[ / / / / / / / / / / / / / ] [ dir / random / abdl / cow / htg / islam / mu / random / rule34 / tingles ][Options][ watchlist ]

/tech/ - Technology

Freedom Isn't Free
You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
Archive
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

[–]

 No.1085463>>1085464 [Watch Thread][Show All Posts]

Hello there, noob here.

Actually, I attend a cram school which basically all the students of my age attend in my country to study for an exam, and they have a website, where online tests are held. Basically, one has to login through his registration code and an OTP they receive on their mobile. I managed to bypass the OTP verification through BurpSuite, to redirect OTP to my phone number instead of the victim's. The compromised account can be used for many purposes, as the account's profile details contains all of the information of the student, including his legal ID number and address. What's more is that one can attempt a test, fill wrong answers and submit to degrade the victim's score. I tried to tell them this issue, e-mailed them but most probably they don't check their email. What should I do?

____________________________
Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.1085464 >>1085465

>>1085463 (OP)

>I tried to tell them this issue, e-mailed them but most probably they don't check their email. What should I do?

If this is not in-house developed solution try contacting developers of that software. If you're in EU if anything else fails you could report a GDPR violation. And I hope that you contacted them from anonymized e-mail because what you did is illegal and if they want to be assholes you could be charged with a crime. This happened to someone in my country when he exposed that encryption of police radio was broken. Even though you have good intentions abusing the service without permission is illegal.

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.1085465 >>1085466

>>1085464

Yes, I used protonmail.

I'm not in the EU, what should I do next? Should I let it go unnoticed, since you say the thing I did is illegal? Does writing this on 8kun trace me back?

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.1085466 >>1085467

>>1085465

>Should I let it go unnoticed, since you say the thing I did is illegal?

If you contacted the administrator that's all you need to do. If they choose to ignore it it's their problem. In that case you can just hope that the service is obscure enough that nobody on the outside will use it to gather personal information.

>Does writing this on 8kun trace me back?

I would be more concerned about your phone number. I assume you used a burner phone? To get your identity (IP) from 8kun would require them issuing a request to law enforcement first, which if you're not in the US 8kun can choose to ignore. It's also very unlikely that people behind the service browse /tech/.

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.

 No.1085467

>>1085466

ok thanks

Disclaimer: this post and the subject matter and contents thereof - text, media, or otherwise - do not necessarily reflect the views of the 8kun administration.



[Return][Go to top][Catalog][Screencap][Nerve Center][Random][Update] ( Scroll to new posts) ( Auto) 5
4 replies | 0 images | Page ???
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / random / abdl / cow / htg / islam / mu / random / rule34 / tingles ][ watchlist ]