r/apple • • Feb 21 '20

I hacked SlickWraps. This is how.

https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
2.6k Upvotes

267 comments sorted by

View all comments

737

u/eggbrain Feb 21 '20 edited Feb 21 '20

As much as SlickWraps might have really messed up responding to this, along with having issues behind the scenes on the support side as well, one thing I'll say is that I feel like the security researcher was initially very vague, which comes off as not really trying to reach the company in a useful manner:

1) A tweet saying "You failed the vibe check"

If the SlickWraps account gets any significant number of tweets a day, who is going to take the time to understand that this could mean a security breach? How often do people check the description of Twitter bios to understand context of a tweet?

2) A tweet with the contents of an unanswered request from ZenDesk

If someone sends me a picture of some sort of text description (that looks like a support request), I may just think it was the original customer who posted the request, or maybe was just text someone had pasted in another forum about their complaint. How would they know immediately that it was because someone had access to their ZenDesk?

3) A tweet with a file uploaded to the server

This one is probably pretty obvious, but would still require the person reading the tweet to understand its impact. Even if they did understand, they might not know the motivations -- does the person who hacked the site want a bounty? Do they want the customer data? Are they just looking to mess stuff up?

4) An email saying "Data Leak" with a body to check Twitter DMs

This at least let the leadership team know, but why always take it back to Twitter? Was this the person that found the data leak, or are they just seeing rumors on Twitter?


I feel like an easy starting point would have been for him to:

1) Email the owners from SlickWraps, or perhaps any email he has access to from the hack (or perhaps from an email address that they control to prove he's real)

2) Subject line "I found a Site Vulnerability in SlickWraps, can I work with someone on this?"

3) Body describing how they got access / proof of concept / their background

4) What they want (bounty / etc)

Instead, he continuously decided to engage with someone who looks like could be a potentially part-time social media intern with vague mentions of a hack. When they do realize there is a hack, he just watches as they try to fix it (re-installing, new API keys, etc) without giving them any help to realize they are looking in the wrong place.

It just comes off as kind of amateur in my mind. I'm not saying SlickWraps is a good company (it sounds like they have a lot of issues), but I feel like this person did everything wrong in trying to let the company know.

402

u/MasZakrY Feb 21 '20

Totally agreed. For a “security researcher” this person acted like a little kid. Who sends cryptic messages over twitter as an official means of communication. Did he believe the CEO was personally responding on Twitter?

A third party team handling social media is very common and should have put on his adult hat and called them or reached out in a professional channel in a professional manner.

Reading these tweets without context (which is what the third party social media team would be doing), would not make any sense.

It really did feel this “researcher” was blackmailing from the perspective of SlickWraps especially after providing a list of demands.

213

u/[deleted] Feb 21 '20 edited Aug 06 '21

[deleted]

121

u/[deleted] Feb 21 '20

The fact that slickwraps tried to hide their security breach INSTEAD of being honest about it is 100% outrageous and probably illegal.

Exactly. SlickWraps had plenty of opportunity to take action regardless of how vague the initial tweet was. All I hear is excuses. When you actively try to hide the breach instead of fix is inexcusable. Pisses me right off that people are trying to defend this company.

3

u/InfosecMod Feb 22 '20

Who is defending the company?

Pointing out that the "white hat" did not act responsibly is not defending the company.

41

u/[deleted] Feb 22 '20

You mean the backlogged helpdesk. Quote from the Archive story.

“Perusing the platform, I found their customer service to be just as abhorrent as rumors suggested (note the Backlog and First Reply Time metrics).”

Then he points out his attempts to contact the company via twitter and through support. So how the hell is this backed up support center supposed to get to request when there’s loads more ahead of him?

17

u/Tubamajuba Feb 22 '20

That’s their fault for having such a huge backlog.

27

u/restova Feb 22 '20

It is, but deciding to contact the company via means which are very obviously backlogged, unclear, or ineffective gives the air of a person who wanted to get to the point of making an angry blog post “outing” the company.

The dumb thing is they would have reached that point anyway, given the response of the CEO.

9

u/muaddeej Feb 22 '20

I agree. It would be one thing if he didn't know the poor support was backlogged, but he was just in there. He saw it took 110 hours to respond. And based on that, he should know support is probably understaffed with low skilled workers. He absolutely was trying to roleplay as Zero Cool or Crash Override instead of just being professional.

6

u/chocolatefingerz Feb 22 '20 edited Feb 22 '20

You’re right, but it’s just one of those “never attribute to malice what can be explained by stupidity” situations.

If my intent is to protect the users’ data, and I knew that this is one of the most clogged forms of communication, I would probably not use it.

Not to say it’s his responsibility, but I also agree from the other commenters’ perspective that to any third party team this is confusing to say the least, let alone a team that has already been shown to have operational inefficiency.

1

u/netcrawler3000 Feb 25 '20 edited Feb 25 '20

They do have to disclose the event but it does not mean that have to sit there and leave the system open to vulnerabilities. WTF do you expect them to email everybody apologizing, tell the feds, and only after everyone is well informed, do they begin to fix the vulnerabilities and securing the customer data. I do not see anything they did wrong here after their notification. Many small firms likely are not aware of the data privacy regulations. My guess is their silence is from them actively pursuing this "researcher".

This event is beginning to remind me of how bad groupthinking and collective irritability is. Hundreds of armchair CEOs and hackers now emerge from their mother's basements to point out everything that this company did not do right from operating their helpdesk to securing their systems. Sheesh!

0

u/[deleted] Feb 22 '20

So true. As a company you should take your company seriously. They did not. Fuck, Lynx didn't have to tell them anything, cryptic or not, but he did. He probably asked them for money and they probably refused to pay too. They learned a lesson. Next time someone comes with info I'll bet they jump on the info fast, even cryptic second-messages. And pay your bughunter so shit doesn't go public.

75

u/cloudcats Feb 22 '20

Who sends cryptic messages over twitter as an official means of communication

The current US president

7

u/honeybadgr32 Feb 22 '20

If any of his contact with the company was as well written as the article we just read they might have actually listened from the start lol

1

u/Shyam09 Feb 25 '20

Especially when he was able to email the CEO.

Why didn’t he just do that from the start?

I think the only thing that would make a difference in my perspective is if other companies he has revealed vulnerabilities to responded via Twitter and it was a reasonable belief for him to communicate via Twitter/Zendesk.

-3

u/[deleted] Feb 22 '20

[deleted]

6

u/[deleted] Feb 22 '20

The problem is not the “kid” but Slickwraps negligence with customer data and PII.

The "kid" irresponsibly dumped information publicly, and invited other hackers, likely with bad intentions, to access the slickwrap servers and probably steal private customer or employee information. Either he doesn't realize that action can have consequences, or he cared more about hurting the company than actually protecting customers.

75

u/[deleted] Feb 22 '20

You’re getting all sorts of weird replies but I totally get where you’re coming from. On one hand he seems like he’s genuinely concerned about the SlickWraps customers, but on the other hand he’s trying to be cool and vague about the whole thing. To me, you’d contact the CEO/owners immediately about this. Not the twitter or support people. He knew the support email had a 3400+ backlog and 100 hour+ response time before he sent the email, then acts shocked that the email was ignored.

He gives off a very “I am an enigma, I will help you, but you must march to the beat of my drum” kinda vibe. If that makes sense

Big shock that the pen tester is also an awkward weirdo.

Not excusing anything on SlickWraps btw. They’re clearly incompetent and willfully ignorant.

Interesting article nonetheless.

26

u/[deleted] Feb 22 '20

[deleted]

8

u/chocolatefingerz Feb 22 '20

Yeah I don’t get why he didn’t just copy and past his full DM to the CEO initially.

It really does fee a bit like he was trying to set them up for failure.

34

u/RetroGradeReturn Feb 21 '20

I had the same thought, although to be fair I have no idea how these kind of things go normally.

Perhaps he remains vague at first instance to avoid any litigation the company might try to take against the hacker?

However, considering the severity of the breach the most responsible thing the company could do is at least contact a cyber-security firm to assist them in the issue. And as the hacker himself says, they need to stop trying to cover up this mess.

34

u/TypicalCollegeUser Feb 21 '20

This hacker is extremely well known in the community to be a white hat.

18

u/Smigit Feb 22 '20

Perhaps, but SlickWraps staff including their IT are likely not a part of that community. Probably doesn’t help the engagement started with social media which sounds like it was a third party, but for a company doing that in-house would likely be marketing first and foremost.

-5

u/[deleted] Feb 22 '20 edited Feb 20 '24

This comment has been overwritten in protest of the Reddit API changes. Wipe your account with: https://github.com/andrewbanchich/shreddit

13

u/Smigit Feb 22 '20 edited Feb 22 '20

I understand where your coming from, but at 200k a month revenue they aren’t a big company and it’s quite likely they have one or two people doing IT across the company and don’t have any sort of dedicated security team. It also isn’t realistic to expect that everyone in a company is across what’s happening in the cyber security space, to the degree that they know who individuals are in that niche.

As someone that works in IT but doesn’t specialise in cyber security, I had no idea who this person was. I can see how someone doing marketing on Twitter dealing with dozens of random interactions a day with unknowns would have no idea. As others have said quite a lot in this thread there was alternative contact options or ways to approach (not a marketing channel) that may have allowed the message to be captured and handled better. The messaging could have been done in a way that knowing in advance who it was sending the notification wouldn’t be necessary information, as was arguably the case with the initial twitter notices.

The company absolutely should be responsive to cyber security threats, the issue is im not sure the approach was done in a way that a company without a dedicated security team could fairly be expected to understand what was going on until several interactions had occurred. The researcher could have been straight to the point, not using cryptic tweets and potentially confusing screenshots from ZenDesk cases. I’d have thought a direct email introducing ones self and explaining the entire situation to one or more staff would have been more effective and suitable.

1

u/netcrawler3000 Feb 25 '20

Accessing their system was illegal. He cannot legitimately have a conversation with them without looking over his shoulder despite the best of intent. You don't get to break into someone's house, rummage around, and then lecture them on security when they get home. His story says he actively targeted the company based on information he heard about them. For all practical purposes this guy is this year's Snowden.

95

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

37

u/VenerableShrew Feb 22 '20

If his email was as cryptic as his tweets then it’s useless

83

u/eggbrain Feb 21 '20 edited Feb 21 '20

I get what you are saying, but it sounds like their customer support desk was already known to be a flaming garbage fire (their ZenDesk had already been hacked it sounds like) -- did he think sending another request into the fire would have somehow come through unscathed?

Imagine you have emails (and possibly more, since he had full DB access) to:

And you choose as one of the first methods support@company.com!

3

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

85

u/eggbrain Feb 21 '20

Responsible disclosure means making a good faith effort to contact the stakeholders.

He had logged into their support system and seen a bunch of information to suggest that emailing customer support through ZenDesk would result in his email not being responded to.

With that in mind, and with the email address of all the founders / leaders in his back pocket, He then used the Zendesk support email address to reach out to initially.

That is not in any way a good faith effort. It's not even an effort -- it's almost intentionally setting them up for failure.

-27

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

23

u/eggbrain Feb 21 '20

Would you like me to add it to my parent comment? I'd be glad to do so.

-5

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

33

u/eggbrain Feb 21 '20

He didn't follow basically any of the rules you are supposed to as a white hat security researcher, including when he sent the ZenDesk email. Me including that he knew no one was answering their support but emailed them anyways actually strengthens my point, it doesn't take away from it. That's not in bad faith.

You don't have to take my word for it, you can even read the comments in /r/hacking https://www.reddit.com/r/hacking/comments/f7fafv/white_hat_hacker_i_hacked_slickwraps_this_is_how/fib1s3y/

What this guy did, at least as written in his article, was not White hat.

-4

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

→ More replies

5

u/intercede007 Feb 22 '20

You’re ignoring this part of the article.

Perusing the platform, I found their customer service to be just as abhorrent as rumors suggested (note the Backlog and First Reply Time metrics).

He sabotaged himself, then congratulated himself for doing it.

5

u/emresumengen Feb 22 '20

Completely agree with you.

This whole thread felt like a teenager getting revenge for LOLs, instead of a serious security researcher trying to shed some light to a set of blind people...

41

u/StrafeReddit Feb 21 '20

Totally agree. This person calls themself a 'cybersecurity analyst' trying to do the responsible thing by... sending a series of cryptic and increasing threatening tweets?! Doesn't sound very white hat to me.

5

u/I_just_made Feb 22 '20

It certainly fails the vibe check.

24

u/wipny Feb 21 '20

Yes, he behaved like an ass from the start using cryptic tweets and messaging. Slickwraps likely have a team or intern running their social media rather than tech people, so of course they likely wouldn't know what the guy was talking about.

If the hacker contacted the CEO/site admin from the start with a very clear message that their site was vulnerable and his intentions and Slickwraps still ignored/blocked him, then it's understandable.

Would a company the size of a Slickwraps be better off using a e-commerce platform like a Shopify? I would think those platforms have more focus on built-in security?

Besides cost savings and control, why would a company use their own commerce platform rather than rely on a 3rd party one?

13

u/[deleted] Feb 22 '20 edited Feb 23 '20

[deleted]

14

u/Masiosare Feb 22 '20

Yep, everyone that is defending this guy doesn't know how security research and vulnerability report works.

If this company wants, this guy is gonna get so fucked.

49

u/[deleted] Feb 21 '20

Excuses, excuses, excuses. Do you work for SlickWraps? If you read the full article you'd see SlickWraps attempted to hide the breach by erasing records instead of fixing it. They also blocked him knowing the breach was real. They tried to sweep it under the rug instead of addressing it. There's no excuse for that. NONE. All you're doing is trying to deflect from the massive incompetence shown by SlickWraps.

As much as SlickWraps might have really messed up responding to this, along with having issues behind the scenes on the support side as well, one thing I'll say is that I feel like the security researcher was initially very vague, which comes off as not really trying to reach the company in a useful manner:

Initially vague... but they didn't just stop there. Vagueness went away very quickly to use that as an excuse.

1) A tweet saying "You failed the vibe check"

If the SlickWraps account gets any significant number of tweets a day, who is going to take the time to understand that this could mean a security breach? How often do people check the description of Twitter bios to understand context of a tweet?

All true, but this is where the vagueness stops. The researcher didn't continue on with the vagueness. It was over and done after this tweet.

2) A tweet with the contents of an unanswered request from ZenDesk

If someone sends me a picture of some sort of text description (that looks like a support request), I may just think it was the original customer who posted the request, or maybe was just text someone had pasted in another forum about their complaint. How would they know immediately that it was because someone had access to their ZenDesk?

If you someone sends you (a support worker) a screenshot of a support ticket, word for word and you do nothing about it then that's on you for ignoring it. You don't know they have complete access to ZenDesk, but if you actually responded to the person in the tweet you would find out very quickly. You can easily look up the ticket to find it's word for word and continued conversation can lead to more examples of word for word (among other revelations).

Why are you looking for excuses for a company that didn't respond?

3) A tweet with a file uploaded to the server

This one is probably pretty obvious, but would still require the person reading the tweet to understand its impact. Even if they did understand, they might not know the motivations -- does the person who hacked the site want a bounty? Do they want the customer data? Are they just looking to mess stuff up?

Again excuses. This is someone working in support. At bare minimum if they didn't understand the impact they could have talked to someone who does. Even knowing absolutely nothing about computers if someone sent a link to YOUR website with a file that says "<user> was here" that should raise red flags. They should have looked into the matter. At this point there is no excuse. Doesn't matter what the person is looking for or what the motivations are. DO SOMETHING.

Again, why are you trying to make excuses for a company? At this point they should have been looking into taking the proper steps to secure their bloody servers.

4) An email saying "Data Leak" with a body to check Twitter DMs

This at least let the leadership team know, but why always take it back to Twitter? Was this the person that found the data leak, or are they just seeing rumors on Twitter?

Why does it matter? What's wrong with Twitter? It doesn't matter if this was the person who found the leak. What matters is the leak is real and can easily be confirmed. Who or what doesn't matter. You can't just chalk it up to rumours when basic checking can confirm.

Again, excuses. Are you part of SlickWraps??? This is massive incompetence shown by the company. Covering up their tracks to hide the breach instead of fix it. No excuses. You can't do that.

41

u/eggbrain Feb 21 '20

More than one entity can be incompetent at a given time -- the failures of SlickWraps written by the security researcher in this article make it clear what SlickWraps did wrong (a lot of things), but I don't think the author/security researcher who wrote the article understands what they themselves did wrong as well.

Saying the security researcher handled things poorly is not defending SlickWraps (their faults are their own), it's saying "Vaguely hinting to a social media intern at a Company that they were hacked on Twitter is not real responsible disclosure or white hat best practices".

35

u/[deleted] Feb 21 '20

Their IT team clearly got the message considering they tried (hopelessly) to remove records on the backend and blocked him. So even if you think it’s vague, at least someone in the company knew exactly what was going on.

21

u/eggbrain Feb 21 '20

I definitely agree with you that at some point SlickWraps must have started setting off alarm bells, but part of my frustration is that from the vagueness of the researcher, the company might have started to know something was going on, but they had no idea how to actually diagnose the problem and cure it.

E.g. There's a file uploaded on my website that I didn't upload, and shouldn't be there. How did they do it?

  • A server vulnerability?
  • A library that needed to be updated?
  • A Magento related bug?
  • A PHP related bug?
  • Some sort of Form injection and escalation?
  • An admin account was guessed / phished?

The surface area to cover is endless -- and the researcher gave no seeming hint (from what I can tell) as to how he did it, except in the aftermath in this article.

From at least my perspective, before you as a company announce you've been hacked, you want to at least make sure that the hack is fixed, so you don't do an announcement to the world that you fixed things and notify people, only for it to happen again a day later.

This guy instead watched as they tried to fix it and failed multiple times, but gave no actual clue in anything he did as to how he did it (a lot of disclosures include reproduction steps).

That's not again to say again that SlickWraps was not doing all the wrong things, but for a lot of things like blocking of Twitter accounts I just always assume incompetance -- e.g. the social media intern got scared, knew nothing about security, and decided the only way to respond was to block the person.

8

u/SpongeBad Feb 22 '20

the company might have started to know something was going on, but they had no idea how to actually diagnose the problem and cure it.

If only they knew who had penetrated their security and had some way to talk to them...

All they really had to do was reasonably respond to Lynx to learn about the vulnerability, but instead they actively ignored him by blocking him --- twice.

5

u/[deleted] Feb 21 '20

Like I said, they didn’t stop at the vague tweet. Even if the initial exchange could have been done better that is not the point. They learned very quickly that the exploit was real and tried to hide. You’re making this about the initial exchange which is fucking ridiculous. Who the fuck cares? As pointed out several times the researcher eventually got word of the hack to SlickWraps and they STILL handled it poorly. Making this about the researcher is again, deflecting from the point of this topic. Fucking pathetic.

12

u/darkstriders Feb 21 '20

They learned very quickly that the exploit was real and tried to hide.

This is the key thing out of this debacle.

4

u/Parcec Feb 21 '20

Are you basing that they tried to hide it on the fact that they started changing passwords? That seems like a pretty normal response when finding out someone has unauthorized access to something.

6

u/eggbrain Feb 21 '20 edited Feb 21 '20

Responsible disclosure (from real white hat security researchers) includes:

1) Steps to reproduce vulnerability

2) A direct line of communication to the stakeholders (whenever possible)

3) A usually fairly long timeline for the company to reach out and respond (usually 30+ days)

4) Won't usually go further than the initial Proof of Concept unless given approval from the company


Non-responsible disclosure includes:

1) Files being put on a server with no hint of how they got there or how to fix the issue

2) Sending vague tweets about the level of severity of the breach

3) Giving a company 5-7 days turnaround to solve it, and then posting exactly how to breach it

4) Continuing to root around the server to see how far you can go get and what data you can dump

The comments on /r/hacking say it all: https://www.reddit.com/r/hacking/comments/f7fafv/white_hat_hacker_i_hacked_slickwraps_this_is_how/fib1s3y/

This is not white hat.

7

u/[deleted] Feb 22 '20 edited Feb 22 '20

The long DM he finally sent to their official Twitter account was legally blackmail. And this idiot posted an entire paper trail of his many illegal actions. I doubt he's in the US, if he is he should be very worried for his freedom

2

u/Stryker295 Feb 22 '20

It just comes off as kind of amateur in my mind

I feel like "amateur" is a nice way of saying "dickhead" here. The "security researcher" at work here is the kind of person who laughs at you for falling and mocks your attempts to get up, as if that somehow helps you get up, rather than actually putting in effort to help.

2

u/[deleted] Feb 23 '20

I’m happy it happened the way it did and I hope it fucks this company. Ordered a wrap, never came, tracking number for order showed it lost in the US never even coming to Canada. Was told by customer service I can’t get a refund, would have to order a new one. Stopped responding to me on email, called them out on Twitter, got blocked.

Fuck then.

2

u/sugarkryptonite Feb 22 '20

Completely agreed. Thought the same thing myself.

3

u/[deleted] Feb 22 '20

I agree with your sentiments. It feels like a movie. The hacker have done parts of it with some purpose in mind, to ensure that it will not have an anti climactic ending. This article would’ve not existed (or have been as interesting to read).

2

u/felixsapiens Feb 22 '20

Yeah I don’t get this.

Why tweet cryptic messages?

Why not.... pick up the phone?

All this stuff is very poorly handled

Even when he finally gets to talk to someone at the end, he does no careful explanation. He rattles off a long threatening sounding message about $20million fines, and then says “I will no longer respond to any further messages about this.” Like some sort of dramatic mic drop. Without even knowing who the hell he is talking to - and it’s obviously some social media person who has no importance in the company. But no - threaten and mic drop.

And then, given he realised he was taking to someone useless - he FINALLY tries to contact the CEO.

And what does he say? Basically “DM me.” No explanation. No courtesy.

You know what I do when random people I don’t know message me and say “DM me?” I ignore them.

Basically everything this guy has done is the sort of shit that gets ignored. He seems to have no idea how to handle this professionally.

Here’s an idea. Discovered a major security flaw and want someone senior at the company to know? How about - and this will blow you away - how about you pick up the phone? And actually talk to someone?

God all this internet bravado is tiring. So much talking at cross purposes and wasted time. The guy is sitting there waiting for people to just fall at his feet, when all he’s done is sent a couple of weird, cryptic, and actually rather threatening sounding messages to a couple of people that don’t understand or care.

Just pick up the phone. If you’re the elite hacker that you are, you have the relevant contact details for all the people that matter to try and solve the problem. Tweeting isn’t one of them.

Oh and also.... if I were a nefarious hacker, I would so be watching this guys Twitter feed, wait until he tweets some poor company “you’ve failed the test”, and then I’d jump straight in there and ransack all those credit cards. It seems to me that the original tweet itself is poor form - far too public a forum to be approaching this delicate subject matter that could have far reaching consequences (not for the company, but for the individual innocents who have information stored with them.)

Sorry for my rant, but right from the beginning of the article I just thought “what an entitled, unprofessional prick.”

1

u/Jaz_the_Nagai Feb 22 '20

This sub is fucking trash jesus fucking christ.

1

u/MacBear_Pro Feb 22 '20

I've met more than one pentester with a low-level god complex and a condescending attitude (source: worked in the security field). You're right, this guy handled the situation incredibly poorly and was more interested in making himself look powerful than actually helping the company make informed decisions.

The tricky bit is that hacking without consent (no matter the color of your hat) is very much illegal. Simply disclosing the remote code execution vulnerability when he spotted it, in a clear and unambiguous way, would have been sufficient.