3 ms·
Alright, this is more than you’re asking for but here’s the full story as I remember it. It was a long time ago so some of it is fuzzy. I don’t think I ever sha
by sickcodebruh 3y ago
Alright, this is more than you’re asking for but here’s the full story as I remember it. It was a long time ago so some of it is fuzzy. I don’t think I ever shared this story publicly before.
October 2011. I went to the rewards program site for my bank one day. I had a problem logging in and was frustrated. I’m fairly certain that it was telling me my account didn’t exist but I was sure I had previously registered. The error message stuck out. I was coding recreationally at the time, LAMP stack, and I was acutely aware of the dangers of SQL injection in PHP forms. The error message struck me as a database error, not an application error, and that combined with some other odd details on the page (I can’t remember what they were, it just seemed weirdly amateurish) made me wonder just how bad the page really was.
I wrote some basic injection query on the login form, some `GET * FROM… WHERE email=` on a users table. I remember limiting it carefully because I didn’t want to see other people’s data. And it came back with another error that was straight from the database! I think my query was malformed but it did show me something about the table. Then I thought, “there’s no way they’re using an account with write privileges, right?” I inserted a row, or maybe changed a row in another injected query and it was successful. I was freaked out! The most disturbing piece was a credit card number column. I can’t remember if I found my own row and saw my own number or what — for all I know it was hashed — but it worried me.
I wasn’t sure how to handle it. I just a moment ago found the old messages in my social media account and… oof. Looking back, I see why they might have been concerned. I was 27 and trolly. My internet behavior was obnoxious. I was the type who posted whatever “funny” thing popped in their head, random observations, argued with every troll, had an opinion about absolutely everything and wanted everyone to know it. In this case I posted a public message, paraphrasing: “Huge vulnerability on @big_bank site. Think they’d be pissed if I posted screenshot or did a blog post or should we talk direct?” Smooth. I can’t find their reply but I think they told me to DM them info. I see a DM that says “RE: vulnerability on your site, {my phone number} ASAP.” Very reassuring.
36 hours passed. I remember getting off the 7 train in Flushing, Queens after work and my phone rang. It was a VP at the bank. He introduced himself, told me they were very concerned about this, and wanted to know what I was looking for. “What am I looking for? I want you to fix it and tell your customers what happened!” Then he asked me to walk him through the timeline, including what (if any) queries I ran. I told him exactly what happened. It sounded like they had already found it through logs so they knew I had injected some simple data via the form. He told me that they had been in meetings all day talking about how to respond and confirmed that people were listening to the call. It was clear that they didn’t look me up in their system despite my name being on my social media profile and the phone number being associated with the account. We talked for maybe 10 minutes.
One interesting detail that came out was about the origin of the credit card reward site. When I was first poking at the page, I noticed that it had a .php extension. This was odd to me first because none of the other pages in their online presence presented that way. I was also used to seeing URLs rewritten — it looked sloppy. I had a hunch that this was built by an outside company, which would explain lack of compliance with the standards they likely had elsewhere. I asked him about this and he said “I can’t confirm that but I think you’re onto something” — something like that. I later did some more investigating and confirmed it. This bank started as a regional bank and grew. They used a web development group in their home town for this particular product. The same company provided it for other banks! I checked some of those pages and none seemed to have the same vulnerability.
So in the end, he was satisfied with my answers and understood that I was just an immature 27 year old with a big mouth but not a threat to anybody. He thanked me for bringing it to their attention. We got off the phone and I never heard from him again. The rewards site was down for a while after this. I still bank with them and have the same accounts.
Years later, I texted him to ask if he could help my retired mother get a job in one of their local branches. He never responded. It always bothered me.
Looking back, I think I did a lot of things wrong here. I should have stopped poking as soon as I saw an error message come back from a database, I never should have injected anything no matter how benign through the form input. When speaking with them, I probably should have consulted an attorney. I also wonder if I should have tried to charge them a consulting fee… but I also wasn’t trying to extort anyone and I’m glad they didn’t call the FBI. The end.
And on the topic of SQL injection and the FBI, I also have a stupid Bumbling Cohen Brothers Antagonist level story about two guys at my former job who hacked into a competitor’s custom CRM. It happened maybe 3-4 years before this. This one does involve the FBI!
- refurb 3y agoGreat story! Thanks for sharing. I always wondered how a company might respond to such a big security flaw being shared with them out of the blue.