Content pfp
Content
@
0 reply
0 recast
0 reaction

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
@nook @slokh @emo.eth nook.social has an interesting logical redirection bug, which doesn't impact normal website usage, hence the decision to disclose it. The bug is triggered when visiting a user's homepage (e.g., users/1), where '1' is the fid (user ID).
5 replies
0 recast
4 reactions

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
query api: https://nook-api.up.railway.app/v0/search/preview?query=0x992
0 reply
0 recast
0 reaction

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
Thus, when we want to visit https://warpcast.com/99, we are erroneously redirected to Jesse's homepage https://nook.social/users/99 instead.
0 reply
0 recast
0 reaction

Hyperfatfingger pfp
Hyperfatfingger
@heapoverflow.eth
Nook doesn't distinguish between username and fid, leading to incorrect redirection when a username identical to a fid is used. As an example, @jessepollak 's fid is '99', if we attempt to visit a user with the username '99', we are wrongly redirected to 'jesse's' homepage.
0 reply
0 recast
0 reaction

Meta🎩 pfp
Meta🎩
@metawgmi
5000 $FOMO
0 reply
0 recast
1 reaction

0xLuo pfp
0xLuo
@0xluo.eth
what a bug. 10000 $FOMO
0 reply
0 recast
1 reaction

Poorboi pfp
Poorboi
@poorboi
10000 $FOMO
0 reply
0 recast
1 reaction

Fanx pfp
Fanx
@fanx
😘 10000 $FOMO
0 reply
0 recast
1 reaction

Theo pfp
Theo
@theodoricxxx
10000 $FOMO
0 reply
0 recast
1 reaction

renesisy pfp
renesisy
@renesisy
1000 $FOMO
0 reply
0 recast
1 reaction