
Medium has become the go-to online publishing platform for writing and documents that exceed Twitter's 140-character limit, and is used not only by researchers and CEOs, but also by the President of the United States. However, a hacker has now found a way to edit or delete any post on the publishing platform.
Speaking to Motherboard in an email, Allan Jay Dumanhug, an independent tester and bug said, “I was trying to think of different possibilities on how I could delete a user’s story. And luckily, I found a serious bug.”
In a blog post published late last month, Dumanhug explained the trick, which centers around Medium’s “Publications” feature. Users can create their own posts, like a page dedicated to INFOSEC, for example, and then request that other users’ posts be added to it. Each post on Medium gets its own unique 12-character identifier.
The person who wrote the post must approve this request. However, Dumanhug discovered that as he added his own story to his own post, he could intercept the HTTP request and simply change the ID to that of another post. It is possible from here to edit or even delete the story entirely. However, Dumanhug did not delete any post while receiving $350 as a fee for informing Medium.
Although Medium uses HTTPS, a protocol for encrypting data in transit, this attack is still possible. However, Dumanhug would not have been able to see or experiment with the content of the post if he had not spied on the encrypted traffic.
But a Medium spokesperson told Motherboard in an email that, “this was a software bug that this researcher uncovered by manipulating parameters in a URL outside of the normal user flow,” which means the traffic would not have been encrypted.
“We are really proud of Medium’s security track record: We have fixed bugs incredibly quickly and the reward program has helped our team be even more rigorous. Furthermore, we have a semi-annual external security audit and can fix and deploy patches very quickly and we really value the research community of white hat researchers.”
