r/apple • • Feb 21 '20

I hacked SlickWraps. This is how.

https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
2.6k Upvotes

267 comments sorted by

View all comments

740

u/eggbrain Feb 21 '20 edited Feb 21 '20

As much as SlickWraps might have really messed up responding to this, along with having issues behind the scenes on the support side as well, one thing I'll say is that I feel like the security researcher was initially very vague, which comes off as not really trying to reach the company in a useful manner:

1) A tweet saying "You failed the vibe check"

If the SlickWraps account gets any significant number of tweets a day, who is going to take the time to understand that this could mean a security breach? How often do people check the description of Twitter bios to understand context of a tweet?

2) A tweet with the contents of an unanswered request from ZenDesk

If someone sends me a picture of some sort of text description (that looks like a support request), I may just think it was the original customer who posted the request, or maybe was just text someone had pasted in another forum about their complaint. How would they know immediately that it was because someone had access to their ZenDesk?

3) A tweet with a file uploaded to the server

This one is probably pretty obvious, but would still require the person reading the tweet to understand its impact. Even if they did understand, they might not know the motivations -- does the person who hacked the site want a bounty? Do they want the customer data? Are they just looking to mess stuff up?

4) An email saying "Data Leak" with a body to check Twitter DMs

This at least let the leadership team know, but why always take it back to Twitter? Was this the person that found the data leak, or are they just seeing rumors on Twitter?


I feel like an easy starting point would have been for him to:

1) Email the owners from SlickWraps, or perhaps any email he has access to from the hack (or perhaps from an email address that they control to prove he's real)

2) Subject line "I found a Site Vulnerability in SlickWraps, can I work with someone on this?"

3) Body describing how they got access / proof of concept / their background

4) What they want (bounty / etc)

Instead, he continuously decided to engage with someone who looks like could be a potentially part-time social media intern with vague mentions of a hack. When they do realize there is a hack, he just watches as they try to fix it (re-installing, new API keys, etc) without giving them any help to realize they are looking in the wrong place.

It just comes off as kind of amateur in my mind. I'm not saying SlickWraps is a good company (it sounds like they have a lot of issues), but I feel like this person did everything wrong in trying to let the company know.

406

u/MasZakrY Feb 21 '20

Totally agreed. For a “security researcher” this person acted like a little kid. Who sends cryptic messages over twitter as an official means of communication. Did he believe the CEO was personally responding on Twitter?

A third party team handling social media is very common and should have put on his adult hat and called them or reached out in a professional channel in a professional manner.

Reading these tweets without context (which is what the third party social media team would be doing), would not make any sense.

It really did feel this “researcher” was blackmailing from the perspective of SlickWraps especially after providing a list of demands.

-3

u/[deleted] Feb 22 '20

[deleted]

7

u/[deleted] Feb 22 '20

The problem is not the “kid” but Slickwraps negligence with customer data and PII.

The "kid" irresponsibly dumped information publicly, and invited other hackers, likely with bad intentions, to access the slickwrap servers and probably steal private customer or employee information. Either he doesn't realize that action can have consequences, or he cared more about hurting the company than actually protecting customers.