Looks like the API is no longer accessible from here. Seems like they have pulled it down.
Moonpig.com Vulnerability – Exposes customer data
31–40 of 124 posts
Re: Moonpig.com Vulnerability – Exposes customer data
#32What I find absurd is that the company hasn't done anything about it. Even if they don't care/know about security they must at least care for bad PR...
But with all of that in mind, I don't know what's the best way to fight these clueless behemoths. You disclose and thousands or even millions of people will be compromised. You don't and those same people could be compromised but no one will know because the attacker(s) will just continue to siphon information quietly.
They should be waterboarded for making a responsible individual have to choose.
For the record, I approve of this disclosure. Better to know the evil than let it go on unnoticed.
Re: Moonpig.com Vulnerability – Exposes customer data
#33This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…
Instead, the disclosure resulted in the API being shut down within the hour. A much better result IMO.
Re: Moonpig.com Vulnerability – Exposes customer data
#34Earlier quoted context omitted.
First of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK. Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at l…
I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence. The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
Re: Moonpig.com Vulnerability – Exposes customer data
#35Earlier quoted context omitted.
First of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK. Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at l…
I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence. The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
In this case there's almost no chance law enforcement would charge the researcher unless Moonpig decided to press charges. And even then, they may decide not to charge due to the facts of the case (though of course they legally can).
Re: Moonpig.com Vulnerability – Exposes customer data
#36Looks like the API is no longer accessible from here. Seems like they have pulled it down.
I wonder who made the decision to take it down. I hope they don't get fired.
Re: Moonpig.com Vulnerability – Exposes customer data
#37I am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't…
My guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc. They might not even have PCI compliance issues alas. The management will argue that they knew nothing, although that is becoming less of a defence now.
Re: Moonpig.com Vulnerability – Exposes customer data
#38This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal chann…
While your point is valid I think you're getting doe voted because you're completely forgetting that the probability of someone malicious finding out about this vulnerability and exploring it without disclosing is quite high. Going through legal channels would just mean the api will be live for longer. Lawyers like to take their time. Instead, the disclosure resulted in the API being shut down within the hour. A much…
Re: Moonpig.com Vulnerability – Exposes customer data
#39Earlier quoted context omitted.
I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence. The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
I don't think that the author violated the CFAA, though: in both cases, he was acting on behalf of his users that he had created in the system -- the same requests he would normally make when using those accounts. ("BobAtHome", "BobAtWork" could concievably be two accounts for Bob.) That seems substantially different than what Weev did, which was try to read ${Everyone}'s data.
As you and I have essentially both just said, it's very unlikely there would be any prosecution due to the facts and the researcher's intentions, but I think it is still a technical violation. Paraphrasing, but the first line of the CFAA is "having knowingly accessed a computer without authorization or exceeding authorized access" (that line is explicitly for access that could jeopardize national security, but it goes on to set similar limits for general unauthorized access of any entity).
In this case it is not necessarily unauthorized access of a customer's account, but unauthorized access to a component of Moonpig's system.
Re: Moonpig.com Vulnerability – Exposes customer data
#40http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...