10 ms·
Moonpig.com Vulnerability – Exposes customer data
- troels 12y agoWow. This is actually still wide open. This is really bad. Fun fact - you don't even have to send the basic aut header - it'll respond just fine without it.
- AAtticus 12y agoI'm sure the (outsourced) dev team will have a bad day tomorrow. This is just unacceptable. According to the blog post he first made contact in 2013! Bugs happen, but this is just bad design.
- deleted 12y ago[deleted]
- driverdan 12y agoTo anyone thinking of enumerating the customer IDs to play with this, be very careful as it's illegal in the USA. That is exactly what weev was arrested and convicted for.
- matthewmacleod 12y agoOr don't do it in the first place, because it's obviously wrong...
- pbhjpbhj 12y ago>because it's obviously wrong... // Are you trying to say it's morally wrong to read data made publicly available through a site's API? I think that's a stretch. Clearly there are very obviously malevolent things you could do with data acquired with such queries, but just iterating on a URL query string seems pretty far from an obvious moral wrong. Legally questionable, for sure. Morally forthright, doubtful. The wrong comes in using data nefariously, surely; not in merely observing it.
- deleted 12y ago[deleted]
- martin_ 12y agoGiven the context is scraping, I'd argue enumerating a customer ID is pretty obviously wrong -- if that wasn't obvious enough, the response data is. And to accidentally, unknowingly harvest and store that data is much more of a stretch.
- matthewmacleod 12y agoI don't think there's any ambiguity here. Deliberately downloading personal information—clearly not intended to be released publicly—does not seem to be a defensible action. We're not talking about downloading a couple of records and alerting someone about it, after all.
- pbhjpbhj 12y ago>does not seem to be a defensible action // What harm is there in viewing data? None. Defended. Which do you find is indefensible, seeking to consume data or consuming it? Or, does one need to actively seek it and also consume it to cross your threshold of immorality? Or ...
- matthewmacleod 12y agoWhat harm is there in viewing data? None. Yes there is – you've consumed other people's data without permission. Would the same apply to physical trespass in your mind? Is there any harm in entering an accidentally unlocked house and snooping around? There's nothing preventing you from doing so... I'd argue that it's wrong, and equivalent to consuming data which is obviously intended to be private. It's not like there's ambiguity about it's status. Which do you find is indefensible, seeking to consume data or consuming it Surely you can only consume data if you seek to do so?
- pbhjpbhj 12y ago>you've consumed other people's data // Except you don't consume it, you view it. The data remains and is accessible at all times to others. If you don't use it you haven't consumed it in any way. >Is there any harm in entering an accidentally unlocked house and snooping around? // There is a lack of equivalence here IMO as personal space, such as in a dwelling place, is quite different from non-dwelling space. The case of viewing data (to me) is like a person walking across your farmland without permission; quite different to finding them in your bedroom. The lack of equivalence between physical and virtual spaces makes this analogy fundamentally flawed. If it's addressable on the internet then it's not private: If you hide your diary under your bed, that's private. If you hide it under a bush in the park, that's not private. >Surely you can only consume data if you seek to do so? // I shouldn't have used "consume", as the data is not consumed but viewed (unless it's used in later actions that "consume" it somehow). That said, you can view data without seeking to view it; you can seek to view data without being able to view it. If in the OP the person had tried altering the account ID and they couldn't view data from their other account would they still be committing an indefensible wrong in your opinion? Interestingly I was just on a site called PC Builder that had price data in INR (Rupee), switching to USD added a section to the URL and I, to see if I could use the site in GBP, went to the URL and altered it ... did I commit a crime in your opinion?
- 0x62 12y agoDoes anyone know what the legal position in Great Britain is?
- grabeh 12y agoGenerally it may fall under the Computer Misuse Act and 'unauthorised access to computer material'. Presumably from Moonpig's perspective inputting alternative customer IDs would be considered to be unauthorised access...
- tripzilch 12y ago> That is exactly what weev was arrested and convicted for. Please don't spread this misinformation, the USA justice system doesn't work (... like that). Weev was arrested for having a (very, very) loud mouth and pissing off the wrong, powerful people/businesses/corporations. If he'd have enumerated customer IDs for a smaller, lesser-known company such as Moonpig, reported it to the media like he did, without being all inflammatory and trollish[0] about it (or without having a history of allegedly doing such things in very different contexts), he'd have gotten a slap on the wrist, a fine, or something (if anything), but not been thrown into prison as he was. Your post makes it seem like Weev was convicted "for" doing something that is illegal in the USA and that the justice system worked "exactly" how it is supposed to, equally as it would apply to anyone. [0] stating this as a fact of how it happened, not judging him about this, at all
- driverdan 12y agoThere is more context to his arrest but the actions and evidence supporting his conviction were as I described.
- dabeeeenster 12y agoSurely this is bad enough to warrant criminal prosecution? Not sure if that's even possible in the UK but it ought to be...Shameful to have sat on that for over a year. Shameful.
- steakejjs 12y agoIf this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research. This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plaintext", Etc.
- meowface 12y agoFirst of all, the company could definitely be sued for negligence in the US. Not sure if they could in the UK. Second, there are not that many similarities between this research and weev's research. In this case, the researcher created 2 accounts which he had control over, then read data from both of the accounts despite not authenticating to either of them. He did not access any other customer's information (or at least he's suggesting he didn't). Weev on the other hand scraped private information for over 100,000 customers and shared it with friends and reporters. Both technically violated the CFAA, but weev's offense is a much greater violation of customer privacy, while this researcher has not violated anyone's privacy. I still don't think weev should have gotten any jail time, but you're making an unfair comparison.
- steakejjs 12y agoI honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence. The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
- 12y ago
- comeonnow 12y agoLots of users on Twitter saying to delete your account, but is there any proof that this will exclude your account from the API?
- dabeeeenster 12y agoOdds on it adds a "deleted" flag to your account record and nothing more...
- kirun 12y agoIt would probably be more effective to update your account with nonsense details.
- Someone1234 12y agoI am a former customer of theirs (in the UK) and just contacted CS about this. I'm also looking into contacting the Information Commissioner's Office as this issue is still open and my personal information (and that of the people I send cards to) is still available to anyone who may want it. I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't authorise them to publish. However I'll leave it to the ICO to make that determination.
- ookware 12y agoI've also sent customer services an email demanding an explanation and the closure of my account and deletion of personal data if true and sent an email to the ICO. In reality I don't hold out much hope but fingers crossed we can get some pressure behind this and force companies to take security seriously, especially when the vulnerability is responsibly reported as this seems to have been originally.
- DanBC 12y agoPlease do contact ICO! Regulation needs people to complain. ICO don't investigate complaints if there's been 3 month (?) delay.
- justincormack 12y agoMy guess is that the ICO wont fine them very much as it did not include full credit card numbers. However they might up it for failings in process, lots of remedial measures etc. They might not even have PCI compliance issues alas. The management will argue that they knew nothing, although that is becoming less of a defence now.
- richardwhiuk 12y agoSocial engineering once you have the last four digits of the credit card number and the billing address is almost certainly enough to score full credit card numbers. (e.g. use them to reset password for e.g. Amazon account).
- cdwhitcombe 12y agoIn the address example you can even emit the arguments and it just returns you a large list of addresses. Would expect this to be hitting the news here in the UK tomorrow! Judging by their parent companies website they seem to be PCI certified (http://careers.photobox.co.uk/security-officer-moonpig/ http://careers.photobox.co.uk/security-officer-moonpig/) which is likely to be removed from them after this, also given the private information on show I would expect this breach of the data protection act to be meaning a large fine for them. For anyone at risk from this you can't just cancel your account, but you can manually go through and delete quite a bit of data such as address books and they then disappear from the API calls.
- MichaelGG 12y agoBeen a while since I read PCI DSS but if the PAN isn't there, does it specify you have to protect that information? Also, if they don't actually have the PAN touch their servers (like, using a BrainTree or Stripe-like solution), PCI compliance is quite minimal. Even PCI DSS 3.0 is trivial to deal with using Stripe (they just insert an iframe so the CC info goes directly to their site). Of course, yeah, they don't deserve the benefit of the doubt here. Given such a terrible API they probably are a mess inside, too.
- cdwhitcombe 12y agoReading that job spec I assumed they handle all the PCI side of things themselves, if using stripe etc I doubt you'd need such an involved role. Given the mess it looks like on the front, I would bet PAN's are stored in clear text too!
- bbcbasic 12y agoDisgusting - this should be priority one for them to fix. I just changed all my details to ones from a fake name/address generator, then emailed moonpig to close my account. I will lose about 80 pence, but nevermind. I didn't see an option to get rid of my credit card details, so that may still be vulnerable, especially with the NameOnCard field in the api.
- Nexxxeh 12y agoI know my mum has a Moonpig account so I'm pissed about this, but I don't recall if I have an account. Recently, I have mostly been using CFHDocmail. It's 96p for a full colour A5 greeting card of your own design. (It's also cheaper to use them to send letters than it is for me to buy a stamp. They also do postcards, going as low as 38p delivered. Lots of mailmerge and API stuff available too iirc, but I've never used any of it.) Edit: They may use windowed envelopes for the cards, when I tested they didn't, but now I've been told they do. I've not sent one to myself since my original testing, and none of the recent recipients have said either way. I'll make a quick one and sent it to myself!
- ksk 12y agohttp://www.conosco.com/case-studies/moonpig-outsourced-it/ http://www.conosco.com/case-studies/moonpig-outsourced-it/ >Protection against cyber attacks Wow...
- andrewstuart 12y agoAwkward.
- helgrind 12y agoTo be fair to them they were just infrastructure not backend. I'm sure their firewall works perfectly, the trouble is the legitimate traffic that's allowed to do anything it wants!
- rst 12y agoSo they delegated security to a separate team, which only got to put "reinforced firewalls and IPS appliances" around an app which was still missing basic internal security checks. (And it's hard to see how firewalls could do the checks on their own, without access to the app's data stores or duplicating app logic -- either of which makes it no longer a firewall.) Unfortunately, it's all too easy to get this kind of partial solution from a "security team" that's distinct from (and worse, sometimes hostile to) the team that actually develops the app.
- networkguy 12y agoThey aren't a full stack security team though and it's not fair to be putting any fault on Conosco; they are enterprise IT consulting and support and that's clear enough from a look on their website. To be basic, a firewall does stateful inspection of inbound and outbound TCP/IP packets and an IPS guards against vulnerabilities with signatures; neither of which understand the applications logic --- there is nothing in off the shelf hardware/software that will prevent a shitty app from giving up the keys to the kingdom. The firewall might block inbound connections to port 22 and the IPS might detect a SQL injection attack and stop it, but if you have an API that just gives up data you're screwed and that's precisely what happened. A legitimate request for information was made on legitimate ports, using legitimate protocols and as far as the hardware defense is concerned, everything is as expected -- the problem is the application.
- josephwegner 12y agoApparently they hired these guys to help with "protection against cyber attacks" http://www.conosco.com/case-studies/moonpig-outsourced-it/ http://www.conosco.com/case-studies/moonpig-outsourced-it/ Awful...
- dabeeeenster 12y agoTheir first "solution": Fixed price outsourced IT department
- georgemcbay 12y agoTo be fair, the complete security failure outlined in the article is at the app level and not something I'd expect most IT departments to bear responsibility for (unless they were directly consulted about how good of an idea using basic auth with hardcoded credentials is and gave an OK on it). Of course, I wouldn't be too surprised if the app/API here were also outsourced to a low fixed price development shop.
- dyadic 12y agoIt's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.
- teh_klev 12y agoOn top of this clusterfuck, I find it galling that I can't just close my account and have all my details removed. Oh, no you need to fill in a contact form.
- clobec 12y agoThis is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data. Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer. Dealing with this via legal channels would have ensured a resolution whilst protecting customer data from any opportunistic bad actor. Shame on you. I can't wait for myself and my wife to get doxxed now. Thanks. Also, FYI; the whole card number isn't returned because they are probably tokenising the full card number with their payment gateway.... Or at least, I hope. DOWNVOTING because you don't agree with me? How rude. I believe I'm a making a valid point, there are legal channels in place to help with this sort of thing. EDIT. someone people think I do no hold moonpig responsible for this. I do! I am not blaming the security researcher. What I am saying is that some countries (like the one where moonpig is incorporated and operates) have agencies that deal with issues like these. Getting these agencies involved before public disclosure is a much nicer way to deal with these sorts of issues. I'm aware that this exploit may already have been used but that doesn't mean that we should tell everyone about it until it is resolved. Getting the ICO involved may have resolved this issue a long time ago. My disclosure - I have a friend that works at the ICO and she tells me that these issues usually take them (on average) 2 months to sort out. COmpanies get very anxious when the ICO contact them.
- arielm 12y agoWhile your point is valid I think you're getting doe voted because you're completely forgetting that the probability of someone malicious finding out about this vulnerability and exploring it without disclosing is quite high. Going through legal channels would just mean the api will be live for longer. Lawyers like to take their time. Instead, the disclosure resulted in the API being shut down within the hour. A much better result IMO.
- scott_karana 12y agoThe guy who found the vulnerability in 2013 could have simply reported it to authorities at the time. If their turnaround was earlier than 2015, it would have worked out better, yes?
- 51Cards 12y agoLooks like the API is no longer accessible from here. Seems like they have pulled it down.
- robtaylor 12y agoYes - appears dead now. Open for around 3hrs after first post of the vun I think.
- justincormack 12y agoThats good, thats their entire business down, so they are going to have to pay attention. I wonder who made the decision to take it down. I hope they don't get fired.
- hanoz 12y agoIn the circumstances that might be a generous explanation for their ID enumerable non rate limited API going down.
- johngd 12y agoThey have 3 other brands: http://photobox.co.uk http://photobox.co.uk http://uk.paper-shaker.com http://uk.paper-shaker.com https://sticky9.com https://sticky9.com Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.
- dpwm 12y agoPhotobox acquired Moonpig in 2011 [1]. In 2010, Photobox got called out for emailing passwords in plaintext[2], and were quick to take to twitter to say "It will never happen again."[3] At that point, it had only been happening for 4 years [4]. Coupled with the tone of the job advert already posted by others [5], it doesn't seem too hard to imagine a corporate culture where security is not a serious concern until things go wrong. [1] http://www.bbc.co.uk/news/business-14275632 http://www.bbc.co.uk/news/business-14275632 [2] http://www.pcpro.co.uk/news/security/360163/photobox-sorry-after-email-screw-up http://www.pcpro.co.uk/news/security/360163/photobox-sorry-a... [3] https://twitter.com/PhotoBox/status/20719242964 https://twitter.com/PhotoBox/status/20719242964 [4] http://blog.dave.org.uk/2006/06/more-password-s.html http://blog.dave.org.uk/2006/06/more-password-s.html [5] http://careers.photobox.co.uk/security-officer-moonpig/ http://careers.photobox.co.uk/security-officer-moonpig/ [edited for clarity]
- mtmail 12y agoThe number of companies that send (and possibly store) plain text passwords is scary. I keep reporting them to http://plaintextoffenders.com/ http://plaintextoffenders.com/
- dpwm 12y agoI was about to ask why anyone would bother sending plain text passwords and store them encrypted. I then remembered a high-school friend's first (and largely unsupervised) job where IIRC he devised a ridiculous password encryption (not hashing) scheme in PHP (on shared hosting). Unrelated horror unfolded a couple of years later when for some peculiar reason he had to move the site to a godaddy VPS. An unencrypted customer database sitting at /db.sql, fully accessible to the world. Apache had been configured to show directory indexes and, to take the site offline, /index.php had been removed. I think at the time I even needed to explain the possible consequences. I just remember being told that the database was restoring and it wouldn't take too much longer! I think any remaining part of me that implicitly trusted interesting websites with personal data died that day.
- arielm 12y agoIt's astonishing that somewhere out in the modern world there's an api that returns personally identifiable information without requiring any sort of authentication. What I find absurd is that the company hasn't done anything about it. Even if they don't care/know about security they must at least care for bad PR... But with all of that in mind, I don't know what's the best way to fight these clueless behemoths. You disclose and thousands or even millions of people will be compromised. You don't and those same people could be compromised but no one will know because the attacker(s) will just continue to siphon information quietly. They should be waterboarded for making a responsible individual have to choose. For the record, I approve of this disclosure. Better to know the evil than let it go on unnoticed.
- tripzilch 12y ago> They should be waterboarded Except, you know, for the part where that is an inhumane thing to do, even when done to people that are actually guilty of committing terrible crimes. > It's astonishing that somewhere out in the modern world there's an api that returns personally identifiable information without requiring any sort of authentication. Hello, have you met the 21st century? It's a freakshow and clusterfuck of planetary proportions. Although even accepting that fact, yes, I suppose that doesn't make it less astonishing. Spoiler alert: things will probably get even more astonishing before it gets less. Fasten your seatbelts, wear a hat, etc.
- knodi123 12y agoI've seen dumber. In my second real job, I was a book editor, but I noticed our web master literally had a file called accounts.js which held a static array of usernames, passwords, and billing information for all of our customers. I told him this was terrible security, and he said, literally, "You'd have to view source to even know passwords.js exists, and our source is pretty hard to read. I'm not worried." I took all the info to our CEO and got him demoted to server maintenance guy, on the spot, and I took over his job. He later gloated that my store was much slower than his, since he downloaded our entire database as JS flat files and did absolutely everything client-side except payment processing and order fulfillment. I pointed out that my store didn't require 10 megabytes of download for the first page view, plus I had industry-standard security. He was in even more trouble a couple of weeks after that, because some russian hackers pwned our server so bad that we had to drive to the colo and replace it with a new piece of hardware. I've got a dozen stories about this guy, he's a hoot. Okay, last story, I promise; he's allergic to electronics power supplies, so he was the only employee who got to work from home (where he kept his CPU in a separate room from his keyboard and monitor).
- wiuiu 12y ago"I took all the info to our CEO and got him demoted to server maintenance guy, on the spot, and I took over his job" WOW. You are a terrible human being.
- knodi123 12y agoNo, I'm really not. This guy was an arrogant ass who ignored me because I was 22 and he was 51 and he "was doing this stuff when I was still pooping my pants". He refused to follow best practices, and he refused to take advice. I told our CEO what this guy was doing, why it was bad, why nobody else does that, and how it ought to be done instead. I honestly thought our boss would just force him to follow my recommendations. But instead he told me to just re-do it the right way myself. Boss made the best decision for the company. You could have presented your objections in a more tactful manner, but you didn't, because you're a judgmental asshole.
- brazzledazzle 12y ago
- LukeB_UK 12y agoMy comment from the other thread: They also make it very difficult to delete your account. Rather than just have a link on the site, you have to contact customer services and they say they'll respond in 24-48 hours. Not to mention the ways they try to hide you removing your card details. If you want to remove your card details, do the following: The easiest way to do this would be to go to the My Account page then click on the ‘Add Moonpig Prepay Credit’ link, click on the Buy link and your saved card details will be shown onscreen. Click on the ‘Remove Card’ option.