Sun or Thurs Run Security issues @ Invicta

View previous topic View next topic Go down

Sun or Thurs Run Security issues @ Invicta

Post by timesonmyside on Thu Feb 10, 2011 10:36 pm

Another royal IWG cluster fuck
02-06-2011, 07:41 AM

TeamInvicta
WatchGeeks VIP
Senior Geek Join Date: Mar 2008
Posts: 321

Sunday Run - message from Eyal

--------------------------------------------------------------------------------

Hi everyone, I wanted to drop a quick note after getting updates all night on the Sundayrun status. Our team has been all over this technical issue, they acknowledge there was a problem with the NEW Sundayrun credit card approval portion of the site. This is related to a “fraud prevention” parameter which we set in place for security purposes. For some technical reason it is not allowing all credit cards (including mine) from being approved instantly, thus not updating the sale availability of products. The problem is now with our bank processor and will only be resolved during “normal business hours”…… All orders attempted unil now will be canceled, no credit cards will be charged and we will start fresh. I am planning to approve a special THURSDAY run with ridiculous offers to make up for this one. More to come – Have a great Super bowl Sunday everyone. Eyal
_________________________________________________________________
Arktander
WatchGeeks Moderator
True WatchGeek Join Date: Mar 2008
Location: Central Illinois
Posts: 9,074
Real Name: David


[Official Thread] BIG THURSDAY RUN -- February 10, 2011

--------------------------------------------------------------------------------
Remaining Security Concern (Invicta Admins Please Read)

--------------------------------------------------------------------------------

I just completed a Run purchase while using Fiddler2 to monitor traffic between my browser and the server. The problem from last night, in which the checkout page where you enter your credit card info was not secured, is fixed as noted elsewhere. That page is now secure and uses HTTPS (SSL) both for page delivery and credit card info submission.

Unfortunately, a problem evidently remains.

The "Check Your Order" page on which you confirm your purchase is NOT secure. This page contains a summary of your order, INCLUDING YOUR CREDIT CARD NUMBER, along with a "CLICK HERE TO PURCHASE" button. The server delivers this page to your browser in the clear, presumably via HTTP 302 redirect at the end of the HTTPS portion of the checkout process, using this URL:

http://www.invictasundayrun.com/checkout/check_order

Note that the URL begins with "http" and not "https". This is NOT a secured page, and the browser accordingly displays no secured page indications. Anyone can verify this easily in their browser.

I've copied below the entire HTML of an example "Check Your Order" page, as captured by Fiddler2. The only changes I made are to my personal information, including replacing my actual credit card number with "X" characters. The fact that Fiddler2 can display this HTML in plain text means by definition the page is not secure, since Fiddler2 is simulating a man-in-the-middle attack and would not be able to display the data were it encrypted.

In summary, the Sunday Run checkout process is only HALF secure. Which of course means it ISN'T secure. The phase in which your browser sends your credit card info TO the server is secure as of this morning. The phase in which your browser receives the "Check Your Order" confirmation page FROM the server is NOT secure.

I hope the Invicta Sunday Run admins will resolve this remaining hole. Every communication between browser and server containing sensitive customer information, regardless of direction, must be secured using HTTPS (SSL). I highly recommend network traffic sniffing techniques such as the one I employed as a primary tool in VERIFYING web commerce site security.

Thanks for reading,
David




timesonmyside
Member

Join date: 2010-04-04

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by Mark on Fri Feb 11, 2011 3:01 am

ohhh he is my hero.. Arktander that is.

Mark
Member

Join date: 2010-06-12

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by Datsun240Z71 on Fri Feb 11, 2011 3:40 am

Why would anyone think IWG can do anything right?
Another example of their highly touted "attention to detail".


Last edited by Datsun240Z71 on Fri Feb 11, 2011 10:19 am; edited 1 time in total

_________________
Randy in Nashville

I never drink water; fish make love in it.

WC Fields

Datsun240Z71
Member

Join date: 2010-02-10
Age: 55

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by boscoe on Fri Feb 11, 2011 7:58 am

LMAO - Invicta wants prompt customer service from its bank!
The computer code to fix things is coming from overseas... in six months!

_________________
If I feed you a line of bullshit and take your money, I'm not a liar or a thief, I'm a salesman. - Eyal "Swiss Made" Lalo


boscoe
Member

Join date: 2010-04-01

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by Seattle on Fri Feb 11, 2011 8:41 am

A little sketchy giving Invicta your credit card info.....

_________________
“I like your Christ, I do not like your Christians. They are so unlike your Christ.” — Gandhi

Seattle
Member

Join date: 2010-09-06

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by DX on Fri Feb 11, 2011 8:45 am

Inflicta strikes again...

2011 is a great year for WL's

_________________
“Being shot out of a cannon will always be better than being squeezed out of a tube. That is why God made fast motorcycles, Bubba…”
― Hunter S. Thompson

DX
Member

Join date: 2010-11-07
Age: 90

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by Falstaff on Fri Feb 11, 2011 8:55 am

Chinese year of the Rabbit! As the stars align all things Chinese with fuzzy bunnies, hilarity ensues. A banner year, no doubt.

Falstaff
Member

Join date: 2010-09-01

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by svoglic on Sat Feb 12, 2011 12:43 am

Some are complaining that when they ordered and the site crashed, they kept hitting I want it until they were allowed into the payment page. It looks like, if their order crashed 10 times until they finally got in, then they were charged 10 times. It sucks to be in love with Invicta. I wonder how many of them were over their credit card limit because of this and will get charged for that.
There is all this information on Watch Geeks about the security of the site and over charges and still they line up for the next Sunday Run.
I wonder how many of them have to wear a helmet to keep from licking the TV screen when Jim and Michael are on Shop?

svoglic
Member

Join date: 2010-12-01

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by bigedsurf on Sat Feb 12, 2011 4:27 am

I wonder how many of them have to wear a helmet to keep from licking the TV screen when Jim and Michael are on Shop?


svoglic

Posts: 63
Join date: 2010-12-01

View user profile Send private message

Back to top


_________________
time flies........

bigedsurf
Member

Join date: 2010-07-25
Age: 91
Location: indiana

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by svoglic on Sat Feb 12, 2011 9:58 pm

Uh oh, this isn't good at all!
Sundays SR new issue.

Today, 05:46 AM
*coolness*
Senior Member
Senior Geek Join Date: Mar 2010
Location: Ohio
Posts: 138
Real Name: Christopher



--------------------------------------------------------------------------------

Not a good sign - I entered my CC info and hit Submit. The next page did not have an S (http://www.invictasundayrun.com/checkout/check_order) and worse yet - it said that my transaction would be charged to a Mastercard ending in 4 digits that are NOT mine.

It then said if everything was correct, to click on the Click Here To Purchase. I did not. But the worry now is, was the CC info submitted openly over the internet? And whose card number was that they listed the last 4 digits of? With all the delays and crashes and concerns tonight, I guess I should've known better than to try this.
__________________
When we first met, me and you, you thought I was common. How right you was, baby. I was common as dirt.


svoglic
Member

Join date: 2010-12-01

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by dude on Sun Feb 13, 2011 12:14 am

Invicta has shit for personel. Cheap fuckers.

You pay peanuts, you get monkeys.

_________________
_____________________________________________


dude
Member

Join date: 2010-06-03

Back to top Go down

Re: Sun or Thurs Run Security issues @ Invicta

Post by Mark on Sun Feb 13, 2011 3:41 am

The whole Invicta problem is Eyal being CHEAP. Use the cheapest of the cheap and this is what you get. I would be he is using some Honduran web programmer for 50 bucks a day.

The web programmer does not know what https is but who gives a shit cause giving your CC info to that company is a "YOUR FUCKED" move anyway.

Mark
Member

Join date: 2010-06-12

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

Permissions in this forum:
You cannot reply to topics in this forum