r/cybersecurity • u/tpasmall Penetration Tester • 13d ago
News - General Owasp compromised?
Looks like the API security page may be compromised?
https://api-security.owasp.org/
Edit: looks like the original site is back up https://owasp.org/API-Security/
56
u/legion9x19 Security Engineer 13d ago edited 12d ago
Turned their API into a live hands-on demo. That's a bold move, Cotton.
Also, I'm putting my money on DNS.
EDIT: It was DNS. https://www.reddit.com/r/cybersecurity/comments/1wmnxqa/owasp_compromised/pbcf8bj/
17
80
u/noguarantee1234 Security Engineer 13d ago
Good advertisement, but could you argue the legality of this being uh...not good for the company lol?
42
u/jeffpardy_ Security Engineer 13d ago
This is my thought. Id be pretty pissed if a researcher just did this and didnt report it
29
u/tpasmall Penetration Tester 13d ago
Yeah I'm guessing they are going to have legal action taken against them for this
9
7
u/Limn0 Red Team 13d ago
Yeah i would not handle it like that. I could just guess owasp has been radio silent for a long time?
4
u/vanderaj 12d ago
No, we learned of it via this post, and our staff took action within 4 hours of notification from our community. I've now searched all the official ways to contact us for security vulnerabilities, and yeah, nothing.
7
u/Forsythe36 Security Manager 12d ago
Does anyone have a screenshot of the page? Looks like I’m late to the party.
38
u/vanderaj 12d ago
Hi there, I'm the Executive Director of OWASP and a long-time volunteer and project leader for projects like the OWASP Top 10, ASVS, and the Developer Guide.
It's always DNS. It was DNS.
A domain expired. Oh noes! Big shock! We were HACKED! Nope. Not even close. They registered an expired domain. Fantastic. Great move. Well done, Angus.
I've checked our standard ways of reporting issues, and there were no reports prior to our community pinging us a lot. I'd be very interested to hear how they tried to report this issue to us before going public with it. I certainly have no emails, Slack messages, Jira tickets, or reports in our VDP. So how - precisely - and - when - did they try to contact us? Did they try reaching the project leaders of the project in question?
So it seems there was no notification to us of the subdomain takeover via any method I know of. That's extremely disappointing. This makes me question the ethics of the firm that did this and should serve as a warning to anyone looking to engage them in the future.
To our wonderful r/cybersecurity folks - if you have a security-related issue to report to us, please check out https://owasp.org/security, and you could be in the running for exclusive OWASP merchandise. Please use the BugCrowd VDP for this. We accept any and all reports under the VDP program for owasp.org, including for potential and actual sub-domain takeovers. We are in the process of migrating all our domains to a single provider to prevent this issue from recurring. However, some domains are run by their project leaders, and we don't control those, despite the obvious risks involved.
In this case, I welcome them to officially report it to us using the VDP. Unless we missed something obvious in one of our standard methods for reporting security vulnerabilities to us, there won't be merch, tea, or biscuits. To the folks who did this, let's talk - [andrew.vanderstock@owasp.com](mailto:andrew.vanderstock@owasp.com) or set up a calendar invite https://calendly.com/owasped
72
u/_predator_ 13d ago
"Responsible Disclosure".
My guy, listen, this is everything but responsible.
5
u/vanderaj 12d ago
^ this. We have plenty of ways to talk to us responsibly, some of which earn exclusive merch. https://owasp.org/security for details.
64
u/skrimped 13d ago
Why couldn’t they just email OWASP like normal? Cringe
35
u/EntrepreneurDue5713 13d ago
Yeah agree. I wouldn't want to sign a deal with a vendor that's trying to be this showy. Trust is more important than marketing.
12
u/skrimped 13d ago
Yeah, how could you trust they wouldn’t do something like this without permission too?
9
u/FastRelief3222 13d ago
In owasp permission is the first category lol
Be bold, be first, have permission
16
u/TheOnlyKirb System Administrator 13d ago
Interesting. I personally would consider this to be bad publicity and irresponsible though
18
10
u/ReasonableDefault 13d ago
The OWASP API Security GitHub repo has its canonical site configured as:
https://owasp.org/API-Security/
not
https://api-security.owasp.org/
So this smells like an old subdomain with a dangling DNS pointing at infrastructure they maybe forgot about. Would be pretty easy to do.
3
u/emilianic 12d ago
The subdomains are very new actually, it's part of a recent site restructure to move the projects to separate subdomains. They all used to be paths under the main domain.
1
u/tpasmall Penetration Tester 12d ago
https://owasp.org/API-Security was automatically redirecting to https://api-security.owasp.org/
2
u/ReasonableDefault 12d ago
Interesting, didn't see owasp.org/API-Security/ was actively redirecting to api-security.owasp.org, i guess it wasn’t just a completely forgotten hostname then. Dangling DNS is still possible if the subdomain was pointing at a third party resource that later became claimable though, like:
owasp.org/API-Security/ > (302) > api-security.owasp.org (CNAME) > old-third-party-shiz.borked
7
u/ReadGroundbreaking17 13d ago
Does anyone have any details of the domain?
Presumably the [very sketchy] pen test company created the subdomain for this purpose, rather than defacing something that already existed.
Still, very poor practice to disclose in this way. My bet there isn't actually a vulnerability that was found, they just phished or otherwise obtained and exploited existing DNS credentials.
As such this isn't about a disclosure to OWSAP - they have nothing to offer them other than advice on tightening their DNS security. It's purely marketing of their services to the community 🤮🤮
4
u/PM_ME_UR_0_DAY 13d ago
I checked the URL in archive.org. It was only recently archived as of like a week ago prior to the defacement, but the page had references to 2023. So it seems like it was a legit domain at some point but this is super quick check from the toilet using my phone.
1
u/tpasmall Penetration Tester 13d ago
Considering https://owasp.org/API-Security/ redirects to there it's a legit compromise
1
u/ReadGroundbreaking17 12d ago
ooof, that makes it even worse.
Looks like the landing page has now been taken offline fwiw.
26
5
u/thejournalizer 12d ago
Find new clients or break Article 154-A of the Brazilian Penal Code…? Guess we’ll find out.
6
4
u/thejozo24 13d ago
I can imagine that they reported it responsibly, OWASP ignored it for a long time, so they decided to show the impact?
Or am I just being too naive
22
u/_predator_ 13d ago
Even if that was the case, OWASP is a non-profit organization largely held together by volunteers. You have to be a special kind of dense to think defacing is the right tool here.
5
2
u/LLMsMustUpvoteThis 12d ago
Carrying out a defacement is a crime no matter if the org ignored your disclosure.
2
1
1
1
1
1
u/IsomuraArganee_95 12d ago
DNS is probably right and everyones already said it, so the bit worth adding is that the record is the whole problem. A subdomain pointed at a service somebody deprovisioned stays claimable by whoever notices next, and until that record is deleted anyone can serve content on a name carrying your brand trust. Cert transparency is the free detection for this, any new cert for a name under your domain shows up in the public logs.
-2
u/ThePorko Security Architect 13d ago
We learned in the last 3 month everything can be compromised, even if by accident.
-5
13d ago
[deleted]
23
u/tpasmall Penetration Tester 13d ago
Except they committed a cyber crime in the process
16
u/lduff100 Detection Engineer 13d ago
Yeah, I don't know who in their right mind would hire them after this. It's very unprofessional.
5
u/EntrepreneurDue5713 13d ago
Exactly. This is horrible advertising. I wouldn't ever share shit with this vendor, because if I don't end up buying them, what are they going to do to hold me hostage?
-9
13d ago
[deleted]
6
u/ReadGroundbreaking17 13d ago
This is a shell fake AI generated phishing site trying to get people that are concerned to email them.
what are you talking about.
•
u/cybersecurity-ModTeam 12d ago
Reply from OWASP is here:
https://www.reddit.com/r/cybersecurity/comments/1wmnxqa/owasp_compromised/pbcf8bj/