7 ms·
Mr. Robot Blind SQL Injection Vulnerability
- deleted 10y ago[deleted]
- d33 10y agoI'm always worried about where is the line with this kind of pentests. I assume that it wasn't ordered by the site owner and even though the author clearly did the webmaster a favor... couldn't he get in a trouble by sqlmapping random sites?
- jvehent 10y agoSites operators should reward responsible disclosure, not get researchers into trouble. Bug bounties are a good way to do that. Unfortunately, there are still people out there who don't understand their true value.
- user_0001 10y agoI broke into your house whilst you were on holiday. Didn't you realise that I could smash your window and climb in? Here is a box of all your valuables. Reward please
- dumbfounder 10y agoAnd he setup a camera to make sure your wife was showering correctly.
- jalada 10y agoI can't think of an alternate analogy but I don't think breaking in to a person's house by smashing their window is equivalent to penetration testing. But I get your point.
- seanc722 10y agoAgree, I think it is more that you left the door unlocked when you meant for it to be locked and the mailman opened the door to yell "Hello??" but no one was home, so he let you know the door is unlocked. :)
- cayal 10y agoTo continue your analogy, 1000 other potential robbers are trying to get in every day, you are virtually always on holiday or otherwise outside the house, and the window was voice-activated. The intruder said a well-known special phrase which caused it to open. The expectation is that you've checked the windows, door, lock, and any other potential openings yourself to make sure they can't be entered like that. So yes, I'd say the person who doesn't take the valuables and run is doing you a huge favor.
- deleted 10y ago[deleted]
- dwild 10y ago> Didn't you realise that I could smash your window and climb in? I did realize, which is why I don't keep your private information in there. They are in a safe hided somewhere. That website clearly didn't realize that they had a window right there. Thanks to this guy, they now replaced it by a wall. You accept the risk of that window, the people that goes into your house or do stuff in your house accept that risk while being near that window because they know the risk. On a website, you deal with other people stuff, not only there's an expectation of security, you won't have the luxury of knowing where's there's a window like that.
- billyhoffman 10y agoYou run a high profile website. Going through your logs you see someone used a blind SQL injection vulnerability to enumerate the data tables and exfiltrate a few hundreds rows from some of the tables. Is this person a just "friendly" pentester who "did you a favor" by finding a problem and just hasn't gotten around to telling you about it yet? Or was this an attacker who found a hole into your organization and is either hacking you further, selling the knowledge about your site's vulnerability to others, or monetizing this information in some other way? You have no way to know. All you know is someone committed a crime.
- dwild 10y agoWhat you say have seriously nothing to do with what the previous comment say. In fact it's an argument for what he say. If someone disclose you a security hole, you reward him. 2 reasons why: - You now know what's the issue and that there's one. He may have sold the whole private data of your organization to some other guy, but that's a constant in your situation. The only difference is knowing the source of the hole. If it help getting disclosure, even if it's from a black hat and he did committed something unethical, he still gave you something to fix. - It give white hat a way to find hole in your security. Without that, they have no incentive to work on it. Again I will work on constant, black hat are a constant in the situation, either way they will try it, but without a bug bounty, you will only have black hat. So what knowing if it's a black hat or a white hat change to you? Nothing, you still should have a bug bounty that reward disclosure because that's the only way to increase your odds of fixing theses security holes (the only thing that matter the most, whatever happens). (I'm not saying not doing anything though if you see a SQL injection in your log, you fix it either way)
- billyhoffman 10y agoI'm describing how it looks from the other side. I have no way of knowing if you are "good". I have no way of knowing anything other than someone used an automated attack tool against my property. This is why exploiting SQL injection you find on some random site is dangerous, Even if you have the best intentions
- corobo 10y agoAs someone just starting out - Is there a decent alternative to cash bug bounties for the penniless webmaster? I could probably afford to chuck someone a tenner or so if they helped out but to be honest that sounds a bit pitiful of a bounty Basically I'd like to say "Hey, we wont sue you if you report security problems" but I feel that due to other available bug bounties with wealthier pockets out there I'd just look like a cheap SOB rather than managing to make the original point of not suing for responsible disclosure
- billyhoffman 10y ago> Couldn't he get in trouble... Yes. Exploiting a blind SQL injection vulnerability to dump database tables and rows of a website you don't control without permission is a crime in most jurisdictions. It's still a crime even if you were trying to "help" the web master. It's still a crime even if you were just dumping the tables to "prove" the vulnerability exists. It's still a crime even you "disclose it responsibility." Why is finding vulns in say, outlook.com a crime but finding vulns in the thick client version of Outlook not a crime? Because of where the software is running.
- DanielShir 10y agoThat's absolutely right. I haven't disclosed vulnerabilities for several websites because of this exact reason. If there's no bug bounty program, then you're liable and can be criminally prosecuted (and I know cases where the person was sued in civil court as well).
- CiPHPerCoder 10y ago> That's absolutely right. I haven't disclosed vulnerabilities for several websites because of this exact reason. Depending on how you learned of said vulnerabilities, you might still be culpable for the mere act of discovering them.
- cookiecaper 10y agoDon't expect a bug bounty program to protect you. I'm not a security researcher, but if I wanted to be one, I would do what I could to conduct that business pseudonymously instead of trusting that the company would stick to the representations made in the bug bounty program. Remember that the CFAA has both a civil and a criminal component; if the state decides to charge you, the opinion of the company whose computers you illegally accessed does not necessarily matter. JSTOR asked Carmen Ortiz to drop the charges against Aaron Swartz and she declined to do so.
- cyphar 10y agoA bug bounty acts as a legal agreement (read: implicit contract). The CFAA doesn't void contracts between two parties.
- taneq 10y agoBut did you delete it? If you deleted it, we got nothing to talk about.
- aaronwidd 10y agoI was actually hoping this was going to be a story about a very clever marketing campaign
- yellowapple 10y agoSame. This would've been the perfect opportunity for some kind of Easter Egg.
- therealmarv 10y agothat would be SO great!
- alexc05 10y agoIt's a great show but, also a fiction. One would not necessarily expect that it was the actual Mr. Robot who created the website for the show. In fact I'd expect it to be a relatively junior agency. Which would mean they've got QA & security process to match. I'd also suspect that as an overwhelmingly awesome show that glorifies hackers, they're probably a relatively "safe" target. I mean, we're talking the game of thrones of computer nerd shows here...
- FussyZeus 10y agoOr attracts hackers. ;) Nevertheless I find it more telling in terms of what the given company is about by their response to being shown a vulnerability than necessarily writing perfect software every time.
- jbaviat 10y agoThe mother of all web vulns - yet I don't recall of much SQL injections in the show, this may land in season 2 ;) Anyway, if you want a reliable SQL injection protection, I suggest you try Sqreen (https://sqreen.io https://sqreen.io) - PHP support is coming soon!