Live data from Hacker News

I compromised 300 stores and a “Spanish consultancy”

edbrsk.dev

1–10 of 49 posts

Re: I compromised 300 stores and a “Spanish consultancy”

#2
By stating "Comunidad autonoma" without a proper English translation for the term (region, subdivision) I already knew the author should be a Spaniard, but setting up that in the clear in the "about" page it' s even worse.

With the "Usuarios" term it wouldn't be too bad, Latin/Greek technical terms mostly are the same in most English and Romance countries.

But, please, never give location info to anyone, FFS.

Re: I compromised 300 stores and a “Spanish consultancy”

#4
Knowing what I know about these kind of consultancies and "concursos publicos" in Spain, I wonder if you saw any illegal or at least shady activity or conversations going on? Are you not concerned about being sued for this prodding? Spanish companies are known for prosecuting white hat hackers.

Re: I compromised 300 stores and a “Spanish consultancy”

#5

The best part of the post is certainly the Spanish author using target.com as a generic placeholder to explain the attack, when target is an actual chain with more than 300 stores :D

Substantially more than 300 stores. Per Wikipedia...

> The eighth-largest retailer in the United States, it is a component of the S&P 500 Index. [...] As of 2019, Target operated 1,844 stores throughout the United States.

Re: I compromised 300 stores and a “Spanish consultancy”

#6
Holy mac-shit-snacks! "..got access to the dashboard as a Super Admin in less than 1 minute. The password of this guy was the same as his username." AND credential reuse. Ouch.

Ding, Ding, Ding! I think we have a winner for the fastest way to the unemployment line.

Re: I compromised 300 stores and a “Spanish consultancy”

#8

Knowing what I know about these kind of consultancies and "concursos publicos" in Spain, I wonder if you saw any illegal or at least shady activity or conversations going on? Are you not concerned about being sued for this prodding? Spanish companies are known for prosecuting white hat hackers.

You meant I___a?

Re: I compromised 300 stores and a “Spanish consultancy”

#10
"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company."

Oof, that's bad behavior. I wouldn't be proudly blogging about this.

Post reply on HN