"How I hacked DStv" - Security researcher

He certainly tested the credentials to make sure it was an actual threat, if that's what you mean. Further down the article he makes clear that he was able to access live SuperSport systems with the creds.

And technically that would be considered at minimum unethical and at maximum illegal especially within our current legal framework.
 
  • Like
Reactions: Jan
Hardly "hacked" DSTV! DSTV should be shot for exposing these details.
Anyone still doing business with DSTV anyway should seriously reconsider for many reasons. Too many cons and hardly any pros, period!!!
 
And technically that would be considered at minimum unethical and at maximum illegal especially within our current legal framework.

Disagree on the minimum. You could also argue that it's just being thorough, so that when you report the issue you don't overstate the threat.

MultiChoice didn't exactly react with speed to address the vulnerability, even when the threat was made clear. How much worse would it be if you don't provide specifics?

Not sure what Kenya's laws look like, but yeah, ours could severely limit the capabilities of security researchers. That was one of the big criticisms of the Cybercrimes Bill if I recall correctly?
 
Why? All it takes is knowing there are people who leave the keys out in the open.

Your analogy assumes that the keys are being stored near the doors they unlock, or that the doors/windows weren't secured at all. That is not the case here.

I'm not trying to distract from his knowledge and achievements here. Just pointing out that it's not something I see as hacking. Editing a boot record with a hex editor would be more hacking for me. I see this trend of overusing words everywhere. Hacking, cloud storage, etc.

Yep, I get that. We're all entitled to an opinion, otherwise these threads would be boring.
 
Disagree on the minimum. You could also argue that it's just being thorough, so that when you report the issue you don't overstate the threat.

MultiChoice didn't exactly react with speed to address the vulnerability, even when the threat was made clear. How much worse would it be if you don't provide specifics?

Not sure what Kenya's laws look like, but yeah, ours could severely limit the capabilities of security researchers. That was one of the big criticisms of the Cybercrimes Bill if I recall correctly?

Because you find the "keys" to something doesn't entitle you to attempt to gain access using those "keys". Multichoice's response would be the same if he reported the discovery of the file or reported the discovery of the file and tested it - the latter just puts the "researcher" at risk. The overstatement is irrelevant as the true extent would only have been able to be determined by Multichoice. The crime is unauthorized access to a computer system internationally and is pretty universally enforced. Unless Multichoice's servers were in Kenya it's still considered a crime in SA - same as if you hacked a server in the US etc.
 
  • Like
Reactions: Jan
Because you find the "keys" to something doesn't entitle you to attempt to gain access using those "keys".

Yes and if MultiChoice had a proper bug bounty and contacts for professional security researchers on its website, things could have gone differently too...

Multichoice's response would be the same if he reported the discovery of the file or reported the discovery of the file and tested it - the latter just puts the "researcher" at risk.

Agree to disagree on the first part of the sentence. Maybe in future when companies take information security more seriously this will be different. Agreed that it currently does put the researcher at risk.

The overstatement is irrelevant as the true extent would only have been able to be determined by Multichoice.

Companies lie to protect their image all the time. To be clear: That has not happened in this case, but I've been involved in several cases now where the internal IT downplay a threat for whatever reason. Maybe it's just ego and maybe it's something else.

I would argue that putting ourselves in a position where the word of someone must be trusted without an independent third-party being allowed to test the veracity of their claims is not good.

It doesn't matter so much in this case, but it has mattered and will matter in other cases.

Unless Multichoice's servers were in Kenya it's still considered a crime in SA - same as if you hacked a server in the US etc.

Indeed. Now two under-resourced law enforcement agencies can try to prosecute someone for performing a free service. The lack of gratitude for security researchers who go through the effort of co-ordinating disclosure astounds me sometimes.
 
Yes and if MultiChoice had a proper bug bounty and contacts for professional security researchers on its website, things could have gone differently too...

The majority of companies don't but that still doesn't provide tacit acceptance of any action by an independent security researcher. It's extremely frowned upon to knowingly access a system without preauthorisation and is considered unethical within the industry.

Agree to disagree on the first part of the sentence. Maybe in future when companies take information security more seriously this will be different. Agreed that it currently does put the researcher at risk.

If its any consolation there is more of a focus on information security as part of general financial audits now at large companies including IT controls etc. Unfortunately it's still early days and they're more interested in whether you have a documented policy saying something or a firewall installed than the implementation of the policy and a correctly configured firewall.

Companies lie to protect their image all the time. To be clear: That has not happened in this case, but I've been involved in several cases now where the internal IT downplay a threat for whatever reason. Maybe it's just ego and maybe it's something else.

I would argue that putting ourselves in a position where the word of someone must be trusted without an independent third-party being allowed to test the veracity of their claims is not good.

It doesn't matter so much in this case, but it has mattered and will matter in other cases.

Noone will admit that they f'd up but my point was more related to the seriousness of credentials being made available publicly was the issue - not what was secured by the credentials. ie. It's the risk which should be focused on by the researcher not the potential gains by a bad actor. That determination is by those who respond to the notification of the risk as in this case it's obviously severe.

Indeed. Now two under-resourced law enforcement agencies can try to prosecute someone for performing a free service. The lack of gratitude for security researchers who go through the effort of co-ordinating disclosure astounds me sometimes.

Well it's a very good point and why in less tech-savvy legal systems such as ours it's even more of a risk. Can you imagine trying to explain to a judge that the only reason you gained unauthorised access was because of your good intentions and security research? If someone gains the keys to your home (even due to your own negligence) and then uses those keys to enter your home and have a look around would that be seen as completely OK?
 
@Jan - As a follow up article maybe it would be great to know if Vodacom/MTN/Telkom/Cell C would value information which is a serious security concern and if they have bounty programs, if they reward researchers or what their general approach to such activity is?
 
  • Like
Reactions: Jan
Sorry bit busy with work,but wasn't there in fact an article a while ago about a security issue being found on a SA company site and investigated,and the company accusing the researcher of hacking?
 
  • Like
Reactions: Jan
Sorry bit busy with work,but wasn't there in fact an article a while ago about a security issue being found on a SA company site and investigated,and the company accusing the researcher of hacking?

I believe it was City of Joburg.
 
  • Like
Reactions: Jan
Well it's a very good point and why in less tech-savvy legal systems such as ours it's even more of a risk. Can you imagine trying to explain to a judge that the only reason you gained unauthorised access was because of your good intentions and security research? If someone gains the keys to your home (even due to your own negligence) and then uses those keys to enter your home and have a look around would that be seen as completely OK?

This is a very interesting discussion, as always. Thank you! I can't disagree with your analogy, except to say that maybe it is going to be necessary to think differently about information security than physical security.

A question to your question: How does the discovery, testing, and disclosure of this vulnerability differ to something like Spectre and Meltdown?

Researchers who discover vulnerabilities in hardware or software, including flaws in cryptographic stuff (to try and make the key analogy fit), often build a proof-of-concept exploit. They certainly test that exploit against vulnerable hardware or software. The only difference is that they have the luxury of being able to buy or set up their own vulnerable component to attack.

My thesis, in short: You have to validate the vulnerability. Otherwise you risk crying wolf.
 
This is a very interesting discussion, as always. Thank you! I can't disagree with your analogy, except to say that maybe it is going to be necessary to think differently about information security than physical security.

A question to your question: How does the discovery, testing, and disclosure of this vulnerability differ to something like Spectre and Meltdown?

Researchers who discover vulnerabilities in hardware or software, including flaws in cryptographic stuff (to try and make the key analogy fit), often build a proof-of-concept exploit. They certainly test that exploit against vulnerable hardware or software. The only difference is that they have the luxury of being able to buy or set up their own vulnerable component to attack.

My thesis, in short: You have to validate the vulnerability. Otherwise you risk crying wolf.

Spectre and Meltdown are obviously exploitative - the difference is that these manipulate a flaw in the underlying physical hardware outside of a users control whereas the finding of credentials by any means is more human failure. Any exploit which is as a result of a hardware or software vendor is something which is more manageable than human stupidity - in this case it's not a misconfigured webserver but a poor policy regarding the sharing and recording of credentials which led to the issue - they shouldn't be written down and stored anywhere, for any reason. In regards to exploitable hardware and software these are usually communicated ad nauseum in the media and via vendors and service providers - so if you haven't patched your systems you're most likely at risk however they can be mitigated to a certain extent by anti-virus/unified threat management software/appliances. These types of exploits are generally researched in labs or by private individuals on their own systems who then disclose them as appropriate - as long as it's an environment within their control and authority, validating the vulnerability isn't an issue.

Security researchers who try to test vulnerabilities in the wild against third parties with no agreement or authorisation to do so run the exact same risk as if they were executing an exploit against that third party whether there is a payload or not. eg. A good unified threat management appliance will still block and alert a bluekeep attack whether it is a pentest or legitimate attack which is why running vulnerability scanners against companies without permission could trigger a investigatory response especially with organisations that actively manage their environments. The risk is generally dependent on how aggressive the network security reacts and if they deem it warranted. ie. Sustained port scans could be reported to the IP block owners as suspicious traffic whereas active brute force attacks may result in a different approach.

In the current matter I don't believe validation was required as simply pointing the company to the information would've resulted in the file being removed or the web server being locked down and action being taken against the individual responsible if an applicable policy was violated.
 
Your analogy assumes that the keys are being stored near the doors they unlock, or that the doors/windows weren't secured at all. That is not the case here.



Yep, I get that. We're all entitled to an opinion, otherwise these threads would be boring.
No I don't assume that. The keys can be on the sill or the doormat or even the street. It doesn't matter as the result is the same. He didn't go looking for a vulnerability with a specific company. It seems to issue is in how we view what he did. You see it as going to a house then going out to find the key. I see it as knowing there are keys lying around then going out till you stumble upon one and opening it's marked locked. So I don't think we'll agree on that.

I do agree with the rest of your points on security. Security researchers shouldn't be at risk for validating obvious vulnerabilities and only if they use them maliciously. But I don't agree with the practice of trying to hack a system to show if it's secure or not.
 
  • Like
Reactions: Jan
Top
Sign up to the MyBroadband newsletter
X