April 2
April 1
Poking at $website and trying to figure out their API. Oh, look, they're using the $platform codebase, and it has a version API call. Oh WOW, that's kinda old. Anyway, I wonder what the API implements? Oh look, the source is on GitHub so I can find the exact version they're using. Hey, cool, here's a useful API call that wasn't mentioned in the docs!

$ curl -s 'http://$website/api/$thingy'

Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 180 bytes) in /var/www/thingy/wossname/etc/etc/etc

Er, sorry! Maybe you guys should turn that off? (I've tried to contact this site directly before, through their built-in "contact-us" form. No response. Shame, because I suspect they'd like to know that they're basically open to a denial-of-service attack.)

