CoJ: exposed bills due to "malicious hack"

The case is still ongoing. No-one has been charged and I remain the "main suspect". Last year a number of ISPs have received subpoenas against users from MyBB - there was talk that CoJ wanted to prosecute some 300 people (but then there was also confusion that it was 300 charges).

So 300 people who clicked the links?
 
Thanks for the update. It must be quite costly for you having to have a legal team and everything? Do you regret being the one to make the issue with their website public?
In my next life I will become a lawyer :whistle: - got a warchest build up and have a few people on call with bail money just in case that CoJ is spiteful enough to come and arrest me. When this case goes to court evidence will surface that CoJ and the company responsible for running/managing e-services had known about this issue for several months (people working within those entities dropped anonymous letters at my office with those details).

I don't regret disclosing it (FWIW - another MyBB'er told me that he contacted CoJ several weeks prior to the incident), but I would never do any interviews with the local news media (especially IOL and 702) as none of them could be bothered to get the story right (MyBB excluded). What is still infuriating is that no-one took CoJ to task for the poor management of rate-payers information and the security issue is really the result of project Phakama (search for "Masana Technologies") - many MyBB'ers have been part of this project and remained cowardly tight-lipped of what happened there (some might even be responsible for the issues disclosed). The other famous IBM project was themed "Sebedisana" - some MyBBers will be familiar with that as well :whistle:

So 300 people who clicked the links?
Sorry - got my numbers wrong (just checked my records). It was 30 people and 300 charges (it is my understanding that charge=invoice accessed). In January 2014 subpoenas had been issued to ISPs to disclose login-details - I am unsure if this was against all people on MyBB or just against the "main suspect". I think MyBB would have been the Hawks first port of call to retrieve user, IP and login information of every person on those threads - not sure if this was ever requested. I don't see that the state will drop the case and eventually it will see it's day in court.
 
Last edited:
In my next life I will become a lawyer :whistle: - got a warchest build up and have a few people on call with bail money just in case that CoJ is spiteful enough to come and arrest me. When this case goes to court evidence will surface that CoJ and the company responsible for running/managing e-services had known about this issue for several months (people working within those entities dropped anonymous letters at my office with those details).

I don't regret disclosing it (FWIW - another MyBB'er told me that he contacted CoJ several weeks prior to the incident), but I would never do any interviews with the local news media (especially IOL and 702) as none of them could be bothered to get the story right (MyBB excluded). What is still infuriating is that no-one took CoJ to task for the poor management of rate-payers information and the security issue is really the result of project Phakama (search for "Masana Technologies") - many MyBB'ers have been part of this project and remained cowardly tight-lipped of what happened there (some might even be responsible for the issues disclosed). The other famous IBM project was themed "Sebedisana" - some MyBBers will be familiar with that as well :whistle:
It seems that you portray yourself as an ethical hacker. A person who ethically tests vulnerabilities and report it to companies to be fixed, so that they cannot be exploited maliciously.

However I am told you are the CTO of bidorbuy, an online auction marketplace which is used to sell goods including amongst other things 2nd hand laptops. I pointed out in another thread you have 2 features on your site 1)flash sales and 2)unverified(anonymous) seller which can be used to commit fraud and I noted some suspicious activity with the sale of large quantities of 2nd laptops for those criteria .

I made a suggestion to combat selling of stolen laptops but you brush me off and argued with irrelevant arguments.

I then pointed out in this post to a another unverified bidorbuy seller using similar strategy for ebooks, mp3s and software. This can without question be proven as illegal for 16000+ auctions, beyond a reasonable doubt. You must admit this is a very large number of auctions. Despite me posting it in that thread a couple of days ago you still haven't blacklisted that user or answered that post, but instead continue to participate in other threads.

For all purposes judging by the suspicious activity I believe your site is used for, I believe you are intentionally turning a blind eye to very large number of stolen goods being auctioned on your site. Ethically it's definitely not a nice thing to do, considering what a big problem theft is in South Africa and that you have by far the biggest auction site in the country. To see you now portray yourself as an ethical hacker. I cant but laugh at it. :whistle:

(PS. Didn't mean to derail your thread, I believe it's on topic considering your ethical hacker discussion and the ignored avoidable fraud on your site which IMO significantly exceeds the fraud that can be committed by malicious hackers accessing exposed CoJ bills)

There is some further discussion in this thread .
 
It seems that you portray yourself as an ethical hacker. A person who ethically tests vulnerabilities and report it to companies to be fixed, so that they cannot be exploited maliciously.

However I am told you are the CTO of bidorbuy, an online auction marketplace which is used to sell goods including amongst other things 2nd hand laptops. I pointed out in another thread you have 2 features on your site 1)flash sales and 2)unverified(anonymous) seller which can be used to commit fraud and I noted some suspicious activity with the sale of large quantities of 2nd laptops for those criteria .

<snip>

TL;DR - @skimread: Let us deal with issue at hand and not attack the person. Unfortunately South Africa has become a society where blaming others and defaming their characters is acceptable. I know from personal experience how demeaning and shaming it is to experience a character assassination, especially in the case of CoJ. Play the ball, not the man.


Let's not derail this thread and continue discussions about bidorbuy related activities in the thread you have opened (I am sorry that I have not responded yet - but I will do so by middle of this week). Our marketplace registers every month over 10K new users and at any given time we have in excess of 1,7m user-generated product listings on our site. Let's remember that those 1,7m products are user-generated content and if said users decide to post illegal / counterfeit products on a marketplace where I happen to be the CTO it is highly unfair from you to judge my personal believes and ethics based on what users attempt to sell.

My ethics are above board and what is not visible to you is that fraudulent users on bidorbuy are dealt with accordingly and our security team with the assistance of the bidorbuy community addresses those issues. Behind the scenes many of those fraudulent users have been brought to book and we have assisted CCU/Hawks in a number of high-profile sting-operations (none of those will ever make the news as the affected companies do not want to have bad publicity).

I take strong exception to your post questioning my integrity and ethics, but I also believe that this level of discussion has no place in a public forum (and specifically not in this thread) - I do however invite you to have a face-to-face discussion about your opinion off my personality and ethics.
 
Top
Sign up to the MyBroadband newsletter
X