New web site published today by the SNCF, the major French train transport company (historically a monopoly but the market is being opened to competitors ~2026)
Theyâve had their own TLD for a while, they just never consolidated everything until now
Theyâve been hyping up the launch of this new website for weeks with feature teasers etc
So today I got an email and I clicked the button. Marketing team is on point, thereâs only one button to click.
But after that, of course my password manager wouldnât suggest my credentials (new domain)
Of course theyâd use a different domain for authentication than the landing page would suggest
Of course my credentials donât work
Of course the forgotten password page doesnât work
But in addition to this:
- the forgotten password page also has an enumeration issue (see OWASP cheat sheet)
- the notification email doesnât accept replies and leaks the name of their hosting provider in the automated response
- the provided FAQ and other pages donât say how to report issues
- there is no security.txt on either of the new domains
- the 404 page leaks technical information that probably shouldnât be made public
- Iâve been on hold for 6 minutes on the phone, last try they disconnected at 8 minutes and theyâre closing in half an hour
- their phone system tells me to please leave a voice message before abruptly hanging up on me
#ModernWebDev