BUG Search functionality also checks hidden content.
by Zix - Wednesday January 8, 2025 at 10:13 PM
#1
Hello,

This may not strictly qualify as a “bug” per se, but I would like to highlight an issue that might need your attention. Specifically, the search functionality currently appears to process the entire content of a thread, including sections marked as hidden. While this design is understandable from a general usability point of view, it introduces a "vulnerability" that can be exploited by automated scripts or bots ( which are common on the forum ).

It is possible for someone to develop a scraper that systematically brute-forces links of hidden content. For instance, consider the scenario where one knows that @IntelBroker, typically uploads files to https://files.waifu.cat. A bot could easily automate the process of querying potential URLs by iterating over characters, like this:

If the next character in the sequence aligns with a valid URL, the SQL query executed by the search function returns a positive match and exposes the corresponding thread link.

To demonstrate, I started with the knowledge that @IntelBroker uploads files to https://files.waifu.cat, and after identifying a thread I had not yet unlocked the hidden data for ( https://breachforums.bf/Thread-SOURCE-CO...ata-Breach ), I began iterating through the characters. It took me approximately six minutes to access the hidden data manually.

Might be you don't find this important, but I hope to get your input on this @Hollow. Thanks in advance!
 
 
~~ Zixshore ~~

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
#2
26 Lower case
10 Numbers
Length cap lets take 8 excluding the file extension

36 * 8 = 288

lol 288 requests is the worst case scenario to figure out the hidden links
#3
(Jan 09, 2025, 05:26 AM)randomdev Wrote: 26 Lower case
10 Numbers
Length cap lets take 8 excluding the file extension

36 * 8 = 288

lol 288 requests is the worst case scenario to figure out the hidden links

Do note that 288 is the worst case scenario, best case scenario is 8 requests, I did it in around 25 requests.

For us upgraded users this might not be the best option, but for leechers / bots that are afraid of bans, this could help.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
#4
(Jan 08, 2025, 10:13 PM)Zixshore Wrote: Hello,

This may not strictly qualify as a “bug” per se, but I would like to highlight an issue that might need your attention. Specifically, the search functionality currently appears to process the entire content of a thread, including sections marked as hidden. While this design is understandable from a general usability point of view, it introduces a "vulnerability" that can be exploited by automated scripts or bots ( which are common on the forum ).

It is possible for someone to develop a scraper that systematically brute-forces links of hidden content. For instance, consider the scenario where one knows that @IntelBroker, typically uploads files to https://files.waifu.cat. A bot could easily automate the process of querying potential URLs by iterating over characters, like this:

If the next character in the sequence aligns with a valid URL, the SQL query executed by the search function returns a positive match and exposes the corresponding thread link.

To demonstrate, I started with the knowledge that @IntelBroker uploads files to https://files.waifu.cat, and after identifying a thread I had not yet unlocked the hidden data for ( https://breachforums.bf/Thread-SOURCE-CO...ata-Breach ), I began iterating through the characters. It took me approximately six minutes to access the hidden data manually.

Might be you don't find this important, but I hope to get your input on this @Hollow. Thanks in advance!
 
 
~~ Zixshore ~~

Is there a way to stop querying hidden data when using the forum search @Hollow?
#5
Well, this issue is not limited to waifu.cat domain only . The Search functionality, also can search for other file hosting services such as [pixeldrain, biteblob] within hidden content too.
#6
(Jan 09, 2025, 12:31 PM)vulture Wrote: Well, this issue is not limited to waifu.cat domain only . The Search functionality, also can search for other file hosting services such as [pixeldrain, biteblob] within hidden content too.

Indeed, but I chose only files.waifu.cat as an example.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
#7
(Jan 09, 2025, 09:38 AM)Zixshore Wrote:
(Jan 09, 2025, 05:26 AM)randomdev Wrote: 26 Lower case
10 Numbers
Length cap lets take 8 excluding the file extension

36 * 8 = 288

lol 288 requests is the worst case scenario to figure out the hidden links

Do note that 288 is the worst case scenario, best case scenario is 8 requests, I did it in around 25 requests.

For us upgraded users this might not be the best option, but for leechers / bots that are afraid of bans, this could help.

Yeah right and even for the worst case it barely takes few seconds - mins depends on implementation. I'm not sure if bf rate limited the searches tho. Hope they will take action to fix this.
#8
Not working anymore, nice

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.


Possibly Related Threads…
Thread Author Replies Views Last Post
  BUG BreachForums Shoutbox Markall 1 59 Apr 11, 2026, 10:04 AM
Last Post: Hollow
  BUG LISTENNN CHAT WE NEED STICKER BACK el_farado 10 311 Feb 08, 2026, 07:27 PM
Last Post: N/A
  BUG When "Sort by: Creation Time" and then "Next Page" does not work M0rk 1 66 Feb 08, 2026, 07:24 PM
Last Post: N/A
  BUG The next page buttons are not responding suicid 8 170 Feb 08, 2026, 07:24 PM
Last Post: N/A
  BUG CDN unstable over TOR (Error 503) DAN_8 3 143 Feb 08, 2026, 07:24 PM
Last Post: N/A

Forum Jump:


 Users browsing this forum: 1 Guest(s)