Live data from Hacker News

I compromised 300 stores and a “Spanish consultancy”

edbrsk.dev

41–49 of 49 posts

Re: I compromised 300 stores and a “Spanish consultancy”

#41
post #13

This is incredibly unethical behavior that we should not be condoning. If this were someone employed under me as a security professional they would be fired for negligence.

Same thought. Not only is this unprofessional and unethical, he's also put himself on the hook for both civil and criminal liability. If he used his employer's resources for this, his employer might also end up in trouble.

Re: I compromised 300 stores and a “Spanish consultancy”

#42

Knowing what I know about these kind of consultancies and "concursos publicos" in Spain, I wonder if you saw any illegal or at least shady activity or conversations going on? Are you not concerned about being sued for this prodding? Spanish companies are known for prosecuting white hat hackers.

Given how most spanish companies work, more than likely.

Re: I compromised 300 stores and a “Spanish consultancy”

#43
post #23

How legal is what this guy did in Spain?

Not legal at all, like in the rest of the European Union. Just publishing this information will make the consultancy send a notification to the Spanish Data Protection Agency, and will cost them money.

Re: I compromised 300 stores and a “Spanish consultancy”

#44
post #22

Earlier quoted context omitted.

Not parent, but I reckon that a company might see "oh this employee didn't follow our clearly signposted security guidelines, let's just fire them and get on with our lives" as an easier way out than "we have to actually start to invest into security". I'm not saying that's good, but I could definitely see it happening.

Yes unfortunately this is also the case - but many companies don't even have the "clearly signposted security guidelines" to begin with.

With GDPR you must take security into account from the design.

If you don't do this, the customer DPO might stop the project anytime, or you would have to undo all the reso it again untilt the DPO approves it.

Re: I compromised 300 stores and a “Spanish consultancy”

#45
post #21

Earlier quoted context omitted.

Which company is shamed in this post?

Two companies: his employer because of his lack of ethics and the consultancy firm. The CMS and the company are very well known in the Spanish technology scene and it’s not the first time I have read this kind of reports about their CMS. I will not disclose the name but easy for any Spaniard working in IT.

Sounds that they need even more shaming to get their act together.

Re: I compromised 300 stores and a “Spanish consultancy”

#46
post #21

Earlier quoted context omitted.

Which company is shamed in this post?

Two companies: his employer because of his lack of ethics and the consultancy firm. The CMS and the company are very well known in the Spanish technology scene and it’s not the first time I have read this kind of reports about their CMS. I will not disclose the name but easy for any Spaniard working in IT.

What's the consultancy firm ? indra ?

Re: I compromised 300 stores and a “Spanish consultancy”

#47
Hi there, I'm the author of the post.

I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all this information available "open to the Internet.", waiting for someone else to come with really unethical purposes. If you ever find a vulnerability and keep quiet about it, I don’t think that makes you any more ethical.

Regards,

edbrsk

Re: I compromised 300 stores and a “Spanish consultancy”

#48
post #47

Hi there, I'm the author of the post. I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all…

You need to go through some proper infosec courses/certifications. Your approach to writing is unprofessional and unethical and you did NOT clarify what measures you took or under which pretense the affected company/companies agreed to you writing this disclosure statement.

As an aside, your writing style comes off as arrogant and childish. Proper disclosures don't read like Hackers fanfic.

Re: I compromised 300 stores and a “Spanish consultancy”

#49
post #48
post #47

Hi there, I'm the author of the post. I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all…

You need to go through some proper infosec courses/certifications. Your approach to writing is unprofessional and unethical and you did NOT clarify what measures you took or under which pretense the affected company/companies agreed to you writing this disclosure statement. As an aside, your writing style comes off as arrogant and childish. Proper disclosures don't read like Hackers fanfic.

Hi Josh,

I don't see where I'm being arrogant in the post, and actually, you are right, it's not a "professional" report, it's just the summary about how "easy" some data can be stolen, and what people with really bad porpoises could do with a little bit of luck (The "big" problem it's just weak credentials in the end). It's a blog post, not the report itself.

About clarifying the measures and the communication with the company, this is something that it's not related to the idea of the post, and no one else's business.

Someone else's published my post here in HN, and I saw some "overreacted concerns", my idea was just to say: "They know, it's safe, I'll help to fix things, don't worry. Take care of your creds, that's all". Also, thank you for the tip, I'm about to get the OSCP soon, I'll take into account your advice.

Regards,

edbrsk

Post reply on HN