Earlier quoted context omitted.
Post them anonymously and see how fast they become too expensive to not fix.
Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…
What Happens When You Send a Zero-Day to a Bank?
381–390 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#382There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
There was a guy who got thrown in prison for bringing a vulnerability to the attention of AT&T. He was thrown in solitary confinement for over a year. Then his sentence got vacated. What did he do as soon as he was released from prison? He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRD…
There are examples of honest people getting fucked over, but this isn't one of them.
Re: What Happens When You Send a Zero-Day to a Bank?
#383Earlier quoted context omitted.
I thought it was significant that they were able to distinguish it as a common-law concept. Are you implying this was something like a lucky guess on their part?
My guess is that 'beefhash is not from a common law country and was only able to figure out for sure that the topic is a part of common law.
Re: What Happens When You Send a Zero-Day to a Bank?
#384this is a major bombshell. I'd hate to be those guys running zecco. The fact that they coerced an NDA to hide the millions of customer transactions that now have no way of proving were legitimate or not. I'm pretty sure the author wasn't the only guy looking for vulnerability. I'm pretty certain criminal minded folks would've already used it....with no way of finding out which are real or manipulated. Which further r…
It's unlikely, but my point is it's a hole in their system which would allow this to happen and it seems like they've deliberately let it continue. :(
Re: What Happens When You Send a Zero-Day to a Bank?
#385Earlier quoted context omitted.
The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.
Maybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.
Re: What Happens When You Send a Zero-Day to a Bank?
#386Earlier quoted context omitted.
I felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says: "But this only affects people that are logged in, right? Yes ..." So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser. If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with…
>eg viewing a malicous email with the IMG tag in a webmail client The article mentions it would occur even without opening the email.
You could also abuse Firefox and Chrome prefetching links. I'm not sure Gmail for example remove prefetching attributes in spam links. They do block images though.
Re: What Happens When You Send a Zero-Day to a Bank?
#387Earlier quoted context omitted.
No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law. The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume…
...I'm worried of how much incentive there is to become a black hat. Either you risk prison... either earn a lot of bitcoin.
Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some goodwill, especially those that include payouts of five figures or more, but those companies have to be careful that they don't accidentally create an environment where bidding wars between exploiters and companies are legitimized.
Re: What Happens When You Send a Zero-Day to a Bank?
#388I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...
Are most of these actually still there? The password requirements have changed dramatically in the last 6 months.
I no longer hold any assets at Schwab, but I do poke around every now and then, and it's possible they changed things without me noticing.
Re: What Happens When You Send a Zero-Day to a Bank?
#389Earlier quoted context omitted.
"The text of the CFAA forbids "unauthorized access" or "exceeding authorized access"." BOOM! And they've been harsh on hackers for a long time. So, the vulnerability must not require violating access controls or system integrity to be safest. Hackers should be in the clear if it was simply noticing something in HTML/HTTP or whatever that indicated insecurity. An example might be a breakable cipher-suite or handling s…
It sounds awfully close to what got weev sent to jail.
1. conspiracy to access a computer without authorization
2. fraud in connection with personal information
This is because Goatse Security not only noticed the vulnerability itself, but because they wrote and executed a script called the "iPad 3G Account Slurper" to iterate over ICC-IDs, returning the associated email address for each one.
Executing the script against AT&T's servers probably is a bona fide violation of the CFAA, not just a conspiracy, but I would guess it's simpler to bring the conspiracy charge since you don't have to get into the nitty gritty of actual requests made, etc.
According to the complaint, they proceeded to email a handful of notable people whose emails had been harvested, including someone on the Board of Directors at News Corp. All of these contacts appear to be media outlets. The Gawker article also lists some of the people whose email addresses were extracted this way (without disclosing their emails).
I'm assuming this direct communication to journalists and/or execs at journalism outlets gives rise to the fraud with personal information charge.
Overall, I don't think that weev did anything that I wouldn't have necessarily have done if I were in that situation (trying to drum up attention and make a name for his consulting firm), but it's different from this disclosure because as far as we know, this researcher did not actually exploit the vulnerability and he has not obtained or disclosed any information from doing so.
Again, not a lawyer.
Re: What Happens When You Send a Zero-Day to a Bank?
#390Earlier quoted context omitted.
...I'm worried of how much incentive there is to become a black hat. Either you risk prison... either earn a lot of bitcoin.
Yeah, the incentives are perverse. This is more of a symptom of the function of our legal apparatus than the law itself, because in theory, going through the legal process should be quick and if not affordable, at least reasonably doable for the individual or small business. Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some g…
Why not? Yes prices can become high, but isn't that the work of the researcher? If the company doesn't want to have to purchase expensive bounties, they can either reduce the exposure (less legacy code, fewer APIs, more firewalls) or use more strict security rules.
I'd feel safer if LastPass' bounty was higher than the value of the assets I put in that vault. If the value of a single vault (mine, actually) is $10,000 and the bug bounty is $2500 (which it is), how can we persuade discoverers to sell to LastPass?