RE: getting DDoSed - mothered - 08-15-2018
(08-14-2018, 06:19 PM)Jiggly Wrote: (08-14-2018, 04:43 PM)mothered Wrote: (08-14-2018, 12:58 PM)l33t Wrote: companies should take their security much more serious.
Unfortunately they don't.
My latest breach clearly demonstrates the lack of security, namely (amongst many other Issues) storing passwords In plain text.
Spoiler:
Spoiler:
If In the hands of someone with malicious Intent, there's no telling the magnitude of subsequent losses both on a personal and corporate level.
It makes you think they're just waiting for something to go wrong before they do anything about it.
It's certainly the case and It's appalling to say the least. You can see In the above screenshots that I've got full raid on their systems and If I was someone who's maliciously-minded, well, I won't go Into detail of the consequences.
A lot of organizations do not even bother to check their logs etc. For testing purposes, I've planted backdoors to gain later access and upon doing so 6 months later, It (backdoor) was still there.
RE: getting DDoSed - Jiggly - 08-16-2018
(08-15-2018, 03:50 AM)mothered Wrote: (08-14-2018, 06:19 PM)Jiggly Wrote: (08-14-2018, 04:43 PM)mothered Wrote: Unfortunately they don't.
My latest breach clearly demonstrates the lack of security, namely (amongst many other Issues) storing passwords In plain text.
Spoiler:
Spoiler:
If In the hands of someone with malicious Intent, there's no telling the magnitude of subsequent losses both on a personal and corporate level.
It makes you think they're just waiting for something to go wrong before they do anything about it.
It's certainly the case and It's appalling to say the least. You can see In the above screenshots that I've got full raid on their systems and If I was someone who's maliciously-minded, well, I won't go Into detail of the consequences.
A lot of organizations do not even bother to check their logs etc. For testing purposes, I've planted backdoors to gain later access and upon doing so 6 months later, It (backdoor) was still there.
That's insane. Out of curiosity, what did you do next? Do you notify the company when you find things like that?
RE: getting DDoSed - mothered - 08-16-2018
(08-16-2018, 07:12 AM)Jiggly Wrote: (08-15-2018, 03:50 AM)mothered Wrote: (08-14-2018, 06:19 PM)Jiggly Wrote: It makes you think they're just waiting for something to go wrong before they do anything about it.
It's certainly the case and It's appalling to say the least. You can see In the above screenshots that I've got full raid on their systems and If I was someone who's maliciously-minded, well, I won't go Into detail of the consequences.
A lot of organizations do not even bother to check their logs etc. For testing purposes, I've planted backdoors to gain later access and upon doing so 6 months later, It (backdoor) was still there.
Out of curiosity, what did you do next? Do you notify the company when you find things like that?
I used to notify the organization outlining their flaws, and recommend corrective measures to help fend off future attacks.
However, (without going Into specifics) most took It as unethical access to critical data and some even threatened to file a lawsuit. As such, I've ceased communication. It's their loss, not mine.
RE: getting DDoSed - Jiggly - 08-16-2018
(08-16-2018, 07:38 AM)mothered Wrote: (08-16-2018, 07:12 AM)Jiggly Wrote: (08-15-2018, 03:50 AM)mothered Wrote: It's certainly the case and It's appalling to say the least. You can see In the above screenshots that I've got full raid on their systems and If I was someone who's maliciously-minded, well, I won't go Into detail of the consequences.
A lot of organizations do not even bother to check their logs etc. For testing purposes, I've planted backdoors to gain later access and upon doing so 6 months later, It (backdoor) was still there.
Out of curiosity, what did you do next? Do you notify the company when you find things like that?
I used to notify the organization outlining their flaws, and recommend corrective measures to help fend off future attacks.
However, (without going Into specifics) most took It as unethical access to critical data and some even threatened to file a lawsuit. As such, I've ceased communication. It's their loss, not mine.
Well, if they're ignorant enough to have major security flaws (or lack of), then it's not surprising that they responded that way. Those that threatened, do they still have those flaws? I'd be of half a mind to go tell their customers. On the other hand, I'm not sure it'd be worth the backlash.
RE: getting DDoSed - mothered - 08-16-2018
(08-16-2018, 01:38 PM)Jiggly Wrote: (08-16-2018, 07:38 AM)mothered Wrote: (08-16-2018, 07:12 AM)Jiggly Wrote: Out of curiosity, what did you do next? Do you notify the company when you find things like that?
I used to notify the organization outlining their flaws, and recommend corrective measures to help fend off future attacks.
However, (without going Into specifics) most took It as unethical access to critical data and some even threatened to file a lawsuit. As such, I've ceased communication. It's their loss, not mine.
Well, if they're ignorant enough to have major security flaws (or lack of), then it's not surprising that they responded that way. Those that threatened, do they still have those flaws? I'd be of half a mind to go tell their customers. On the other hand, I'm not sure it'd be worth the backlash.
Precisely. They're not appreciative of being Informed of their vulnerabilities, but rather try and punish those who bring It to their attention.
In terms of flaws, the majority remain unpatched- either due to lack of awareness and/or knowledge, or the cost factor. With lot of sites, I've checked back 6 months later and I've exploited them via the exact same gateway and attack vector.
RE: getting DDoSed - l33t - 08-16-2018
(08-14-2018, 04:43 PM)mothered Wrote: (08-14-2018, 12:58 PM)l33t Wrote: companies should take their security much more serious.
Unfortunately they don't.
My latest breach clearly demonstrates the lack of security, namely (amongst many other Issues) storing passwords In plain text.
Spoiler:
Spoiler:
If In the hands of someone with malicious Intent, there's no telling the magnitude of subsequent losses both on a personal and corporate level.
thank god this db leak didn't have passwords, only usernames and IPs
RE: getting DDoSed - mothered - 08-17-2018
(08-16-2018, 07:15 PM)l33t Wrote: (08-14-2018, 04:43 PM)mothered Wrote: (08-14-2018, 12:58 PM)l33t Wrote: companies should take their security much more serious.
Unfortunately they don't.
My latest breach clearly demonstrates the lack of security, namely (amongst many other Issues) storing passwords In plain text.
Spoiler:
Spoiler:
If In the hands of someone with malicious Intent, there's no telling the magnitude of subsequent losses both on a personal and corporate level.
thank god this db leak didn't have passwords, only usernames and IPs
Very fortunate In that sense.
I can confidently say, that the majority do store their passwords In plain text. They're obviously on the assumption that they only have access.
RE: getting DDoSed - Jiggly - 08-18-2018
(08-16-2018, 03:54 PM)mothered Wrote: (08-16-2018, 01:38 PM)Jiggly Wrote: (08-16-2018, 07:38 AM)mothered Wrote: I used to notify the organization outlining their flaws, and recommend corrective measures to help fend off future attacks.
However, (without going Into specifics) most took It as unethical access to critical data and some even threatened to file a lawsuit. As such, I've ceased communication. It's their loss, not mine.
Well, if they're ignorant enough to have major security flaws (or lack of), then it's not surprising that they responded that way. Those that threatened, do they still have those flaws? I'd be of half a mind to go tell their customers. On the other hand, I'm not sure it'd be worth the backlash.
Precisely. They're not appreciative of being Informed of their vulnerabilities, but rather try and punish those who bring It to their attention.
In terms of flaws, the majority remain unpatched- either due to lack of awareness and/or knowledge, or the cost factor. With lot of sites, I've checked back 6 months later and I've exploited them via the exact same gateway and attack vector.
That's nuts. I still think we should be taught more about these things in schools. IT classes have always been embarrassingly behind the times, but security and awareness of such, should be intertwined with curriculum. Even at college level. Surely a Business Management degree would benefit from a course that teaches people to consider how they test their security and to plan to adapt security measures over time.
RE: getting DDoSed - mothered - 08-18-2018
(08-18-2018, 01:57 PM)Jiggly Wrote: (08-16-2018, 03:54 PM)mothered Wrote: (08-16-2018, 01:38 PM)Jiggly Wrote: Well, if they're ignorant enough to have major security flaws (or lack of), then it's not surprising that they responded that way. Those that threatened, do they still have those flaws? I'd be of half a mind to go tell their customers. On the other hand, I'm not sure it'd be worth the backlash.
Precisely. They're not appreciative of being Informed of their vulnerabilities, but rather try and punish those who bring It to their attention.
In terms of flaws, the majority remain unpatched- either due to lack of awareness and/or knowledge, or the cost factor. With lot of sites, I've checked back 6 months later and I've exploited them via the exact same gateway and attack vector.
That's nuts. I still think we should be taught more about these things in schools. IT classes have always been embarrassingly behind the times, but security and awareness of such, should be intertwined with curriculum. Even at college level. Surely a Business Management degree would benefit from a course that teaches people to consider how they test their security and to plan to adapt security measures over time.
I don't have any certifications nor have I attended a single minute of schooling In the IT sector, so I wouldn't know what Is/Isn't covered.
I certainly agree that all facets of security training and awareness, Inclusive of exploitation, should be covered. To defend against attacks, you need to know how to execute them yourself. That Is, to protect against hackers, you must also be a (ex) hacker.
RE: getting DDoSed - Jiggly - 08-19-2018
(08-18-2018, 04:08 PM)mothered Wrote: (08-18-2018, 01:57 PM)Jiggly Wrote: (08-16-2018, 03:54 PM)mothered Wrote: Precisely. They're not appreciative of being Informed of their vulnerabilities, but rather try and punish those who bring It to their attention.
In terms of flaws, the majority remain unpatched- either due to lack of awareness and/or knowledge, or the cost factor. With lot of sites, I've checked back 6 months later and I've exploited them via the exact same gateway and attack vector.
That's nuts. I still think we should be taught more about these things in schools. IT classes have always been embarrassingly behind the times, but security and awareness of such, should be intertwined with curriculum. Even at college level. Surely a Business Management degree would benefit from a course that teaches people to consider how they test their security and to plan to adapt security measures over time.
I don't have any certifications nor have I attended a single minute of schooling In the IT sector, so I wouldn't know what Is/Isn't covered.
I certainly agree that all facets of security training and awareness, Inclusive of exploitation, should be covered. To defend against attacks, you need to know how to execute them yourself. That Is, to protect against hackers, you must also be a (ex) hacker.
Not even in high school or below? We had IT/ICT as a subject in school from the moment we could read/write. Interesting.
I'd certainly benefit from learning more. Comparative to members here, I know very little. However, I've found that I know a lot more than many of my peers IRL, and that concerns me.
|