing personal bookmarks (transferring to others) is the basis of the development concept, and we named it as a bookmark that everyone can edit.


I developed "http://url-wiki.com". note becomes the operation manual. I'm sorry I'm not used to using Hoker News.


I think it would have been much clearer to link straight to your site, as most of us don't know Japanese. However, url-wiki seems to be down at the moment, as all it says is "wtf". You may want to make a better error message.


I should have written a direct link. Sorry for confusing Hack News. After that, please be careful.


Checking the page source, this website almost seems like a quine? The whole HTML is embedded inside a hidden form field.


Thank you very much for your comment. There was a part where the HTML of the top page was recursively repeated. We will consider how to improve it.


SSL_ERROR_BAD_CERT_DOMAIN on HTTPS :(


Thank you very much for your comment. We apologize for the inconvenience. I think that it does not support SSL and a warning is issued depending on the browser. When the funds to purchase https are accumulated, we will solve it with the highest priority.


You can have free SSL certification with Let's Encrypt! Highly recommended, good job on the site :)


Let's Encrypt was able to introduce free SSL authentication! Thank you for your advice!


Thank you very much for your comment. Can I get free SSL! We would like to thank you for your valuable information.


Visual bookmarks nice..


Thank you very much for your comment. I am very happy as a developer. I would like to update it little by little.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: