This is incredibly unethical behavior that we should not be condoning. If this were someone employed under me as a security professional they would be fired for negligence.
I compromised 300 stores and a “Spanish consultancy”
41–49 of 49 posts
Re: I compromised 300 stores and a “Spanish consultancy”
#42Knowing what I know about these kind of consultancies and "concursos publicos" in Spain, I wonder if you saw any illegal or at least shady activity or conversations going on? Are you not concerned about being sued for this prodding? Spanish companies are known for prosecuting white hat hackers.
Re: I compromised 300 stores and a “Spanish consultancy”
#43How legal is what this guy did in Spain?
Re: I compromised 300 stores and a “Spanish consultancy”
#44Earlier quoted context omitted.
Not parent, but I reckon that a company might see "oh this employee didn't follow our clearly signposted security guidelines, let's just fire them and get on with our lives" as an easier way out than "we have to actually start to invest into security". I'm not saying that's good, but I could definitely see it happening.
Yes unfortunately this is also the case - but many companies don't even have the "clearly signposted security guidelines" to begin with.
If you don't do this, the customer DPO might stop the project anytime, or you would have to undo all the reso it again untilt the DPO approves it.
Re: I compromised 300 stores and a “Spanish consultancy”
#45Earlier quoted context omitted.
Which company is shamed in this post?
Two companies: his employer because of his lack of ethics and the consultancy firm. The CMS and the company are very well known in the Spanish technology scene and it’s not the first time I have read this kind of reports about their CMS. I will not disclose the name but easy for any Spaniard working in IT.
Re: I compromised 300 stores and a “Spanish consultancy”
#46Earlier quoted context omitted.
Which company is shamed in this post?
Two companies: his employer because of his lack of ethics and the consultancy firm. The CMS and the company are very well known in the Spanish technology scene and it’s not the first time I have read this kind of reports about their CMS. I will not disclose the name but easy for any Spaniard working in IT.
Re: I compromised 300 stores and a “Spanish consultancy”
#47I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all this information available "open to the Internet.", waiting for someone else to come with really unethical purposes. If you ever find a vulnerability and keep quiet about it, I don’t think that makes you any more ethical.
Regards,
edbrsk
Re: I compromised 300 stores and a “Spanish consultancy”
#48Hi there, I'm the author of the post. I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all…
As an aside, your writing style comes off as arrogant and childish. Proper disclosures don't read like Hackers fanfic.
Re: I compromised 300 stores and a “Spanish consultancy”
#49Hi there, I'm the author of the post. I want to clarify that the post/report has been agreed with the consultancy. Some of you would consider this as bad behavior from my side, and I'm sorry to hear that. What would you do if you ever find something like this? All this has been reported, and it’s being fixed. DISCLOSURE accepted, and that’s why the post/report won’t contain names ever. IMHO bad behavior is having all…
You need to go through some proper infosec courses/certifications. Your approach to writing is unprofessional and unethical and you did NOT clarify what measures you took or under which pretense the affected company/companies agreed to you writing this disclosure statement. As an aside, your writing style comes off as arrogant and childish. Proper disclosures don't read like Hackers fanfic.
I don't see where I'm being arrogant in the post, and actually, you are right, it's not a "professional" report, it's just the summary about how "easy" some data can be stolen, and what people with really bad porpoises could do with a little bit of luck (The "big" problem it's just weak credentials in the end). It's a blog post, not the report itself.
About clarifying the measures and the communication with the company, this is something that it's not related to the idea of the post, and no one else's business.
Someone else's published my post here in HN, and I saw some "overreacted concerns", my idea was just to say: "They know, it's safe, I'll help to fix things, don't worry. Take care of your creds, that's all". Also, thank you for the tip, I'm about to get the OSCP soon, I'll take into account your advice.
Regards,
edbrsk