Disclosure Record

This is a record of security problems I have found and reported over the years, and how the people responsible handled it. It is not complete. Most organizations asked not to be named, and I honor that. Some findings are still unpatched, so the details stay vague until they are fixed.

Every one of these was reported privately before anything was published. The “Response” column is the part I care about most. Fixing a hole is expected. How a company treats the person who told them about it says more about their security than any policy page.

Reported and fixed

OrganizationIssueReportedResponse
Alienware Arena (Dell)Blind SQL injection, database not locked down2013Fixed. Courteous throughout, and they sent a thank-you.
Smith & WessonSQL injection via ad redirect; database account had full rootSept 2013Silence for six weeks, then a quick patch once they understood it. Fixed Dec 2013.
Brinker (Chili’s) and ZioskTable-top kiosk configuration and admin access reachable by patrons; same hardware at Applebee’sApril 2014Ziosk responded within a day and fixed it. Exactly how it should go.
NetGearRemote root command execution on far more router models than initially reportedDec 2016Updated their advisory to the full model list and shipped firmware.
Cyberoptix Tie LabPayPal cart accepted any price the buyer sent, including zeroJuly 2012Grateful. Small shop without the means for a code fix, so they now approve every order by hand. They sent me a tie.
ArrisCable modem configuration changes with no authentication, triggered by visiting a web pageFeb 2017Engineering reached out within days. Patched within six weeks.

Reported and ignored

OrganizationIssueReportedResponse
FacebookMobile password reset handed over the wrong account with no challengeMay 2016Dismissed through their White Hat program. Others found and demonstrated it publicly a month later.
Buffalo Wild WingsKiosk and Wi-Fi exposure with enough detail to reach the payment gatewayOct 2015Two contact attempts, Twitter, Facebook, and a conversation with a manager. Nothing. Still unfixed when I stopped checking.
Radixx InternationalUnsecured access to customer data and internal informationSept 2014No response to two reports.
BIOMIDSUnsecured licensing server; intellectual property exposureSept 2014No response to two reports.
IntravNewsUnauthenticated web service could generate valid license keysSept 2014No reply. The site went offline instead.
A U.S. defense contractor (unnamed)Employee IDs, schedules, and personal details exposedSept 2014“We will be working to secure our site.” Still open a month later. Unnamed because of what they build.
Tambov regional government, RussiaPostgreSQL injection on the public siteDec 2014Every email bounced and every contact form timed out. I tried.

Also reported

Findings I have not written up, or that were handled entirely in private: CJ Pony Parts, Maricopa Community College, Microsoft, Sig Sauer, Springfield Armory, and others.

And roughly fifteen thousand MongoDB operators in the United States whose databases I found open in January 2017, most of which were ransomed before anyone could be told. That one gets its own post.

If you are on this list

If your entry is out of date because you fixed the problem, tell me and I will update it. Gladly. If you would like to be moved off the ignored list, the way to do that is to respond.

To the companies I help going forward: please let me write about the issue and the fix once it is closed. A lesson nobody can read teaches nobody anything.