Google Account Recovery Vulnerability
orenh.com
orenh.com
I emailed the company (a US mobile phone company I haven't heard of; I'm based in the UK) and their response was along the lines of "call us (at your expense) and tell us your phone number and we'll sort it out". In the end, out of sheer frustration, I reset the account's email address to that of the company's WHOIS technical contact; that was the safest way I could think of getting my email address off the account.
Google, of course, handle this kind of thing properly. But for every google, there are thousands of companies who will give your personal data away without a care in the world.
Did I get any sort of response to the disclosure email? Nope. That said, if not getting a reply was the only issue, I really wouldn't care.
What did I get? Added to a spam newsletter from gogvo/Joel Therien:
"true 100% commissions for life!!"
"How To Take ACTION In Your Business LIVE tomorrow night!"
Thanks, gogvo, for that.
On the other hand, for every gogvo, I've had a handful of companies sincerely thank me for my reports. It varies a lot.
Web developers: Please make sure to include a "Didn't sign up for this? Click here to disable/unsubscribe" option in sign up emails, rather than assuming that the person receiving the email is the correct person who knows the password.
More of a problem with common big-name services like Facebook and Apple ID and whatnot.
2013
197 Reward Recipients [1]
168 Honorable Mention [2]
2012
191 Reward Recipients [1]
147 Honorable Mention [2]
2011
121 Reward Recipients [1]
68 Honorable Mention [2]
[0] http://www.google.com/about/appsecurity/hall-of-fame/[1] http://www.google.com/about/appsecurity/hall-of-fame/reward/
[2] http://www.google.com/about/appsecurity/hall-of-fame/distinc...
Now the fix comes out before anyone gets harmed by it, AND the person who discovered it gets PAID for it. Whoever thought up the rewards program is keeping people safe and still giving hackers a good reason to keep hacking. The future is amazing.
On a related note, I love that bug bounty programs are becoming more popular. Still too rare, but great. That said, the majority of companies out there still make reporting vulnerabilities tough. I've reported a number of vulnerabilities, and all but a few companies had no security@ email address nor a security contact under Contact Us. The tech/admin contact of the DNS record often does the trick, but doesn't always work.
Please, companies, make it easier for us to report security vulnerabilities!
Wow I couldn't imagine how long a 'slower' response cloud be.
Not every company values this sort of feedback from their users. Some go out of their way to prosecute those that break their services this way.
> If you rely on CAPTCHA's as CSRF protection, make it consistent.
This was discussed at today AppSecUSA [1] that it is rarely ever seen anyone use CAPTCHA as CSRF protection.
[1]: http://appsecusa2013.sched.org/event/10d6389173e14b246720d83...
very bend over to customer who loses pass
so fuck user who retains pass and cares about security
much credible company
cloud wow
2013 very XSS