12 comments

[ 2.8 ms ] story [ 52.1 ms ] thread
Oh man, that site is a blast from the past in terms of web development.
Oh no.. they've locked it to authorised users only. Anyone get a screengrab?
>> Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International is not wanted and was put there without our permission. Please remove it immediately. We have our own security system and it has never been breached in more than 15 years. Your notice is causing concern by our subscribers and is detrimental to our business.

Oh my... HTTPS was already well established 15 years ago... are people like this in charge of nuclear facilities, too?

Quick question regarding this security pop-up. I don't have much experience with the security side of things apart from HTTPS certs/etc, but isn't Dell's NZ website a bit iffy?

i.e. dell.com/nz/ -> 'My Account' looks like it's done over plain HTTP. Is my assumption correct?

I think they broke all the best-practices to make websites [1]:

> Update: Around the same time this post was going live, participants of this Reddit thread claimed to hack the site using what's known as a SQL injection exploit.

> Multiple people claimed that passwords were stored in plaintext

> the site's subscription page transmits credit card information over plain-vanilla HTTP pages as well.

[1] https://arstechnica.com/security/2017/03/firefox-gets-compla...

Users or all tables were dropped, site is entirely a 500 now. I seriously doubt they have any backups either...
> Your notice of insecure password and/or log-in automatically appearing on the log-in for my website, Oil and Gas International, is not wanted and was put there without our permission

Just wait until he finds out that firefox is blitting pixels to the display buffer! Who invited them anyways?

It's unfortunate the IT had to find out the hard way just how broken their site security was. It's worse that this isn't the only site out there that is that broken. It's common, they just happened to publicize their lack of knowledge of security and then users went poking around. "Oh hey, SQLi works." and that's that...

Here's hoping they manage to give proper disclosure to their customers/users (hah...doubtful).