3 ms·
I discovered a SQL injection vulnerability in the credit card rewards site of a major US bank in 2011. A VP finally called me a day later and asked what I wante
by sickcodebruh 3y ago
I discovered a SQL injection vulnerability in the credit card rewards site of a major US bank in 2011. A VP finally called me a day later and asked what I wanted — they thought I was a hacker trying to extort them, he told me they had been in meetings all day about it. They didn’t bother looking up my information to see that I had been an account holder for more than ten years.
The site was down for a few months while I assume they fixed and audited the whole product. They never told customers what happened.
- l33t233372 3y agoI bet you could have gotten far with a reply to the effect of “a job.”
- bob1029 3y agoMuch of the time this stuff is outsourced to a 3rd party. Even many "big" banks don't really want anything to do with developing their own software.
- qup 3y agoI'm sure the ONLY capacity they could think to use this guy would have been to actively develop their web software. /s
- redprince 3y agoWhatever you ask for may be (mis-)interpreted as extortion. There's very thin ice in that direction.
- refurb 3y agoOh you cant stop there. What did you tell them you were doing? how did they react? Super interesting story.
- sickcodebruh 3y agoAlright, this is more than you’re asking for but here’s the full story as I remember it. It was a long time ago so some of it is fuzzy. I don’t think I ever shared this story publicly before. October 2011. I went to the rewards program site for my bank one day. I had a problem logging in and was frustrated. I’m fairly certain that it was telling me my account didn’t exist but I was sure I had previously registered. The error message stuck out. I was coding recreationally at the time, LAMP stack, and I was acutely aware of the dangers of SQL injection in PHP forms. The error message struck me as a database error, not an application error, and that combined with some other odd details on the page (I can’t remember what they were, it just seemed weirdly amateurish) made me wonder just how bad the page really was. I wrote some basic injection query on the login form, some `GET * FROM… WHERE email=` on a users table. I remember limiting it carefully because I didn’t want to see other people’s data. And it came back with another error that was straight from the database! I think my query was malformed but it did show me something about the table. Then I thought, “there’s no way they’re using an account with write privileges, right?” I inserted a row, or maybe changed a row in another injected query and it was successful. I was freaked out! The most disturbing piece was a credit card number column. I can’t remember if I found my own row and saw my own number or what — for all I know it was hashed — but it worried me. I wasn’t sure how to handle it. I just a moment ago found the old messages in my social media account and… oof. Looking back, I see why they might have been concerned. I was 27 and trolly. My internet behavior was obnoxious. I was the type who posted whatever “funny” thing popped in their head, random observations, argued with every troll, had an opinion about absolutely everything and wanted everyone to know it. In this case I posted a public message, paraphrasing: “Huge vulnerability on @big_bank site. Think they’d be pissed if I posted screenshot or did a blog post or should we talk direct?” Smooth. I can’t find their reply but I think they told me to DM them info. I see a DM that says “RE: vulnerability on your site, {my phone number} ASAP.” Very reassuring. 36 hours passed. I remember getting off the 7 train in Flushing, Queens after work and my phone rang. It was a VP at the bank. He introduced himself, told me they were very concerned about this, and wanted to know what I was looking for. “What am I looking for? I want you to fix it and tell your customers what happened!” Then he asked me to walk him through the timeline, including what (if any) queries I ran. I told him exactly what happened. It sounded like they had already found it through logs so they knew I had injected some simple data via the form. He told me that they had been in meetings all day talking about how to respond and confirmed that people were listening to the call. It was clear that they didn’t look me up in their system despite my name being on my social media profile and the phone number being associated with the account. We talked for maybe 10 minutes. One interesting detail that came out was about the origin of the credit card reward site. When I was first poking at the page, I noticed that it had a .php extension. This was odd to me first because none of the other pages in their online presence presented that way. I was also used to seeing URLs rewritten — it looked sloppy. I had a hunch that this was built by an outside company, which would explain lack of compliance with the standards they likely had elsewhere. I asked him about this and he said “I can’t confirm that but I think you’re onto something” — something like that. I later did some more investigating and confirmed it. This bank started as a regional bank and grew. They used a web development group in their home town for this particular product. The same company provided it for other banks! I checked some of those pages and none seemed to have the same vulnerability. So in the end, he was satisfied with my answers and understood that I was just an immature 27 year old with a big mouth but not a threat to anybody. He thanked me for bringing it to their attention. We got off the phone and I never heard from him again. The rewards site was down for a while after this. I still bank with them and have the same accounts. Years later, I texted him to ask if he could help my retired mother get a job in one of their local branches. He never responded. It always bothered me. Looking back, I think I did a lot of things wrong here. I should have stopped poking as soon as I saw an error message come back from a database, I never should have injected anything no matter how benign through the form input. When speaking with them, I probably should have consulted an attorney. I also wonder if I should have tried to charge them a consulting fee… but I also wasn’t trying to extort anyone and I’m glad they didn’t call the FBI. The end. And on the topic of SQL injection and the FBI, I also have a stupid Bumbling Cohen Brothers Antagonist level story about two guys at my former job who hacked into a competitor’s custom CRM. It happened maybe 3-4 years before this. This one does involve the FBI!
- deleted 3y ago[deleted]