Live data from Hacker News

Websmart, Inc. and 100,000 Vulnerable Websites

samsclass.info

31–40 of 74 posts

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#31

Earlier quoted context omitted.

Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…

And now, realizing the danger they are in, they fix the door or harass their vendor into doing it. Finally, thanks to the efforts of one good samaritan, they're safe.

Who each have to go through the contractor to get them fixed resulting in a bottleneck. Thieves are already running rampant at the disclosure while the contractor is frantically fixing the windows.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#32
post #4

I appreciate that the guy's attitude is just awful, but the author really should have given him a chance to respond/react before contacting his clients. Doing so doesn't preclude notifying them eventually. It's just common courtesy.

What does the vendor have to do with anything?

If I'm walking down a street and notice a broken door, do I have some obligation to track down the builder of the house and tell him about the issue?

To my mind, the good deed would be to inform the homeowner. At that point, I've done my part, and it's up to him to organise to fix his door if he wants to.

This dude went the extra mile even contacting the vendor.

I'm guessing the people on here all sympathise with the vendor because they can see themselves being in his shoes.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#33

This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.

This is best for the vendor, but not best for the customers. Vendors should have a healthy fear that if they don't provide substantial security they will be exposed for their lack of quality. Now, I hope I'm not soliciting a 'test' of my work by saying this...

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#34
Nice one including the XSS injection flaw posted to inj3ct0rs within your own page there. Did your forget to sanitize your own HTML?

Secondly, publicly publishing the email addresses of the (innocent) victims, and emailing those clients with To instead of Bcc fields are both really inconsiderate moves.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#38
post #21

LOL http://www.websmartconsulting.com/profile.php?ClientID='

Its sad that this is 2013 and these basic fucking issues still plague websites (and the people who make them). I wonder if the root of these issues is in education or the tools used? Or both?

It seems to be a combination of both a lack of knowledge with respect to security and often a lack of respect. With many smaller companies, it is often ignorance. With many others, it is still too often the case that security concerns end up getting thrown in the "yeah, we should fix that eventually" pile of bugs.

Another issue is that security issues are often not visible to normal users. In the websmart example, a normal user looking for development services would have no idea that websmart has absolutely no clue how to do security. So, websmart gets the business, while the client gets a ticking time bomb, without even knowing it.

That, and most developers don't have any formal training in security concerns. I know I didn't when I first started - I had to pick it up as I went. It does not surprise me that these sorts of things keep coming up. Unless something changes - e.g. the majority of computer science degree programs include a course or two on security, I don't expect things to get drastically better.

That said, things like bug bounty programs help raise the visibility. And, at least many of the large tech companies do now respect security. We've at least improved in some ways as an industry.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#39

Surprise, many websites are not secure. Does he go around testing people's door locks to see how vulnerable they are to being picked with a basic lock pick set? Maybe knock on some doors and tell the home owners that their home contractor doesn't take security seriously enough and demonstrate how easily the standard door lock can be picked? I could understand if he was making a business out of this, selling improved…

Or maybe he could, you know, be trying to teach his students about security so they don't do shit like this in the future? "My students and I have been notifying administrators of vulnerable websites for several years now"

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#40

Earlier quoted context omitted.

Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.

Maybe he was, maybe he wasn't, only he knows. But when you're running 100000 websites, you should Google yourself once in a while at least. Besides, this isn't some 0-day, it's some extremely basic SQL injection vulnerability. This company wasn't capable of doing extremely basic security, and should be out of business. This is the kind of company that stores your passwords in plaintext. He doesn't seem to have done a…

Oh, I'm definitely not disagreeing that the company was irresponsible in their coding practices and having found the previously released notices on their own - they are certainly at fault for that negligence - and if they have indeed been notified before, then they are even worse of a company; but I still think the Sam didn't approach the disclosure properly, but that's just an opinion.
Post reply on HN