Jump to content

Welcome to Grasscity Forums
Register now to gain access to all of our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. This message will be removed once you have signed in.
Login to Account Create an Account
Photo

At a hotel right now, they have multiple security holes, should I report them?

- - - - -

  • Please log in to reply
29 replies to this topic

#1
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts
Alright guys, so I'm staying at a hotel right now, not gonna say which one.
I've basically done some security testing, they have a couple of critical open ports, FTP, and SSH open, unfiltered, able to be fucked over.

I've tried packet sniffing on their network, to see if they encrypt their traffic at all, and of course they don't... Which is incredibly stupid seeing as this is a huge hotel, and there is a potential treasure trove of information waiting for a person with malicious intent to come along.

I feel like going down to the office, and asking to speak with the hotel manager, and give them some tips on how they can improve their security. As I'm sure their reception desk uses the same wifi, so if they scan credit cards or what not, and transmit them over the wifi.... Well I'm sure you will know what can happen.

However I took a look at their TOS regarding internet usage, and it looks like what I'm doing is Illegal, even though I have non-malicious intent. I am not sniffing their network anymore, and not attempting to break into their open ports. However being in the US on vacation, and not being a US citizen, I don't really feel like putting myself in danger.

So what do GC, this is a multi-billion dollar hotel chain, that has very critical security flaws just out in the open. I've done this sort of thing before and have been threatened to be arrested and tried in court. The main difference is that I wasn't at the actual location, and was hiding myself.

Anyone telling me to go malicious: Suck a dick.

#2
phil3

phil3

    Furious Magician

  • Registered
  • 1,651 posts
Email maybe. I'm sure you know how to work some proxy magic to cover your tracks.

#3
HSO Bandages

HSO Bandages

    Gone like Houdini

  • Registered
  • 2,093 posts
Maybe leave a note ?

#4
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

Email maybe. I'm sure you know how to work some proxy magic to cover your tracks.


Yea I'm pretty sure that's what I'm goingg to do; What I'm worried about is them then checking through their internet logs, and finding out who was doing the packet sniffing and port scanning.


@HSO: Lol, than when I'm on my way to the airport, they could place a warrant for my arrest and I could get pulled over at customs.

#5
Omega369

Omega369

    Registered User

  • Registered
  • 2,731 posts
I would use my powers for evil

#6
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

I would use my powers for evil


I would argue that opening wireshark, and zenmap isn't really having any powers.... But hey, to each their own.

#7
BigNinjaFoo

BigNinjaFoo

    That guy from Washington

  • Registered
  • 652 posts
As Nirvana would say..Come as you are

#8
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

As Nirvana would say..Come as you are


So you're saying go report it?

#9
nate256

nate256

    Professional

  • Registered
  • PipPipPip
  • 72 posts
Tell me which hotel and I will go further investigate this situation ;)

#10
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

Tell me which hotel and I will go further investigate this situation ;)


Too bad each hotel under this chain will have different internal networks, as they aren't hosted on the same data center.

Lear moar pl0x than reply here :)

#11
nate256

nate256

    Professional

  • Registered
  • PipPipPip
  • 72 posts
But for real just ignore it, they are not paying you to secure their network so it is not your problem. Maybe say you will offer some security tips if your stay is free ;)

#12
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

But for real just ignore it, they are not paying you to secure their network so it is not your problem. Maybe say you will offer some security tips if your stay is free ;)


I've reported security holes to websites before just because I felt like it, and I've been paid before. Same thing could happen this time.

#13
Jumbo

Jumbo

    Pro Bong Packer

  • Registered
  • 5,911 posts

I've reported security holes to websites before just because I felt like it, and I've been paid before. Same thing could happen this time.


i would be doing this every where just to make some cheddar.

id be hustling everyone for money lol :smoke:

#14
dawnofwar

dawnofwar

    Banned

  • Banned by Moderators
  • 3,299 posts

i would be doing this every where just to make some cheddar.

id be hustling everyone for money lol :smoke:


It works quite well, get a little good at Social Engineering, and you can almost convince admins to toss you a little denero for reporting them vulns :3

#15
SunStoner

SunStoner

    Corruption in Disguise

  • Registered
  • 271 posts
I work for a hotel the owner is very cheap. IF it costs money he wont pay for it.

#16
flapjack1439

flapjack1439

    Registered User

  • Registered
  • 949 posts
send an email to the manager from the manager saying how shitty their security is

#17
Fëanor

Fëanor

    Lazy Blunt-Lover

  • Old School
  • 6,806 posts

Yea I'm pretty sure that's what I'm goingg to do; What I'm worried about is them then checking through their internet logs, and finding out who was doing the packet sniffing and port scanning.

If their network security is as loose as you say it is, it's unlikely they are logging any sort of network traffic (costs a lot of $ for a setup like that).

I would say e-mail them after you get home, with some evidence you gathered showing the weaknesses. Maybe wait a while so they don't know you were just at the hotel.

Open ports or not, I still highly doubt that they are transmitting unencrypted credit card data. Keep in mind that for inbound network connections to function, a port needs to be open. For example having SSH open still means that they can only connect to an SSH daemon and must go through SSH authentication to do anything.

#18
RooRgle

RooRgle

    Senior Member

  • Registered
  • 1,530 posts
Same as Sun Stoner, I just left my job at a hotel, we had roaches infesting our LL employee areas, it was fuggin disgusting.

They are probably too cheap to care...it's sad, but the hotel business is dirty.

#19
Thewastedyouth

Thewastedyouth

    Hey beautiful stranger...

  • Registered
  • 1,291 posts
I thought this thread was gunna be about peepholes where people can watch sex through the wall!

#20
blackleaf28

blackleaf28

    Registered User

  • Registered
  • 1,288 posts

I thought this thread was gunna be about peepholes where people can watch sex through the wall!


honestly i did too




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users