Report a security bug found in DJI.COM
2011 5 2015-1-15
Uploading and Loding Picture ...(0/1)
o(^-^)o
juansacco
New

Netherlands
Offline

Hello guys. My name is Juan Sacco and I love your products ( I do not have any but still.. )

Well I am a security researcher and I was looking  when just by curiosity I found a SQL Injection and a XSS scripting on DJI.COM ( Besides other things ).

This is really critical because for instance, the XSS is stored. And this could allow any malicious user to control or modify / steal other users credentials, credit cards, etc. from the shop or forum.. And well the SQL Injection can be used directly to modify the site.

I am trying since yesterday to contact someone from DJI.. tried every email you have on the page without luck.

Could you put me in contact as soon as possible with one of your technical engineers so I can report this?

My only intention is to report this to help you guys to have a better and more secure site, knowing that you have a online store at dji.com if this vulnerabilities are used by an attacker he could potentially do a lot of damage not only to your site, to your online presence.

Besides. I would like to know if there is any reward for reporting this?

Linkedin: https://www.linkedin.com/profile/view?id=30640166
Website: http://exploitpack.com

Thanks.
JSacco





2015-1-15
Use props
pbofavl
lvl.2
Flight distance : 1307631 ft
United States
Offline

Thanks for reporting this.  
2015-1-17
Use props
Thampiss.gmail
New

United States
Offline

Hi Juan
Has it been rectified? Else you should post this in the wider community of DJI product users. I just made a purchase at the online store, mercifully using Paypal.
I think DJI should reward you well for services freely rendered :-)
2015-2-2
Use props
markus2015
lvl.4

Germany
Offline

I remember someone finding a major security breach in Facebook. He wrote multiple times to the admins and got no response, they just ignored him. He then hacked Marc's personal account and posted his findings on his wall. Only then did they acknowledge (or care) about the weak spot and fixed it.

I hope DJI is taking this seriously for the sake of it's customers and it's own reputation.
2015-2-3
Use props
juansacco
New

Netherlands
Offline

Hello guys, this has been fixed. DJI took it seriously.

Great company.
2015-2-23
Use props
markus2015
lvl.4

Germany
Offline

juansacco Posted at 2015-2-23 22:52
Hello guys, this has been fixed. DJI took it seriously.

Great company.

Great news, thanks for that feedback!
2015-2-23
Use props
Advanced
You need to log in before you can reply Login | Register now

Credit Rules