MoviePass,Switzerland erotic the cinema subscription service that's gone from "This is too good to be true" to "What is even going on I'm so tired" in a series of reinventions, has had another setback.
The company left thousands of customer card details, and tens of thousands of customers' credit card details, visible on a server that was not password protected, according to a security research firm.
The database, which a reporter from TechCrunch observed "growing in real time," contained more than 161 million records and counting, ranging from logging details generated in the course of a normal running day to unencrypted user details. Credit or debit card details were available, too, including card numbers, expiration dates, cardholder names, and billing addresses in plaintext.
MoviePass customer cards are basically MasterCard-issued debit cards; customers pay the monthly fee, and the service loads up the cards with the price of a movie ticket when a screening is booked, so subscribers can then buy them at the box office with the card.
(A MoviePass card could technically be used to make any debit purchase, users theorise, although it would get the account holder banned pretty swiftly.)
This Tweet is currently unavailable. It might be loading or has been removed.
The unprotected dataset was detected by systems developed by Dubai-based firm spiderSilk, and confirmed manually by the firm's security team before they notified MoviePass, which did not respond.
Security researcher Mossab Hussein told Mashable while his team can't tell for sure whether the database had been accessed by other parties, they estimate the number of credit cards that could be exposed in the dataset runs into the tens of thousands, in addition to around 50,000 MoviePass cards.
SEE ALSO: A new limited MoviePass offer comes close to the tantalizing original plan"Simple best practices should have prevented any of this from happening in the first place," Hussein said. "But we see a lot of companies not worrying as much as they should, when it comes to 'internal tools' and 'internal logging.' And they justify this by saying something along the lines [of] 'Oh, it's only for internal use and analysis.'"
Mashable has contacted MoviePass's parent company Helios + Matheson for comment on the exposure, including the reasons why the database was only taken offline after TechCrunch notified them of the issue and not when Hussein reached out over the weekend.
"We've seen companies that took 30 days to acknowledge a finding, and we've also seen companies that acknowledged and patched a finding within 60 minutes," Hussein said. "But our position has always been very strict about this topic. Companies panic and respond in seconds if their apps are down ... they should treat the safety of their customer data just the same."
Topics Cybersecurity
Previous:You Are Not a Rebel
Next:Othering the Godman
Fullscreen Live launches new national tour feat. Ricky Dillon, Chachi GonzalesBroncos quarterback Trevor Siemian is no longer a punchlineHero Orlando Bloom rescued a wounded dogEmma Watson really wishes she could vote in the U.S. electionsAmsterdam airport expertly trolls Heathrow with this sweet deliveryThe NBA is tripling its Snapchat output for the 2016'Destiny' Halloween event finally puts your raisins to good useMystery Japanese dude's levitating magic tricks are seriously impressiveHere's how 'The Walking Dead' pulled off those chilling death scenes10 reasons you should root for the Cubs even if you don't like baseballBerlin police post creepy pictures to warn about creepy clownsUber is giving out free flu shotsAmsterdam airport expertly trolls Heathrow with this sweet deliveryHit Korean movie 'Sunny' getting U.S. remake from producer Brett Ratner (Exclusive)Hero Orlando Bloom rescued a wounded dogReport: New Zealand company selling surveillance tech to global spiesAT&T rakes in cash by selling spy service to law enforcementThe 7 devices in your home that could be used for next DDoS attackAT&T rakes in cash by selling spy service to law enforcementAT&T's upcoming internet Plane evacuates upon landing at Australia's Perth airport Man becomes goat for 3 days, wins award Creative mom puts her napping twins into awesome settings Luna Lovegood reveals her Patronus on Twitter, and she's not happy 'SNL' newbie deleted 2,000 tweets, including comments about race Hillary Clinton's new ad highlights Trump's misogynistic moments 5 creative ways to trick people into eating healthy Proposal for marriage equality AND free McNuggets is the perfect deal The Backstreet Boys are getting a Vegas residency, so start screaming New video by Keith Scott's wife shows his fatal encounter with police Here's how much Snapchat's glasses will cost 'I felt like it was my family': The stories behind the protesters Gennifer Flowers tweets she supports Trump, will accept invitation to debate Police arrest creepy clown found lurking in Kentucky woods What's coming to and leaving Netflix in October 'Harambe' the movie? Studio head promises he'll do it at 1 million retweets Japanese ad giant admits to overcharging more than 100 clients What to watch on Amazon Prime in October Can GoPro win over normals with its new cameras and drone? UPS is testing out its own delivery drones
2.2647s , 8222.9375 kb
Copyright © 2025 Powered by 【Switzerland erotic】,Pursuit Information Network