4 ms·
The idea is to show my work. I tried to add a touch of humor, I think it's funny to try to earn money like this (actually you can't because they verify all tran
by deadf00d 5y ago
The idea is to show my work. I tried to add a touch of humor, I think it's funny to try to earn money like this (actually you can't because they verify all transaction). If you think I can be seen as a black hat, I might modify some of it.
Also, a lot of developer (and some of my colleague too) tends to think that "hacking" doesn't exist like in movies or even doesn't exist at all (because they use ORM, don't laugh, I really got this one). By taking a real world example, I think It's a cool way to get people back in reality.
Anyway, people and my customers, hire me for my skills, and for what I did. Nobody care that you hacked an office, but if this office is the CIA, then it's cool.
For the lack of structure, it probably is, if you can give me example that I could fix, It would be very kind of you.
Thanks for your feedback.
- mr-wendel 5y agoI would like to highlight the parent post's comment about attempting to contact the people whose work you are exposing vulnerabilities in. I have to say that if this is "showing your work" then the most important thing you've shown is poor judgement in publishing their secrets in a submission to a very popular website. The fact that they have followed such shockingly bad security practices themselves is absolutely no excuse. The work I wish we saw was the valiant effort you made to contact the company and help them see their mistakes. That is an area where we can all use more good examples, even if only to show how difficult it is to get something so obviously problematic taken seriously. I'm certain you mean no ill will, but the lack of consideration here is concerning. [EDIT] As per the posters comments, the keys included weren't the real ones. I still think the point stands: they are trivial to obtain when you know they are included in the package so their exclusion only means so much.
- noasaservice 5y agoThis is an 0day public disclosure. The company affected should THANK this person for not selling the exploit on the dark web and making bank. And this goes back to the whole "responsible vulnerability disclosure". The damned white hats want to demonize anybody not reaching out to some opaque company and being told it might be fixed in 90-360 days. 0Days are JUST AS responsible as other types of disclosure. You owe them nothing, and they owe you nothing. And you're publishing info to everyone. Information symmetry.
- deadf00d 5y agoYeah, that's what I think too.
- deleted 5y ago[deleted]
- mr-wendel 5y agoI can't disagree more. They should thank him if he actually reached out to help, even if only to say "look how bad this is; you're easy pwnbait, kthxbye". Based on this article we don't even know if they are opaque (or worse, belligerent). I've tried to be as careful as possible in my wording to avoid demonizing the poster. I still see absolutely nothing indicating maliciousness or ill intent and I would just as strongly disagree with anyone trying to do that. My apologies if I have come across as being hateful in any way. I prefer to champion a web that goes back to a "hacker" culture I learned from in my youth that predates Internet culture: we believe DO owe each other something, somewhere in the positive gradient: basic decency, an assumption that we're all worthy of respect (unless proven otherwise), and that you never try to "score points" at the expense of someone else. But that is just what I believe and what my preferences are. Certainly "do no harm" is the rock bottom line.
- orf 5y agoYou don’t owe companies that don’t invest in security anything. This whole comment smells of upmost naïvete. It’s a for-profit company without a bug bounty program, in no way whatsoever should they expect someone to work for free to fix issues they created. The keys are public, they made them public. Do you expect that there are not automated systems trawling apps from the g-play store and doing what he’s doing?
- noasaservice 5y agoI'm sitting there at -3 for what amounts to be an "unpopular opinion" (aside: downvotes/silencing/dead'ing is common here for unpopular but realistic comments in IT, or how dare you offend the techbros, who are invariably writing shitty apps with garbage APIs.) I've made money from selling exploits to companies. Ive also been cheated out and had bugs downrated so they could pay less. Ive also seen colleagues who reported bugs they inadvertently found get hit with a felony (found not guilty). Frankly, this company should thank its lucky stars that the disclosure was an 0Day and not "sell this on dark web and have it exploited for 3mo from 1500 accounts and drain the company's coffers". This person owes the company *nothing*. They found an exploit due to bad API implementation, and wrote about it publicly. If they were in the USA, that's completely in 1fa territory.
- deadf00d 5y agoThere is no vulnerability here. Secrets has been anonymised, tokens and secrets provided are not the real ones. I'll follow your advice and update the article once I have an answer from the company.
- dncornholio 5y ago> Secrets has been anonymised After or before posting it to the internet?
- deadf00d 5y agoBefore. I'm not that crazy.
- dncornholio 5y agoThey don't look redacted though, I also don't remember reading you redacted them.
- deadf00d 5y agoI dont say it. If people try, it's gonna lead to nothing. But it's going to be fixed soon.
- mr-wendel 5y ago> ... and update the article once I have an answer from the company I look forward to the update and will be very curious to see how that goes. Best of luck! [EDIT] Also I think it worth adding one more thing. I think the poster has demonstrated an openness to feedback that is wonderful. Coming back to the keyboard to read "let me give that a try; I'll update things" is really cool.
- deleted 5y ago[deleted]
- noasaservice 5y agoYou're going to get a lot of hate here from the tech bros. This, however, is much more inline with Defcon, CCC, and hacking culture. And this sort of writeup about (React, API endpoint insecurity, cheating apps) would be a straight-up accepted submission to the respective cons.
- deadf00d 5y agoAs usual. That's cool ! Might try to do a submission.
- UncleMeat 5y ago> I think it's funny to try to earn money like this A lot of us think it is unethical and would take it as a huge red flag.
- deadf00d 5y agoIt's a concept, what I mean is the goal is cool. Feeling like in a movie.
- gigaflop 5y agoFirst off, you've done useful and valid work. Not that you should need me to say it, but I'll throw some kudos. Explaining that it's not possible to actually 'cash out' would be great, and that would probably help deter script kiddies from trying to defraud the app. There are real people on the other side! Tokens should be marked as redacted imo, and code sections could probably do to be snipped. If you wanted a tl;dr, I guess it would be that it looks like ctrl-c and ctrl-v were your primary editing tools. They're great, and I use them all the time, but that w(t) thing took me 10 seconds of scrolling to get through when skimming, which was 10 seconds with none of your own words on screen. Less can often be more! Especially if I'm looking at disassembled gibberish.
- deadf00d 5y agoThanks for your wonderful feedback. I understood my mistake. I think the article humor has not been received as intended, that's why I added a disclaimer in the top level of the article to contextualize it a little bit more. Hope I've not done any harm to their infrastructure. I'll definitely take care to this in my next articles. I also trimmed a bit the long code of the w() function, making the article easier to read.
- ska 5y agoFor what it's worth, I think that is an idiosyncratic use of "earn".
- sockpuppet69 5y agoYeahhhhhh you’re not gonna get hired by any scrupulous company.