>> Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International is not wanted and was put there without our permission. Please remove it immediately. We have our own security system and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business.
Oh my... HTTPS was already well established 15 years ago... are people like this in charge of nuclear facilities, too?
Also this reddit thread is interesting; looks like someone already dropped their user table. Which may have been for the best considering it appears that they stored passwords in plain text (then again I'm sure someone dumped it before dropping it).
Quick question regarding this security pop-up. I don't have much experience with the security side of things apart from HTTPS certs/etc, but isn't Dell's NZ website a bit iffy?
i.e. dell.com/nz/ -> 'My Account' looks like it's done over plain HTTP. Is my assumption correct?
I think they broke all the best-practices to make websites [1]:
> Update: Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit.
> Multiple people claimed that passwords were stored in plaintext
> the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.
> Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International, is not wanted and was put there without our permission
Just wait until he finds out that firefox is blitting pixels to the display buffer! Who invited them anyways?
It's unfortunate the IT had to find out the hard way just how broken their site security was. It's worse that this isn't the only site out there that is that broken. It's common, they just happened to publicize their lack of knowledge of security and then users went poking around. "Oh hey, SQLi works." and that's that...
Here's hoping they manage to give proper disclosure to their customers/users (hah...doubtful).
12 comments
[ 2.8 ms ] story [ 52.1 ms ] threadOh my... HTTPS was already well established 15 years ago... are people like this in charge of nuclear facilities, too?
https://www.reddit.com/r/programming/comments/60jc69/company...
i.e. dell.com/nz/ -> 'My Account' looks like it's done over plain HTTP. Is my assumption correct?
> Update: Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit.
> Multiple people claimed that passwords were stored in plaintext
> the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.
[1] https://arstechnica.com/security/2017/03/firefox-gets-compla...
Just wait until he finds out that firefox is blitting pixels to the display buffer! Who invited them anyways?
Here's hoping they manage to give proper disclosure to their customers/users (hah...doubtful).