![]() |
|
|
|
Registered
|
Discovered a vulnerability in another website. Make it public?
I am in midst of a minor moral quandry. I am sure that some of the folks here can offer their opinions.
A few months back, I discovered a vulnerability with a points-based loyalty system that affects 613 different websites/radio stations that I am aware of. There may be more. I have attempted to do the right thing by notifying and communicating with the owner of the system. But, I guess it is not important to them to run a loyalty system that cannot be compromised. Now, it is quite possible that you may participate in some of these programs yourself. Some stations refer to their programs with monikers such as "Work Force", "VIP Program", "Loyal Listeners", etc. If so, your ability to win prizes such as free concert tickets may be severly impacted if I am not the only one aware of the flaws. I know it is not a big thing. But, the lack of concern displayed by the Loyalty Company really irks me. My email communictions regarding this are spelled out below. Quote:
Quote:
Quote:
Quote:
What should I do? 1. Let it go. It is not important enough to worry about. 2. Notify the station managers of all of the subscribing stations. 3. Make the flaw and the steps to compromise it public. 4. PM the compromise to me. I like free tickets. |
||||
![]() |
|
The Unsettler
|
Hmmm,
I'd read the privacy and EULA for the Loyalty Program. You may have exposed yourself to a legal issue. Very common verbiage in them regarding using tech/packet sniffers/scripts to manipulate the system. I know you are trying to do the right thing but as we've all found out at various times in our lives, no good deed goes unpunished. Scott
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
RETIRED
|
No good deed goes unpunished.....
__________________
1983/3.6, backdate to long hood 2012 ML350 3.0 Turbo Diesel |
||
![]() |
|
Registered
|
I've carefully read the ToS for the loyalty program. I have not violated any of the terms and conditions. Since I have not attempted to redeem or otherwise use my accumulated points, the best they can do is to terminate my account.
The latest court cases that have dealt with accessing systems through URL-manipulation have all been in favor of the manipulator. The prevailing opinion of the courts has been that the burden falls on the site owner to make sure that their sites are secure and content that should not be available is really secured and NOT AVAILABLE. |
||
![]() |
|
Band.
|
Notify the folks you can, maybe find "Loyalty Company Douchebag"'s superior, and then you have to just let it go.
__________________
1983 SC Coupe 1963 BMW R60/2 1972 Triumph Tiger 1995 Triumph Daytona SuperIII |
||
![]() |
|
Registered
Join Date: Jan 2002
Location: I'm out there.
Posts: 13,084
|
Dear neighbor,
I noticed you installed a very primitive security system in your home, so I bypassed it and stole your TV. Regards, Moses ![]() ![]() ![]()
__________________
My work here is nearly finished.
|
||
![]() |
|
![]() |
Bill is Dead.
Join Date: Jul 2005
Location: Alaska.
Posts: 9,633
|
You should report the flaw to Wikileaks.
__________________
-.-. .- ... .... ..-. .-.. -.-- . .-. The souls of the righteous are in the hand of God, and no torment will ever touch them. |
||
![]() |
|
Too big to fail
|
While you haven't violated the TOS, you've probably violated the DMCA.
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs |
||
![]() |
|
Formerly reformed
Join Date: Jan 2008
Location: Rutherfordton NC
Posts: 2,424
|
I'm guessing that if it were made public they'd address the issue rather quickly.
__________________
1968 911P (Paperweight) |
||
![]() |
|
i'm just a cook
Join Date: Apr 2006
Location: downtown vernon,central new york
Posts: 4,868
|
huh?
|
||
![]() |
|