Accessing Max Verstappen's passport and PII through FIA bugs
1–10 of 151 posts
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#2Just out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#3well at least it was a password hash :D
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#4Strange, the site is run by an Ian Carroll, but the examples show Sam Curry, who is a very famous bug bounty hunter.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#5Strange, the site is run by an Ian Carroll, but the examples show Sam Curry, who is a very famous bug bounty hunter.
if you look at his other posts, it looks like they collaborate often.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#6That is shamefully poor security.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#7Just use a framework to build your site. Don’t reinvent the wheel!
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#8well at least it was a password hash :D
Don't get too excited. They never said what kind of hash. Given the rest of the site's security design, might have easily been unsalted md5
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#9Archaic company has archaic security. Well done on the RD, but boy does it not surprise me one bit. Would almost be willing to bet that the hash was MD5 too.
Re: Accessing Max Verstappen's passport and PII through FIA bugs
#10Just out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?
When I was still in university I reported a vulnerability and when the company started threatening me with legal action, my professor wrote a strongly worded email and they dropped it. Haven't had it since in 8 years. Feels like many companies understand what we do now, atleast compared to 10 years ago.