4 ms·
I want to write a similar write-up for a company which basically does everything over HTTP with their own half-baked hardcoded AES key in app for sending credit
by coworkerblues 9y ago
I want to write a similar write-up for a company which basically does everything over HTTP with their own half-baked hardcoded AES key in app for sending credit card info. and that their confirmation checkup is stupid (for SMS) and can be bypassed.
The problem is that their site TOS forbids reverse engineering, and I am afraid their lawyers will go after me instead of fixing the security issues (even if I just contact them), any tips for me ?
- cwsx 9y agoJust formally ask the company, if they don't want you to they will tell you. Could be worth including a pitch of sorts ('Hey, Ive noticed a few problems using your site...') but MAKE SURE you don't incriminate yourself. Do NOT show evidence of you 'reverse engineering' anything. Do not do anything without gaining permission, as there's a very good chance you're going to run into their legal team.
- coworkerblues 9y agoI don't want to contact them in a way that they can trace me, since I'm pretty sure that they will try to covert up / threat me (I would hope that someone there already knows this is an issue....).
- shinolajla1 9y agoStarbucks has a bug bounty program, and they do actually pay out. https://www.starbucks.com/whitehat https://www.starbucks.com/whitehat
- coworkerblues 9y agoNice (altough the URL does not work) unfortunately in our startup nation there are 0 programs like this :(
- qb45 9y ago> HTTP with their own half-baked hardcoded AES key in app for sending credit card info. You mean, no TLS, JavaScript crypto and credit card info? Are there no authorities to report that kind of garbage? No certification they are supposed to pass? I would research that angle first before hacking. It doesn't take any reversing to realize everyone can pwn you on a public WiFi. Otherwise, at the very least use tor...
- Rjevski 9y agoDisclose everything over Tor. The kind of scum that sends credit card data over insecure homebrew crypto deserves no mercy.
- coworkerblues 9y agoI would rather contact them anonymously first, also I don't understand exactly how Tor would help me with this.
- mplewis 9y agoRjevski suggests you publicly disclose the vulnerability in an anonymous way that can't be traced back to you.
- Rjevski 9y agoTor will help you by hiding your identity so they will be in a dead end when they sue and try to find you. And yes of course you can also use Tor to contact them anonymously before disclosing.
- coworkerblues 9y agoBesides telling me to use tor (which I know in general what it is), is there a guide I can use ? (i.e. how to send / recv anonymous email on tor from a non tor address ?) or something ???
- Rjevski 9y agoUse the following to get a live OS with Tor preinstalled: https://tails.boum.org https://tails.boum.org Once you're in there you can just use the Tor browser to create an email account at any email provider (make sure you give them fake details though) and send your email.
- coworkerblues 9y agoWhich email provider allow opening an account from a known tor exit node ?