MoviePass,Watch online Dangerous Sex Games (2005) the cinema subscription service that's gone from "This is too good to be true" to "What is even going on I'm so tired" in a series of reinventions, has had another setback.
The company left thousands of customer card details, and tens of thousands of customers' credit card details, visible on a server that was not password protected, according to a security research firm.
The database, which a reporter from TechCrunch observed "growing in real time," contained more than 161 million records and counting, ranging from logging details generated in the course of a normal running day to unencrypted user details. Credit or debit card details were available, too, including card numbers, expiration dates, cardholder names, and billing addresses in plaintext.
MoviePass customer cards are basically MasterCard-issued debit cards; customers pay the monthly fee, and the service loads up the cards with the price of a movie ticket when a screening is booked, so subscribers can then buy them at the box office with the card.
(A MoviePass card could technically be used to make any debit purchase, users theorise, although it would get the account holder banned pretty swiftly.)
This Tweet is currently unavailable. It might be loading or has been removed.
The unprotected dataset was detected by systems developed by Dubai-based firm spiderSilk, and confirmed manually by the firm's security team before they notified MoviePass, which did not respond.
Security researcher Mossab Hussein told Mashable while his team can't tell for sure whether the database had been accessed by other parties, they estimate the number of credit cards that could be exposed in the dataset runs into the tens of thousands, in addition to around 50,000 MoviePass cards.
SEE ALSO: A new limited MoviePass offer comes close to the tantalizing original plan"Simple best practices should have prevented any of this from happening in the first place," Hussein said. "But we see a lot of companies not worrying as much as they should, when it comes to 'internal tools' and 'internal logging.' And they justify this by saying something along the lines [of] 'Oh, it's only for internal use and analysis.'"
Mashable has contacted MoviePass's parent company Helios + Matheson for comment on the exposure, including the reasons why the database was only taken offline after TechCrunch notified them of the issue and not when Hussein reached out over the weekend.
"We've seen companies that took 30 days to acknowledge a finding, and we've also seen companies that acknowledged and patched a finding within 60 minutes," Hussein said. "But our position has always been very strict about this topic. Companies panic and respond in seconds if their apps are down ... they should treat the safety of their customer data just the same."
Topics Cybersecurity
This is the first Indian city to install sanitary pad vending machines on a large scaleCows, spiders and dogs kill more people in the U.S. than alligatorsTravelers beware: Zika not covered by some travel insurance plansTwitter reports $100 million net income, flat user growthMcDonald's is launching its own currency because of courseRoseanne Barr apologizes to Valerie Jarrett (kinda) before saying she needs a new haircutAmazon finally makes collaborative wish lists a realityHow Hannah Gadsby's 'Nanette' made it to NetflixHeat waves scorching Europe were given a boost by global warmingWatch this Nest Cam catch a truly 'terrifying" home invaderGripping video offers a firstRoseanne Barr apologizes to Valerie Jarrett (kinda) before saying she needs a new haircutCalvin Harris and Taylor Swift shake off all social media traces of their relationshipOn North West's third birthday, we honor her growing personal brand2 'Doctor Who' actors hugged IRL and fans were like woahTaylor Swift and Tom Hiddleston are KJustin Bieber calls on his Belieber army to silence the pressCalvin Harris and Taylor Swift shake off all social media traces of their relationshipTom Cruise movies make more money when he's running, hard data proves'Mission: Impossible' led to another round of headaches for MoviePass Kellyanne Conway follows @NoToFeminism, but does she get the joke? Granddad, believed to be the world's oldest aquarium fish, dies in its 90s I ran speed tests on Sprint's 5G network and recorded everything YouTube will now let you auto Rachel Maddow has been cast in CW's 'Batwoman' The fall heat wave was gnarly Simone Biles nails signature dismount, now known as 'The Biles' Walking Dead spin In blow to Facebook, PayPal pulls out of Libra cryptocurrency project A new icon in the iOS 13.2 beta hints at noise Daniel Craig's James Bond is back in the first 'No Time To Die' poster Veterans group has some advice for Donald Trump in powerful new video A climate change: an unstoppable movement takes hold Pray for Trumble: A sinkhole opened up near the Australian PM's house Tesla finally has Spotify, but there are other hacks for the Model 3 screen 'Joker' is nothing to smile about: Movie review Chrissy Teigen had a very Chrissy Teigen response to her Super Bowl nip slip Drake unleashed a passionate rant against Trump during a London tour stop Woman begs senator to vote against DeVos with pizza delivery Instagram now lets you shop with augmented reality
2.618s , 8222.4765625 kb
Copyright © 2025 Powered by 【Watch online Dangerous Sex Games (2005)】,New Knowledge Information Network