How is something like this not picked up in a pen test? Can only assume there never has been..
I've done tests several years on a row where I pop a service using the first years report.
21–30 of 91 posts
How is something like this not picked up in a pen test? Can only assume there never has been..
I've done tests several years on a row where I pop a service using the first years report.
Earlier quoted context omitted.
This has to do with being on a public network (an airplane), does it not? Maybe your outrage is over-the-top.
Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.
Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN?
I don't know what "address of the credit cards" means, but let's assume it's the target's home address.
You don't get their credit card number or security code. You don't get access information on any of their web accounts. Correct?
If you spy on their internet activity during the flight, it's all encrypted. You won't learn anything.
However, you do have the ability to change their password, so they can't get into their own account anymore.
You could also bill all your own activity to their account. I don't know if you can bill other things to the account.
You could get access to whatever data was stored in that account. I don't know what that would be, other than when & how much you used it in the past.
Is this a complete summary of the potential damage?
Since there's no Reply button for the two answers to this:
Neither of them answer my last question ("is this a complete summary..."). Should I assume it is?
And I never said "oh but the data leak isn't really that bad of a vulnerability" -- you did.
I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
These types of fails are generally due to incompetence, in my experience.
I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
Earlier quoted context omitted.
so many "pentests" are: * run scanner * print out report not a lot of deep diving
Yep. It's a shame. I once (long ago :)) alerted our CTO to an ongoing attack in production after seeing some obviously attack-oriented requests coming in and hitting our gateway. It became a pretty high-visibility incident for about 20 minutes until a manager spoke up that his "pen test" was being performed. Looking into the "testing" that was occurring they were attempting to scan for decade-old PHP bugs in a set of…
Can you recommend companies that you've personally worked with who employ knowledgeable security engineers (hackers) to perform real penetration tests and conduct valuable security scans resulting in value-add reports your engineering team can work with?
Not looking for naming and shaming...but rather "Who doesn't suck at doing this?".
Earlier quoted context omitted.
Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.
> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…
This has to do with API endpoints that exposed customer information and allowed password changes without checking that the request was coming from the customer. The customer didn't have to be logged in to the account, or even on the flight in the first place. If they had an account, it was exposed.
Earlier quoted context omitted.
Absolutely not. This has to do with how accounts for that network are managed. Even if you use a VPN you will still have an account there and your data were at risk to this vulnerability.
> The impact of these two bugs was signifcant. It was access to first name, last name, address, and email of the user as well as last 4 digits, expiration date, billing name, and address of the credit cards. Assuming you're a black hat exploiting this bug, what can you do, if the target is using a VPN? I don't know what "address of the credit cards" means, but let's assume it's the target's home address. You don't ge…
Earlier quoted context omitted.
Airplane wifi is very much still in the "enterprise software" phase, by which I mean a lowest bidder sells it to someone who will never use it and buys it with only some corporate objective in mind. I've been using it a lot recently, across several airlines, and the experience is universally bad. It doesn't surprise me they also skimped on security
At least as far as the connectivity itself goes, Viasat's Ka-band airplane WiFi is actually really good. As luck would have it, I've got a flight coming up in a few days on a plane using the provider implicated in this article. I'll be doing some poking around myself for sure.