May 13, 2005

IPayBuddy.com And Lucent.com - where great minds meet

If you look at IPayBuddy.com, you would never confuse it with lucent.com right? Obviously IPayBuddy.com is some second hand paypal wannabe who as I write this doesn't even have a proper cert. Lucent.com on the other hand is the site of the world renowned bell labs. (no direct links so the kids don't see us, just cut-n-paste the urls).

IPayBuddy.com looks like it is a half-way completed web template (many of the links go to yoursite.com), lucent's site excited points out they are world leaders in almost everything to do with communication.

I wouldn't trust IPayBuddy.com with 10 cents. I think I am trusting Lucent with all kinds of patents inside technology I use.

What could these two companies have in common? They both use my domain. And they both expose user's passwords because of this.

IPayBuddy.com sends out new user signup info from admin at donotreply.com - which while this email only lists username and email, it does also send itself one at donotreply.com for every single new user signup. That is annoying, but it gets worse, users respond to the emails with their passwords asking questions about logins.

To be honest, looking at IPayBuddy.com, the users deserve what they get if they trusted that site. I am thinking the email list i could create from new user signup would make a great suckers list who would purchase anything I pitched them. Here is a funny link abou tIpaybuddy.com - well okay,not funny if you fell for it...

Okay, so everyone reading here can easily see that ipaybuddy.com is just not a world class site, or even a very legit looking site. The site is just one guy being an idiot, surely his level of security and privacy should not be on par with an international tech company that at one time was comprised of some of the greatest minds.

And lucent being a world class company should not have any security/privacy systems in place that are as bad as ipaybuddy.com - right?

Sadly the two seem to have a lot in common. Here is a bounced email from lucent which was sent using autogenerated at donotreply.com, the user responded to the fake email address and i got the goods.

Thank you!

-----Original Message-----
From: autogenerated@donotreply.com [mailto:autogenerated at donotreply.com]
Sent: Monday, January 10, 2005 11:53 AM
To: XXXXXXXXX@MurrayHill.Exchange.Lucent.Com
Subject: Your help desk user account for Lucent Technologies has been
updated


Terri,

Your help desk user account has been updated.

Use the following link to access your help desk account:
http://www.XXXXXX.com/LucentTechnologies/LLPublishingPlatforms/index.cfm

Your user name is: XXXXXXXX
Your password is: XXXXXXXXX

Regards,
autogenerated at donotreply.com

Yes, I hid their data and changed the @ to at. Past that, the email was created by the genuis that now is lucent. Hopefully Alexander will rise up from the grave and give some zombie love to the bright folks working at his bell labs. They have fallen pretty far to be doing things this stupid. I remember when hacking took skills of social engineering, not just simply checking your email.

Posted by Chet at May 13, 2005 07:15 PM