HN user

atom_enger

758 karma
Posts9
Comments106
View on HN

I remember reading this when I was the sole Infrastructure Engineer for Reverb.com. I knew we were being attacked and I knew we had issues but I didn't have any idea where to start. This article sparked my interested in Cyber Security and helped me find a bug in the website that allowed me to set the CEO's credit card as a primary card on my account in production. That was an amazing day.

All I had to do was modify a post parameter in flight and the backend would accept it. Turns out this is what is known as an "unscoped find". More info here: https://brakemanscanner.org/docs/warning_types/unscoped_find...

Thanks to the author of the article for inspiring me to dig in the rails codebase and find vulnerable patterns that I could exploit. Thankfully I was able to pivot into a cyber security focused career and I credit this article for starting me down that path.

Rails has a few things going for it that other languages and frameworks don't but it still lets you shoot yourself in the foot if you're not careful. I ended up writing a blog article about preventing XSS in rails as a direct inspiration from the OPs article: https://product.reverb.com/stay-safe-while-using-html-safe-i...

Just because this article is old doesn't mean it's not useful. Thanks for posting!

Not many people would believe that you can be a better parent after consuming cannabis. I'm a much better parent after consuming cannabis. I listen more, play harder and can let go of the parental thoughts that silently occupy my brain when I'm sober and playing with my kids. Cannabis really helps me let go of parental world and enter theirs for just a little while..

I agree. I felt that way when my friends started doing dabs and telling me how amazing it was. It kind of scared me to be honest. I've switched from smoking to making my own cannabis tinctures and have been using that for years. I've found that a minimal dose of cannabis in the morning really helps me dial the knob on my radio just right. They're really easy to make and so much more efficient than smoking.

In a corporate setting: At Etsy we use OSQuery on all of our corp machines(macOS) to help with malware/virus detection. We use community rules: https://github.com/facebook/osquery/blob/master/packs/osx-at...

In addition to community rules we also curate a bunch of rules in house from malware we've discovered across our fleet. We then aggregate this info into ELK and alert on it.

At Home: OSQuery as well + tiny elk stack + Elastalert. Overkill for a typical home setup but I like it.

Matt - if you see this I'm terribly sorry for your loss. I just married my best friend in December and I'd be so lost without her. I can't imagine how you're feeling. I don't know what else to say besides that I'm sending you love and support from across the net. Stay strong my friend, your blog has powered many of my adventures into SEO and beyond.

So how do we balance personal liberty with respect for others? I don't know the solution but welcome the discourse. Part of the problem I think is that the people who engage in these behaviors don't care very much for themselves, let alone others. I've often wondered if people who partake in cigarette smoking have a death wish of sorts, just unable to take the fast route.

This is the wrong thing to focus on. The situation we're in isn't a result of where this person was educated. The fact that they had a lack of professional experience required to demand a standard of security that would prevent this type of problem is the only thing I think worth discussing here.

I dropped out of school as soon as I realized I could make 50k/year doing IT work vs paying 50k a year to a school whose curriculum was from the stone age. I fully endorse education of all forms but our current model for educating the next generation of workforce is broken but I digress.

The super fucked up part is that it automatically signs you up for their "Credit protection" if you use their site to see if you were impacted. Doesn't ask if you'd like to, just says "Thanks for signing up, your year starts now!"

I think it's most likely a bubble. Enjoy it while it lasts and build a sturdy parachute for when(and likely if) it doesn't. Maybe one day there will be too many of us and our price will be driven downwards.

"I thought everyone knew this" is a dangerous assumption. Not only are you assuming equal knowledge access but you're also assuming equal legal access. I'd argue the legal system is not equally accessible and knowledge of the system is even less accessible. I think the only safe assumption here is that Kate did _not_ know the proper way to respond to this and asked for help from the community. I would've done the same.

This isn't that uncommon, unfortunately. You'd be surprised what you can find out there that's waiting to be taken by the wrong person if you use a tool like masscan to scan large portions of the internet quickly. Search default ports for elasticsearch, mongo.. etc. It's scary how easy it is to find these and set these databases up with insecure defaults. Question is, how do you go about safely reporting this especially when you find this kind of data? I blame operator ignorance and service provider insecure defaults(I'm looking at you AWS Elasticsearch).

WikipediaP2P 10 years ago

I encourage a repeating donation. If you work a tech job you can very likely afford 5/month. The site has changed my life for the better and I constantly find myself on there satisfying whatever is piquing my curiosity at the moment. To be clear, I'm not affiliated in any way just a huge supporter.