Live data from Hacker News

I compromised 300 stores and a “Spanish consultancy”

edbrsk.dev

31–40 of 49 posts

Re: I compromised 300 stores and a “Spanish consultancy”

#31
post #15

Earlier quoted context omitted.

If I was interviewing the author for a role their complete disregard for infosec ethics would be a hard "no" from me - no matter how good they might be at interviewing.

I think this depends somewhat on how old they were - young people do stupid things.

His LinkedIn profile photo would indicate he's not exactly early-20s.

Re: I compromised 300 stores and a “Spanish consultancy”

#32

"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.

Yeah, once I read that, the entire rest of the post had a suspect tone, even if it was very informative and enlightening (as someone with 0.00 infosec experience). I understand if you discover the vulnerability from curiosity and stop and report. But to keep going to “find more things [about] the company” seems pretty obviously illegal or at least gray morally.

Re: I compromised 300 stores and a “Spanish consultancy”

#34
post #21

I don’t think HN should be a place for “company shaming”… unless the author contacted the company and they denied/rejected/threaten him instead of fixing the issues. I guess it did not happen. I see HN as a place for collective learning. I don’t see what we can learn from this post.

Which company is shamed in this post?

Two companies: his employer because of his lack of ethics and the consultancy firm. The CMS and the company are very well known in the Spanish technology scene and it’s not the first time I have read this kind of reports about their CMS. I will not disclose the name but easy for any Spaniard working in IT.

Re: I compromised 300 stores and a “Spanish consultancy”

#36
post #7

Umm this guy should tread lightly. Whats up with the prodding? This is some straight up blackhat hacking.

Yes, this crosses all the lines. You can debate the finer points of the SQL injection bit, but the moment he got into Rocket Chat admin and started gratuitously stealing employee cookies, there's just no way to paint that any color other than black. As his bio states, he's a software engineer - clearly not a security professional, because he's steamrolling right through all infosec ethics. A quick Google search for h…

Dude, I'm not comfortable posting source of my online radio, because it uses ytdl, and here a guy casually strolls into blackhat territory, downloads 3k tables (presumably from to his home computer, using home pc, bonus points if that happens at work), then logs in as super admin to an e-shop, effectively takes over someones company chat and steals employee cookies. And writes about it AND ADVERTISES ON TWITTER under HIS OWN NAME. Is he INSANE or taking coke by a handful? Dude, you want to be legally forbidden to use a computer? because that's how you get legally forbidden to use one.

Re: I compromised 300 stores and a “Spanish consultancy”

#37
post #25

"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.

Once he found the SQL injection, downloading the tables was too far IMO. On the other hand if he had stopped at this point, the company would have no idea about the weak admin credentials that could lead to real data breach and internal compromise at a later date.

If he has no malicious intent and is not going to view/sell or do anything malicious with the data, I think it’s fine or even beneficial for him to continue to find further vulnerabilities and then report the whole package of vulnerabilities to the company. As long as he wraps it up within a few hours or say max 24 hrs and then immediately reports after that.

Re: I compromised 300 stores and a “Spanish consultancy”

#38
Reading this makes me appreciate all the burglars out there helping us figure out how easy it is to break in to our houses and take all of our stuff, especially the ones who don't just take the TV and electronics, but who put out that extra bit of effort to rummage through our collectibles to see if they can steal something that's really hard to replace.

Re: I compromised 300 stores and a “Spanish consultancy”

#39

"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.

Yeah, very poor judgement. What he did was deeply unethical and almost certainly illegal. You don't get a free pass to break into wherever you like simply because your intentions aren't malicious. That's what professional pen-testers are for.

Re: I compromised 300 stores and a “Spanish consultancy”

#40
post #23

How legal is what this guy did in Spain?

He did not disclose the company name (but easy to guess if you work on IT in Spain), so I don’t think he could have legal issues because of the post.

But, the cyber security professionals working in the consultancy firm can gather easily the small pieces of information left behind and sue him if they find out data extraction, for example.

Keep in mind that he claims he extracted sensitive data, but he could be lying just to be in the HN front page. Who knows.

Unethical, risky… and very stupid.

Post reply on HN