66
submitted 1 day ago* (last edited 1 day ago) by spectre@hexbear.net to c/videos@hexbear.net
you are viewing a single comment's thread
view the rest of the comments
[-] daniyeg@hexbear.net 28 points 1 day ago* (last edited 1 day ago)

based on how coffeezilla talks about it, how easy it is and similar stories from the past, i suspect that their website generated shipping labels, receipts or whatever automatic documentation that is given to customers as a proof of purchase, and stored it on the server in a way that could be publicly served to everyone not just the original customer. this way you just have to know the file's name, which was probably generated in a deterministic way, in order to extract people's information. with this you usually won't get everyone's information so 10k is probably an underestimate.

if this is the exploit, this is basic web security from like early 2000, with reoccurring minor drama about small sites fucking it up until mid 2010s. they either hired some boomer (or worse former government contractor) to shit it out with raw php or some kid (and i mean literal kid, most likely 14 as even 15 year olds won't make this mistake) to do this as a summer job. embarrassing even if this wasn't how it was done.

EDIT: looking again at the coffee video, the data has a column account_status which wouldn't make sense with what i just described. however it could be basic SQL injection, which is still laughable but increases the age rage from 14 to 16. just wanted to say the original comment i made 10 minutes ago is wrong lmao.

this post was submitted on 20 May 2026
66 points (100.0% liked)

videos

23304 readers
129 users here now

Breadtube if it didn't suck.

Post videos you genuinely enjoy and want to share, duh. Celebrate the diversity of interests shared by chapochatters by posting a deep dive into Venetian kelp farming, I dunno. Also media criticism, bite-sized versions of left-wing theory, all the stuff you expected. But I am curious about that kelp farming thing now that you mentioned it.

Low effort / spam videos might be removed, especially weeb content.

There is a cytube that you can paste videos into and watch with whoever happens to be around. It's open submission unless there's something important to commandeer it with at the time.

A weekly watch party happens every Saturday (Sunday down under), with video nominations Saturday-Monday, voting Monday-Thursday. See the pin for whatever stage it's currently in.

founded 5 years ago
MODERATORS