How to earn money by hacking a “walking for money” app
deadf00d.com
deadf00d.com
EDIT: I'm waiting for WeWard answer. And will help them fix stuff presented in this article.
This is a shitty article that isn't humorous at all. It would've been funny if you had reported it, they had fixed and you'd posted the article after. This reads like an engineer trying to get an ego boost and a pat on the back.
Be angry at the company who clearly don’t have a clue how to secure anything.
They keys may already be public (technically), but he is the one publicizing it and posting it on Hacker News. OP is also clearly aware of how much harm can be done using these keys, since he asks people to not use them.
Maybe you can provide sources ?
Legally, those API calls signify something in the real world. You are representing that the action/status signified by the API call happened in the real world. _It's one thing to accidentally or mistakenly call those APIs, but to do so deliberately if such action/status is not true is fraud.
By itself, that the API calls are fraudulent wouldn't matter. But in your case, the purpose of the fraud is financial gain: each API call earns you money. In the U.S., this would be (felony) theft by fraud, among other crimes. French laws are more complicated, and as I'm not French nor do I speak French I won't attempt to go into any detail as to what the specific crimes would be, other than to say it appears that your actions, if performed, would appear to constitute several different crimes.
[Note that in the U.S., intent matters, so fake API calls for purposes of QA testing, security testing, etc., isn't fraud...but could be a crime if performed without the website owner's permission.]
I can understand why you did all this (and hopefully, you reached out to the app provider to let them know about these holes), and it seems like you know enough about what you're doing. I'm just scratching my head at the end of all of this, and the article itself feels like it lacks structure.
Also, a lot of developer (and some of my colleague too) tends to think that "hacking" doesn't exist like in movies or even doesn't exist at all (because they use ORM, don't laugh, I really got this one). By taking a real world example, I think It's a cool way to get people back in reality.
Anyway, people and my customers, hire me for my skills, and for what I did. Nobody care that you hacked an office, but if this office is the CIA, then it's cool.
For the lack of structure, it probably is, if you can give me example that I could fix, It would be very kind of you.
Thanks for your feedback.
I have to say that if this is "showing your work" then the most important thing you've shown is poor judgement in publishing their secrets in a submission to a very popular website. The fact that they have followed such shockingly bad security practices themselves is absolutely no excuse.
The work I wish we saw was the valiant effort you made to contact the company and help them see their mistakes. That is an area where we can all use more good examples, even if only to show how difficult it is to get something so obviously problematic taken seriously.
I'm certain you mean no ill will, but the lack of consideration here is concerning.
[EDIT] As per the posters comments, the keys included weren't the real ones. I still think the point stands: they are trivial to obtain when you know they are included in the package so their exclusion only means so much.
And this goes back to the whole "responsible vulnerability disclosure". The damned white hats want to demonize anybody not reaching out to some opaque company and being told it might be fixed in 90-360 days.
0Days are JUST AS responsible as other types of disclosure. You owe them nothing, and they owe you nothing. And you're publishing info to everyone. Information symmetry.
I've tried to be as careful as possible in my wording to avoid demonizing the poster. I still see absolutely nothing indicating maliciousness or ill intent and I would just as strongly disagree with anyone trying to do that. My apologies if I have come across as being hateful in any way.
I prefer to champion a web that goes back to a "hacker" culture I learned from in my youth that predates Internet culture: we believe DO owe each other something, somewhere in the positive gradient: basic decency, an assumption that we're all worthy of respect (unless proven otherwise), and that you never try to "score points" at the expense of someone else.
But that is just what I believe and what my preferences are. Certainly "do no harm" is the rock bottom line.
It’s a for-profit company without a bug bounty program, in no way whatsoever should they expect someone to work for free to fix issues they created.
The keys are public, they made them public. Do you expect that there are not automated systems trawling apps from the g-play store and doing what he’s doing?
I've made money from selling exploits to companies. Ive also been cheated out and had bugs downrated so they could pay less. Ive also seen colleagues who reported bugs they inadvertently found get hit with a felony (found not guilty).
Frankly, this company should thank its lucky stars that the disclosure was an 0Day and not "sell this on dark web and have it exploited for 3mo from 1500 accounts and drain the company's coffers".
This person owes the company *nothing*. They found an exploit due to bad API implementation, and wrote about it publicly. If they were in the USA, that's completely in 1fa territory.
That they are a for-profit company is completely irrelevant, as is whether or not they have a bug bounty program. Legal abstractions aside, it's still just people on both sides.
The expectation isn't that the poster work for free. The poster could have easily obscured identifying details and the content of his article would not be diminished. It is my opinion that if he wanted to "show his work", work done of his own initiative, then I think it would be more interesting and useful to include something about attempting to assist in remediation. I think, as mentioned by others, it would make a far stronger argument to click that "hire me!" button than anything in his technical analysis.
Of course automated systems are on the hunt for this stuff. Same with public code repositories, Docker images, and if you operate a subscription-based service with any popularity then your web interfaces for sign-up, login, etc will be subject to well-orchestrated brute force attacks. That someone did a poor job is all the more reason to avoid potentially contributing to their exploitation.
A response within the positive spectrum is absolutely above and beyond. Of all the feedback this community can provide, I think this is the most useful and I'm grateful that the poster has been responsive to it.
If I accidentally leave my door unlocked, and someone comes in and steals my TV, I'd be upset. I made an honest mistake, and had to pay for it when I wasn't expecting to.
If ..., and someone makes a blog post to tell the world that my door is unlocked, my dwelling may be in a permanent state of disrepair by the time I notice. I'd be incredibly unhappy.
Mischief doesn't need to cause misery.
After or before posting it to the internet?
I'm not that crazy.
But it's going to be fixed soon.
I look forward to the update and will be very curious to see how that goes. Best of luck!
[EDIT] Also I think it worth adding one more thing. I think the poster has demonstrated an openness to feedback that is wonderful. Coming back to the keyboard to read "let me give that a try; I'll update things" is really cool.
This, however, is much more inline with Defcon, CCC, and hacking culture. And this sort of writeup about (React, API endpoint insecurity, cheating apps) would be a straight-up accepted submission to the respective cons.
That's cool ! Might try to do a submission.
A lot of us think it is unethical and would take it as a huge red flag.
Explaining that it's not possible to actually 'cash out' would be great, and that would probably help deter script kiddies from trying to defraud the app. There are real people on the other side!
Tokens should be marked as redacted imo, and code sections could probably do to be snipped.
If you wanted a tl;dr, I guess it would be that it looks like ctrl-c and ctrl-v were your primary editing tools. They're great, and I use them all the time, but that w(t) thing took me 10 seconds of scrolling to get through when skimming, which was 10 seconds with none of your own words on screen. Less can often be more! Especially if I'm looking at disassembled gibberish.
I understood my mistake. I think the article humor has not been received as intended, that's why I added a disclaimer in the top level of the article to contextualize it a little bit more. Hope I've not done any harm to their infrastructure.
I'll definitely take care to this in my next articles.
I also trimmed a bit the long code of the w() function, making the article easier to read.
I imagine they probably have a pretty liberal regex working on the source code so that it can also rewrite URLs in JavaScript/CSS/etc.
That is, what is a non-hackable way to measure the physical environment of a consumer smartphone?
Can the critical data be stored in a DRM module protected by OEM TPM module?
At this point you need to be more precise about what you exactly intend to measure. Even if you build something perfectly unbreakable, nothing prevents an attacker from simulating the environment around it, whether movement (by building a robot to shake the device), visual (monitor in front of camera sensor), radio (GPS constellation simulators, etc).
I've seen physical security companies enforce patrols by having their guards tap their phone on a physical device in the secured property (which does a challenge-response) to prove that they've indeed been there at a given time, but even that can be defeated by attaching a device with a microcontroller and some out-of-band channel (cellular, etc) to relay the signals over the internet and allow them to "check-in" at every location without physically being there. The system works because in most cases the cost & skill required for such an attack isn't worth it (if you have those skills you typically already have access to better-paying jobs).
Health tracker apps typically don't have this problem because the incentives are aligned - the user has no incentive to lie to their health tracking app so no security is needed. It's a problem for this particular app because the true purpose of the app isn't to encourage healthy living, it's "growth and engagement" where advertisers can pay to get people to go to certain places and most likely buy their location data as well - in this case the relationship is adversarial and there's no bulletproof solution, it will always be a game of cat & mouse. The proper solution is to just find a better business model where incentives are aligned.
- wanna be GPS spoofers would need to emulate the whole OS/sensors to send spoofed data to Apple/Google
- the platform/OS developers would have more ressources and incentives to detect spoofed data
The cat&mouse game is harder when played against Apple/Google than against a single small developer.
A simple UI on my phone that tells me how many steps I have and a progress bar was enough to make me religious about getting my 10k steps each day, and it's been nothing but a good thing in my life. I even got my girlfriend addicted.
We'll take a walk to the grocery store together to buy a pineapple, just for the steps.
Conning them into believing the app is after their well-being while stalking them in the background and selling their personal data is scummy.
Our incentives simply align. I want to exercise more, they want to sell me something that I want to use.
Everyone is free to do push-ups and run at their own leisure without giving money to anyone else. Unfortunately most of us have trouble with that. It seems too much to call something a "con" if it can compel someone to improve their health just because it's transactional.
If someone can figure out how to make money from compelling people to exercise, I think it's a net positive. At least it's certainly better than all the money being made by compelling people to indulge in habits that are bad for them, which seems like just about everything.
If not on the user, then on the advertisers who fund it?
This makes it sound a lot like the only reason you didn't exploit this for profit is because you tried and failed.
But reality is different, I didn't earned money on this.
Strapi:
- [2022-02-28T14:27:04.385Z] error KnexTimeoutError: Knex: Timeout acquiring a connection. The pool is probably full. Are you missing a .transacting(trx) call?
- That's the best I can do.
Step 1. Get a dog.
Step 2. Walk your dog.
That's it.
- walk
And it has been amazing.