Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Powaqoatse posted:

some danish developer noticed that his daycare had a form where you could look up anyone by their ss# & it had no ratelimiting, so you could pretty much enumerate the entire search space & get all valid #s + name + address (only 36,500,000 possibles).

he disclosed it to the vendor, and then went directly to the media & now the vendor is pressing charges for hacking

article in danish
http://nyheder.tv2.dk/krimi/2017-06-21-fandt-fejl-i-it-system-da-son-skulle-i-institution-nu-er-han-sigtet-for-hacking
On the IT solution is a field where using social security number can beat his partner up.

Family Guy has previously told TV2 that he wrote his girlfriend's social security number, after which the IT system came up with her name.

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

some danish developer noticed that his daycare had a form where you could look up anyone by their ss# & it had no ratelimiting, so you could pretty much enumerate the entire search space & get all valid #s + name + address (only 36,500,000 possibles).

he disclosed it to the vendor, and then went directly to the media & now the vendor is pressing charges for hacking

article in danish
http://nyheder.tv2.dk/krimi/2017-06-21-fandt-fejl-i-it-system-da-son-skulle-i-institution-nu-er-han-sigtet-for-hacking
thankfully it is a scandinavian court so there might be someone familiar with modernity on the other end, presuming that disclosure happened after the vuln got fixed, or it was partial when vendor said "wontfix"

besides, someone is going to be really loving dead over the eu pii laws

Cybernetic Vermin
Apr 18, 2005

cinci zoo sniper posted:

thankfully it is a scandinavian court so there might be someone familiar with modernity on the other end, presuming that disclosure happened after the vuln got fixed, or it was partial when vendor said "wontfix"

besides, someone is going to be really loving dead over the eu pii laws

this. there is no loving way they win that lawsuit. they are deep in the wrong, and liable, when they disclose personal info like that

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



anthonypants posted:

On the IT solution is a field where using social security number can beat his partner up.

Family Guy has previously told TV2 that he wrote his girlfriend's social security number, after which the IT system came up with her name.

lmao

ps: :thumbsup: google. "slå op" means "look up", not "beat"

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



he contacted media the day following the disclosure. he contacted the municipality that runs the daycare, who said they would pass on the info to the vendor. no word on what the vendor said.

it also mentions he works for a competing vendor, so that muddies it a bit

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



but yeah, vendor KMD hosed up big time with that lookup form.

cinci zoo sniper
Mar 15, 2013




Powaqoatse posted:

he contacted media the day following the disclosure. he contacted the municipality that runs the daycare, who said they would pass on the info to the vendor. no word on what the vendor said.

it also mentions he works for a competing vendor, so that muddies it a bit

dude might be in for a rough ride then

SeaborneClink
Aug 27, 2010

MAWP... MAWP!
So to clarify, the daycare form, queried the gov database of identity numbers, and therefore you could enumerate the entire search space of all issued (past/present) identity numbers? I'm presuming that is what happened as it mentions he checked using his girlfriend's number and I sure hope she wasn't listed in the daycare's database...

That's some secfuck

cinci zoo sniper
Mar 15, 2013




SeaborneClink posted:

So to clarify, the daycare form, queried the gov database of identity numbers, and therefore you could enumerate the entire search space of all issued (past/present) identity numbers? I'm presuming that is what happened as it mentions he checked using his girlfriend's number and I sure hope she wasn't listed in the daycare's database...

That's some secfuck

yeah, euronumbers often follow some kind of predefined pattern, so you can generated them in bulk (and also they are mostly worthless for id fraud)

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



CPR numbers are of the form yyyyymmdd-cccc

date is birthday obv
checksum is even for women, uneven for men (can be changed as part of legal gender reassignment).

a number by itself is worthless (checksum algo is public so theyre easy to generate by yourself).
number + matching name & address has previously been used to do some basic identity theft (i think step #1 was redirecting mail) and step piecemeal up to bank accounts and drivers licenses, but i have no idea if thats possible anymore. dont think it is..

all public services are now online & use cpr# + password + physical otp unless you get a deferment because youre too old to computer

Carthag Tuek fucked around with this message at 18:44 on Jun 23, 2017

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
it's that time again, https://twitter.com/taviso/status/878314575149506561

also microsoft's fix broke his linux wrapper, lol

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
itt: itt (it's tavis time)

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

if tavis stood under Niagara falls he would probably solve p/np

FlapYoJacks
Feb 12, 2009
Security Fuckup Megathread - v13.70: Tavis does Redmond.

cinci zoo sniper
Mar 15, 2013




Lutha Mahtin posted:

if tavis stood under Niagara falls he would probably solve p/np
no suicide requests in yospos

flakeloaf
Feb 26, 2003

Still better than android clock

https://twitter.com/taviso/status/878317891984048129

aces

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
has anyone said tavis ownmandy yet?

surebet
Jan 10, 2013

avatar
specialist


http://i.imgur.com/k5lcM8D.mp4

NFX
Jun 2, 2008

Fun Shoe

antivirus-turnstile.gif

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




ok thats just beautiful

NFX
Jun 2, 2008

Fun Shoe

Powaqoatse posted:

he contacted media the day following the disclosure. he contacted the municipality that runs the daycare, who said they would pass on the info to the vendor. no word on what the vendor said.

it also mentions he works for a competing vendor, so that muddies it a bit

he contacted media the day after, but the story wasn't published until 14+ days later after no word from the vendor or municipality


and then when the tv station contacted the vendor, they (the vendor) called up his boss to say "hey your guy is hacking us!"

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

cinci zoo sniper posted:

no suicide requests in yospos

it was a joke about how he once realized the solution to something while he was in the shower

cinci zoo sniper
Mar 15, 2013




Lutha Mahtin posted:

it was a joke about how he once realized the solution to something while he was in the shower
i was not being serious, sorry

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
if tavis ever wants to break into your house he'll just stand outside and blast himself with the garden hose for a few minutes before teleporting into your living room

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



NFX posted:

he contacted media the day after, but the story wasn't published until 14+ days later after no word from the vendor or municipality


and then when the tv station contacted the vendor, they (the vendor) called up his boss to say "hey your guy is hacking us!"

yea its a mess but imo he shouldnt have talked to anybody but the vendor & given them a chance to fix it. only then talked to the media if they didnt give a poo poo

responsible disclosure yo

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
responsible disclosure is so boring

cinci zoo sniper
Mar 15, 2013




CRIP EATIN BREAD posted:

responsible disclosure is so boring
less boring than serving a prison time

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
so i've just discovered while transitioning services for a client, that the all-in-one (industry targeted) MSP they were using has their "Zoolz" cloud backup service tied to an employee email address.

the same address is used for multiple customers

you can browse and restore from the other customers data

these customers have massive amounts of PII including medical information for their members

i don't even know where to start with this one

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

oh shiiiiiiiiit

https://www.theregister.co.uk/AMP/2017/06/23/windows_10_leak/

32TB of Windows 10 internal builds, core source code leak online

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat

infernal machines posted:

so i've just discovered while transitioning services for a client, that the all-in-one (industry targeted) MSP they were using has their "Zoolz" cloud backup service tied to an employee email address.

the same address is used for multiple customers

you can browse and restore from the other customers data

these customers have massive amounts of PII including medical information for their members

i don't even know where to start with this one

is it a government thing?

burning swine
May 26, 2004



BangersInMyKnickers posted:

oh shiiiiiiiiit

https://www.theregister.co.uk/AMP/2017/06/23/windows_10_leak/

32TB of Windows 10 internal builds, core source code leak online

wooo

zero-days for decades

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

oh shiiiiiiiiit

https://www.theregister.co.uk/AMP/2017/06/23/windows_10_leak/

32TB of Windows 10 internal builds, core source code leak online
:hellyeah:

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

BangersInMyKnickers posted:

oh shiiiiiiiiit

https://www.theregister.co.uk/AMP/2017/06/23/windows_10_leak/

32TB of Windows 10 internal builds, core source code leak online

oh boy. now that's a secfuck

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

oh shiiiiiiiiit

https://www.theregister.co.uk/AMP/2017/06/23/windows_10_leak/

32TB of Windows 10 internal builds, core source code leak online

блять

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

CRIP EATIN BREAD posted:

is it a government thing?

the MSP offers services specifically to unions, so some of the people exposed are likely government employees, but they don't to my knowledge provide services directly to the government

i'm setting up a meeting with my client to discuss their exposure, then i guess i'm contacting the privacy commissioner

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I fully support Microsoft's commitment to opensource

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
where's shaggar

Broken Machine
Oct 22, 2010

I wonder how much noxious poo poo they're going to find buried in that MS code, good stuff.

Last Chance
Dec 31, 2004

oopsy daisies.

Adbot
ADBOT LOVES YOU

burning swine
May 26, 2004



all the source code leaks for previous windows versions were riddled with profanity

  • Locked thread