Late last week we were informed of a security vulnerability on Flippa.com. Within hours we’d patched the site to fix the vulnerability, and conducted a thorough audit of security logs. The delay in this post informing you was caused by a legal insurance requirement to fully assess any exposure, which has now been done.

First, and most importantly, no financial details were in any way compromised, we don’t store credit card numbers at all so these are completely safe.

Second, no passwords were compromised, as again, we don’t store these in plaintext so there is no way any Flippa admin can access them.

Our information came from Adam Hosker from a “whitehat” hacker site. Adam is a Flippa.com member from the UK and he says he found the issue in the course of his day-to-day activities on Flippa.

Essentially, Adam was able to log in as another Flippa user. He used that mechanism to log in as an admin user and therefore could access a small range of admin functions:

  • Dispute resolution
  • Add credits to user accounts
  • Promotional credit campaign creation
  • Moderate auction comments
  • Ability to (un)ban/(un)suspend user
  • Spreadsheet of member name/email address pairs

Having fixed the vulnerability, we’ve also conducted a full security audit of the entire Flippa website marketplace system, to ensure that this doesn’t happen again. We’re completely committed to ensuring the safety of our users and the integrity of our system.