Live data from Hacker News

Websmart, Inc. and 100,000 Vulnerable Websites

samsclass.info

11–20 of 74 posts

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#11
post #2

Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.

Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderate.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#12
post #5

Contact the vendor, give them time to fix it. Wtf are your contacting his customers? Sam, you are truly a moron.

It doesn't seem that he felt like taking any action since 2010

Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#13
post #5

Contact the vendor, give them time to fix it. Wtf are your contacting his customers? Sam, you are truly a moron.

It doesn't seem that he felt like taking any action since 2010

Yes, the company has had plenty of time to fix this amateurish error on their own, especially since it has been reported/detailed on exploit sites in the past.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#14
post #4

I appreciate that the guy's attitude is just awful, but the author really should have given him a chance to respond/react before contacting his clients. Doing so doesn't preclude notifying them eventually. It's just common courtesy.

I think he's doing the site owners a favor by contacting the person who could actually do something about it in addition to the owner. Ordinarily, he'd probably only contact the site owner. In this case, he saw that the builder of the site was consistent across multiple sites and chose to additionally contact the builder and not just the owner.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#16
post #2

Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.

Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…

No, he notified 11 of the vulnerable parties and failed to blind CC them.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#17

This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.

Technically the vendor responding is the only practical course of action. The customers are not likely going to abandon the software or patch it themselves.

This would only makes sense if the vendor didn't care. But even then its a long uphill battle.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#20

Earlier quoted context omitted.

It doesn't seem that he felt like taking any action since 2010

Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.

Maybe he was, maybe he wasn't, only he knows. But when you're running 100000 websites, you should Google yourself once in a while at least. Besides, this isn't some 0-day, it's some extremely basic SQL injection vulnerability. This company wasn't capable of doing extremely basic security, and should be out of business. This is the kind of company that stores your passwords in plaintext. He doesn't seem to have done anything since he was notified either (see Phil's comment)
Post reply on HN