A security researcher discovered that goHardDrive, a used hard drive retailer, was exposing thousands of customer records through an insecure RMA status check system. The vulnerability allowed anyone to access customer names, addresses, emails, and order details by simply guessing sequential RMA numbers. Despite initial attempts to fix the issue by adding ZIP code and house number verification, the researcher demonstrated this was still easily exploitable. goHardDrive ultimately removed the RMA status page entirely and now handles status updates via email only.

โ€ข8m read timeโ€ขFrom mtlynch.io
Post cover image
Table of contents
The leak ๐Ÿ”—๏ธŽScale of leak ๐Ÿ”—๏ธŽgoHardDriveโ€™s attempted fix ๐Ÿ”—๏ธŽgoHardDrive removes RMA status checks entirely ๐Ÿ”—๏ธŽBug bounty ๐Ÿ”—๏ธŽTimeline ๐Ÿ”—๏ธŽSidenote: Leaks aside, this is a terrible return process ๐Ÿ”—๏ธŽ

Sort: