Stealing checks worth millions and pwning a bank
jhaddix.com
jhaddix.com
Maybe that's true, and certainly the vulnerabilities described in more detail are already quite a big deal, but the author probably should have omitted the above quote from their post as it leaves the reader with some suspicion that perhaps this is a bit of a "Fish Story" (fisherman exaggerating the size of the fish they caught) https://www.urbandictionary.com/define.php?term=Fish%20Story
Its like hiring a guy with a sledgehammer to test the stability of your bridge. You should hire a structural engineer instead, before building it. If the guy with the sledgehammer is successful, you should never have built the bridge in the first place.
People make mistakes. Systems fail. Pen tests exist to find out if your people are making mistakes, and if your system is failing.
Even the avionics and carmakers get software right, why cant we?
Do they deploy multiple times daily? Deal with vague sometimes contradictory client requirements? Do their tools and platforms change daily?
Instead we have project who care only about shipping their latest favorite features yesterday to meet the over-promised new capabilities to the new client/market, and figure any problems will get caught with the update cycle, and the coders scrambling to ship the first thing that'll compile and pass the test screens, with QA being a minimally funded function as yet another cost center to be minimized... Oh, and all liability for failure is disclaimed or fobbed off on the consumer for their failure to maintain proper opsec. Oh, and in many cases, the blame is put squarely on anyone who finds such a fault instead of on the builder (e.g., when the governor recently tried to jail a journalist who found an egregious flaw in a state website).
So, yeah, it SHOULD never be the case if there were proper development and proper QA. But it hasn't happened in a half century of large commercial software. So, we do really need pentesters. They're just delayed QA after all.
QA doesn't find XSS, SQL injection, CSRF, IDOR
There's still a privacy issue, and if he ran OCR on them, he'd have a bunch of account numbers, which would also be bad.
How would that not be super abused in the wild ?
Of course, any of those options are going to end up with transactions reversed eventually, so you've got to have a quick exit planned.
Sure, I'll take the karma hit for this comment.
But only in an off the cuff remark as a passive observer, amused by the circumstance and grandstanding necessary to fail so hard.
I guess Troy Hunt didn't get the memo either.