New web site published today by the SNCF, the major French train transport company (historically a monopoly but the market is being opened to competitors ~2026)
They’ve had their own TLD for a while, they just never consolidated everything until now
They’ve been hyping up the launch of this new website for weeks with feature teasers etc
So today I got an email and I clicked the button. Marketing team is on point, there’s only one button to click.
But after that, of course my password manager wouldn’t suggest my credentials (new domain)
Of course they’d use a different domain for authentication than the landing page would suggest
Of course my credentials don’t work
Of course the forgotten password page doesn’t work
But in addition to this:
- the forgotten password page also has an enumeration issue (see OWASP cheat sheet)
- the notification email doesn’t accept replies and leaks the name of their hosting provider in the automated response
- the provided FAQ and other pages don’t say how to report issues
- there is no security.txt on either of the new domains
- the 404 page leaks technical information that probably shouldn’t be made public
- I’ve been on hold for 6 minutes on the phone, last try they disconnected at 8 minutes and they’re closing in half an hour
- their phone system tells me to please leave a voice message before abruptly hanging up on me
#ModernWebDev