https://hulbee.com/?query=perl%20-e%20'print%20%22%3CIMG%20S...
Edit: I had an example of displaying the IP address back to the user from my server, but it went over capacity in a few short minutes, so I took it down and removed the link. I am sure everyone gets the point, specially with a lot of the other examples provided by other HN users below.
Here is a screen shot for future reference: http://imgur.com/PkAGhqn
<IMG SRC=http://kt-media.knowtechie.netdna-cdn.com/wp-content/uploads/2014/12/hacker1.jpg>
works as well. the server isn't executing perl, it's just not escaping client input allowing you to add html tags to the result page.edit: i should say - it's absurd that anyone can launch a website with this kind of vulnerability in 2015. every html rendering framework i've ever used/read about automatically sanitizes user input when generating the html. the only accidental way i can imagine someone doing this is building html from string concatenations...
edit2: for a simple challenge, try to embed other tags. like A or SCRIPT
https://hulbee.com/?query=%3C%2Fscript%3E%3Cimg%20src%3Dsdf%...
It runs on Chrome and bypasses the filter.
Edit: for context, the parent found an XSS issue. It was patched within a few hours. The patch was incomplete, and this one still worked. So, not only do they get it wrong for launch. When presented with an exploit they don't even patch the full vulnerability. I'll trust my data with someone who understands security, thank you very much.
The question here is whether this is a respect worthy effort at privacy protection.
EDIT: Flaws or holes have been found in Tor. Does that mean we reject the Tor effort outright? If anything, the holes found in Tor are more serious and fundamental, because they raise doubts about Tor's approach and whether their goal can ever be achieved. An HTML injection hole in Hulbee is simply an issue of incomplete execution of their vision, which may or may not be forgivable depending on the technical and non-technical circumstances (which none of us here know yet).
Contrastingly, websites sanitizing inputs has been done for quite some time; it is hardly new, difficult, or complex. It's fundamental. I would guess most people's answer is that this is not a sufficient effort to protect privacy or security.
If they've launched with an HTML injection vulnerability, their security infrastructure is not sufficient to protect your privacy. Game over.
https://hulbee.com/?query=%3CIMG%20SRC%3D..%2FImages%2Flogo-...
<IMG SRC=../Images/logo-hulbee.png onload=alert('hello')>
BTW google is doing it, Mickysoft and Apple is doing it - only difference is that they try to maintain exclusive customer access to these features, but it does not work out always.
hulbee entering the scene as an unrestricted distributed code execution platform freely available for anybody will change everything!
When you place an IMG tag, it tries to find some results by that image (similar to Google's seach by image->URL). Try using an invalid reference or IFRAME SRC.
Edit: I stand corrected. They do embed poorly-filtered request text into the results page.
There's no reason I should be able to embed the following onto someone else's page:
https://hulbee.com/?query=%3Ca%20href%3D%22%23%22%20obfuscate%3D%22238942932djwdj928%22%20onClick%3D%22alert('pwnd')%3B%22%3Eclick%20here%20for%20results%3C%2Fa%3E®ion=browser&uiLanguage=browserI see a "Clear my activity" link, why would it keep my activity at all? https://hulbee.com/Utils/ClearSettings?returnUrl=%2F%3Fquery...
Surly you could have afforded a better certificate than a C+ graded GoDaddy one? Sure, its 2048 bit SSL, but that is quite the SSL chain for being privacy focused.
https://www.ssllabs.com/ssltest/analyze.html?d=hulbee.com -vs- https://www.ssllabs.com/ssltest/analyze.html?d=duckduckgo.co...
Offering advertising on a privacy focused search engine? Could work, but when you're marketing to privacy focused individuals, you've just lost them.
In the end, I'm from Canada, my connection routes through New York (like most North American connections). My privacy is still being abused by greater forces whom likely have at least one of the private keys for one of the many certificates that make up that GoDaddy certificate, so I'll likely just stick with Google, or perhaps even DuckDuckGo.
Are you aware that adannonce.com belongs to Hulbee? Loading ads from adannonce.com should not bother you more than loading ads from hulbee.com . And the fact that it contains ads is no secret.
Please do your research before crying wolf in future.
It really doesn't matter what the CA cert is (I mean the CA infrastructure itself is kind of weak coughdiginotarcough) - what should matter more is configuring the server and the key size of the certificate.
I should note it's not hard to get an A+ on the test - I run a small source code hosting service and I have an A+ result from ssllabs.
gitlab has an A-/A and github has an A/A+ (yes - they are 2 different scores based on different servers.
See for yourself: https://hulbee.com/imprint | https://swisscows.ch/imprint
These sites `appear` to be exactly the same, I wonder what the difference is other than the design, branding and domain.
I've been using https://swisscows.ch for almost 6 months now. and was sharing it with my friends and family. Even made it the default on a lot of devices from friends and family. No negative feedback so far! I also shared it with you: https://news.ycombinator.com/item?id=9628904
So far there are only one two things that make me go back to google.com in rare occassions. On google "<search-term>" strictly gives me results with that term, that's appears not working similarly on hulbee/swisscows. If only I could sort search results by date and `strip results older than x` I would have no more reason to "google". What I really like about swisscows is the image and music search.
One questions bugs me: How does it work? I mean the results have the same and sometimes even higher quality than google. BIG +: No self-/government-/geo-censored results like on google/bing, I can find so called "illegal URLs" (links that don't appear on the big sites like DMCAed links and results for certain stopwords)
#bug: There is a bug on Firefox on Android in the image search. Clicking results opens a modal window with the resulting image below the viewable region. Screenshot: http://i.imgur.com/KClGfUO.png
The minute any business describes itself as "innovative", I assume they write everything in PL/SQL.
I've once done an informal "research", comparing some of the worst software sweatshops that I know against companies such as SpaceX. The metric used was the number of references to "innovation" and "innovative".
The results were very interesting. Highly recommended.
"In partnership with Bing" "Powered by Yandex" etc etc
https://hulbee.com/?query=how%20tall%20is%20mt%20everest%3F&...
vs.
https://encrypted.google.com/search?hl=en&q=how%20tall%20is%...
Hulbee can correlate the words "mt everest" to "Nepal," but it can't give me the actual answer. That's weak for a engine that claims to be "the first intelligent answer engine because it is based on semantic information recognition and offers users intuitive help in their search for answers."
If so that would be better than trusting all of these small companies to not sell you out a week before IPO.
Consider this: If before Wikipedia existed someone proposed to create an online encyclopedia that anyone in the world could anonymously edit, that it be funded by donations and that it become the encyclopedia that most people refer to, nearly 100% of us would have rolled on the floor and laughed out loud.
hulbee.ch uses an invalid security certificate. The
certificate is only valid for the following names:
*.hulbee.com, hulbee.comForce-TLS and HTTP Nowhere does what you describe.
It appears that a visual advertisement for Coke appears in the left frame, no matter what the search term is.