5 ms·
I found a similar vulnerability in one of our vendors' online order system. I noticed after placing an order an integer in the order confirmation page URL. I r
by watchdogtimer 5y ago
I found a similar vulnerability in one of our vendors' online order system. I noticed after placing an order an integer in the order confirmation page URL. I reduced it by one and refreshed the page. Sure enough, I got all the order details of the previous customer's sale. Reducing _that_ URL by one got the next previous sale details etc. I notified the company about it. They fixed it, and in gratitude sent me a small package containing a pen and other office kitsch branded with their logo. Not much of a bug bounty, but the pen has proven useful.
- kirlfiend_grill 5y agoI let a company know that the url for their receipts (including name, address etc) was simply an md5 of the order number. They graciously offered 15% off on my next order as a thank you.
- Something1234 5y agoI feel like that would be a decent option for a surrogate key for public identification of an item and potentially cheaper than generating a uuid or something else. Maybe combine that with a salt and you have alright protection. How did you figure out that it was an md5 of the order number?
- cryptofistMonk 5y agoPresumably order numbers are easily guessable, so the md5 really offers no protection at all in this case and is no better than just using the order number
- exikyut 5y agoAnd the thing is, even if they can't be guessed, it's only 999,999 calls to try every 6-digit possibility. And you'd only take 11 days if you were nice and paced yourself to 1 req/sec.
- renonce 5y agoSearching for that MD5 would probably be sufficient to find that out.
- andrei_says_ 5y agoI think the main difference is the one between acknowledgment, action + (small) gratitude vs. fear, paralysis and scare tactics / trying to control the environment instead of fixing the issue.
- datavirtue 5y agoI notified the State of Ohio about the unemployment site displaying full blown debug information in error messages (it genuinely errored out on me while doing legit stuff). The amount of information was very interesting and detailed, basically begging a malicious actor to probe further. I sent screenshots and a detailed writeup about what my next moves would be if I were a "hacker" straight to the CISO/CTO and their boss (my info is in that system!). No response...thankfully.