microsoft
Report a problem

Bing cashback exploit discovered, Microsoft sends in lawyers

Tom Warren   on 10 November 2009 - 14:09 · 29 comments & 7877 views

Advertisement (Why?)
A Bing cashback vulnerability has been discovered by Samir Meghani of the Bountii Team.

The flaw exists due to a software API oversight that allows users to fake transactions to Bing. Currently, Bing does not detect these faked transactions. The flaw affects both the customer and merchant. According to Samir, in his original posting, "merchants have a few options for reporting, but Bing suggests using a tracking pixel. Basically, the merchant adds a tracking pixel to their order confirmation page, which will report the the transaction details back to Bing." Samir detailed that the process was flawed but didn't pin point exactly how to generate fake transactions.

Bing Cashback is an initiative that pays people to search with Bing. Customers can also get cashback rewards, meaning you could get cashback from online purchases made when Bing is used.

In a follow up post over the weekend entitled "Surrendering to Microsoft", Samir posted a legal letter from Microsoft's legal team demanding he remove the original blog post to which he complied. Microsoft also terminated Samir's Bing cash back account. Some may argue that this is a heavy handed approach but clearly Microsoft doesn't take kindly to fraud.



Thanks to Jugalator for the news tip

Post a comment · Send to friend Comments · There are 29 additional comments
(4 replies) #1 SmNet on 10 Nov 2009 - 14:12
lol now lets see how he reacts
#1.1 Jugalator on 10 Nov 2009 - 15:57
He pulled his blog post, and MS shut down his account. I don't think more will happen here.
#1.2 SmNet on 10 Nov 2009 - 18:54
actually!

"The post is gone. I will still write a “non-technical” post on all the problems I see with Bing Cashback in the next few days."
#1.3 MaJoR on 10 Nov 2009 - 21:59
He was making money with this error, and nice enough to point it out and not reveal how to do it. If I was making money from a website the last thing I would do is tell the site it was broken! So he did something very nice by pointing the out the error.

But despite his benevolence, MS got all ticked off. They should have worked with him to figure out the ins and outs of the error then shut it down, and allow him to continue doing what he was doing as a reward and to stimulate them to fix it quickly. Instead, they vilified him. There is only one option left to him: reveal how to steal money from MS to the rest of the world. They could lose a ton before MS swats the problem.
#1.4 M_Lyons10 on 11 Nov 2009 - 02:17
MaJoR said,
He was making money with this error, and nice enough to point it out and not reveal how to do it. If I was making money from a website the last thing I would do is tell the site it was broken! So he did something very nice by pointing the out the error.

But despite his benevolence, MS got all ticked off. They should have worked with him to figure out the ins and outs of the error then shut it down, and allow him to continue doing what he was doing as a reward and to stimulate them to fix it quickly. Instead, they vilified him. There is only one option left to him: reveal how to steal money from MS to the rest of the world. They could lose a ton before MS swats the problem.


Yeah, having not seen the blog I can't come to a conclusion on it, but it does seem like he did the right thing. I don't know all the facts though of course, so who knows.
(1 reply) #2 GreyWolfSC on 10 Nov 2009 - 14:26
I don't think responding to fraud is "heavy handed."

Last edited by GreyWolfSC on 10 Nov 2009 - 15:08
#2.1 M_Lyons10 on 11 Nov 2009 - 02:18
No, if that was in fact what was occurring, I see nothing wrong with the response. We don't of course know what the situation entailed. It seems like the assumption (As it tends to be) is that Microsoft is just wrong... LOL
#3 SojIrOu on 10 Nov 2009 - 14:28
I spot a typo in the letter. lol.
(4 replies) #4 BaZurk on 10 Nov 2009 - 14:33
You have to love Microsoft I personally love their software but hate when they act like this. Fix the damn mistake and dont jump down the guys throat who caught it or next time he wont bother to post it, just exploit it.
#4.1 Julius Caro on 10 Nov 2009 - 14:39
BaZurk said,
You have to love Microsoft I personally love their software but hate when they act like this. Fix the damn mistake and dont jump down the guys throat who caught it or next time he wont bother to post it, just exploit it.


Well, if he's a merchant that uses bing cashback (or whatever the hell that is), it makes more sense that he reports it to microsoft instead of divulging the vulnerability. After all, if he's a merchant it's in his best interest that people don't cheat the whole thing
#4.2 DarkNovaGamer on 10 Nov 2009 - 19:01
BaZurk said,
You have to love Microsoft I personally love their software but hate when they act like this. Fix the damn mistake and dont jump down the guys throat who caught it or next time he wont bother to post it, just exploit it.


If he had good intentions he would have reported it directly to Microsoft. Obviously he did not post it with good intentions. Maybe you should open your eyes and realize not everyone these days do things for good.

Microsoft did the right thing, they gave him a chance to take it down before creating any legal action.
#4.3 daPhoenix on 10 Nov 2009 - 20:10
DarkNovaGamer said,
If he had good intentions he would have reported it directly to Microsoft.

So Microsoft can keep their "we have no security problems" track record while blaming everyone else?

Tsk tsk.
#4.4 M_Lyons10 on 11 Nov 2009 - 02:20
daPhoenix said,
So Microsoft can keep their "we have no security problems" track record while blaming everyone else?

Tsk tsk.


What? I would say that reporting it to the company who develops whatever has a security vulnerability, is not only common practice, but appropriate. I see nothing wrong with expecting that at all...
#5 +Anarkii on 10 Nov 2009 - 14:46
If I ever got a letter like that from lawyers in the USA id reply to them in the same fashion as the pirate bay did lol. But then again I dont live in America where they actually can make good on the threats carried within...
(5 replies) #6 XerXis on 10 Nov 2009 - 14:53
standard response from Microsoft (and imho nothing wrong with it) he should have reported the bug to microsoft instead of posting about on his blog.
#6.1 DomZ on 10 Nov 2009 - 15:39
He has no obligation to report the bug to microsoft, and as far as I am concerned he can post whatever he likes on his blog.
#6.2 GP007 on 10 Nov 2009 - 16:12
So if he happend to come accross some private data about you or others and just decided to post it on his blog that'd be fine right?

We're not talking about a simple matter of finding a security bug in some app, this bug can be used to basically steal money. It's on a different level, and MS acted in the best interest of themselves and any customers who use the servers and could be taken advantage of.

You don't go arund posting the bank vault code and think no one will care about it.

#6.3 Nick Brunt on 10 Nov 2009 - 16:19
+1 to GP007.

Sometimes it's not about what is lawful or not, sometimes it's just about what is the right thing to do. He should have told Microsoft privately.
#6.4 XerXis on 10 Nov 2009 - 17:13
DomZ said,
He has no obligation to report the bug to microsoft, and as far as I am concerned he can post whatever he likes on his blog.


the first part is true, he doesn't have the obligation to report back to microsoft, however he also doesn't have the right to post about it on his blog
#6.5 M_Lyons10 on 11 Nov 2009 - 02:24
Nick Brunt said,
+1 to GP007.

Sometimes it's not about what is lawful or not, sometimes it's just about what is the right thing to do. He should have told Microsoft privately.


+1 Exactly.
(2 replies) #7 +d4v1d05 on 10 Nov 2009 - 15:28
Maybe Microsoft should remove the cached page from Bing? I can still see how to do it, all thanks to Microsoft themselves
#7.1 Nick Brunt on 10 Nov 2009 - 16:20
oh the irony
#7.2 Galactor963 on 10 Nov 2009 - 16:36
Haha, just came here to say that. Slashdot links over to it. Looks like it'll be hard to fix, considering it's the basic way the system works, as outlined in the SDK.
(2 replies) #8 tuxplorer on 10 Nov 2009 - 15:29
The pulled down post from his blog is a search away from Google.
#8.1 Jugalator on 10 Nov 2009 - 16:00
Yes, MS need to fix this now. It's posted elsewhere online now too.
#8.2 GP007 on 10 Nov 2009 - 16:13
For now they can stop the cashback service until they fix the API. Even if it's posted I don't think you can take advantage of it now.
#9 Nicholas P. on 10 Nov 2009 - 17:22
Haha! LOL
#10 Growled on 10 Nov 2009 - 19:01
I guess he'll know better than to post it next time.
#11 mixdrink on 11 Nov 2009 - 03:59
this show how stupid he was.

As far a i know, he has no obligation to whether reporting the bug to microsoft or not, and who care. But by law he can't post in his blog ppl how to steal money. it's consider as fraudent. MS did a right thing, and that was a formal response in regarding to the post on is blog. and MS did gave him a chance to remove it instead, they sueing him for showing ppl how to steal the money.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)