[HN Gopher] Drop Table "Companies";- LTD (2016)
___________________________________________________________________
Drop Table "Companies";- LTD (2016)
Author : nojs
Score : 163 points
Date : 2023-08-03 17:04 UTC (5 hours ago)
(HTM) web link (find-and-update.company-information.service.gov.uk)
(TXT) w3m dump (find-and-update.company-information.service.gov.uk)
| superluserdo wrote:
| See also https://find-and-update.company-
| information.service.gov.uk/c...
|
| >THAT COMPANY WHOSE NAME USED TO CONTAIN HTML SCRIPT TAGS LTD
|
| >Previous company names
|
| >[NAME AVAILABLE ON REQUEST FROM COMPANIES HOUSE]
|
| https://forum.aws.chdev.org/t/cross-site-scripting-xss-softw...
| rendx wrote:
| For a moment I thought the previous company name was "[NAME
| AVAILABLE ON REQUEST FROM COMPANIES HOUSE]".
| SilasX wrote:
| I think the whole problem is that, based on conventions for
| communicating this stuff, you can't always rule that out.
| benlivengood wrote:
| I wonder what happened to it; maybe there's another company named
| "; UPDATE COMPANIES SET STATUS='DISSOLVED' WHERE ID=10542519;--
| LTD"
| sdflhasjd wrote:
| There's a piece of software that's used by insurance companies
| for providing online quotes that (used to) contain some pretty
| egregious SQL injection vulns.
|
| When this was discovered during the development of an
| integration, their solution wasn't to fix the disgusting
| spaghetti of SQL functions causing it, their recommendation was
| to use Javascript to remove any special characters from html
| inputs.
|
| _HEAD DESK_
| qingcharles wrote:
| Back in 2000 Coca-Cola had an auction site. I put a HTML comment
| tag in my username and the words "AUCTION ENDED". The result of
| which was that whenever I bid on anything it would erase the bid
| submit button after my name -- therefore no-one else could bid on
| anything.
|
| https://web.archive.org/web/20010223090106/http://cokeauctio...
|
| This worked for a short time. Then my account disappeared with
| all my (very hard earned) credits in it. Then I received a letter
| from the MD of Coke UK telling me I was a very naughty boy.
| henrydark wrote:
| Similarly, in 2003, they had some code-under-caps promotion. I
| wrote a script to submit thousands of random codes to the
| website, and subsequently someone from Coca-Cola NZ called my
| home. They calmed down when my dad said I wasn't home, but at
| school.
|
| Mind you, in 2002 no called, and I got a free shirt and a
| folding chair.
| ben_w wrote:
| > I wrote a script to submit thousands of random codes to the
| website, and subsequently someone from Coca-Cola NZ called my
| home.
|
| I managed to get a phone call and a personal visit from a
| script.
|
| Much less interesting than it sounds: I was downloading
| satellite data from NASA, the increased bandwidth use worried
| the sysadmin in my research lab, and we each had landline
| phones on our desks because this was the mid-noughties.
| OhMeadhbh wrote:
| I got my TI-99/4 confiscated by law enforcement when, after
| watching War Games, I wrote a script to "war dial"
| connection strings on the local Tymnet POP. Turns out one
| of the systems I connected to was the backend clearing
| system for Credit Suisse. They were neither happy nor had a
| sense of humor. After logs showed I didn't try to steal
| money or do anything damaging I got my computer back in a
| couple of weeks.
|
| A couple of takeaways:
|
| a. Credit Suisse did not have a username / password to log
| in. They were using "security by obscurity" in 1980.
|
| b. The local FBI guys in Dallas didn't know you could
| purchase a modem for a couple hundred bux and hook it up to
| a $1000 personal computer. They seemed truly surprised to
| discover I wasn't part of a well-funded white collar crime
| syndicate and just a kid in jr. high school whose parents
| eventually gave in when I begged for a modem for a couple
| months.
|
| c. You can apparently do damage to your reputation at 300
| baud.
| stevehawk wrote:
| > c. You can apparently do damage to your reputation at
| 300 baud.
|
| lol. that's a great line.
| reaperducer wrote:
| In the 1980's, the New York State Police visited the
| local police department in the town I lived because of
| some dialup mischief I caused. The local police chief
| toldd them he'd handle it.
|
| The lesson I learned was to do a better job of covering
| my tracks. But I stayed away from that mainframe after
| that.
|
| The things many of us did to learn about computers back
| then would get someone prison time today.
| blantonl wrote:
| In the early 90's I worked for Louisiana State University's
| AG Center purchasing department and had a mainframe TSO
| account. I figured out how to use Gopher to various other
| research universities and download weather satellite photos
| and other various weather data (sometihng I was interested
| in at the time). I was then able to subsequently use Zmodem
| downloads over a 3270 dial up session to do this from home.
| I thought being able to get this info was pure magic at the
| time, since it was primarly only available to researchers.
|
| My supervisor got the next month's TSO departmental
| chargeback bill for my user account from the University's
| IT group, and it was tens of thousands of dollars of TSO
| time :). They told me "don't do that anymore"
| Dwedit wrote:
| Around this era, you could make posts on message boards where
| your subject was all spaces, and make an unclickable post.
| smcleod wrote:
| Bidding on a "cokeauction" is a very different thing in 2023.
| nchase wrote:
| What is a cokeauction in 2023?
| smcleod wrote:
| I assume it would be something folks would do on the dark
| web.
| sdflhasjd wrote:
| > Then I received a letter from the MD of Coke UK telling me I
| was a very naughty boy.
|
| Truly better than any prize. I got a similar letter from my
| school's headteacher after some extracurricular IT shenanigans.
| I'm still proud of that one.
| justinator wrote:
| Somewhat related, in '99 my school gave everyone shell
| accounts, so they could check their email through pine. But the
| shell accounts were pretty functional with access to command
| line tools, such a perl.
|
| It took me a lot of restraint not to harvest everyone's
| usernames (which was just the name of the home directory easily
| grokked) and email everyone at username@highered.edu (since
| sendmail was also available) something silly during winter
| break- like the fact that flooding had happened in the dorm
| rooms, and that everyone would have to move out before Spring
| semester due to needed maintenance and everyone will receive
| $500 in compensation because everyone's stuff in their dorm was
| destroyed.
|
| Surely I would have been expelled, but what a story to tell my
| next employer.
|
| Anyways, looking for a QA job if anyone's hiring. I would like
| to break your stuff.
| nidnogg wrote:
| Appears on Linkedin [1] as well, albeit automatically generated
|
| [1] https://www.linkedin.com/company/-drop-table-companies----
| lt...
| politelemon wrote:
| A company used to have an xss attack in its name.
| https://www.theregister.com/2020/10/30/companies_house_xss_s...
|
| They changed it and you can only see the old name upon request
|
| https://find-and-update.company-information.service.gov.uk/c...
| TazeTSchnitzel wrote:
| To stop this happening again, the Economic Crime and Corporate
| Transparency Bill (which hasn't finished going through
| Parliament yet) adds the following text to the Companies Act
| 2006:
|
| > A company must not be registered under this Act by a name
| that, in the opinion of the Secretary of State, consists of or
| includes computer code.
| jeroenhd wrote:
| The old name was in this tweet:
| https://x.com/zofrex/status/1319286955314614275
|
| Looks like the XSS tried to load this script that has since
| been banned: https://mjt.xss.ht/
|
| Edit: huh, looks like HN translate X into xn--971h.com, but the
| link still works. So much for my dumb twitter link.
| wcedmisten wrote:
| I believe that's called punycode, and it's a common way to
| encode Unicode as ASCII. It also means you can use emojis in
| your domain.
|
| https://en.m.wikipedia.org/wiki/Punycode
|
| https://xn--i-7iq.ws
| jeroenhd wrote:
| Yup! I was just surprised that HN translates unicode into
| punycode rather than letting the browser do it. I suppose
| it's an anti phishing system?
| bspammer wrote:
| I remember this - the companies house website actually wasn't
| vulnerable to the attack. They removed it because someone else
| who downloaded and hosted the data might be.
| aduffy wrote:
| I believe in their culture this is called a "total mad lad move"
| xenophonf wrote:
| Now I want to register a company named "Pure Big Mad Computer
| Man" (with apologies to Iain Banks).
| pertymcpert wrote:
| You're almost there. Just s/total/totes
| oaktowner wrote:
| CEO: Bobby Tables.
| bitwize wrote:
| Better him than Kotick.
| nathell wrote:
| Similarly-named Polish company:
| https://aplikacja.ceidg.gov.pl/ceidg/ceidg.public.ui/searchd...
|
| Also relevant: https://www.theguardian.com/uk-
| news/2020/nov/06/companies-ho...
| notahacker wrote:
| Blog on it by the company founder: https://pizzey.me/posts/no-i-
| didnt-try-to-break-companies-ho...
| bbarnett wrote:
| _But I need to clear something up: I did not attempt to break
| Companies House!_
|
| This reads like someone drinking, and then waking up the next
| morning in damage control mode.
| pizzeys wrote:
| No comment
| saulr wrote:
| This ultimately resulted in a new restriction in a bill making
| its way through Parliament that "a company must not be registered
| under this Act by a name that, in the opinion of the Secretary of
| State, consists of or includes computer code".
|
| See page 16 of the Economic Crime and Corporate Transparency Bill
| (https://bills.parliament.uk/publications/49554/documents/283...)
| schoen wrote:
| That's kind of awesome!
|
| Although it would be sad if this meant that, for example, one
| couldn't name a company after a programming language keyword
| (!?).
| beardyw wrote:
| Like
|
| https://find-and-update.company-
| information.service.gov.uk/c...
|
| https://find-and-update.company-
| information.service.gov.uk/c...
|
| https://find-and-update.company-
| information.service.gov.uk/c...
|
| ... I could go on.
| lastangryman wrote:
| Amazing. I would absolutely love to sit down with the Secretary
| of State and test their knowledge of what does of does not
| consist of of computer.
| omnicognate wrote:
| Assuming this means the Secretary of State for Business and
| Trade (the UK has 17 Secretaries of State), the current one
| has a degree in computer systems engineering and has worked
| as a software engineer [1], so she probably has a fairly good
| idea.
|
| [1] https://en.m.wikipedia.org/wiki/Kemi_Badenoch
| pizzeys wrote:
| I didn't know this, and have made the same snarky joke in
| dumb interviews about the company registration etc. -
| that's very cool and I will eat my words.
| yreg wrote:
| | This is the founder of Drop Table
| mhh__ wrote:
| She somehow got away with hacking into a rivals
| computer/server -- she would contest the use of the word
| hacking but by the wording of the computer misuse act it's
| what she did.
| zapdrive wrote:
| So "SELECT TRAVELS LTD." is prohibited? How about "Class Moving
| Ltd.", or "Sarah's wedding functions", or "Goto Grocery"?
| miquels wrote:
| Wait till they learn about Whitespace .. (
| https://en.wikipedia.org/wiki/Whitespace_(programming_langua...
| )
| popcalc wrote:
| Relevant: https://news.ycombinator.com/item?id=36094691
| krylon wrote:
| That must be in the top five, possibly even top three of the
| coolest company names of all time.
| hparadiz wrote:
| I have a little bobby tables unit test in my framework and I was
| grinning the entire time I was writing it.
| mhh__ wrote:
| Side note: UK companies are really easy to find & view filings
| of.
|
| Deserves praise especially considering how much of a black hole
| the UK can be for conniving businesspeople and so on
| seydor wrote:
| Now we know, Samuel Pizzey is Bobby Tables
| retrocryptid wrote:
| I believe he's Bobby's brother... Sammy Tables.
| gumballindie wrote:
| From what I've seen, gov contractors don't really know what an
| SQL injection is, but they use frameworks so its all good. Bad
| thing is that some of these frameworks sanitise rather than
| escape data and the injection may slip through. I wouldn't be
| surprised if a system somewhere that reads this company name will
| just crash one day out of the blue.
| abulman wrote:
| I can assure you that as someone that has done a couple Gov-
| related public-sites, some developers do think about it, and
| use suitable tools to ensure there's no issues.
|
| Before the last-and-stolen-passports site went live (that I
| spent most of 2014 getting live - not writing - but mostly
| trying to get deployed), we did have a conversation, and easily
| proved that people called Mr or Mrs Null and/or O'Brien would
| have no problems. That conversation was also somewhat prompted
| by the Dartford Crossing site that went live a little before us
| - which had 'some issues'.
| ta1243 wrote:
| GDS are great - and at the time this company was registered
| they were even better, hence this doesn't cause any problems.
|
| However that doesn't mean downstream users of the data treat
| data sources correctly
| ZeroClickOk wrote:
| I know that does not solve the problem, but I find amazing that
| it is so hard to open a "read-only" connection to a sql database.
| At least in Sql Server we need to create a User with specific
| rights in order to do it, and even so it is not perfect.
| highwaylights wrote:
| Bobby Tables Incorporated
| luispa wrote:
| Bobby tables, COO
| _the_inflator wrote:
| Someone has to do it:
|
| https://xkcd.com/327/
| Dwedit wrote:
| That's the joke.
| kijin wrote:
| Unfortunately, the Companies House doesn't seem to allow a quote
| character at the beginning. Gotta terminate that string literal
| before you start injecting your own statements!
| freitzkriesler2 wrote:
| My heros
| cryptonector wrote:
| Bobby Tables strikes again!
| ninkendo wrote:
| shouldn't it be: '; DROP TABLE "COMPANIES";--
|
| ?
|
| ie. end the single quote first, so that searching by the text
| would be: SELECT * FROM "COMPANIES" WHERE
| "NAME" = ''; DROP TABLE "COMPANIES";--'
| [deleted]
| Zuider wrote:
| As the blog post says, most SQL databases won't accept a name
| given in double quotes as the name of a table.
| pxeger1 wrote:
| From https://pizzey.me/posts/no-i-didnt-try-to-break-companies-
| ho... The company name is a bit of hacker
| sleight-of-hand... or as some astute people have put it, it's
| 'wrong'. Of course it's wrong - I'm not a /total/ arsehole. :
| rickreynoldssf wrote:
| It would have been better if Bobby Tables was listed as an
| officer.
| seabass-labrax wrote:
| A missed opportunity, even, as you can trade under any name in
| Britain as long as it's not deceptive.
| dang wrote:
| Related:
|
| _; DROP TABLE "COMPANIES";-- LTD_ -
| https://news.ycombinator.com/item?id=27815396 - July 2021 (30
| comments)
|
| _Drop Table "Companies";-- LTD_ -
| https://news.ycombinator.com/item?id=21534156 - Nov 2019 (7
| comments)
|
| _Drop Table "Companies";- LTD_ -
| https://news.ycombinator.com/item?id=20583540 - Aug 2019 (2
| comments)
|
| _Drop Table Companies Ltd_ -
| https://news.ycombinator.com/item?id=17003588 - May 2018 (27
| comments)
|
| _Drop Table Companies Ltd_ -
| https://news.ycombinator.com/item?id=13280494 - Dec 2016 (23
| comments)
| lifeisstillgood wrote:
| Of course the CEO is "little Bobby Tables"
|
| I love this - great idea :-)
| throw_a_grenade wrote:
| https://find-and-update.company-information.service.gov.uk/c...
|
| "Fuck Poverty Ltd.", but in Polish.
|
| Over here we're surprised it's still up, after like two years,
| and no-one did anything.
| amelius wrote:
| Don't give your tables reasonable names.
___________________________________________________________________
(page generated 2023-08-03 23:02 UTC)