Live data from Hacker News

I compromised 300 stores and a “Spanish consultancy”

edbrsk.dev

11–20 of 49 posts

Re: I compromised 300 stores and a “Spanish consultancy”

#11
post #7

Umm this guy should tread lightly. Whats up with the prodding? This is some straight up blackhat hacking.

Yes, this crosses all the lines. You can debate the finer points of the SQL injection bit, but the moment he got into Rocket Chat admin and started gratuitously stealing employee cookies, there's just no way to paint that any color other than black.

As his bio states, he's a software engineer - clearly not a security professional, because he's steamrolling right through all infosec ethics.

A quick Google search for his username yields his GitHub with his real name, and he has a LinkedIn. He graduated from the same university as me.

Blackhat is not a good hobby, especially not with no opsec.

Re: I compromised 300 stores and a “Spanish consultancy”

#12
I don’t think HN should be a place for “company shaming”… unless the author contacted the company and they denied/rejected/threaten him instead of fixing the issues. I guess it did not happen.

I see HN as a place for collective learning. I don’t see what we can learn from this post.

Re: I compromised 300 stores and a “Spanish consultancy”

#14

Holy mac-shit-snacks! "..got access to the dashboard as a Super Admin in less than 1 minute. The password of this guy was the same as his username." AND credential reuse. Ouch. Ding, Ding, Ding! I think we have a winner for the fastest way to the unemployment line.

Firing employees for not knowing proper security practices is like being a teacher and firing your student for not knowing the answers on a test.

The employer should be performing proper audits and password rotations and/or educating their employees. It should never be "stupid users", but "stupid me".

Re: I compromised 300 stores and a “Spanish consultancy”

#15
post #7

Umm this guy should tread lightly. Whats up with the prodding? This is some straight up blackhat hacking.

Yes, this crosses all the lines. You can debate the finer points of the SQL injection bit, but the moment he got into Rocket Chat admin and started gratuitously stealing employee cookies, there's just no way to paint that any color other than black. As his bio states, he's a software engineer - clearly not a security professional, because he's steamrolling right through all infosec ethics. A quick Google search for h…

If I was interviewing the author for a role their complete disregard for infosec ethics would be a hard "no" from me - no matter how good they might be at interviewing.

Re: I compromised 300 stores and a “Spanish consultancy”

#16
post #7

Umm this guy should tread lightly. Whats up with the prodding? This is some straight up blackhat hacking.

Yes, this crosses all the lines. You can debate the finer points of the SQL injection bit, but the moment he got into Rocket Chat admin and started gratuitously stealing employee cookies, there's just no way to paint that any color other than black. As his bio states, he's a software engineer - clearly not a security professional, because he's steamrolling right through all infosec ethics. A quick Google search for h…

>Blackhat is not a good hobby, especially not with no opsec.

Putting your ident in the clear (or at least trivially bound to a real ID) is not better than having shitty security defaults.

Re: I compromised 300 stores and a “Spanish consultancy”

#17
post #14

Holy mac-shit-snacks! "..got access to the dashboard as a Super Admin in less than 1 minute. The password of this guy was the same as his username." AND credential reuse. Ouch. Ding, Ding, Ding! I think we have a winner for the fastest way to the unemployment line.

Firing employees for not knowing proper security practices is like being a teacher and firing your student for not knowing the answers on a test. The employer should be performing proper audits and password rotations and/or educating their employees. It should never be "stupid users", but "stupid me".

Not parent, but I reckon that a company might see "oh this employee didn't follow our clearly signposted security guidelines, let's just fire them and get on with our lives" as an easier way out than "we have to actually start to invest into security".

I'm not saying that's good, but I could definitely see it happening.

Re: I compromised 300 stores and a “Spanish consultancy”

#18
post #14

Holy mac-shit-snacks! "..got access to the dashboard as a Super Admin in less than 1 minute. The password of this guy was the same as his username." AND credential reuse. Ouch. Ding, Ding, Ding! I think we have a winner for the fastest way to the unemployment line.

Firing employees for not knowing proper security practices is like being a teacher and firing your student for not knowing the answers on a test. The employer should be performing proper audits and password rotations and/or educating their employees. It should never be "stupid users", but "stupid me".

I have no wish to start a flame-war here but I would politely disagree with your point of view. Even non-techie users are taught not to reuse credentials. Sure, they still do buuuttt...as an Admin for a 300+ client CMS system ... to not know any better is inexcusable. Even if they didn't know it at the time of starting out in the industry - at what point would they be so blind as to not know / have read about hacks of others and/or the existance of haveibeenpwned and seen the error of their ways?

Sorry but no. No.

Re: I compromised 300 stores and a “Spanish consultancy”

#20
post #14

Earlier quoted context omitted.

Firing employees for not knowing proper security practices is like being a teacher and firing your student for not knowing the answers on a test. The employer should be performing proper audits and password rotations and/or educating their employees. It should never be "stupid users", but "stupid me".

I have no wish to start a flame-war here but I would politely disagree with your point of view. Even non-techie users are taught not to reuse credentials. Sure, they still do buuuttt...as an Admin for a 300+ client CMS system ... to not know any better is inexcusable. Even if they didn't know it at the time of starting out in the industry - at what point would they be so blind as to not know / have read about hacks o…

> to not know any better is inexcusable

Where are they supposed to get this information if they're never taught it?

> at what point would they be so blind as to not know / have read about hacks of others and/or the existance of haveibeenpwned and seen the error of their ways?

Most people outside the tech departments have no idea what those things are. They think hacking is stuff that happens in movies, not in real life.

Sorry, but yes yes.

Post reply on HN