Hacker News new | past | comments | ask | show | jobs | submit login

> Apache/2.4.6 (CentOS) OpenSSL/1.0.1e-fips mod_fcgid/2.3.9 PHP/5.4.16 mod_python/3.5.0- Python/2.7.5

Eek! I wouldn't trust them with my data if I was a bank. They haven't updated their server since 2013. All of the versions listed in that header have major vulns. This is a disaster waiting to happen.




Most, if not all, of those versions are the latest provided by CentOS 7. They backport security patches, see https://access.redhat.com/security/updates/backporting



They really have no clue what they are doing... No security headers and their SSL is insecure. Someone needs to tell them to shut their servers down right now.

Directly from their website:

"Patrick Brown - Chief Technology Officer. Mr. Brown is the co-founder of Eye Candy Creative, a highly successful technology and marketing company."

So their CTO is a marketing guy. No wonder they suck.


Yikes, Qualys SSL Labs gives them a grade of C. They may be vulnerable to a POODLE attack. They probably should disable SSL 3 support to protect their customers.

https://www.ssllabs.com/ssltest/analyze.html?d=banclist.com


It doesn't sound like they hold any really sensitive data though, at least not any customer data.


It seems dir listing is not properly disabled https://banclist.com/app/webroot/img/


It it now, by the look of it.


Not an expert but I don't think it's considered good practice to expose your directory structure like that. It should have been 404 or redirection to /home.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: