Possible security issue with download link

A secret forum for people who preorder Overgrowth!
Post Reply
brettalton
Posts: 7
Joined: Thu Aug 05, 2010 1:19 pm

Possible security issue with download link

Post by brettalton » Fri Aug 06, 2010 11:58 am

Hi guys,

I looked at the download link that is posted on the alpha 90 topic and saw it was...

http://www.wolfire.com/spf-download/a90-win.exe

However, that link made me enter my alpha key, which I did. Then the file started downloading. I tried to run the file, but it turned out the file didn't download fully and started with an error.

So I check the download link and it was...

http://static.wolfire.com/alpha/a90-win ... 1281113688

I re-ran the link to try and download the file, but it came up with an error saying the file expired. As a web developer, I looked at the query string and it looked like the file could be downloaded with it deleted, so I then used...

http://static.wolfire.com/alpha/a90-win.exe

And was able to download the file. I then ran another browser that had no session data with wolfire.com and tried to download the link with the file above and was still able to download the file.

This means someone could leak this link online and people could then download your alphas (assume your next one will be a91-win.exe). Now I know someone could easily put the file up as a torrent or megaupload/mediafire/rapidshare or even on their own personal server, but I thought you guys would like to know about this vulnerability I found.

Precastwig
Posts: 157
Joined: Sat Oct 31, 2009 6:27 pm

Re: Possible security issue with download link

Post by Precastwig » Fri Aug 06, 2010 2:05 pm

I see.....

Yes.

User avatar
Sandurz
Posts: 1105
Joined: Wed Dec 31, 2008 10:55 pm
Location: My House

Re: Possible security issue with download link

Post by Sandurz » Fri Aug 06, 2010 3:25 pm

You still have to enter your key into the file to activate it though, right?

brettalton
Posts: 7
Joined: Thu Aug 05, 2010 1:19 pm

Re: Possible security issue with download link

Post by brettalton » Fri Aug 06, 2010 7:44 pm

Sandurz wrote:You still have to enter your key into the file to activate it though, right?
Not from what I saw. I was able to download, run and install the game without entering my alpha key.

User avatar
Freshbite
Posts: 3256
Joined: Thu Jan 14, 2010 3:02 pm
Location: Stockholm, Sweden.

Re: Possible security issue with download link

Post by Freshbite » Fri Aug 06, 2010 8:42 pm

Removing the link with your key in it would be a great idea then, wouldn't it?
Not because the people here in the SPF would need it to share the game, but still.

User avatar
Endoperez
Posts: 5668
Joined: Sun Jan 11, 2009 7:41 am
Location: cold and dark and lovely Finland

Re: Possible security issue with download link

Post by Endoperez » Sat Aug 07, 2010 8:10 am

Same thing happens to me.

Jeff
Evil Twin
Posts: 2892
Joined: Wed Nov 19, 2003 10:48 pm
Location: San Francisco, CA
Contact:

Re: Possible security issue with download link

Post by Jeff » Sat Aug 07, 2010 11:56 am

fixed

User avatar
Count Roland
Posts: 2937
Joined: Tue Sep 25, 2007 11:15 pm
Location: Galapagos Islands, rodeoin some turtles.
Contact:

Re: Possible security issue with download link

Post by Count Roland » Sun Aug 08, 2010 3:06 am

Hooray for Jeff, and Wolfire in general.

User avatar
Ebrahim
Posts: 84
Joined: Sun Dec 13, 2009 6:47 pm
Location: London, England

Re: Possible security issue with download link

Post by Ebrahim » Sun Aug 08, 2010 5:02 am

and the internet ... ( and jaffacakes )

User avatar
Count Roland
Posts: 2937
Joined: Tue Sep 25, 2007 11:15 pm
Location: Galapagos Islands, rodeoin some turtles.
Contact:

Re: Possible security issue with download link

Post by Count Roland » Sun Aug 08, 2010 9:35 pm

and brettalton!

User avatar
OneEyedOdin
Posts: 17
Joined: Mon Jul 05, 2010 2:45 pm

Re: Possible security issue with download link

Post by OneEyedOdin » Tue Aug 10, 2010 8:44 am

and now I can finally pause/resume the 5** Mb download!!

Post Reply