webdev companies don't care!

...let us know what you think, free speech!
Post Reply
User avatar
l0ngb1t
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 598
Joined: 15 Apr 2009, 16:00
15
Contact:

webdev companies don't care!

Post by l0ngb1t »

So i was playing around last night and i came across a website which sql injectable... it had minor protection which can be easily bypassed... so i went to the website of that company that created this website and checked there portfolio, i tested some of there clients websites (this company has branches in canada and Emirate... they also provide anti-hacking systems!!!) some of their clients are also vulnerable! after several jack Daniels glasses.... the gentelman in me decided to do some good, so i e-mailed the chief developer telling him about the issue, and today, while trying to recover from the hangover i checked my e-mail (a fake one ofcourse) and i got this reply from the dude (copy past as is)
I did not understand what you mean
And what is the relation between my emails and my clients accounts ?
is he for real 8O
ain't gonna contact them... let them drawn in their own shit... i didn't ask him for anything i just told him some of your clients have security issues bla bla bla...
There is an UNEQUAL amount of good and bad in most things, the trick is to work out the ratio and act accordingly. "The Jester"

reparto
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 288
Joined: 27 May 2013, 11:30
10

Re: webdev companies don't care!

Post by reparto »

I've seen this as well, people complain about hackers and stuff but they don't realise that the companies who are attacked probably knew about the vulnerability but chose not to act on it.
Selling invisible pets:
Dogs - 0.5 Bitcoins
Cats - 0.7 Bitcoins
Unicorns - 10 Bitcoins
Chimpanzee - 2 Bitcoins

PM me if you are interested, will ship via priority airmail, will accept escrow services

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Re: webdev companies don't care!

Post by bad_brain »

I don't bother with informing companies about flaws anymore (well, not that I ever really did :lol: )...the only exceptions I would make are in context with FOSS, and there developers ask for that anyway because it's a main part of the whole idea.

and hey, what sense does it make? in the best case you will get a "thanks."...but often they either don't care at all and ignore you or even act like you are the one to blame for their sloppy security....so yes, better cut down the Jack Daniels, it obviously makes you too kind. :lol:

P.S. here's a nice one I discovered recently when trying to set up a customer site I created on their lunarpages.com "web hosting" package: they still use PHP 4.4.9, release date Aug 2008.
Image

Post Reply