Earlier quoted context omitted.
You know exactly, what I have been referring to. The system is broken. Honestly, who cares if a young guy purchased a ticket to prove his right regarding a bug? How could he do otherwise? You need to make sure about the backend part of the system, too. Meanwhile, the company that developed this "service" is silent and the financing part is also not public, but we can be sure it was not cheap. The whole BKK e-ticket s…
No I do not know.
18yo arrested for reporting a bug in the new Budapest e-Ticket system
121–130 of 329 posts
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#122is HN hugging shop.bkk.hu to death?
visiting https://bkk.hu/ (and watching the dev console) shows that they obviously develop their page http-first (various resources won't load in firefox due mixed http(s))
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#123I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…
I'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocke…
To push your analogy further, the non-tech person thinks of this type of exploit discovery as if someone has trespassed onto their private yard in the cover of darkness, trying every door and window.
A tech savvy person might instead think of it as a row of doors lined up next to a busy street, in broad daylight.
Knocking, and telling someone that they have "forgot their keys in the door" seems a bit creepy in the first scenario, but completely legitimate in the second.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#124I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found. Protection from this kind of blame-shifting and misdirected retaliation should be guarantee…
I understand that it's good to have cover for this sort of thing. I think the line is pretty grey though. One analogy is telling a company that their front door is unlocked. Another analogy is going into an unlocked front door, and going deeper into the building, and then reporting to the company that you could, in fact, get to classified information from this door. IRL Pentesters get permission before trying to snea…
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#125Earlier quoted context omitted.
visiting https://bkk.hu/ (and watching the dev console) shows that they obviously develop their page http-first (various resources won't load in firefox due mixed http(s))
and after switching to english the search on the top of the page is broken
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#126Earlier quoted context omitted.
Maybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed and modified , using . You have to send Bitcoins to , or I your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.
So you should just become a malicious actor and actually break the law? Good plan.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#127I've reported several of these issues, sometimes all I get is single reply months later saying: "fixed".. mostly, nothing.
Once I found a SQL injection in a courier service's (very broken) web portal. This was very serious because any idiot could drop all the tables, so I sent an email to the most important worded member of their tiny, yet already bureaucratically structured team. I followed up several times because I knew someone saw my email (I embed beacons in my emails) but gave up after the sixth time. Three months later someone else replied saying "thanks Amin, we've fixed it"
On a separate occasion, a large government agency's emails routinely ended up in my spam folder. It was a huge problem, and they acknowledged it and said they couldn't figure out what was wrong. I took five minutes and found the problem to be a misconfigured server on the domain. The server sending the email thought it was `server-a.governmentdomain.com` but there were no DNS entries pointing the subdomain to the server. I reported this problem with clear instructions to test and fix the issue, but I was called despite the instructions, multiple times, to explain the issue with my words over the phone. This was 2 years ago, last I checked, the issue was still present.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#128Actually he exploited the bug and purchased a ticket for the fraction of the price and than reported it to the public transportation company. The company that runs the infrastructure (not the public transportation one) followed its internal policy and Hungarian law reported the incident to authorities. Police brought in the guy for questioning.
Besides this has been used for decades by corps to prosecute vulnerability reporters, see Serge Humpich who discovered a huge vulnerabilty in bank cards back in 1997. He reported to european bank card Economic Interest Group (EIG) with the support of a lawyer who said they would not believe him until he proved it practically. So he went an bought metro tickets that he did not use but sent them with every details of the transaction. The EIG then got him arrested, prosecuted and sentenced for bank fraud and falsifying a bank card. The fun part is that this got publicized and it was not long before bad guys found the vulnerability too and started issuing yescards (bank card that say yes to any withdrawal from an ATM) and it cost them many tens of billions of euros over a few years due to fraud and upgrading their security and hardware in a hurry.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#129Earlier quoted context omitted.
They took him as a criminal, got his fingerprints, took a photo of him. I do not think they proceeded this in the right way. They should have fixed the bugs, protect our personal data and say sorry for this.
No, they brought him in as a person of interest following Hungarian law. If you do not like the law please vote the next election a party that changes that or move to a country that does not require police to follow the law. Determining if he is going to be charged with a crime is at later stage in the investigation anyways. There is no such a thing as "They took him as a criminal". Moreover, it is not only Hungarian…
Sorry but how exactly electing a different party is supposed to change anything ? Moving to another country will not help either as most other countries are the same or worse.
Re: 18yo arrested for reporting a bug in the new Budapest e-Ticket system
#130Earlier quoted context omitted.
By purchasing the ticket, he was confirming the vulnerability. I am sure he knew that they would cancel the ticket when he reported it. I don't find any wrong doing here.
And you think that this is going to be enough at the court? Have a look at this list, many of them thought they are not doing anything wrong: https://en.wikipedia.org/wiki/List_of_computer_criminals The point is that we live by the law, not how you feel about a certain action. I agree that the law is a bit problematic but regardless we cannot cherrypick which law to follow and which not.