"How I hacked DStv" - Security researcher

Bradley Prior

MyBroadband Journalist
Staff member
Super Moderator
Joined
Oct 16, 2018
Messages
5,031
Reaction score
1,585
"How I hacked DStv" - Security researcher

When security researcher Bright Gameli Mawudor stumbled upon a treasure trove of MultiChoice credentials on the open Internet, his attempts to disclose it responsibly were met with legal threats.

Mawudor was a speaker at the recent MyBroadband CyberSec Conference.
 
To think that Google is a ‘good’ crawler. There are many malicious crawlers out in the wild. This window is already indexed. Multichoice will need to do more than patching.
 
The issue company response of threatening with the law. No consideration that they put the info out there and what the user did is not illegal.

To think that Google is a ‘good’ crawler. There are many malicious crawlers out in the wild. This window is already indexed. Multichoice will need to do more than patching.
The more worrying part is that it can't be indexed if it's not exposed already. These companies should tighten up security.
 
The issue company response of threatening with the law. No consideration that they put the info out there and what the user did is not illegal.

Technically theres a very fine line between what is ethical and what is illegal. Just because I find a piece of paper with your email address and password doesn't entitle me to go through your email. The same as all the loose cannons that love to run around running pentests against companies "ethically". And to add, good luck to any company who thinks that running any vulnerability scanner is gonna help against some idiot who uploads a spreadsheet with credentials to a public cloud.
 
Technically theres a very fine line between what is ethical and what is illegal. Just because I find a piece of paper with your email address and password doesn't entitle me to go through your email. The same as all the loose cannons that love to run around running pentests against companies "ethically". And to add, good luck to any company who thinks that running any vulnerability scanner is gonna help against some idiot who uploads a spreadsheet with credentials to a public cloud.
That's true but there is a difference between possessing information and using it. They put it out there so it's not illegal to be in possession of it. Using it would be illegal.
 
You are completely missing the point of a pentest then.

And you're completely missing my point in the context of the article.

That's true but there is a difference between possessing information and using it. They put it out there so it's not illegal to be in possession of it. Using it would be illegal.

Yes, so in the context of the article he magically knew the information he was in possession of was completely legit?
 
Yes, so in the context of the article he magically knew the information he was in possession of was completely legit?
Don't know what your point is. The info was on the open web. There's no mention he used it to do anything malicious but rather that he could have if he was so inclined. Sure some of it is probably outdated but that's not the point here.
 
Hardly "hacked" DSTV! DSTV should be shot for exposing these details.

Exactly, sensational BS headline at best.

They left config on an open webserver and let it be indexed. He didn't hack ****. He simply used a search engine in a somewhat intelligent manner.
 
Exactly, sensational BS headline at best.

They left config on an open webserver and let it be indexed. He didn't hack ****. He simply used a search engine in a somewhat intelligent manner.

Well the guy probably hasn't changed his API key for sending email which is clearly visible on the photo on the article. Even showing that at a security conference is a risk in itself but thats my 2c.
 
Don't know what your point is. The info was on the open web. There's no mention he used it to do anything malicious but rather that he could have if he was so inclined. Sure some of it is probably outdated but that's not the point here.

My point is that he either had access or he didn't. If he found credentials for a system he wouldn't necessarily be able to access that system neither does it mean those credentials were valid or were valid in the past. Yes, it's pretty damn obvious that it is a major oversight by an idiot employee but any verification or "hack" would have technically been illegal even under the guise of "free security consulting".
 
My point is that he either had access or he didn't. If he found credentials for a system he wouldn't necessarily be able to access that system neither does it mean those credentials were valid or were valid in the past. Yes, it's pretty damn obvious that it is a major oversight by an idiot employee but any verification or "hack" would have technically been illegal even under the guise of "free security consulting".
Sigh. The point is he wasn't in possession of it illegally whether they were valid or not. A security breach happened. He informed them and instead of saying they'll take action he was threatened with the law.
 
Wowser - why all the hate on the security researcher? If you compromised a system you compromised a system. It doesn't matter if you broke 2048-bit encryption or used Google. The technique doesn't matter - the impact does. He was demonstrating vulnerabilities and how easy it is to find them and he succeeded. XKCD to the rescue https://xkcd.com/2176/, https://xkcd.com/538/.

The Dstv networking and web team is a joke - this is just another symptom.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X