So our public transportation company started to sell tickets online with their brand new fancy​ system.

• You can buy tickets and passes for the price you want
• Passwords are in plaintext
• Communication is through HTTP
• Login state are checked before the password match so you can basically view who is online
• Email password reminders security code can be read from servers response

Oh and I almost forgot admin credentials are FUCKING admin/admin

Who in the fucking name of all gods can commit such idiocracy with a system that would be used by almost millions of people. I hope you will burn in programming hell. Or even worse...

I'm glad I'm having a car and don't have to use that security black hole.

    Free tickets inc

    Also bojler eladó
    Sadly, I think it's the opposite. They've got charged thousands of dollars and received that piece of garbage.
    @dontbeevil @HnDev
    It's Hungary
    But does it look good?
    I don't use it personally thank God, checked the intro page, looked good, but there's no way I am going to input anything on that site.

    BTW. Monthly operating costs approximately 83000$. WTF???
    @Teosz report it to them and pitch them that you can do a better job than that

    maybe you can rebuild it, start your own company 😉
    @Teosz you meant yearly $83k ?
    Our town major paied 50.000 got a logotype design. So yeah
    No. It's MONTHLY...

    It's in public beta and the vulnerabilities already hit the news. They've​ said the bugs will be patched to official release.
    @Teosz wow! What infrastructure costs such money? And do they actually generate such much income to cover up those huge recurring costs?
    Sounds like a new Dev company will be their feature request
    @some-one That cost is not unlikely I guess. Our government ordered a tailored system to recover taxes, which was faulty from the very beginning, yet it made production. That resulted in nearly 18 billion dollars not being recovered. And the system itself cost around 150 million dollars
    the cost is normal for railway companies. i guess the website was made by a relative of the director, i smell coruption. 😆
