Pwning eBay – How I Dumped eBay Japan's Website Source Code
slashcrypto.org
slashcrypto.org
Anyone want to hazard a guess at whether anyone else between 2015 and 2018 also thought to run the same experiment with the same parameters and thus also downloaded ebay.co.jp's production database passwords and Wordpress admin credentials?
Of course, that would only be a concern if the master hacker in question decided eBay Japan's backend data was more valuable than having their name on a website that says "good job thanks".
But maybe I'm wrong and in the real world there is not much penalty for exposing data of thousands or millions of users..
Wikipedia excerpt: "... for all individuals within the European Union (EU) and the European Economic Area (EEA)."
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Perhaps by then companies around the world will be forced into paying more attention to these matters, and a system of reward for white hats may become the norm.
After some time smaller companies will be forced to work on market siloses, to not jave to worry about such lawsuits.
The quote that you provide here that supposedly shows that the GDPR is irrelevant to Ebay Japan does not in fact contradict that claim.
Do you have an excerpt or other source that does?
This is fairly ridiculous, if you're have no European presence, you're free to ignore the GDPR. The EU has no legal jurisdiction over you, the only recourse would be for the EU to block your site and that's just not going to happen - no one wants to see a Great Firewall of the EU, can you imagine the backlash?
Or your trademarks become unenforceable in EU?
Imagine the mess if I start usatoday.eu, but « focussed only on the EU market ».
Since .com doesn’t operate in the EU market because of GDPR, am I really infringing in their mark?
That being said, it sure will be fun when all the British people/corporations won't be able to renew their .eu domains no more!
Which is bizarre reasoning: geo-IP databases are not foolproof, and thus you will get legitimate EU traffic from EU ISPs regardless. Further, by this reasoning, what's to say an EU customer using a VPN to exit in the US is somehow excluded from GDPR?
At some point the responsibility has to fall on the user instead of the business, and the I think actively skirting the rules is sufficient and a nice, clear line, to fault the user.
From there, it is not surprising that they would not bother to compensate white hat hackers, because we have established that the organization is fundamentally broken.
Who? They?
Some were actually pretty high profile sites (probably top 100 at the time) but I was worried they'd come after me if I reported the vulnerabilities (that was the standard response before bounty programs and such) so I just dumped it and moved on.
I'm sure I'm not the only one that just did it for sport.
The main problem is that new developers come and go, so does the exposed gits.
Good find though, and embarrassing failure. Especially since most eBay properties have penetration testing and automated scanners being run on them
"If you prepend www. or https://www. it works."
Pizzahut recently fixed theirs after years of bitching about it.
You got their source code, passwords. That deserves at least $10K.
If you don't plan to do any harm to the company with what you know is there anything wrong with asking for a reward before you disclose the bug?
They show up and take all your electronics to investigate an extortion claim
How far down the rabbit hole do you want to go? You might win in the end. You might get jail time. You might have a pretty rough 6 months and get nothing.
Being internet tough and going to court tend to be very different things.
The larger point, and the nugget you probably should come away with, is that there's a prohibitively high cost for doing what's being discussed. There most definitely is plenty to worry about here.
It does matter how easy you make it, but it is nonetheless illegal.
Because someone kept the door open, doesn't allow you or give you the right to go into it. Never has been never will be.
First of, there is also in legal a huge difference between publishing your secret in an ad and putting some .git folder in /.
Second it would probably still be illegal to reproduce coca-cola original receipe. There is probably some (c) or similiar thing protecting it.
If I steal a companies IP and then try to basically sell it back to them is it a crime? Of course it is in most sane countries.
The answer is no.
It's not theft either; and we could have immediately destroyed all our data except some excerpt as proof the hack is available so we would not be handling any infringing data (despite the initial act potentially being infringing, depending on jurisdiction).
This is akin to "I went past your property and saw the door open, stepped inside and took a picture as proof; do you want to see the picture?".
If I find a security issue with someones site why do I have any obligation to tell them?
Punishing the person for telling you you have a problem seems a bit silly, even if the photo they took included copyrighted material (maybe an architecture model on the counter).
Well that just sucks. It was clearly in scope and should have been rewarded. Clear example of information leakage.
Ebay being a private company with boatloads of money is definitely not a part of that.
However, storing database passwords or password hashes in git (at least inside the same repo) is a major design flaw.
There will be a massive amount of customization, so revealing source code probably is a security risk. I’m willing to bet a competent code auditor could find secondary vulns in that code.
Other people finding flaws with eBay might be more tempted now to sell it to the highest bidder rather than expose it to them.
(Assuming their morals are already a bit questionable to begin with)
Can't imagine ebay having any problem moving to new URLs nor getting any significant boost in referrals from such actions. What other backwards compatibility is at issue, scraping apps?
I am surprised EbayISAPI.dll was C++ - I always assumed it was a mess of .NET. It makes sense considering how old Ebay is though.
I see over and over again the 'no database would scale big enough, so we had to build our own'. If only opensource databases got spanner-style auto-sharding and auto-loadbalancing sooner, millions of engineer-hours could have been better spent!
Fuck this.
Why didn't eBay alert the FBI or something?
I got 1.2 GB of data to go through. The data-set
contained:
Wordpress configuration files (yes, they use Wordpress)
including hashed user credentials for the backend login
Database passwords for production databases
Log files
A lot of PHP source code
(who could have guessed?!)
much more …You can use those to obtain user data.
> Log files
Easily could contain user data.
Also the git repo was publicly available, he didn't "hack" anything.