And folks, this is why you sell your exploits to the highest bidder. Being "good" and giving companies free work is a HORRIBLE idea. They're never gonna pay, or even than you. If they're not willing to treat security researchers properly, I see no reason to return the favor. Remember security groups: if your company wont pay, there are others that will.
I pwned half of America's fast food chains simultaneously
291–300 of 513 posts
Re: I pwned half of America's fast food chains simultaneously
#292Re: I pwned half of America's fast food chains simultaneously
#293>With an upbeat pling my console alerted me that my script had finished running Forget the pwn how do I do this Also, HN used to think this was cool now there are 20 posts blaming the hacker…
Yeah, what happened to the "Hacker" in Hacker News. (responding to people blaming the 'hacker', not the sites). This guy just grabbed publicly available information, and by 'public' I mean put out onto the web un-protected, just put out there. If you can just basically browse to something, is it really his fault for finding it. It's like if I have a front door on my house, and just in the front hallway I have a huge…
Re: I pwned half of America's fast food chains simultaneously
#294> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…
When you turn actual, creative and exhausting work (vulnerability research) into some kind of high stakes gig job you deserve this problem. I am not against bug hunting by any means, but if you want to me act like I care about your product and not about my money, pay me monthly.
You don’t make HackerOne your primary source of security testing. It’s a fun thing you do in addition to your formal security work internally.
The reason people do it is because so many people expect or even demand payment and public recognition for submitting security issues they found. Just look at how many comments in this thread are insisting that they pay the author various amounts of money. The blog post even has a line about how they have not provided recognition (despite being posted exactly on the day it was fixed, giving the company almost no time to actually do so).
HackerOne style programs provide a way to formalize this, publicize the rules (e.g we pay $25K for privilege escalation or something) and give recognition to people finding the bugs.
Pentesters like it not only because they get paid, but now they can point to their record on a public website.
This isn’t a “gig economy bad” situation.
Re: I pwned half of America's fast food chains simultaneously
#295> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…
In cases where a small vulnerability is successfully turned into a larger vulnerability, everyone wins, right? Considering that there is “more than one way to skin a cat”, it is not a given that vulnerabilities further along the chain will be resolved by closing the initial vector. When a chain of vulnerabilities is reported it might become clear that not only does the initial attack vector need to be closed, but add…
Nope! The two vulnerabilities are usually one and the same. The person is just trying to find a clever way to access additional data to make their payout larger.
From the customer perspective, getting the initial vulnerability fixed ASAP is the best outcome.
When they start delaying things to explore creative ways to make their payout larger, everything goes unfixed longer.
Re: I pwned half of America's fast food chains simultaneously
#296Earlier quoted context omitted.
No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…
> No rules or laws that require it It will just be FTC knocking on your door…
Re: I pwned half of America's fast food chains simultaneously
#297>With an upbeat pling my console alerted me that my script had finished running Forget the pwn how do I do this Also, HN used to think this was cool now there are 20 posts blaming the hacker…
Fish config: https://github.com/qznc/dot/blob/master/config/fish/config.f...
Notification script: https://github.com/qznc/dot/blob/master/bin/notify_long_runn...
I stole it from some zsh solution originally.
Re: I pwned half of America's fast food chains simultaneously
#298If this had been exploited and the job applicants to Target, Subway, Dunkin et al, had bank/credit fraud committed in their name's, would the big companies be liable for not performing due dilligence on chatter.ai? To be clear, I'm asking from a legal standpoint not a practical one.
Re: I pwned half of America's fast food chains simultaneously
#299Re: I pwned half of America's fast food chains simultaneously
#300And folks, this is why you sell your exploits to the highest bidder. Being "good" and giving companies free work is a HORRIBLE idea. They're never gonna pay, or even than you. If they're not willing to treat security researchers properly, I see no reason to return the favor. Remember security groups: if your company wont pay, there are others that will.
Did you not see the part where applicants info was exposed? Make a few bucks by selling their data to is 10000x worse than the chatr dev not securing the files.
Chances are some blackhat already discovered this data and sold it.