Live data from Hacker News

Websmart, Inc. and 100,000 Vulnerable Websites

samsclass.info

41–50 of 74 posts

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#41
It's reasonable to contact the affected sites, as well as Websmart. The sites might be able to fix themselves, depending on their level of technical involvement, and (despite the "Web Site by Websmart Inc." line) it's reasonable for an outsider to simply consider the vendor/contractor/hoster as an internal implementation detail, and the brand-at-risk as the principal.

But, the notification didn't need to inform all of them at once in the same message - revealing multiple vulnerable customers to each other, ratcheting up the embarrassment for Websmart before even seeing their initial reply. And the one week deadline before pursuing "more drastic remedies, such as contacting news media" starts things in a confrontational, threatening manner.

If the aim was being helpful, a notice to Websmart first, and then to each other site individually, would have highlighted the problem without activating defensive egos. The messages to individual sites wouldn't even have to name Websmart, just an indication that "your vendor or host may be the party best able to fix". (The fact that not all the "…by Websmart" sites have the bug may indicate it's only a certain type or generation of their work that's problematic, or that a fix is relatively easy.)

So I see both sides unnecessarily escalating the righteous anger with their communication choices.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#42
He seems to be confused by the difference between pages and sites - 100,000 pages is not 100,000 sites. And the search in question only finds 274 pages anyway.

So this is actually: "handful of sites have a sql injection vulnerability - owners & operators incapable of fixing". Hardly big news.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#43
My personal advice to all small-business-owners: Don't get into pissing matches!

Yeah, I don't like Sam Bowne's approach. His initial email read as someone looking to make a name for himself (this is the biggest security flaw I've ever found! You have 6 days to respond!).

Despite this, if I had received an email like this I would have sent back a personal thank you followed with an outline of action steps. If I get another email from Sam asking more questions I'd reply as quickly as possible. Every transaction between him and I would be professional.

I'm reminded of a time when someone was convinced I was a hacker. It's a bit of a long story; I was tasked with creating a certification course for 2,000 employees. They all get emails telling them to log in and one guy saw the domain (companyname.columbo-companyname.com) and thought it was a Phishing scam. This employee then pulled up my company, does a WHOIS, called my cell phone a few times* and then promptly sent an email to the CTO (and about 6 other VPs) about a rogue hacker.

The whole thing turned into a massive cluster, suddenly I'm getting emails and phone-calls about a hacker in MY site (the CTO assumed I had been hacked and they had been hacked by proxy, nobody knew what was going on).

Took a few days to sort out and when they found out where it started the CTO sent me an apology to which I responded "Hey, it's no big deal, it's great you have an employee willing to raise alarm bells like this.".

Problem Solved.

There's nothing to gain from pissing matches or threats.

* I suspect he's the one that called me, got a strange call & text right before all this went down from a number I didn't recognize.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#44
post #33

This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.

This is best for the vendor, but not best for the customers. Vendors should have a healthy fear that if they don't provide substantial security they will be exposed for their lack of quality. Now, I hope I'm not soliciting a 'test' of my work by saying this...

To a certain degree, I do agree. If websmart can't do this right, I imagine there are many other security vulnerabilities plaguing client sites. I will say that, as a client, I would want to know this.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#45
I'm picking up that Sam may be a little off. Or at least his reading skills are really questionable. The developer clearly stated that he would look into it, which is what you say when you first get word of something serious that needs to be looked into. And he was appreciative, emphatically so, about being informed. And annoyed about his customers being informed as well, but that annoyance is very understandable, even though he may have deserved some annoyance by his apparent lapse in coding rigor.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#46
Sam is in dangerous territory here. IANAL, but I think he may be close to being accused of Tortious Interference[1]

I noticed this in the initial response of websmart's owner that I've seen before in legal docs.

"I do not appreciate you taking the liberty of contacting my clients directly [...] you have no right or authority here. You could very well damage my business with this. If that happens you will be hearing from our lawyer."

This line in Sam's last email is especially dangerous (stating things he doesn't know and something which can be perceived as "soliciting for business"):

"This is a serious security defect. It is easy to fix, but Websmart has made it clear that they have no intention of fixing it. [...] If you have questions, or would like help fixing your website, feel free to contact me."

isn't very smart to say the least.

[1] http://en.wikipedia.org/wiki/Tortious_interference

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#47
There are several dead links and sql injection vulnerabilities on the company's website.

I can appreciate that it takes time and tact to deal with all the clients something he is hopefully doing but not even doing some basic work on your own corporate site is hard to understand.

There are also exploits in the Frontpage module his web server is running according to online databases.

Does this company have its own "cms" system? Is that why the error is so pervasive?

From what he says about his business under "About Us" the owner has a solid background of over 10 years in the broadcast industry as a radio personality.

My assumption is that he owns the business, and has owned it for a long time. He probably has very rudimentary html skills and can open his tool of choice DreamWeaver on a good day.

From what he says I think he outsources pretty much anything more than writing plain html. So he might be trying to deal with one or more contractors that he has hired for different sites. That probably makes it difficult for him to roll out any changes / patches in a timely manner. He is probably trying to get his / one of his contractors do it for free, since he has discovered its broken.

I think the appropriate action is for Owen Smart to take a step back. Take a deep breathe. Realize that he is in a shitstorm now since the story hit HN.

He needs to reach out to and reassure his clients. He might want some help from a PR person here to make sure he presents well. Make them see that he is competent and taking action.

Hire in a developer with a strong background in security to review the code base(s) for additional problems, and come up with an immediate mitigation plan, and work out a longer term plan to deal with the issues identified.

Make sure to follow up with the clients about target dates for fixing their sites.

He may also have to add a section on his corporate page, with some help from a PR person, and give his version of events in the best, least confrontational manner, and again say that he has the resources and the plan for addressing the issues that have been raised. Some BS about thanking the people who helped him find the issues. and reassuring future clients that this will no longer pose any problems.

Happiness all around.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#48

This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.

I think that the issue of customer contact is a red-herring. What caused the issue was not that Sam contacted the customers, but that he cc'ed his threatening e-mail to the vendor to the vendor's customers.

Any reasonable person would expect the vendor to take umbrage to being threatened with press coverage in front of his customers. Sam would have had the best chance getting the problem fixed by sending a separate e-mail to the vendor that did not include a presumption of bad faith.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#50

I find Websmart's attempt at trying to put this man out of a job absolutely disgusting. No doubt, Sam Bowne will think twice before reporting vulnerabilities next time. Even though I'm not in any way related to this incident, I've send Sam a thank you note because I think the web community needs more people like him. If you want to do the same, his e-mails are in the link, but for ease of access: sam(dot)bowne at gma…

Did they really try to put him out of work? I could not read any such thing in the vendor's emails. Perhaps the vendor just wanted to complain to the researcher's manager so he might receive additional training or so protocols could be set up for handling such issues?
Post reply on HN