Security Researchers were able to use a FIA website vulnerability to access Max Verstappen's Passport and personal information of thousands of drivers

https://ian.sh/fia

cross-posted from: https://lemmy.bestiver.se/post/692501

Comments

35 points · 7 comments · view on lemmy.world

7 Comments

mannycalavera@feddit.uk · 9 pts · 310d

5 second time penalty awarded to the hackers after stewards enquiry.

tyler@programming.dev · 7 pts · 310d (2 replies)

“Hack” is a very strong word here. They asked the website if they could be admin and the website happily said yes and made them admins.

ninth_plane@lemmy.world · 3 pts · 310d (1 reply)

I agree, but I also think the researchers should be awarded a hefty bounty for knowing which part of the website to ask.

tyler@programming.dev · 2 pts · 309d

Oh definitely. They found a glaring vulnerability, it just doesn’t mean they hacked it. An equivalent would be somebody paying a pen testing team to see what they can do and the team finds an open window into the accounting office and they climb in, put a note on the desk stating that the pen testing team needs to get paid three times as much, and then accounting does it no questions asked after they find the note.

atocci@lemmy.world · 3 pts · 310d

Not even surprised considering the FIA.

ninth_plane@lemmy.world · 3 pts · 310d

This blog is part 1 of 3 in a series of vulnerabilities found in Formula 1.

davetortoise@reddthat.com · 1 pts · 310d

Lol