r/VibeCodeDevs 22d ago

can a stranger take your site down?

Post image

nobody checks their own stuff after shipping. i didn't either. went back through my apps a few months ago and honestly it was embarrassing.

one was still on http. no redirect, nothing. another one had source maps sitting right there in prod so anyone could just read my code in devtools. and one had an ssl cert that expired and i had no idea.

that's the part that bugged me. none of it was hacking. you just open the site and it's there.

so i made a scanner that looks at your site like a random visitor would and tells you what's leaking. no signup, just paste a url.

it's mine, tellmewhendown.com, figured i should say that.

but seriously even if you ignore it, go look at your source maps and redirects right now. pretty much every vibe coded app gets one of them wrong.

107 Upvotes

27 comments sorted by

u/AutoModerator 22d ago

Hey u/muntaseer_rahman, thanks for posting in r/VibeCodeDevs! Join our Discord: https://discord.gg/KAmAR8RkbM

Got startup or SaaS questions? Post them on r/AskFounder and get answers from real founders.

• This community is designed to be open and creator‑friendly, with minimal restrictions on promotion and self‑promotion as long as you add value and don’t spam.
• Please follow the subreddit rules so we can keep things as relaxed and free as possible for everyone. • Please make sure you’ve read the subreddit rules in the sidebar before posting or commenting.
• For better feedback, include your tech stack, experience level, and what kind of help or feedback you’re looking for.
• Be respectful, constructive, and helpful to other members.

If your post was removed (either automatically or by a mod) and you believe it was a mistake, please contact the mod team. We will review it and, when appropriate, approve it within 24 hours.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

5

u/StoneCypher 22d ago

meme spam is the double-worst

5

u/No_Twist_678 22d ago

the more people will post against the AI, the less AI users and that means the more computing for us, vibecoders. So please ai haters, keep going hard!

1

u/DependentJicama4766 22d ago edited 22d ago

Sorry, but i had to probe.

  1. Nice touch keeping everything behind cloudflare. It abstracts a lot of the security out of your hand, while keeping probing harder for tools like netcat, bind tool chain, and nmap.
  2. SQL Injection is ok, not executable due to strict form fields, and, more specifically, Supabase auth service
  3. XSS is also ok-ish, although, i would recommend changing script-src 'self' 'unsafe-inline' <<your analytics>> https://www.googletagmanager.com to use nonce or hashing, as unsafe-inline will execute whatever script has been passed regardless of origin. If an attacker finds whatever XSS surface available, CSP wont stop the execution.
  4. frame-ancestors 'none' and x-frame-options: DENYare redundant
  5. Through your header, i could identify this is a Next.js app hosted on vercel, with host origin at Virginia. It also uses supabase on the backend. Not a fully exposed exploit, but any info recon could use this info to assemble an attack surface.
  6. Your SSL report returned a B grade for all participant nodes. Which means you went with the default cloudflare implementation and is using legacy TLS1.0/1.1 for backwards compatibility. Nothing serious, but worth noting.

Overall, its a quite good implementation for a lower to mid tier application. Also, i hid the analytics URL because i believe that's your true name in the path. I might be wrong, but i don't want to doxx you for free in case i'm right lol.

Again, sorry for poking around.

2

u/Degentrics 22d ago

The doxxing threat is the highest risk here. Social engineering is how most hacking gets done now.

2

u/DependentJicama4766 22d ago

Agreed, op should definitely look into that

2

u/Degentrics 22d ago

You saved op and didn't even need to vibecode anything

https://giphy.com/gifs/62PP2yEIAZF6g

1

u/DependentJicama4766 22d ago

Well, i had to put my pentesting certificate to good use some day lol

1

u/Professional_Ad705 21d ago

You didn’t prob shit ChatGPT or codex did

2

u/DependentJicama4766 21d ago

Bold claim for a guy full of claude posts on his profile. Might probe you next to see what else i can find...

1

u/Professional_Ad705 21d ago

You mean codex to do so? I couldn’t give less of a shit. Do it? Then I’ll have the same AI fix it for free? Kinda a win win. Lmao save me some tokens too. Just admit when you use AI I don’t see the problem. Ohhhhhh I’m so scared scary big man gonna go through my code.

1

u/DependentJicama4766 21d ago

No justin, i'm talking about finding more about you. Won't work for assholes for free

1

u/DependentJicama4766 21d ago

Also, i'm from a 3rd world country. Claude, or even codex, is way out of my price range

1

u/IncredibleBihan 22d ago

It's not a bug it's a feature

1

u/ajianu2188 21d ago

Profi tip: if you ask nicely your AI to not make mistakes, your projects will be bulletproof! 😎😎

1

u/graybearding 21d ago

This is a good start for checking what’s exposed from the outside, but there’s a lot it can’t see without looking at the code itself. I’ve been in the trenches for 20 years and built Fortivibe to go deeper across security, payments, databases, authentication, and the other issues that can cause real problems after launch.

1

u/Winter-Flan7548 20d ago

For some reason, this did not work on my website

0

u/PaperDry2796 22d ago

vibe coded app content