Live data from Hacker News

Stealing checks worth millions and pwning a bank

jhaddix.com

11–20 of 35 posts

Re: Stealing checks worth millions and pwning a bank

#12
post #4

"The web app was so sensitive in nature I can’t really even describe the contents, but it was a big find by itself." Maybe that's true, and certainly the vulnerabilities described in more detail are already quite a big deal, but the author probably should have omitted the above quote from their post as it leaves the reader with some suspicion that perhaps this is a bit of a "Fish Story" (fisherman exaggerating the si…

Its self-promotion. Basically an ad for themselves. IMHO as annoying as an ad, except HN allows me to downvote it.

I like it because it describes how specifically the vulnerabilities were found and what specifically they were. If you’re doing security review or building a secure tool there are 5 items for your checklist.

Re: Stealing checks worth millions and pwning a bank

#14

The story ends inconclusively. I was expecting to know what the bank's reaction was or if they ever addressed these issues.

Also, aren't the checks worthless at that point, since they've already been cashed?

Yes, It's pretty difficult to deposit check images in bulk for other people's accounts.

There's still a privacy issue, and if he ran OCR on them, he'd have a bunch of account numbers, which would also be bad.

Re: Stealing checks worth millions and pwning a bank

#15

It's 2022, can we please stop saying 'pwned'? Sure, I'll take the karma hit for this comment.

Allow me my fantasy: I imagine you are a younger, polite, curmudgeonly person who sadly missed the bouncy joy of this word when it was fresh. This fantasy makes me want to keep using this annoying word that I somehow love.

Re: Stealing checks worth millions and pwning a bank

#16

It's 2022, can we please stop saying 'pwned'? Sure, I'll take the karma hit for this comment.

I'm down for using it in limited circumstances, like maximum pwnage, like when a university or municipality gets all of their computers ransomwared and negotiations fail with all the data being deleted with no backup.

But only in an off the cuff remark as a passive observer, amused by the circumstance and grandstanding necessary to fail so hard.

Re: Stealing checks worth millions and pwning a bank

#17

It's 2022, can we please stop saying 'pwned'? Sure, I'll take the karma hit for this comment.

What does it being 2022 have to do with it? Do colloquialisms have pre-determined expiration dates?

I guess Troy Hunt didn't get the memo either.

Re: Stealing checks worth millions and pwning a bank

#18
post #4

Earlier quoted context omitted.

Its self-promotion. Basically an ad for themselves. IMHO as annoying as an ad, except HN allows me to downvote it.

I like it because it describes how specifically the vulnerabilities were found and what specifically they were. If you’re doing security review or building a secure tool there are 5 items for your checklist.

They are bad mistakes that should have never have passed QA. Think a bit. Pentesting only makes sense if you don't have a functional QA.

Its like hiring a guy with a sledgehammer to test the stability of your bridge. You should hire a structural engineer instead, before building it. If the guy with the sledgehammer is successful, you should never have built the bridge in the first place.

Re: Stealing checks worth millions and pwning a bank

#19

The story ends inconclusively. I was expecting to know what the bank's reaction was or if they ever addressed these issues.

Also, aren't the checks worthless at that point, since they've already been cashed?

No, of course they aren't worthless. They give you the routing number, account number, and next check number in order to print your own fake checks on other people's accounts.

Re: Stealing checks worth millions and pwning a bank

#20

Earlier quoted context omitted.

I like it because it describes how specifically the vulnerabilities were found and what specifically they were. If you’re doing security review or building a secure tool there are 5 items for your checklist.

They are bad mistakes that should have never have passed QA. Think a bit. Pentesting only makes sense if you don't have a functional QA. Its like hiring a guy with a sledgehammer to test the stability of your bridge. You should hire a structural engineer instead, before building it. If the guy with the sledgehammer is successful, you should never have built the bridge in the first place.

You're assuming some companies have ways of testing their QA effectiveness. Especially in the case where your structural engineer is incompetent.
Post reply on HN