Earlier quoted context omitted.
Actual legal threats are uncommon but I have seen some companies try to offer a bribe disguised as a retroactive bug bounty program, in exchange for not publishing. Obviously it is important to decline that.
Decline because it'd mean you were profiting off of a crime? Or that the opportunity of publishing has higher value than the bribe?
Accessing Max Verstappen's passport and PII through FIA bugs
121–130 of 151 posts
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#122Earlier quoted context omitted.
I’ve used browser dev tools to regularly add additional drop down options to menus that weren’t present. Huel, for example, only offered 2 or 4 week subscriptions, so I added 3 weeks to it because that’s the frequency I needed, and it worked no problem. 3 weeks later my shakes arrived and every 3 weeks since.
My insurance company has different frontend password regex on registration page and on login page. My password passed the registration regex but fails the login regex. In order to log in, I need to manually remove the frontend-side password regex check.
If your software doesn't accept this password, please change career immediately:
ú¨$¼ÿa÷mH¦ñ%?6ñE$l#DhqI£«{'Ø"V^c4u
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#123Earlier quoted context omitted.
> A kid showed up a bunch of big names. The kid purposely changed the price of a service to lower it to an insignificant fraction (reportedly from ~27£ to ~0.15£). If that same kid went around a supermarket replacing price tags to lower the selling price, would you call it "showing up a bunch of big names"? Say what you may about how broken and buggy the system was. Purposely misusing it for financial advantage is st…
if the kid could successfully modify the scanned value of physical barcodes a) that would be quite the feat and b) that would absolutely be showing up a bunch of big names
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#124Earlier quoted context omitted.
Lesson: instead of being the good guy and reporting shit, just sell it on black market.
(playing the devil's advocate here) But that's not the case- if you find someone's physical keys in the street, will try to open the neighbor's door with it? so why is it ok to use a password that you "found" to log into a site?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#125That's not just one vulnerability, that's a whole slew of failures. For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hope you got at least free tickets for life out of this.
I hate this kind of post-hoc finger pointing people do after security breaches. There are other concerns in life beyond security - youre naive to think differently. Is your house secure or could somebody break past your protections? Have you harmed your defensive posture with negligence of security? Do you even care?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#126Rule 1. NEVER trust user supplied data. Once that rule was broken, any other rules broken became clear to everyone
Rule 0: Any networked computer should be considered semi-public. Don't store any information you do not want to be public, or give access to controls that you do not want to be publicly accessible, on a networked computer. There are simply too many vulnerabilities to assume otherwise.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#127Earlier quoted context omitted.
Rule 0: Any networked computer should be considered semi-public. Don't store any information you do not want to be public, or give access to controls that you do not want to be publicly accessible, on a networked computer. There are simply too many vulnerabilities to assume otherwise.
I doubt there are many people in rich countries that follow this rule, given that smartphones are networked computers and people don't want their personal photos to he publicly accessible.
I agree, there definitely are many people who don't follow the rule! And so we get things like this, https://en.wikipedia.org/wiki/2014_celebrity_nude_photo_leak
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#128That's not just one vulnerability, that's a whole slew of failures. For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hope you got at least free tickets for life out of this.
> For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hate this kind of post-hoc finger pointing people do after security breaches. There are other concerns in life beyond security - youre naive to think differently. Is your house secure or could somebody break past your protectio…
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#129They took the website offline on the same day it was reported! That’s amazing!
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#130Earlier quoted context omitted.
> A kid showed up a bunch of big names. The kid purposely changed the price of a service to lower it to an insignificant fraction (reportedly from ~27£ to ~0.15£). If that same kid went around a supermarket replacing price tags to lower the selling price, would you call it "showing up a bunch of big names"? Say what you may about how broken and buggy the system was. Purposely misusing it for financial advantage is st…
if the kid could successfully modify the scanned value of physical barcodes a) that would be quite the feat and b) that would absolutely be showing up a bunch of big names