7 ms·
United Airlines Bug Bounty: An experience in reporting a serious vulnerability
- jacquesm 11y agoInteresting terms, if you can't talk about it afterwards how do people know that any of these bounties were paid out? After all there is a pretty simple loophole here: mark any and all reports as duplicates, no need to pay out.
- deleted 11y ago[deleted]
- jacquesm 11y agoYou may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.
- deleted 11y ago[deleted]
- throwaway28474 11y agoDoes the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?
- hellbanner 11y agoIs there a kind of "union" for bug finders, some corporate shell anonymous hackers can hide behind to avoid legal crushes?
- lostlogin 11y agoAnonymous hackers just use a mask. Sorry, I couldn't resist.
- rodgerd 11y agoThere can be a fine line between full disclosure and blackmail. I would be concerned "give me airpoints or else" would go over it.
- jacquesm 11y agoThat's a good point. If you get something out of it then it's not exactly as if you only have the public interest at heart. Which makes me wonder what would be the way to act if you found a major vulnerability in some vendors product and they point blank refuse to fix it even given plenty of time. The public good would (could?) clearly outweigh the company's interest if the hole is bad enough but it could get extremely expensive if you went public with the flaw against their wishes (assuming they know who you are and you're in a location where they can make your life hard). This is probably very different from jurisdiction to jurisdiction, here in NL we have a government watchdog for such cases which starting 1/1/2016 will have a lot more teeth but in other countries the situation will surely be very different. Anonymity would seem to be an asset in such cases.
- thaumasiotes 11y agoThere's never really a line between blackmail and anything, only Cantor dust. :/ Blackmail is one of those rare crimes that consist entirely of legal conduct.
- Buge 11y agoIt sounds like they are disqualified from receiving any rewards any time in the future. But other than that, there is nothing preventing you from revealing the vulnerability, or worse, selling it on the grey market. The US government is a heavy buyer of vulnerabilities (although usually in applications, not in airline websites).
- eyeareque 11y agoYou could, but they have lawyers.
- tptacek 11y agoWhy are you looking for off-site vulnerabilities? Would this be something you did even if they weren't running a bounty? You should be careful testing sites out of scope. The bounty gives you implied permission to test for vulnerabilities on sites in-scope, but "I was just security testing" is demonstrably not sufficient to insulate you from civil litigation or even criminal charges --- you would probably win in court, but it would be ruinously expensive.
- girvo 11y agoWhat are your thoughts on the bug bounties that have extremely limited scopes, considering the in-scope domains typically rely on the out-of-scope parts?
- eyeareque 11y agoThey are not explicit in what domains or ip addresses are in scope. This makes it difficult. You'd expect them to have a list of approved sites for testing.. But they don't (or didn't when I tested.)
- ssclafani 11y agoYou can't talk about the details of the bug but you can talk about the reward: https://twitter.com/Stephen/status/627190837735239680 https://twitter.com/Stephen/status/627190837735239680 The program is legit, they are just very slow (I didn't actually receive the miles until October).
- MrQuincle 11y agoMine was a duplicate as well. Anyone here who was paid out?
- mjg59 11y agoYes
- dsacco 11y agoYes.
- deleted 11y ago[deleted]
- tptacek 11y agoWhat are some examples of bullshit out-of-scope judgements? Some scope issues are more bullshit than others.
- deleted 11y ago[deleted]
- nl 11y agoCan you escalate one of the 3-rd party vulnerabilities to give you access to something that is in scope? I agree that United's attitude on this is silly.
- ryandrake 11y agoIs six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.
- oneJob 11y agoYes, it's really unreasonable.
- kbenson 11y agoBloated beauracracies need agile ways to respond to important situations. Giving them a pass because they are bloated won't make that happen any sooner, and it does need to happen.
- jfoutz 11y agoOrganizations like that have no code hygiene. They have smart talented people that are entrenched in their way of doing things. They don't have the money to throw the code away and start over. They don't have the control to enforce code standards. There are a couple of terrible effects that slow them down. I'll bet you a nickel that the json is generated by a stored procedure. In that kind of environment, you can't really run a local version of the system. if you're lucky there's a prod, qa, and development version. the development version is shared by everybody. What winds up happening is the dev system has lots of in-progress stuff, and i can't release my stuff till the other in-progress stuff is ready to go, or is rolled back. Also high priority stuff tends to go to "that one wizard guy". Unfortunately that one wizard guy is backed up with 6 months of other projects, cause he's the wizard. Is it "right"? no, of course not. These systems evolve from people making good decisions in the moment, that don't really take into account the global state of the system. Finally, every few years a new CIO comes into power and wants to clean things up. a few new folks buy in, but the older entrenched interests just pay lip service, because they know the only way to actually get software out the door is to do it their way. (They tried and were burned by at least one of the prior CIO approaches) I think those organizations are pretty screwed. they are incapable of change at the layer they need. Banks, schools, airlines, machine shops, anyplace there's a large sized in house dev team (30+), that team is going to very likely kind of suck. There are exceptions, but generally, it's a rough state. So, yes, i agree, but actually solving that problem in a way that won't kill the business is incredibly hard.
- jsjohnst 11y agoIf you know the PNR of an itinerary and the person's last name you can quite easily do most of what was described in this article via United's website or over the phone. Always makes me laugh when I see folks posting full images of their plane tickets online, they so easily could have their travel plans screwed. :(
- MichaelGG 11y agoYeah at one point their app endpoints returned full pnr and last names, then truncated for display. I always thought it'd have been fun to exploit it to bump yourself up on the upgrade list by changing the flights of those in front of you.
- swang 11y agoJust checked this using mitmproxy. My United MileagePlus Account is definitely there. Also, you need a valid MP#, and the # is not sequential (nor all numbers). At least they're using https. Edit: Also annoying the app keeps making calls to Gogo wifi and some other Wifi page. Edit2: I just realized United _did_ fix it. Thought it said they refused to fix it.
- jcdavis 11y agoI reported 2 admittedly minor web security bugs to them several months back that surprisingly I was apparently the first to report, but still haven't heard back about either.
- deleted 11y ago[deleted]
- vezzy-fnord 11y agoClassic case of confused deputies caused by ambient authority. Wonder if we'll ever outlive these kinds of bugs.
- deleteme01 11y agoI have same problem with one of the Salesforce's subdomains. Report accepted and assigned status low. 7 months later XSS is still there. Not sure what to do by now.
- eyeareque 11y agoIf you've participated in their program, you'll probably find that they have their fair share of issues. This is probably where their delay is coming from (but not a valid excuse). I found two serious problems in less than a hour. I reported the issues to them and was subsequently told that both submissions were out of scope and a firm warning to follow the rules. You're welcome for the free findings.
- manigandham 11y agoIt's pretty ridiculous that actual problems are "out of scope".
- debaserab2 11y agoMaybe it is, but given that the original commentor did not describe what the problems were, we have no idea as to their severity.
- mcv 11y agoIf only TSA considered security out of scope, and settled on a firm warning to follow the rules. Sure, planes may not fall out of the sky through webservice vulnerabilities, but but you'd think airlines would be slightly more aware of how security works.
- blantonl 11y agoHow was this vulnerability able to be exposed in the first place if the API is communicating over SSL?
- peterkelly 11y agoYou can intercept your own SSL communications if you create your own certificate authority and add it to the list of trusted CAs on your device. You can then use this to generate SSL certificates for arbitrary domains, and by proxying traffic through your own machine you can grab the plaintext by impersonating the real site. Of course this will only work for devices you have added your CA to; you won't be able to intercept just anyone's traffic. There's an app for OS X called Charles, which automates this process for you, acting as a proxy and generating the fake certificates on-demand. See https://www.charlesproxy.com/documentation/using-charles/ssl-certificates/ https://www.charlesproxy.com/documentation/using-charles/ssl...
- joshmn 11y ago> There's an app for OS X called Charles, which automates this process for you, acting as a proxy and generating the fake certificates on-demand. It's a bit more difficult than just loading up an MITM and generating the certs; if they've pinned (which they have), you have to go a _bit_ deeper than _just_ using an MITM proxy.
- thedogeye 11y agoHave you participated in a bug bounty program on Hacker One? We are running one there now.
- deleteme01 11y agoTrying to repost because of low karme on throwaway account: I have similar problem with one of the Salesforce's subdomains. Report accepted and assigned status low. 7 months later XSS is still there. Not sure what to do by now.
- cm2187 11y agoThe author is being nice calling it a bug. A buffer overflow is a bug. This is a moronic design, like a sql vulnerability. I am shocked that in these days and age, so many web developers have not adopted the mentality "everything coming back from the client may and will ultimately be tainted". Relying on an ID provided by the client without checking the appropriate access is unexcusable. How many years ago was the Dell shopping cart bug (where a client could alter the price of an order)?
- buro9 11y agoIt's frequently scarier than that. I've seen applications do the right thing by IDs and queries, but then attempt to audit access and not correctly escape or sanitise HTTP headers. Literally, every single piece of information that an application receives is not to be trusted. Even if it's something you think you have set and have full control of (a cookie value), you're wrong... you have no control, and attackers can and will manipulate every field or property to gain a foothold.
- buro9 11y agoActually, case in point... X-Forwarded-For. This is not in a spec, people are using it as an unofficial standard. But so long as your edge removes it and then sets it... you're good. Except Google are doing their page speed optimisation thing in the style of the Opera Mini proxy, but for Chrome users on Android. Google have chosen to populate X-Forwarded-For, so any website that wants to audit the IP address of an end user now has to read this untrusted header. So devs will realise this, look at the header, stop stripping it at the edge, and start trusting what is essentially a string that anyone can set.
- xena 11y agoI like the way IRC networks handle this, they use a pre-connection protocol verb called WEBIRC (de-facto standard documented here: http://git.io/vBLYp http://git.io/vBLYp) that also enforces a whitelist of ip address + password combination. This stops most abuse of this feature. Maybe HTTP servers should have something similar.
- phphphph 11y ago> Using just these two values, an attacker could completely manage any aspect of a flight reservation using United’s website. Don't most airline websites allow that when you get the last name and date of departure right?
- fphilipe 11y agoYes. But the point is that he was able to gain these two bits of information.
- erikb 11y agoIt's so funny to see how surprised people are about the "corp" IT compared to the "free" IT world. Once I was also surprised about how long it takes and that very important things can be out of scope. I think the reason is that in fact in teams >10 people nobody really knows what's going on. That anything happens is more the result of many attempts and some luck. That nothing succeeds is the default. Think of it more as "Twitch Programs Flight Ticketmanager App" than actual software development as you read it in a book. (I once worked with >5 other guys on getting a string in one computer pointing to another computer, took the whole week)