Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

381–390 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#381
post #67

Stepping aside for a moment and thinking about the scope of this, I think it’s a good example of why technological diversity is something to long for. If Chattr can be pwned like this so easily, they likely have many much more serious issues which in turn will affect half of America’s fast food chains.

I've heard it told that's why BIND and unbound exist alongside each other

Re: I pwned half of America's fast food chains simultaneously

#382

This is extremely annoying. Instead of fucking with other people’s companies why not build your own? You pwned them? What are you twelve? All you did was commit a felony and post it online.

Pretty sure that poking around for holes/exploits is part of the definition of what is a hacker. They notified the relevant organization as well. Not sure why you take that stance.

Re: I pwned half of America's fast food chains simultaneously

#383

This is extremely annoying. Instead of fucking with other people’s companies why not build your own? You pwned them? What are you twelve? All you did was commit a felony and post it online.

How did the author "fuck with" the company beyond discovering a vulnerability and helping them fix it?

Re: I pwned half of America's fast food chains simultaneously

#384

If they're already using firebase, can anyone think why they are storing passwords? Firebase Authentication is incredibly easy and quick to setup and use (less than a day for someone new to it), which means you have no need to worry about passwords.

offshore workers

Re: I pwned half of America's fast food chains simultaneously

#385
post #124

If you view this page in Safari, it’s just a text document

Since this is a post about security, this is your daily reminder to update your browser to stay safe on the internet. Up-to-date versions of Safari support AVIF images, and there have been multiple RCE vulnerabilities with known exploits fixed last year in Safari...

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#386

Earlier quoted context omitted.

Deciding to sell this on the darknet is a life changing decision, white to black overnight and imagine not really something most would contemplate. Payment in BTC probably from an already compromised address so loads of factors. Probably an easy + quick 2BTC though

This is an easy and obvious exploit so an attacker would need to extract the data from all sources ASAP. High risk of getting caught and ending in jail to be honest for measly 2BTC. Not worth it for anyone in the US or even Europe.

> Not worth it for anyone in the US or even Europe.

Lots of crimes are not "worth it". And yet criminals do it anyway. Because criminals (nor most humans) are not perfectly rational.

There's routinely reports where people try to rob a gas station with a loaded gun - a $200 haul if everything goes perfect. It doesn't and now they have 10 years in jail...

Re: I pwned half of America's fast food chains simultaneously

#387
post #335

> No contact or thanks has been received back so far WTF.

I'm curious if the best monetary approach for a white hat hacker would be to show them the problem, give them time to fix it, and then give them an option to pay a consulting fee for the discovery in exchange for NOT publishing the exploit (after it has been fixed). The idea being the showing what you have found on other sites has marketing value for a white hat hacker, but had the company hired you to discover the f…

> give them an option to pay a consulting fee for the discovery in exchange for NOT publishing the exploit (after it has been fixed)

I'm not making any moral judgments, but purely from a legal perspective this sounds dangerously like blackmail. If anyone decides to take this path, be sure you understand the risks involved.

Re: I pwned half of America's fast food chains simultaneously

#388
post #61
post #56

It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan. If it is indeed the latter, I wonder how they are so brazen about it. Does chattr.ai have a responsible disclosure policy? In my eyes people should be free to pentest whatever as long as there is no intent to cause harm and any findings are reported. Sadly, many companies will freak out and get the law involved, even if you are…

> Good Samaritan The web is insecure enough as it is, I just want to do my part to make it that little bit safer :)

Either way it is a fascinating write-up. It will hopefully be a cautionary tale for other businesses and companies out there, and will inspire them to lockdown this credentialing issue. I've noticed a similar blasé attitude when implementing SSO; the devil is in the details as they say.

Re: I pwned half of America's fast food chains simultaneously

#389
post #69
post #61

Earlier quoted context omitted.

> Good Samaritan The web is insecure enough as it is, I just want to do my part to make it that little bit safer :)

I salute you for it. Take caution though. The bad guys don't play by the rules so the rules only hinder the good guys from helping. I think Internet security would be in a better position if we had legislation to protect good samaritan pentesters. Even moreso if they were appropriately rewarded.

How do you propose such a law would work?

Re: I pwned half of America's fast food chains simultaneously

#390
post #124

If you view this page in Safari, it’s just a text document

Since this is a post about security, this is your daily reminder to update your browser to stay safe on the internet. Up-to-date versions of Safari support AVIF images, and there have been multiple RCE vulnerabilities with known exploits fixed last year in Safari...

iphones are the scariest device to do anything important on.

I had a moment of total freakout when I realized the person across from me at lunch had an iPhone on the table. Actually he had an Android, and we continued talking like no big deal.

To be clear, we were talking about a 10-100M dollar problem, this wasnt small potatoes.

Too many exploits, I can't imagine having anything of value on an iphone.

Post reply on HN