3 ms·
Thank you so much for this. (xpto123 as well). I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice e
by sah88 12y ago
Thank you so much for this. (xpto123 as well).
I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice early season cold going so not really interested in sitting on the phone for hours so I've given up on that.
I'm going to email blast as many of the emails I can get and if I don't hear anything back from them by Monday I'll pass it onto CERT.
- ams6110 12y ago1) Be careful, people who submit proof-of-concept exploits to websites have been arrested for circumventing digital security measures. 2) It's HIGHLY unlikely that you are the first person to discover this, especially if it's a top 100 site. Those sites are constantly probed by attackers looking for exploits precicely because they are so valuable. Something like XSS due to unsanitized input would he found quickly as there are automated tools that do exactly that. Just report it to CERT, as suggested. 3) You may have hit a honeypot.
- shangxiao 12y agoA couple of years ago in Australia a security consultant noticed that firststatesuper.com.au had a gaping security hole in that he could manually change an ID in the URL and gain access to other users' account information. He kindly notified First State like any good samaritan, and so what do First State do in return? Disable his account, report the "offence" to the police, demand that their IT dept examine his computer, demanded that he sign a letter to admit liability and threaten to pursue any costs related to the matter. Luckily the Police had more common sense, realised what had actually happened and decided not to take any action. Reference: http://www.theage.com.au/technology/security/super-bad-first-state-set-police-on-man-who-showed-them-how--770000-accounts-could-be-ripped-off-20111018-1lvx1.html http://www.theage.com.au/technology/security/super-bad-first...
- joshschreuder 12y agoThe same thing happened this year with a teenager who found a SQL injection in the Victorian public transport website: http://www.pcworld.idg.com.au/article/549362/australian_teen_accepts_police_caution_avoid_hacking_charge/ http://www.pcworld.idg.com.au/article/549362/australian_teen... He disclosed to the organisation who then set the police onto him. Luckily he got off with a warning from police, but that's after having equipment seized etc.
- patcheudor 12y agoI'll add to this. Be careful in the future. You stated that you are an amateur at this and aren't entirely sure on what to do. That's the quickest way to set yourself up for some long term hurt. The problem is, when you start poking at server-side flaws as opposed to ones that might exist in applications you run client side like mobile apps, you are entering some very dangerous territory as you are engaged in what is generally considered to be hacking someone else's infrastructure. In the last few years a lot of people in the security community have been probing sites for XSS, SQLi and many other server side vulnerabilities but they are doing so at fairly high risk and as such many use multiple techniques to remain anonymous. All it takes is someone on the receiving end to decide to call the FBI and it doesn't matter how good your intentions were, your life is most likely going to change. I've seen this happen first hand to people I know. One guy I know reported an XSS flaw, offered to help fix it, and was accused of extortion as the receiving company figured his offer to "fix it" came at some cost. Luckily they backed down & he only lost about a weeks worth of pay after being suspended while an investigation took place.
- niels_olson 12y agoI know at least one fellow who's entire group is employed because the company got a phone call from the government that their network was exposed. In that case, it was also known to be actively exploited by a state actor, but the point stands that management takes phone calls from Uncle Sam quite seriously. If a house is on fire, don't be a hero. Call 911.
- xpto123 12y agoAll of this should be done in an anonymous way: I would say just create an anonymous gmail and open an anonymous linkedin account. Hit the same invitation message to a list of persons that work there, and really don't think about it anymore. The law is not on your side in most countries, there are honest security researchers in jail for doing things like this, so beware of your personal safety at all times. If you already identified yourself and followed their security submission page and they did not follow up, then its best to leave it at that. Above all don't get in personal trouble because of this, it's not worth it.