Live data from Hacker News

Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

strix.ai

31–40 of 112 posts

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#32
post #21
post #18

Earlier quoted context omitted.

I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…

From the looks of it, they actually asked for a way to report.

Yeah. I'm just saying how it could have been overlooked. Doesn't excuse it, though.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#34
post #18

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…

Yeah, the signal to noise ratio on vulnerability reports is very weak, especially when the initial report withholds any detail.

I get tons of these messages too and the ones that do include details are the kind of junk you get from free "website vulnerability scanners" that are a bunch of garbage that means nothing -- "missing headers" for things I didn't set on purpose, "information disclosure vulnerabilities" for things that are intentionally there, etc... You can put google.com into these things and get dozens of results.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#35
post #31
post #28

Earlier quoted context omitted.

The guidelines require using the same title on HN as is on the original post.

Even when the author submits? :)

Yes... unless we think it's fine to tailor a title to activate a particular reaction from the HN audience :)

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#36
Two questions prompted by this disclosure:

1. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved?

2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher to report it?

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#37
post #19

Earlier quoted context omitted.

Yes, there are also many other lucrative illegal activities.

Isn't it also illegal to withhold knowledge of a vulnerability for payment? It sounds like it should fall under some variety of blackmail.

That would be even worse than our already bad system.

The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor.

I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#38
post #9

Earlier quoted context omitted.

fixed now

Thanks! Happy to have my comment hidden by the mods if they get around to it.

Perhaps the community could band together and crowdsource the moderation action through flags. Kidding.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#40
post #36

Two questions prompted by this disclosure: 1. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved? 2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher…

> How do independent researchers do this with legal safety?

In my experience it’s usually foreign nationals from third-world countries doing drive-by beg-bounty testing. Presumably they don’t much consider legality.

Post reply on HN