Were cookies shared across sites in 2008? It seems pretty odd..
What Happens When You Send a Zero-Day to a Bank?
311–320 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#312Earlier quoted context omitted.
Sure banks can. Source: did software security for a number of banks. Big banks are chock full o' CSRFs, XSS, SSRFs, and SQLIs. They get found all the time. For every valid report they get, they get 3 that aren't valid. Nobody's hair achieves ignition over this stuff. There are two types of financial service organizations: the big banks, and random firms (like Zecco was, before Ally bought them). There's no point in c…
I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…
Re: What Happens When You Send a Zero-Day to a Bank?
#313Earlier quoted context omitted.
There is. Carnegie-Mellon University's CERT. Here's the form for reporting a vulnerability.[1] For this kind of problem, select "Request Vulnerability Coordination Assistance". You can even do this anonymously. The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact th…
I don't recommend submitting to CERT unless you genuinely don't care about the outcome of reporting. Yes, reporting to CERT is "safe"; you almost certainly aren't going to get sued for doing it. But don't count on CERT coordinating a fix or even figuring out how to report flaws to. It's unlikely that anyone at CERT knows who "Zecco" is. CERT themselves ask you not to submit to CERT unless your vulnerability fits some…
Re: What Happens When You Send a Zero-Day to a Bank?
#314Earlier quoted context omitted.
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
Someone in another forum commented recently that there should be a new top-line federal agency whose mission is to promote the security of America's information infrastructure. They suggested it should be established as an adversarial check/balance against e.g., the CIA and NSA. https://twitter.com/Snowden/status/839168025517522944 Maybe if they were required by statute to accept anonymous submissions and make FOIA-s…
The offensive organization wold probably then still sit on vulnerabilities only it knew about, but at least this would be better than the current situation.
Re: What Happens When You Send a Zero-Day to a Bank?
#315Earlier quoted context omitted.
Sure banks can. Source: did software security for a number of banks. Big banks are chock full o' CSRFs, XSS, SSRFs, and SQLIs. They get found all the time. For every valid report they get, they get 3 that aren't valid. Nobody's hair achieves ignition over this stuff. There are two types of financial service organizations: the big banks, and random firms (like Zecco was, before Ally bought them). There's no point in c…
I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…
Re: What Happens When You Send a Zero-Day to a Bank?
#316Earlier quoted context omitted.
I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…
As someone who has been on the receiving end of a bug bounty's mailbox, 3-to-1 sounds about right. We got a ton of invalid "security vulnerabilities" that were essentially either people reporting OAuth as a vulnerability or not understanding how XSS actually worked. Most of these came from teenagers in southeast Asia.
Re: What Happens When You Send a Zero-Day to a Bank?
#317Earlier quoted context omitted.
Your definition would include tradesmen and craftworkers, then, who are not strictly professionals. Anyone can work in wood long enough to say "That wooden bridge looks like it'll hold X people," and not have any way of conveying how they came to that conclusion, because they didn't learn via a means of studying a specific body of work that can be measured and accredited. Without this distinction, many professions wo…
> Your definition would include tradesmen and craftworkers, then, who are not strictly professionals. According to what definition? > Anyone can work in wood long enough to say "That wooden bridge looks like it'll hold X people,"... I severely doubt that, given the complexity of trussed bridge designs [0]. There's a lot more to it than how much weight a 4-by-4 can support. > ... and not have any way of conveying how…
The dictionary's.
> You can't just throw out "circular definition is fallacy" and dismiss the idea.
Your definition was illogical, and I dismissed it, so yes, I can.
Re: What Happens When You Send a Zero-Day to a Bank?
#318Earlier quoted context omitted.
> For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. Again, the IP address would obviously be associated with him and the browser because that's how the vulnerability works. The attacker just has to get the victim to visit…
The attack would leave traces. Timestamps would show when exactly the request was made, ISP logs or data from the claimants computer would show other requests in the same seconds (i.e. wherever the victim got served the malicious link); Sending the img link by email would be visible in that email; getting the user to view a malicious post on some webpage/forum/etc is likely to leave evidence there. In general, you ma…
Re: What Happens When You Send a Zero-Day to a Bank?
#319Earlier quoted context omitted.
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.
It is unlikely that there is a company in the US that has a security team that hasn't heard of H1. They're kind of a big deal. Since they're the ones handling the first contact in these situations, you can safely let their name be their problem; they know how to explain themselves. The more realistic concern here is that for these kinds of findings --- CSRFs in random web applications --- there simply isn't going to…
You'd be surprised. HackerOne is relatively new, just several years old. Does everyone know OWASP, almost certainly yes. Does everyone know the BSide community? No.
Anyway, H1 can act as a shield, in this case. On the other hand, companies like WhiteHat or Rapid7 are probably more well-known since they will probably spam your security team on a regular basis trying to sell their products.
Re: What Happens When You Send a Zero-Day to a Bank?
#320I would not be surprised if this turns into a class action lawsuit. The negligence here is remarkable.
You need damages to have a class action lawsuit. What are your damages? I am not saying no one has damages, but if 100s of people had damages, I expect something would have happened...