This is extremely annoying. Instead of fucking with other people’s companies why not build your own? You pwned them? What are you twelve? All you did was commit a felony and post it online.
Pretty sure that poking around for holes/exploits is part of the definition of what is a hacker. They notified the relevant organization as well. Not sure why you take that stance.
I pwned half of America's fast food chains simultaneously
401–410 of 513 posts
Re: I pwned half of America's fast food chains simultaneously
#402Earlier quoted context omitted.
Still missing something - the garage would have to be on your private property, not visible from public property, and the only way he could check for you is if he entered your property and tried to get into your garage.
On the contrary, I would say that this is a garage you rent on a public space. The internet is open and I can do requests to any server. If you don't want your system to answer me, make sure it does not. If I am in front of an ATM on the public street, it doesn't give me money without authorization. Make sure your server does the same.
Re: I pwned half of America's fast food chains simultaneously
#403> No contact or thanks has been received back so far WTF.
I'm curious if the best monetary approach for a white hat hacker would be to show them the problem, give them time to fix it, and then give them an option to pay a consulting fee for the discovery in exchange for NOT publishing the exploit (after it has been fixed). The idea being the showing what you have found on other sites has marketing value for a white hat hacker, but had the company hired you to discover the f…
So... you're suggesting blackmail?
Re: I pwned half of America's fast food chains simultaneously
#404If you view this page in Safari, it’s just a text document
It is using the Avif format (for images) for a 2x compression bonus over PNG while still maintaining a higher quality over JPG. If you can't view the images then it means you are likely using an outdated browser, all current versions of browsers support it (afaik) except Internet Explorer.[0] ...And if you are using Internet Explorer, then god help you. [0] https://caniuse.com/avif
Re: I pwned half of America's fast food chains simultaneously
#405Earlier quoted context omitted.
This is an easy and obvious exploit so an attacker would need to extract the data from all sources ASAP. High risk of getting caught and ending in jail to be honest for measly 2BTC. Not worth it for anyone in the US or even Europe.
> Not worth it for anyone in the US or even Europe. Lots of crimes are not "worth it". And yet criminals do it anyway. Because criminals (nor most humans) are not perfectly rational. There's routinely reports where people try to rob a gas station with a loaded gun - a $200 haul if everything goes perfect. It doesn't and now they have 10 years in jail...
If you’re a felon and unskilled you’re as desperate as it gets in America.
Re: I pwned half of America's fast food chains simultaneously
#406Earlier quoted context omitted.
No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…
There are state laws that this runs afoul of. https://www.mass.gov/regulations/201-CMR-1700-standards-for-...
It’s very basic. There’s no best practices clauses it’s all “reasonable” clauses. Also no requirement for an external audit.
Re: I pwned half of America's fast food chains simultaneously
#407Earlier quoted context omitted.
Since this is a post about security, this is your daily reminder to update your browser to stay safe on the internet. Up-to-date versions of Safari support AVIF images, and there have been multiple RCE vulnerabilities with known exploits fixed last year in Safari...
iphones are the scariest device to do anything important on. I had a moment of total freakout when I realized the person across from me at lunch had an iPhone on the table. Actually he had an Android, and we continued talking like no big deal. To be clear, we were talking about a 10-100M dollar problem, this wasnt small potatoes. Too many exploits, I can't imagine having anything of value on an iphone.
Why?
Re: I pwned half of America's fast food chains simultaneously
#408Re: I pwned half of America's fast food chains simultaneously
#409Earlier quoted context omitted.
No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…
> No rules or laws that require it It will just be FTC knocking on your door…
Re: I pwned half of America's fast food chains simultaneously
#410Earlier quoted context omitted.
I salute you for it. Take caution though. The bad guys don't play by the rules so the rules only hinder the good guys from helping. I think Internet security would be in a better position if we had legislation to protect good samaritan pentesters. Even moreso if they were appropriately rewarded.
How do you propose such a law would work?
1. White hat submits a "Notice of Vulnerability Testing" document to target company (copy also sent to government body) including their information, what systems will be tested, and in what time window
2. Company is required to acknowledge the notice within X hours and grant permission or respond with a reason that the test cannot take place
3. White hat performs testing according to the plan
4. White hat discloses any findings to the company (keeping government body in the loop)
5. Company patches systems and may reward white hat at their discretion
6. Government body determines if fines should be applied and may also reward white hat at their discretion
Something like that. The white hat would have legal immunity as long as they submit the document, stick to the plan, and don't cause damage.