Moonpig.com Vulnerability – Exposes customer data
1–10 of 124 posts
Re: Moonpig.com Vulnerability – Exposes customer data
#2Fun fact - you don't even have to send the basic aut header - it'll respond just fine without it.
Re: Moonpig.com Vulnerability – Exposes customer data
#3Re: Moonpig.com Vulnerability – Exposes customer data
#4I'm sure the (outsourced) dev team will have a bad day tomorrow. This is just unacceptable. According to the blog post he first made contact in 2013! Bugs happen, but this is just bad design.
Re: Moonpig.com Vulnerability – Exposes customer data
#5Re: Moonpig.com Vulnerability – Exposes customer data
#6Re: Moonpig.com Vulnerability – Exposes customer data
#7Re: Moonpig.com Vulnerability – Exposes customer data
#8Lots of users on Twitter saying to delete your account, but is there any proof that this will exclude your account from the API?
Re: Moonpig.com Vulnerability – Exposes customer data
#9I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't authorise them to publish. However I'll leave it to the ICO to make that determination.
Re: Moonpig.com Vulnerability – Exposes customer data
#10Surely this is bad enough to warrant criminal prosecution? Not sure if that's even possible in the UK but it ought to be...Shameful to have sat on that for over a year. Shameful.
This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plaintext", Etc.