Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

171–180 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#171

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

When you turn actual, creative and exhausting work (vulnerability research) into some kind of high stakes gig job you deserve this problem.

I am not against bug hunting by any means, but if you want to me act like I care about your product and not about my money, pay me monthly.

Re: I pwned half of America's fast food chains simultaneously

#172

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

thanks for the clarification - I also read this as it took them a MONTH to fix the vulnerability.

Re: I pwned half of America's fast food chains simultaneously

#173

Earlier quoted context omitted.

That's what i was thinking too, not because it's not already 10th January in europe, but because i doubt you can except a 'thank you' in <8 hours. So I assume this might have been 2023?

It's 2024-01-10 07:11 in France

Duh, my head was still not awake. I wanted to write 'it's not even 8 am in europe'.

Re: I pwned half of America's fast food chains simultaneously

#174
post #170
post #58

Earlier quoted context omitted.

> It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan Pretty clear to me, "it was searching for exposed Firebase credentials on any of the hundreds of recent AI startups.", running a script to scan hundreds of startups > Sadly, many companies will freak out and get the law involved, even if you are a good samaritan. Yeah, but that also ends with that company being shamed a lot of…

Plain text passwords, seriously. At that point, I'm not sure what would be a similarity with any other engineering profession. The plain text passwords are beyond any rhyme or reason... and then returned to the end user client. If anything, I'd consider it malicious negligence - in the EU the leak would be a GDPR issue as well.

Don't worry, it was only a couple passwords for their admin accounts.

Re: I pwned half of America's fast food chains simultaneously

#175

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

Yeah... Is it ok to do a public writeup on the same date the vuln was patched without an acknowledgement from the client? I would have scheduled this blog post at least a week later.

Re: I pwned half of America's fast food chains simultaneously

#176

Earlier quoted context omitted.

what the hell, i see the same thing. it's crazy to me when large companies don't even have an option for: in case of dumpster fire, send an email here.

Technically it's not my problem (or on any other basis), but it bothers me because I'm weird. I was tempted to find their CTO on linked in and post a message there, along with the fact that there was no reply to my outreach nor a proper channel to do so. I think the only think in their defense is that they must get a lot of angry customer messages and they just don't want to deal with that.

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#177

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

When you turn actual, creative and exhausting work (vulnerability research) into some kind of high stakes gig job you deserve this problem. I am not against bug hunting by any means, but if you want to me act like I care about your product and not about my money, pay me monthly.

How do you measure productivity? How do you budget for a bug hunting department?

Re: I pwned half of America's fast food chains simultaneously

#178
post #31

Article gets to the point very quickly, nice.

Much appreciated, I am always open for further feedback too! (If there are ways I can improve my writing)

Article was good, and your instincts proved correct -- but if you want some truthful feedback, your headline is clickbait. You pwned a single vendor that happens to work with some fast food restaurants, you did not find a vulnerability within the restaurant companies themselves. "I pwned an applicant management system" is a lot less compelling than the headline you used.

Re: I pwned half of America's fast food chains simultaneously

#179

From Eva’s post: > we didnt know much about firebase at the time so we simply tried to find a tool to see if it was vulnerable to something obvious and we found firepwn, which seemed nice for a GUI tool, so we simply entered the details of chattr's firebase Genuinely curious (I’ve no infosec experience), wouldn’t there be a risk that a tool like this could phone home and log everything you find while doing research?

Yes, but that might also be caught by infosec users of said tool who have things similar to “littlesnitch” alerting them to the outbound API call attempt.

there used to be windows GUIs for forcing new connections to ask, but i haven't seen anything like it. I can't recall the name of the one i used to use, but it scored perfectly on shieldsUp - oh, Zone Alarm.

Littlesnitch iirc is macos only, but it sounds lovely for this sort of thing.

Re: I pwned half of America's fast food chains simultaneously

#180
post #162

Earlier quoted context omitted.

How so?

Because everyone makes mistakes, if you antagonize someone they are less likely to care about you and feel more obligation to protect their own.

Using plain text passwords goes well beyond a simple “mistake” in my book. It is negligent.
Post reply on HN