Just use a framework to build your site. Don’t reinvent the wheel!
Accessing Max Verstappen's passport and PII through FIA bugs
11–20 of 151 posts
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#12Re: Accessing Max Verstappen's passport and PII through FIA bugs
#13Just use a framework to build your site. Don’t reinvent the wheel!
i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#14Just out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#15Just use a framework to build your site. Don’t reinvent the wheel!
How do you arrive at that conclusion after reading an article on how an API had a broken access control vulnerability?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#16Archaic company has archaic security. Well done on the RD, but boy does it not surprise me one bit. Would almost be willing to bet that the hash was MD5 too.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#17Just use a framework to build your site. Don’t reinvent the wheel!
> Just use a framework to build your site. Don’t reinvent the wheel! How do you arrive at that conclusion after reading an article on how an API had a broken access control vulnerability?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#18Earlier quoted context omitted.
i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.
It can. But it can be very bad at producing wheels that don't break.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#19That is shamefully poor security.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#20Strange, the site is run by an Ian Carroll, but the examples show Sam Curry, who is a very famous bug bounty hunter.
"Having been able to attend these events by hoarding airline miles and schmoozing certain cybersecurity vendors, Gal Nagli, Sam Curry, and I thought it would be fun to try and hack some of the different supporting websites for the Formula 1 events."