privacy issues in metor.com (a search engine)

From: Tom Micklovitch (h_bugtraqat_private)
Date: Wed Mar 27 2002 - 01:57:05 PST

  • Next message: Lucien Fransman: "Re: Oracle9i TSN DoS Attack"

    I was justr checking the stats to my homepage, 
    and I saw this URL:
    
    http://www.metor.com/[91CB-0154-21F0]/se/results
    
    if you go there, you can see what was searched
    for. I have verified this, check out:
    
    http://www.metor.com/[91DE-056F-8A93]/se/results
    
    You'll see I typed "I search for this"
    
    On an interesting side-note, this could be an
    anonymous communication route - I've just left
    you a message that no-one can access unless they
    have the number-code between the square brackets.
    
    If there was some way to predict the next numbers
    in the sequence, you could trawl through for the
    next reply (say by always using "plipflop" in the
    replys, simply sequence through the next numbers,
    looking for "plipflop")
    
    anyway, that's all.
    
    User24
    
    =====
    -----BEGIN GEEK CODE BLOCK-----
    Version: 3.12 - www.ebb.org/ungeek/
    GIT d--- s--:- a--- C++++ UL++ P+ L+ E--- W+++ N- o-- K- w 
    O- M-- V- PS+++ PE-- Y+ PGP++ t+ 5- X+ R tv-- b+ DI++ D+ 
    G+ e* h r++ y+++ 
    ------END GEEK CODE BLOCK------
    
    __________________________________________________
    Do You Yahoo!?
    Yahoo! Movies - coverage of the 74th Academy Awards®
    http://movies.yahoo.com/
    



    This archive was generated by hypermail 2b30 : Fri Mar 29 2002 - 12:24:13 PST