Posted: Sat May 18, 2013 8:47 pm Post subject: Stupid Drivers-Ed Website
So I'm taking this Drivers-Ed course which has a website where you can log on, and view all your account information, including all personal information they have. Via a very simple URL edit (I mean like changing "ACCID=17719" to another number), you can view any users personal information. You don't even need to have a logged-on cookie to view other users profiles! Is there anything I can do with this? Obviously nothing malicious, I mean like demand a refund? Or something like that? Surely having 17000 peoples personal information publicly available is punishable in some way?
Nathan
Sponsor Sponsor
Tony
Posted: Sun May 19, 2013 3:18 am Post subject: RE:Stupid Drivers-Ed Website
Posted: Sun May 19, 2013 8:32 am Post subject: RE:Stupid Drivers-Ed Website
Definitetly report the vulnerability to the website, and be on there butts about fixing it. If you wanted you could even offer to fix it for them for a price
Insectoid
Posted: Sun May 19, 2013 8:36 am Post subject: RE:Stupid Drivers-Ed Website
Or threaten to pull yourself out of the program and publicize the situation. Presumably the records contain phone numbers or email addresses. Tell them you'll contact all their customers and inform them that their information is at risk. If they don't overhaul their site after that, they deserve to lose their customers.
Nathan4102
Posted: Sun May 19, 2013 9:23 am Post subject: RE:Stupid Drivers-Ed Website
Full names, home and mobile numbers, home adress, email adress, birth date, license number, theres a bunch of stuff. Ill probably threaten to sell the story to the Sun or something, I dunno yet.
@mirhagk, I wouldnt know how to fix it! I could give 80% to someone here to fix it though.Anyone?
mirhagk
Posted: Sun May 19, 2013 10:53 am Post subject: RE:Stupid Drivers-Ed Website
Well I most likely could fix it, a simple check for permission is all that would be required
Insectoid
Posted: Sun May 19, 2013 10:57 am Post subject: RE:Stupid Drivers-Ed Website
Quote:
a simple check for permission is all that would be required
That's assuming they have any framework in place for it at all. They might not even be encrypting their login data (in fact, they probably aren't).
Nathan4102
Posted: Sun May 19, 2013 11:19 am Post subject: RE:Stupid Drivers-Ed Website
Wow, you'd expect more from one of the biggest driving schools in ontario. Mirhagk, ill message you if he asks me to fix it. What would be a fair price to charge them?
Sponsor Sponsor
mirhagk
Posted: Sun May 19, 2013 6:06 pm Post subject: RE:Stupid Drivers-Ed Website
Well if there is a log-in in place, I would hope they have at least a basic check to see if you're logged in to access the page. If they have that then it probably won't be too much more to make it restrict to only your login page.
It's probably not a huge deal if the login info is encrypted while transmitted, but I would hope that it's hashed in the database.... and if not and anyone helps them, please do that.
@Nathan, I don't really know a fair price. For my software contracting I generally charge around $25/hour, depending on the job and the client. I don't know how long it'd take, and I'd need to take a look at their framework to make a good estimate. PM me if you want to talk more.
Nathan4102
Posted: Sun May 19, 2013 8:02 pm Post subject: RE:Stupid Drivers-Ed Website
The log in system obviously meeds lots of work. I could give you the URL to my profile right now, and youd be able to access my full profile. If the guy asks me to fix it, ill PM you and we can work something out.
Dan
Posted: Sun May 19, 2013 8:11 pm Post subject: Re: RE:Stupid Drivers-Ed Website
Nathan4102 @ 19th May 2013, 9:23 am wrote:
Ill probably threaten to sell the story to the Sun or something, I dunno yet.
@mirhagk, I wouldnt know how to fix it! I could give 80% to someone here to fix it though.Anyone?
This would get you sued and/or arrested. It's one thing to find an exploit and report it, but extorting the owner of the website is illegal.
Computer Science CanadaHelp with programming in C, C++, Java, PHP, Ruby, Turing, VB and more!
mirhagk
Posted: Sun May 19, 2013 8:42 pm Post subject: RE:Stupid Drivers-Ed Website
I think Nathan meant he'll go public with the story if the site owner refuses to fix it, which is actually exactly what responsible disclosure is (tell the site owner, and if they don't do anything after a reasonable amount of time, you can publish the details).
I really hope he didn't mean to say he'd sell the story to the sun without giving the site owner notice and time to fix it.
Dan
Posted: Sun May 19, 2013 8:58 pm Post subject: RE:Stupid Drivers-Ed Website
He said he would sell the story to sun in the same post he discussed splitting the profits of extorting the website owner to pay him to fix. He might have not meant it that way, but it would look bad enough to be evidence in a court case should the sites owner freak out and go to the authorities or start a law suit.
Computer Science CanadaHelp with programming in C, C++, Java, PHP, Ruby, Turing, VB and more!
Nathan4102
Posted: Sun May 19, 2013 9:14 pm Post subject: RE:Stupid Drivers-Ed Website
Sorry if that came out wrong, Ill give him time to fix it first, before I publicise anything. Hes been trying to contact me all day today while I was out though, so I doubt itll come to that.
Dan
Posted: Sun May 19, 2013 9:42 pm Post subject: RE:Stupid Drivers-Ed Website
Even if you have no plans to extort them you should know that responsible disclosure does not normally go over well unless you have a lot of support behind you.
Most companies are not overwhelmed to hear that they are being accused of failing to secure there software (especially from a high school student) and often treat it as more of a threat than any kind of help. Ideally they will see the light and fix there site, however, they are just as likely to ignore you or threaten criminal or civil action against you.
I hope it works out for you, and the guy is not trying to contact you to threaten you.
Computer Science CanadaHelp with programming in C, C++, Java, PHP, Ruby, Turing, VB and more!