【natural sex videos】
MoviePass,natural sex videos the cinema subscription service that's gone from "This is too good to be true" to "What is even going on I'm so tired" in a series of reinventions, has had another setback.
The company left thousands of customer card details, and tens of thousands of customers' credit card details, visible on a server that was not password protected, according to a security research firm.
The database, which a reporter from TechCrunch observed "growing in real time," contained more than 161 million records and counting, ranging from logging details generated in the course of a normal running day to unencrypted user details. Credit or debit card details were available, too, including card numbers, expiration dates, cardholder names, and billing addresses in plaintext.
MoviePass customer cards are basically MasterCard-issued debit cards; customers pay the monthly fee, and the service loads up the cards with the price of a movie ticket when a screening is booked, so subscribers can then buy them at the box office with the card.
(A MoviePass card could technically be used to make any debit purchase, users theorise, although it would get the account holder banned pretty swiftly.)
This Tweet is currently unavailable. It might be loading or has been removed.
The unprotected dataset was detected by systems developed by Dubai-based firm spiderSilk, and confirmed manually by the firm's security team before they notified MoviePass, which did not respond.
Security researcher Mossab Hussein told Mashable while his team can't tell for sure whether the database had been accessed by other parties, they estimate the number of credit cards that could be exposed in the dataset runs into the tens of thousands, in addition to around 50,000 MoviePass cards.
SEE ALSO: A new limited MoviePass offer comes close to the tantalizing original plan"Simple best practices should have prevented any of this from happening in the first place," Hussein said. "But we see a lot of companies not worrying as much as they should, when it comes to 'internal tools' and 'internal logging.' And they justify this by saying something along the lines [of] 'Oh, it's only for internal use and analysis.'"
Mashable has contacted MoviePass's parent company Helios + Matheson for comment on the exposure, including the reasons why the database was only taken offline after TechCrunch notified them of the issue and not when Hussein reached out over the weekend.
"We've seen companies that took 30 days to acknowledge a finding, and we've also seen companies that acknowledged and patched a finding within 60 minutes," Hussein said. "But our position has always been very strict about this topic. Companies panic and respond in seconds if their apps are down ... they should treat the safety of their customer data just the same."
Featured Video For You
Instagram users’ location data, stories were tracked by marketing company
Topics Cybersecurity
Search
Categories
Latest Posts
Apocalypse films of the 2000s: What the end of the world looked like
2025-06-27 08:07Silly dog gets stuck in the backseat
2025-06-27 08:04Three Apps to Combine All Your Messaging Clients Into One
2025-06-27 06:52Popular Posts
HP Touchscreen Laptop deal: Get $240 off at Best Buy
2025-06-27 07:56Gaga's "The Fame Monster" unmasked the bad romance of 00s celebrity
2025-06-27 07:53How the hottest, most extreme temperatures in the world are verified
2025-06-27 07:04Featured Posts
Hands on with Lenovo's 'rollable' display laptop at CES 2025
2025-06-27 09:21This guy hid an awesome Easter Egg in a week's worth of tweets
2025-06-27 09:19Twitter flags another lying, rule
2025-06-27 08:34Teslas might get a sensor that detects a child left in a hot car
2025-06-27 08:08Miami Heat vs. Los Angeles Lakers 2025 livestream: Watch NBA online
2025-06-27 07:32Popular Articles
GPU Availability and Pricing Update: April 2022
2025-06-27 09:11California fires look like a nightmare from space right now
2025-06-27 08:46How to help victims of the California wildfires now
2025-06-27 08:35The Ultrahuman Ring Air now comes in 18K gold – for a steep price
2025-06-27 06:46Newsletter
Subscribe to our newsletter for the latest updates.
Comments (44773)
New Knowledge Information Network
Best Dyson deal: Save over $100 on Dyson V11 Origin cordless vacuum
2025-06-27 08:54Unique Information Network
Instagrammers are staging fake camping pictures, and this account is calling them out
2025-06-27 08:34Dream Information Network
Popular wildlife cam just became a dreadful California fire cam
2025-06-27 08:01Pursuit Information Network
BTS' 'Dynamite' smashes YouTube's 24
2025-06-27 08:01Unobstructed Information Network
How to unblock xHamster for free
2025-06-27 07:55