Howto crack plimus "MD5hex encryption"
It’s been a while since I have reported a few security bugs to Plimus. It took a few blogposts explaining the issues publicly before I got in contact with an engineer. I understand that making backwards incompatible changes to your customer facing API’s is not a trivial task, however the way Plimus handles these issues is just terrible. One engineer asks me for more feedback while in the same mail thread another Plimus employee demands proof I’m PCI certified and wants to know what applications I’m going to build before I get access to the test API of Plimus. If you don’t even let me test security bugs before I report them you won’t get the bugreport at all. Maybe I can test them after you have gone live and customers already depend on the API. ...