Earlier quoted context omitted.
Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…
And now, realizing the danger they are in, they fix the door or harass their vendor into doing it. Finally, thanks to the efforts of one good samaritan, they're safe.
Websmart, Inc. and 100,000 Vulnerable Websites
31–40 of 74 posts
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#32I appreciate that the guy's attitude is just awful, but the author really should have given him a chance to respond/react before contacting his clients. Doing so doesn't preclude notifying them eventually. It's just common courtesy.
If I'm walking down a street and notice a broken door, do I have some obligation to track down the builder of the house and tell him about the issue?
To my mind, the good deed would be to inform the homeowner. At that point, I've done my part, and it's up to him to organise to fix his door if he wants to.
This dude went the extra mile even contacting the vendor.
I'm guessing the people on here all sympathise with the vendor because they can see themselves being in his shoes.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#33This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#34Secondly, publicly publishing the email addresses of the (innocent) victims, and emailing those clients with To instead of Bcc fields are both really inconsiderate moves.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#35Re: Websmart, Inc. and 100,000 Vulnerable Websites
#36What is the point of hacking some random sites? Leave it to indian haxors.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#37 We are currently working on upgrading our Portfolio of web
sites and special projects. Please check back again soon.
Does anyone want to use an apostrophe and help him work on this page?Re: Websmart, Inc. and 100,000 Vulnerable Websites
#38LOL http://www.websmartconsulting.com/profile.php?ClientID='
Its sad that this is 2013 and these basic fucking issues still plague websites (and the people who make them). I wonder if the root of these issues is in education or the tools used? Or both?
Another issue is that security issues are often not visible to normal users. In the websmart example, a normal user looking for development services would have no idea that websmart has absolutely no clue how to do security. So, websmart gets the business, while the client gets a ticking time bomb, without even knowing it.
That, and most developers don't have any formal training in security concerns. I know I didn't when I first started - I had to pick it up as I went. It does not surprise me that these sorts of things keep coming up. Unless something changes - e.g. the majority of computer science degree programs include a course or two on security, I don't expect things to get drastically better.
That said, things like bug bounty programs help raise the visibility. And, at least many of the large tech companies do now respect security. We've at least improved in some ways as an industry.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#39Surprise, many websites are not secure. Does he go around testing people's door locks to see how vulnerable they are to being picked with a basic lock pick set? Maybe knock on some doors and tell the home owners that their home contractor doesn't take security seriously enough and demonstrate how easily the standard door lock can be picked? I could understand if he was making a business out of this, selling improved…
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#40Earlier quoted context omitted.
Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.
Maybe he was, maybe he wasn't, only he knows. But when you're running 100000 websites, you should Google yourself once in a while at least. Besides, this isn't some 0-day, it's some extremely basic SQL injection vulnerability. This company wasn't capable of doing extremely basic security, and should be out of business. This is the kind of company that stores your passwords in plaintext. He doesn't seem to have done a…