Rave Panic Button: Vulnerabilities in a Nationwide Emergency Alert System
randywestergren.com
randywestergren.com
It seems like maybe the vendor's communication trailed off toward the end leaving OP with bad feelings which show up in the write-up.
Generally I like to see security research and vulnerabilities reported as a way to document the process used and experience gained, but not to skewer the company except with respect to their responsiveness of a patch.
Of course, everyone here is free to skewer the app as much as they like, I just don't like reading it in the actual write-up.
It's a common rookie mistake, but perhaps the takeaway is that this kind of area isn't something that rookies should be tackling.
To your point and going back to what zaroth was getting at I'm wondering why I didn't see the typical references to a bug bounty, permission or payout that are typical in write-ups of this nature. This really does concern me.
Poking around server-side with an account you clearly weren't meant to interact with could have serious repercussions up to and including service outages. You'd be amazed at the sorts of mistakes I've seen in code that could lead to unintentionally taking down a service. A number of years ago I discovered a flaw with a major identity management provider. If the POST request parameters were placed out of expected order it crashed the application into a zombied state where it could no longer accept requests, causing a denial of service situation until it was restarted. Worse, the event wasn't logged. You don't typically log POSTs in the HTTPD and they didn't have application layer logging at that level either so without monitoring HTTPS traffic there was no way to troubleshoot why the application was hanging.
I've seen lots of vulnerabilities like this including in life critical systems. Because of the unexpected as well as US law, I always check to see if there's a bug bounty first or I reach out to the vendor and get written permission. I really am paranoid about what's in criminal code as well as accidentally causing an outage.
There are certainly a number of ethics and possibly legal issue which appear to be at play here beyond just embarrassing the company.
Hopefully we'll here more about the bug bounty program.
This article does lead me to wonder if Rave has missed an opportunity - installation of an app on Crestron / Andoird room automation systems that accomplish similar things. That would take the mobile component out but still have a benefit from a facilities / awareness perspective.
I'm not sure what other customers were charged for the app, but if they were all $70K (as my County was), then that's a hefty rake.
I don't know how long it took, but depending on the size of the team etc, it sounds pretty cheap TBH - certainly not enough $ there to make something secure and supported.
Not sure what each customer was charged, but it sounds like the app/system was resold to individual customers at a pretty hefty price.
That doesn't seem like enough funding for a secure app with proper testing, and a free app is a terrible idea if they want software that is maintained and supported.
http://www.cultofmac.com/132300/occupy-app-store-u-s-governm...
The vulns found here are serious, but any moderately detailed app security review should/would have found them.
Until customers start requiring security reviews for the software their buying we'll see a load more insecure apps being sold.
I ask because it looks like you were performing testing which touched their infrastructure, not just your phone and the US Computer Fraud and Abuse act gets pretty scary (Felony scary) when it comes to such things:
https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
I do a ton of mobile application reviews and find stuff like this quite often but back away at the point I start touching their infrastructure rather than just my phone.
Am I wrong in assuming that being able to proxy the app's HTTPS traffic is evidence of another security problem, specifically that the app is not validating the server's SSL certificate?
It does mean they are not pinning their cert, but most apps do not.
Even if it was pinned, you just have to disassemble and modify the pin and you can still MITM.
Courtesy /u/Vusys on Reddit from /r/netsec