April 27, 2007

Mom's credit card number

The Month of MySpace Bugs observes:

When learning of this bug, we realized that there would be at least several thousand typical Myspace users who may be concerned about this sort information disclosure attack -- many more than would be concerned about a null pointer dereference, a local-only privilege escalation in Mac OSX, or a double-free in PHP4. While these other bugs, and even some XSS bugs detailed here at MOMBY, are more closely associated with information security, there is about zero common interest in these issues outside of a small, highly-trained circle of professional attackers and defenders. On the other hand, Myspace is simultaneously a common reference implementation of poor web application design, and one of the most popular and useful destinations in the history of the Internet. This is paradoxical to technical professionals, and the security set seems to be suffering a serious bout of cognitive dissonance on this point. Kids (12 to 24 year olds) are learning their Internet habits on Myspace -- that means cleartext authentication, random errors and re-logins, mysterious loss of data [and] privileges, and easy XSS-enabled session hijacking are pretty much the sum total of their day-to-day experience.
One commonly known security bug in MySpace is that password authentication is case-insensitive. This would seem to imply that MySpace stores your plaintext password in their database, and not a hash of it. This in turn implies that if you ever hacked MySpace's authentication database, you would have a lot of pwnies.

Posted by Jeffrey at April 27, 2007 11:09 AM
What is a TrackBack? Learn more here.

TrackBack URL for this entry:
http://www.geekable.com/cgi-bin/mt-tb.cgi/1390

Listed below are links to the 0 weblogs that reference 'Mom's credit card number' from Geekable.com.