• Anonymous (unregistered)

    So, their site is hilarious. On http://www.federalsuppliers.com/company.html they claim at the same time: "Federal Suppliers Guide is a small business..." and "We are the oldest and largest publishing company in this industry!"

    So, they're small when they want to claim to understand small businesses. But they're huge when they're claiming credibility.

  • Yep (unregistered)

    zzzzzz fffxxx

    Rofl

  • Rev. Spaminator (unregistered)

    For some reason I imagine the sales rep has the voice of Phil Hartman.

  • (cs) in reply to Lucy
    Lucy:
    As an employee of the company, I was just made aware of your site. Our company is legitimate and we're not a scam. The fact that our site security is weak is something we are addressing. We are staffed with good people, we offer a great service, and you are trying to ruin our reputation. You are crossing legal lines.

    I am asking you to stop your actions immediately.

    Μολὼν Λαβέ.

  • (cs) in reply to Rev. Spaminator
    Rev. Spaminator:
    For some reason I imagine the sales rep has the voice of Phil Hartman.

    I'm hearing Gil Gunderson (the hapless salesman) . . . "Well, if you, well ... really? Wow, Hot, hot dog! A sale!"

  • Changed again (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    zzzzzz

    fffxxx

    But when you log in it gives a 404. Haha.

    Wonder if the person who built the site got the work from the guide? Probably was the comapny she mentioned and they probably charged the 500,000 for the security too...

  • (cs) in reply to Lucy
    Lucy:
    As an employee of the company, I was just made aware of your site. Our company is legitimate and we're not a scam. The fact that our site security is weak is something we are addressing. We are staffed with good people, we offer a great service, and you are trying to ruin our reputation. You are crossing legal lines.

    I am asking you to stop your actions immediately.

    Anyone can say anything on the internet. Can you prove that what you say is true?

    Responding on the forums is one of the least effective ways to get your message to the site operators.

    --BK

  • Yep (unregistered) in reply to Lucy
    Lucy:
    As an employee of the company, I was just made aware of your site. Our company is legitimate and we're not a scam. The fact that our site security is weak is something we are addressing. We are staffed with good people, we offer a great service, and you are trying to ruin our reputation. You are crossing legal lines.

    I am asking you to stop your actions immediately.

    Lucy,

    Having a community of programmers like this one discover a vulnerability in your site is actually a good thing. Most of these people are non-malicious and are actually professionals in the field. Take this opportunity to fix a huge security problem and use the services of one of the many capable coders available here.

    The people on this forum are entitled to their opinion about your business as well as your website's security. That's what this site is about; poking fun at IT problems throughout the industry. The entity that is your company should not take this personally, and proceed to use this as free advice that your site lacks any security measure and that you should hire someone new immediately to solve the problem.

  • Sys (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Just changed again...

    <script language="javascript"> <!--// /*This Script allows people to enter by using a form that asks for a UserID and Password*/ function pasuser(form) { if (form.id.value=="zzzzzz") { if (form.pass.value=="fffxxx") { location="http://officers.federalsuppliers.com/agents.html" } else { alert("Invalid Password") } } else { alert("Invalid UserID") } } //--> </script>

    Somebody should tell them that changing the password will not help as long as the password is written there...

  • Michael (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    I have NEVER posted on this site ever, despite reading it for more than a year. But I just can't let this slide.

    It may be because this is the first not-anonymous-company post ever. But this is the FUNNIEST thing I have ever seen! For obvious reasons, I hope this de-evolves into a flame war. Wouldn't that be great? Looking forward to the responses on this one.

  • Ares (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    LOL wow... report him to the authorities for what? Viewing the source code to a website? Cause, um, hate to break it to you, but that's not illegal. :-P

  • Neil (unregistered)

    D'you think we could get it indexed by Google?

  • Nick (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Just a tip - if you paid a professional consulting company to put this together for you, fire 'em.

    If you put it together yourself, it's time to grow up and have someone who knows what they're doing help you with your site.

  • Troy McClure (unregistered) in reply to Michael

    Looks like the site is down - they keep changing the passwords, but they took down the main page.

    Seriously Alex this story makes up for all the shit you've taken for changing the name of the site...etc. Well done!

  • Boris (unregistered)

    /This Script allows people to enter by using a form that asks for a UserID and Password/ function pasuser(form) { if (form.id.value=="zzzzzz") { if (form.pass.value=="fffxxx") {
    location="http://officers.federalsuppliers.com/agents.html" } else { alert("Invalid Password") } } else { alert("Invalid UserID") } } //-->

  • nh (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    wow... you are some bad bad hackers! Shame on you all guys.

  • Matthew (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    If you and your company are TRULY who you claim to be, then you will be able to naturally rise above this.

    Everything happens for a reason, and your 4 kids may just have to see daddy work a little harder, who knows, maybe you'll lose a little weight too - Now that's American!

  • Thadeous (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Sir, that is the most unsecure site in the history of unsecure sites. Hire a developer.

  • (cs)

    I don't know what's funnier. That they keep changing the password, or that the SECURE page is unprotected anyway.

    Although at this point I almost feel bad for them... almost.

  • Annaleemac (unregistered)

    Aren't all you wienies, I mean geeks, just so proud of yourselves? I guess between taking a few tokes you have nothing better to do than slam people trying to actually work for a living. While you have all day to sit around in your underwear trying to prove your superiority breaking into what amounts to other people's houses, (albeit, online houses) the rest of the world is working. It must be tough for you to justify your lives without vilifying others. I'm sure you don't even try. People who make false statements about others may find themselves at the wrong end of a lawsuit. People in glass houses shouldn't throw stones. But, don't worry, nothing could possibly happen to you. I'm sure no one could find your address. I'm sure you all operate everything in your life on the up and up and can hold up to scrutiny as well. So, just smoke another one and don't you worry about it.

  • (cs) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT
    FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT:
    sorry our site wasn't protected to your standards however all of you are being reported to the appropriate authorities as we have your information too. you should of protected your info a little better.

    It's true to say that the site wasn't protected to our standards, but also true to say that it wasn't protected to any reasonable standard. The security on that page is of a level that could be broken in moments by a reasonably intelligent 10-year-old; what you've got there is the electronic equivalent of locking the door but leaving a key under the welcome mat.

  • Steve (unregistered) in reply to Lucy
    Lucy:
    As an employee of the company, I was just made aware of your site. Our company is legitimate and we're not a scam. The fact that our site security is weak is something we are addressing. We are staffed with good people, we offer a great service, and you are trying to ruin our reputation. You are crossing legal lines.

    I am asking you to stop your actions immediately.

    Lucy: I suggest you dust off the old resume and start shopping around for a new job.

    Preferably a legitimate one.

  • Casual observer (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    It's not hacking if you send me a document that requests a User and Password, then provides the User and Password in the very same document.

    This probably isn't the first time a non-member has entered the user name and password you sent them through the web page.

  • A new comic with every refresh. (unregistered)

    oh man.

    this entry fucking rocks.

    this is why i read the daily WTF.

    my hats are off to you.

  • It's like this (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    This is so funny. The way they've been handling this situation today, I actually believe that they are inept enough that a scam does not need to be supposed to explain any of this; they trip my Hanlon's Razor.

    What's even funnier is that this site (the definitive "The Real WTF") decided to ignore their own very wise anonymity policies and possibly exposed themselves to legal retaliation. Best hope they prove to be malicious, stupidity isn't illegal.

  • Another *Perplexed* customer (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    form.id.value=="zzzzzz" form.pass.value=="fffxxx"

    the "agents page is still offline. I guess they are "updating it"

  • SilentBob (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Immature? How about you LEARN HOW TO CODE PROPER?!? There is NO excuse for this kind of mistake, even a first year student could have told you this was a bad idea. Don't come crying here because you don't know how to secure a webpage.

  • (cs) in reply to stephane
    stephane:
    seems to work, they're hiring! http://www.pr.com/job/3441945

    I just wanted to copy the wonderful bits of that page to here, since it will probably disappear soon:

    "Salary Range 7,000 USD per year"

    "GUARANTEED PRE-QUALIFIED LEADS!!"

    "Benefits" [no explanation or details]

    "Potential of earning $65,000-$120,000 ++"

    "Manager assistance is available during entire presentation"

    I can't imagine anyone not jumping at this chance . . .

  • Medlir (unregistered)

    It's now...

    if (form.id.value=="zzzzzz") { if (form.pass.value=="fffxxx") {

    I like how even though the page is 404 now, the username and password keep changing as if that was the really unsecure part.

  • government salesman (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Having worked for a small business that DID government sales I know a) image and talk is EVERYTHING and b) that shit is NOT hard. I signed up with Dun and Bradstreet and several local states. I was 18 at the time. Any monkey that passed grade school could do your job. I'm willing to put you into that category, although capitalization and a basic understanding of how computer security works would put you into the "monkeys that graduated high school" category. Our "technical knowledge" here isn't impressive; you should understand plaintext vs encryption before using ANY kind of online banking or else you're being an irresponsible user.

  • SB (unregistered)

    Now I know with whom I shall not do business in the future. Thanks TDWTF! This is exactly why every post that mentions WTFs should list the company's name. So the consumers and business owners out here in the real world know which businesses display really, really bad business practices.

    Why would I want my credit card number to go into the hands of a company like this?

    Stop anonymizing companies in future posts, TDWTF. Please.

  • <myName>Nunya Bidness</myName> (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT
    FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT:
    thank you hackers for trying to destroy federal suppliers guides reputation. i have worked here with my wife for 10 years now and have helped hundreds of clients obtain federal government work. i have 4 children and though you don't care you are hurting the feelings of many good employees and customers by your immature actions. sorry our site wasn't protected to your standards however all of you are being reported to the appropriate authorities as we have your information too. you should of protected your info a little better. not only is the company legit we actually have held a 5 year GSA contract with the federal government and one of my best clients just broke 500,000 dollars in federal sales directly related to the GSA contract we got them. i am proud to work here and help small businesses obtain government workand also help federal buyers locate qualified small businesses to do business with. if you not interested in government work or our services of helping small businesses navigate the federal market fine but please don't slander the company. its rude, your comments are not truthful we are not a scam and i hope someday you realize that all you have to do is check us out with dun & bradstreet or GSA or the florida local and state chambers of commerce to see that what we do is real and federal buyers do request both our hardcopy guides and the online directory as well.

    Nobody accused you of scamming anyone. I think the inference is that you are selling something of very little value for waaaaayyy too much money. No one gives a sh!t how long you and your wife have worked there or how proud you are. That doesn't mean diddly in when attempting to establish the value proposition of your offering. Perhaps you could make available the average ROI for advertising $ invested with your company by your clients. That would make a compelling case (in either direction).

    Oh yeah, and your idea of computer security is a joke. That's what you get for buying a developer on price instead of on value, d!ckhead.

  • JaredR26 (unregistered)

    I hereby nominate this wtf for legendary status.

  • Welshy (unregistered) in reply to Annaleemac

    Yeah, get on with shooting the messenger while your dodgy little business slides down the pan. Unbelievable.

  • Nuked (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    So is he still eligible?

    btw, if he did call your 'customers' that haven't heard anything back: so fucking what? I would have tried to find some references on it too.

  • Gw (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Share your name so we can all know what companies to avoid that do little to nothing for their own security.

  • fert (unregistered) in reply to Annaleemac
    Annaleemac:
    Aren't all you wienies, I mean geeks, just so proud of yourselves? I guess between taking a few tokes you have nothing better to do than slam people trying to actually work for a living. While you have all day to sit around in your underwear trying to prove your superiority breaking into what amounts to other people's houses, (albeit, online houses) the rest of the world is working. It must be tough for you to justify your lives without vilifying others. I'm sure you don't even try. People who make false statements about others may find themselves at the wrong end of a lawsuit. People in glass houses shouldn't throw stones. But, don't worry, nothing could possibly happen to you. I'm sure no one could find your address. I'm sure you all operate everything in your life on the up and up and can hold up to scrutiny as well. So, just smoke another one and don't you worry about it.

    what can you even say to someone as ignorant as this?

    Hello, if you read all the comments there are people trying to help you!

  • Heather (unregistered)

    LMFAO - that's awesome.

  • sorakiu (unregistered)

    I think this is really crappy. This website in the past has changed names and not provided real URLs to a company. Maybe you don't like this guy's business, but I think it is inexcusable to post exploits to another website. Shame on daily wtf.

  • $500,000? (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    STFU

  • None (unregistered) in reply to Annaleemac
    Annaleemac:
    Aren't all you wienies, I mean geeks, just so proud of yourselves? I guess between taking a few tokes you have nothing better to do than slam people trying to actually work for a living. While you have all day to sit around in your underwear trying to prove your superiority breaking into what amounts to other people's houses, (albeit, online houses) the rest of the world is working. It must be tough for you to justify your lives without vilifying others. I'm sure you don't even try. People who make false statements about others may find themselves at the wrong end of a lawsuit. People in glass houses shouldn't throw stones. But, don't worry, nothing could possibly happen to you. I'm sure no one could find your address. I'm sure you all operate everything in your life on the up and up and can hold up to scrutiny as well. So, just smoke another one and don't you worry about it.

    Seriously the best WTF ever. They really don't understand.

  • Federal Catalog Scam (unregistered)

    This is a joke right? This perceived security is analogous with leaving the keys in the lock of your front door, but throwing a plastic bag over the keys and calling it secure.

    You reap what you sow, and your reputation is what it is... this post changes nothing

  • Thadeous (unregistered) in reply to sorakiu

    Dude, he just got some expensive consulting for free. He should be elated.

  • this webcomic is a wtf (unregistered) in reply to Fry-kun
    Fry-kun:
    Henk Poley:
    Too bad the page it points to if offline

    It was taken offline a few minutes ago, probably in response to all the "hacking" that's been going on.

    you aren't a very good customer then!

    using:

    http://www.google.com/search?q=site%3Aofficers.federalsuppliers.com&hl=en

    I could used google's cached entries and browse their fine merchandise at my leisure.

  • Troy McClure (unregistered) in reply to Federal Catalog Scam
    Federal Catalog Scam:
    This is a joke right? This perceived security is analogous with leaving the keys in the lock of your front door, but throwing a plastic bag over the keys and calling it secure.

    You reap what you sow, and your reputation is what it is... this post changes nothing

    I was thinking putting the key under the mat and locking the door, but putting a sign on the door telling everyone the key is under the mat. And then being surprised when someone breaks in.

  • Thadeous (unregistered) in reply to Troy McClure
    Troy McClure:
    Federal Catalog Scam:
    This is a joke right? This perceived security is analogous with leaving the keys in the lock of your front door, but throwing a plastic bag over the keys and calling it secure.

    You reap what you sow, and your reputation is what it is... this post changes nothing

    I was thinking putting the key under the mat and locking the door, but putting a sign on the door telling everyone the key is under the mat. And then being surprised when someone breaks in.

    Whoops, forgot the robots.txt file.

  • (cs) in reply to fert

    Wow, this just wouldn't be half so funny if not for their sad attempts at "security" by changing the password in plain sight over and over, and the unbelievably naive and simple-minded comments from supposed employees of the company. Now I'm hooked.

  • Horton Hears a FAIL (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Good news!!!!

    You may be eligible for support to fix your horrible coding.....Wow! really good news....For only $1500 I can fix that for you....Whaddaya say>?

    702-229-3111

  • Troy McClure (unregistered) in reply to sorakiu
    sorakiu:
    I think this is really crappy. This website in the past has changed names and not provided real URLs to a company. Maybe you don't like this guy's business, but I think it is inexcusable to post exploits to another website. Shame on daily wtf.

    You think its bad to expose an obvious scam? Shame on this catalog more like it. They're charging for a service (a LOT of money) so they are to blame.

    FUCK YOU.

  • blubberfest (unregistered) in reply to FEDERAL SUPPLIERS GUIDE CUSTOMER SUPPORT

    Then why don't you provide us with some links proving the veracity of your statements? Maybe something believable? That would be grand, thanks.

Leave a comment on “So You Hacked Our Site!?”

Log In or post as a guest

Replying to comment #:

« Return to Article