5 ms·
In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that co
by sah88 12y ago
In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website.
My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(to emphasize I never published anything on the site, this item was posted by another user and I was actually interested in purchasing it until I got redirected) which I have reported by phone and by form is still up on their site redirecting users. This one redirect doesn't actually appear malicious though but I have no way of telling how many other items are affected. At some point I feel there is a moral obligation for me to disclose the information which leads me to my second problem.
I have no fucking idea if I'm just overly worried (judging by the comments it would seem so) about the vulnerability. I also have no real idea of how serious it is. But it seems to me that even if a fraction of a fraction of transactions are affected it would still amount to a large amount of stolen information.
What I would really like is for them to email me back and say either "Oh wow yeah thanks for catching that" or "God damn you dumbass, no that's not actually a problem because xyz"
- not_kurt_godel 12y ago> What I would really like is for them to email me back and say either "Oh wow yeah thanks for catching that" or "God damn you dumbass, no that's not actually a problem because xyz" They're not going to acknowledge any issue until they've patched it if they're smart.
- tzs 12y agoIt's always fun to learn the first time how little some big organizations care about security. I received an offer about 10 years ago, on a Friday evening, to sell me 100k stolen credit cards, and was given a sample of 10k stolen credit cards to show they were serious. I did some checking and determined that samples seemed real. I called the FBI to report this. They were not interested, and suggested I try the Secret Service. I did, and they were not interested. I tried a couple major credit card companies. One was not interested. One gave me an email address to forward the sample list and the full list offer to and said someone would look at it Monday morning.
- gone35 12y agoYou would be surprised. The BBC has been reporting on a similar XSS vulnerability on over a hundred eBay listings with custom Javascript for months now, to no avail [1,2,3]. I guess people really like their parallax sparkles nowadays. [1] http://www.bbc.com/news/technology-29310042 http://www.bbc.com/news/technology-29310042 [2] http://www.bbc.com/news/technology-29279213 http://www.bbc.com/news/technology-29279213 [3] http://www.net-security.org/secworld.php?id=17377 http://www.net-security.org/secworld.php?id=17377