well at least it was a password hash :D
Accessing Max Verstappen's passport and PII through FIA bugs
21–30 of 151 posts
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#22Re: Accessing Max Verstappen's passport and PII through FIA bugs
#23Re: Accessing Max Verstappen's passport and PII through FIA bugs
#24Ian, it would be great to see an RSS feed on your website if you want to gain another regular reader :)
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#25I hope you got at least free tickets for life out of this.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#26Archaic company has archaic security. Well done on the RD, but boy does it not surprise me one bit. Would almost be willing to bet that the hash was MD5 too.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#27Just out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#28Archaic company has archaic security. Well done on the RD, but boy does it not surprise me one bit. Would almost be willing to bet that the hash was MD5 too.
It's an F1 racing site, their job is literally to move fast and break things. https://xkcd.com/1428/
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#29Just use a framework to build your site. Don’t reinvent the wheel!
i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.