Commission Junction Security Hole Discovered

Jul 22, 2005 - 4:28 pm 0 by

T0PS3O sent me a PM about this thread at DigitalPoint forums. The thread uncovers a security loophole in CJ's template repository management system. It was discovered when a DigitalPoint member asked;

When I check my site log stat. I found this dns ace.cj.com with ip address 216.34.209.23. It crawl every pages of my site. Are you familiar with it?

After more digging, one found the issues:

1. They have this machine publicly-accessible (it's not their main web server, somebody actually put in on the outside). 2. This apparently wasn't enough publicity for them and somebody ran/running a crawler on this machine, which identifies the machine to all the sites it's visiting. 3. There's no authentication of any kind for this system.

More information at the DigitalPoint thread.

 

Popular Categories

The Pulse of the search community

Search Video Recaps

 
Video Details More Videos Subscribe to Videos

Most Recent Articles

Search Forum Recap

Daily Search Forum Recap: November 14, 2025

Nov 14, 2025 - 10:00 am
Search Video Recaps

Search News Buzz Video Recap: Movemeber Google Update, Opal AI Spam, Discover Spam Fix, Copilot Search, Google Image Ads & More

Nov 14, 2025 - 8:01 am
Google Ads

Google Ads Advertiser Suspension Improvements: Faster & More Accurate

Nov 14, 2025 - 7:51 am
Google Ads

Google: Don't Close Your Google Ads Account To Make LSAs Work

Nov 14, 2025 - 7:41 am
Google

Google Shopping With AI Mode Comparisons, Call Store, Track Price & Agentic Checkout

Nov 14, 2025 - 7:31 am
Google Ads

Google Ads Brings Brand Inclusions To Standard Shopping Campaigns (NOPE)

Nov 14, 2025 - 7:21 am
 
Previous Story: Brazilian Use Orkut as Drug Selling Network