Navigate Select ESC Close

Hacking websites with your company name

2025-05-13 Science & Technology
69.1k
2.3k
141
Theo - t3․gg
Theo - t3․gg
539.0k subscribers

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

Cross site scripting in a government database and a license plate that broke the DMV. Oh boy... Thank you Bright Data for sponsoring! Check them out at: https://soydev.link/brightdata SOURCES https://www.theguardian.com/uk-news/2020/nov/06/companies-house-forces-business-name-change-to-prevent-security-risk https://news.ycombinator.com/item?id=41948666 https://www.youtube.com/watch?v=TwRE2QK1Ibc https://www.wired.com/story/null-license-plate-landed-one-hacker-ticket-hell/ Want to sponsor a video? Learn more here: https://soydev.link/sponsor-me Check out my Twitch, Twitter, Discord more at https://t3.gg S/O Ph4se0n3 for the awesome edit 🙏

Top Comments (10)

@tagKnife 2025-05-13

For clarity that Theo completely overlooked. Company House wasnt vulnerable, 3rd party sites that index, read and stuff from Company house was vulnerable. And instead of fixxing their own shit they complained to Company house and instead of pushing back for them to fix their own shit, Company house removed the name entries.

223 1 replies
@randxalthor 2025-05-13

Ask any Irish person with an apostrophe in their name how name websites they've broken. I had to call an antivirus sales website to get directly in touch with the sysadmin so they could remove an apostrophe in the DB directly. The sign-up page allowed the character, but the login didn't.

114 6 replies
@vonderklaas 2025-05-13

Wtf Theo how many videos were made in advance? Wow.

358 9 replies
@dead-claudia 2025-05-13

4:24 "only government code" are you sure about that?

44
@scottishross91 2025-05-14

The UKs gov website is actually quite secure. They were the first to really do digital services and they put a lot of effort into it. They may not look spectacular, but thats because it's focused on performance, security, and accessibility.

13
@AnderzL7 2025-05-13

Video starts at 3:09 btw. You’re welcome

108 8 replies
@seedmole 2025-05-13

brb naming a company "Company name available on request"

8
@unusedTV 2025-05-13

Seems like the Company House wasn't the issue, but consumers of their data products.

10
@sanderbreivik 2025-05-13

I guess the reason the name was changed is that the Companies House has an open API and the name poses a security risk to OTHER applications.

122 7 replies
@elmax5748 2025-05-13

Companies house ≠ The House Of Lords. Apologies for the nitpick 😢

28

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot