Live data from Hacker News

Websmart, Inc. and 100,000 Vulnerable Websites

samsclass.info

51–60 of 74 posts

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#51

Sam is in dangerous territory here. IANAL, but I think he may be close to being accused of Tortious Interference[1] I noticed this in the initial response of websmart's owner that I've seen before in legal docs. "I do not appreciate you taking the liberty of contacting my clients directly [...] you have no right or authority here. You could very well damage my business with this. If that happens you will be hearing f…

Truthful warnings to people who are in danger is not tortious interference.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#52

Sam is in dangerous territory here. IANAL, but I think he may be close to being accused of Tortious Interference[1] I noticed this in the initial response of websmart's owner that I've seen before in legal docs. "I do not appreciate you taking the liberty of contacting my clients directly [...] you have no right or authority here. You could very well damage my business with this. If that happens you will be hearing f…

Truthful warnings to people who are in danger is not tortious interference.

being 100% correct and legally in the right is no defense against years of lawsuits

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#53

Earlier quoted context omitted.

Truthful warnings to people who are in danger is not tortious interference.

being 100% correct and legally in the right is no defense against years of lawsuits

If the law doesn't matter, then don't bring it up. Under your logic, you can replace "tortious interference" with "turnip testicles" and this discussion is equally meaningful.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#54
Is there really a SQL injection vulnerability?

Can someone describe the specific vulnerability in more detail? All the example URLs in the article yield an SQL syntax error, which definitely puts the site at high risk for such vulnerabilities. However, on the other hand, I saw no URLs that actually demonstrated successful injection.

For it to be an injection vulnerability, the server needs to execute the query (not fail with a syntax error).

Does anyone have a working example? Nothing malicious please. I tried several basic techniques and was unsuccessful, due to what appears to be escaping on double and single quote characters.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#55
post #45

I'm picking up that Sam may be a little off. Or at least his reading skills are really questionable. The developer clearly stated that he would look into it, which is what you say when you first get word of something serious that needs to be looked into. And he was appreciative, emphatically so, about being informed. And annoyed about his customers being informed as well, but that annoyance is very understandable, ev…

> The developer clearly stated that he would look into it

Belied by the developer's inaction since 2010. Did you read the whole page?

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#56

Surprise, many websites are not secure. Does he go around testing people's door locks to see how vulnerable they are to being picked with a basic lock pick set? Maybe knock on some doors and tell the home owners that their home contractor doesn't take security seriously enough and demonstrate how easily the standard door lock can be picked? I could understand if he was making a business out of this, selling improved…

Or maybe he could, you know, be trying to teach his students about security so they don't do shit like this in the future? "My students and I have been notifying administrators of vulnerable websites for several years now"

Teaching about security by looking for some basic low hanging fruit? Perhaps. But what he's also teaching is how to blame and shame, and needlessly tread into murky legal territory.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#57
post #29

Wow. Just wow. I used to manage client accounts at an agency. Here's how I'm seeing this: - Author sends a condescending, threatening, passive-aggressive, and shaming email to a vendor and its clients. - Vendor respectfully explains that it was an unprofessional thing to do, because their client relationships were put at risk without them having a chance to correct their mistake. - Author completely fails to understa…

[deleted]

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#58

Earlier quoted context omitted.

being 100% correct and legally in the right is no defense against years of lawsuits

If the law doesn't matter, then don't bring it up. Under your logic, you can replace "tortious interference" with "turnip testicles" and this discussion is equally meaningful.

Unlike a complaint naming turnip testicles, one that says tortious interference is less likely to get kicked by the judge in four seconds. Skating ->this<- close to the legal edge is definitely something worth bringing up.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#59
post #45

I'm picking up that Sam may be a little off. Or at least his reading skills are really questionable. The developer clearly stated that he would look into it, which is what you say when you first get word of something serious that needs to be looked into. And he was appreciative, emphatically so, about being informed. And annoyed about his customers being informed as well, but that annoyance is very understandable, ev…

> The developer clearly stated that he would look into it Belied by the developer's inaction since 2010. Did you read the whole page?

Looked like the developer was notified in 2013, not 2010. The flaw was just posted somewhere in 2010.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#60

Earlier quoted context omitted.

If the law doesn't matter, then don't bring it up. Under your logic, you can replace "tortious interference" with "turnip testicles" and this discussion is equally meaningful.

Unlike a complaint naming turnip testicles, one that says tortious interference is less likely to get kicked by the judge in four seconds. Skating ->this<- close to the legal edge is definitely something worth bringing up.

And I could sue you for libel and have it last more than four seconds, too. You're skating awfully close to the legal edge!

No, actually, you're not, any more than Sam is. This isn't a close call.

Post reply on HN