Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

#293221 6-Jan-2022 21:19
Send private message

I’ve just received a domain search alert from haveibeenpwnd for a specific address I use for bunnings only.

 

 

 

Here’s a link to the site https://haveibeenpwned.com/PwnedWebsites#FlexBooker 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
Oblivian
7354 posts

Uber Geek
+1 received by user: 2123

ID Verified

  #2844674 6-Jan-2022 21:40
Send private message

Looks like they may not be the last/only using that service too

Saas pickup bookings for covid

“The pandemic gave us an opportunity to help in lots of new and unexpected spaces,” Ford said. “It opened up new markets in retail. We never anticipated having a retail footprint, yet one of our biggest customers is Bunnings Warehouse in Australia. Since they went into lockdown, a couple of hundred locations found us; we have no idea how. has All their customers have to do drive up and collect their purchases. They built us into their order flow. We make about 30,000 bookings a day through that one client alone. If you had told me a warehouse in Australia would have using our system, I would have said you were crazy.”



Stu

Stu
Hammered
8785 posts

Uber Geek
+1 received by user: 2426

Moderator
ID Verified
Trusted
Lifetime subscriber

  #2844675 6-Jan-2022 21:47
Send private message

Also received the email. Not sure if Bunnings use FlexBooker for payments, though? I'll have a better hunt tomorrow, but it may only be that they use FlexBooker for booking Click and Collect pickups (I think you only end up using FlexBooker once the staff have made up your order and you get notified to go and select a pickup time). At least, I hope that's all they use it for!




People often mistake me for an adult because of my age.

 

Keep calm, and carry on posting.

 

Referral Links: Sharesies

 

Are you happy with what you get from Geekzone? If so, please consider supporting us by subscribing.

 

No matter where you go, there you are.


davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

  #2844677 6-Jan-2022 21:52
Send private message

Stu: Also received the email. Not sure if Bunnings use FlexBooker for payments, though? I'll have a better hunt tomorrow, but it may only be that they use FlexBooker for booking Click and Collect pickups (I think you only end up using FlexBooker once the staff have made up your order and you get notified to go and select a pickup time). At least, I hope that's all they use it for!

 

 

 

ahh ok.  I had used click and collect once I think. 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 




Lias
5662 posts

Uber Geek
+1 received by user: 3983

ID Verified
Trusted
Lifetime subscriber

  #2844687 6-Jan-2022 23:15
Send private message

I also use a unique address for bunnings.. No notification (nor flag on manual check).

 

Last time I did a click and collect from Bunnings was June, so looks like this may be a relatively new system?

 

 





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup. Opinions are my own and not the views of my employer.


Kraven
738 posts

Ultimate Geek
+1 received by user: 190


  #2844689 6-Jan-2022 23:25
Send private message

I too received this and found an Bunnings Drive & Collect booking confirmation email and it does indeed originate from Flexbooker. Booking was in Sept 2021.


Senecio
2868 posts

Uber Geek
+1 received by user: 3189

ID Verified
Lifetime subscriber

  #2844723 7-Jan-2022 08:43
Send private message

Thank you for posting this. I too received the same alert but as I don’t use unique email addresses (yet!) I had no idea which online retailer was involved. Now at least I know to change my Bunnings password.

 
 
 

Shop now at Mighty Ape (affiliate link).
davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

  #2844731 7-Jan-2022 09:09
Send private message

Senecio: Thank you for posting this. I too received the same alert but as I don’t use unique email addresses (yet!) I had no idea which online retailer was involved. Now at least I know to change my Bunnings password.

 

 

 

good luck.   I’m Not actually sure how. I think maybe you have to perform a reset on it.  If you figure it out, let me know 

 

 

 

EDIT:  unless you  can find something in the site for changing a password, the only method I’ve seen is a password reset.   I’ve just done this for mine





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


Jase2985
13755 posts

Uber Geek
+1 received by user: 6236

ID Verified
Lifetime subscriber

  #2844734 7-Jan-2022 09:17
Send private message

is it actually related to the bunnings website and account info?

 

doesnt bunnings just pass your order off to FlexBooker so you can book your click and collect?


Oblivian
7354 posts

Uber Geek
+1 received by user: 2123

ID Verified

  #2844740 7-Jan-2022 09:35
Send private message

Jase2985:

is it actually related to the bunnings website and account info?


doesnt bunnings just pass your order off to FlexBooker so you can book your click and collect?



See my quoted testimony. It isn't clear what is passed on. But likely just the scheduling minimal. Potentially even the source for all the mobile spam increase...

It's now on reddit. With the aussies raising it with privacy as their requirements mean the company has to disclose and advise customers asap or face penalties.

Senecio
2868 posts

Uber Geek
+1 received by user: 3189

ID Verified
Lifetime subscriber

  #2844762 7-Jan-2022 10:14
Send private message

davidcole:

 

Senecio: Thank you for posting this. I too received the same alert but as I don’t use unique email addresses (yet!) I had no idea which online retailer was involved. Now at least I know to change my Bunnings password.

 

 

 

good luck.   I’m Not actually sure how. I think maybe you have to perform a reset on it.  If you figure it out, let me know 

 

 

 

EDIT:  unless you  can find something in the site for changing a password, the only method I’ve seen is a password reset.   I’ve just done this for mine

 

 

Yes, password reset was the only way. I've found that's not uncommon. Many websites don't provide the ability to update a password. You have to log out click forgo password to get a reset.

 

 


freitasm
BDFL - Memuneh
80802 posts

Uber Geek
+1 received by user: 41402

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2844794 7-Jan-2022 11:48
Send private message

FlexBooker discloses data breach, over 3.7 million accounts impacted (bleepingcomputer.com)

 

 

Accounts of more than three million users of the U.S.-based FlexBooker appointment scheduling service have been stolen in an attack before the holidays and are now being traded on hacker forums.

 

The same intruders are offering databases claiming to be from two other entities: racing media organization Racing.com and Redbourne Group’s rediCASE case management software, both from Australia.

 

Pre-holiday breaches
All three breaches allegedly occurred a few days before Christmas and the intruder published the data on a hacker forum.

 

The latest data dump appears to be from FlexBooker, a popular tool for scheduling appointments and synchronizing employee calendar.

 

Among FlexBooker’s customers are owners of any business that needs to schedule appointments, which is everything from accountants, barbers, doctors, mechanics, lawyers, dentists, gyms, salons, therapists, trainers, spas, and the list goes on.

 

Claiming the attack seems to be a group calling themselves Uawrongteam, who shared links to archives and files with sensitive information, such as photos, driver’s licenses, and other IDs.

 

According to Uawrongteam, the database contains a table with 10 million lines of customer information that ranges from payment forms and charges to driver’s license photos.

 

The actor notes that some “juicy columns” in the database are names, emails, phone numbers, password salt, and hashed passwords.

 





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


 
 
 

Shop on-line at New World now for your groceries (affiliate link).
davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

  #2844795 7-Jan-2022 11:53
Send private message

Be Interesting to know what Informstion bunnings has passed.   I’d assume email and phone number.   Maybe address details.  If payment I’d be really pissed 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

  #2844851 7-Jan-2022 15:08
Send private message

Hi.  Received the following via pm.   Edited to removed users comments and just left the technical details.

 

 

 

 

We send the following information to FlexBooker, and only if the customer chooses to book a collection time slot by clicking a link in an email we send from our own platforms: customer name, customer email address, order number (Wxxxxxxxxx-x), collection store. Of course the date and time of the slot the customer chooses is also retained by FlexBooker.

 

https://a.flexbooker.com/reserve/bunnings?firstName=FIRSTNAME%20LASTNAME&order-number=Wxxxxxxxxx-x&email=EMAIL&locationId=STORE#calendar

 

We do not send any other information, including addresses, payment information or credit card details etc to FlexBooker.

 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


Oblivian
7354 posts

Uber Geek
+1 received by user: 2123

ID Verified

  #2844863 7-Jan-2022 15:25
Send private message

Perhaps redact role/name? ;) Cant be too many. And passing that is making it kinda public

(A paraphrase may be better)

davidcole

6099 posts

Uber Geek
+1 received by user: 1465

Trusted

  #2844865 7-Jan-2022 15:32
Send private message

Oblivian: Perhaps redact role/name? ;) Cant be too many. And passing that is making it kinda public

(A paraphrase may be better)

 

 

 

yeah I was doing on phone so just copy pasted.   I’ve gone and left just the technical details now.   Rather than any comment from the pm sender. 





Previously known as psycik

Home Assistant: Gigabyte AMD A8 Brix, Home Assistant with Aeotech ZWave Controller, Raspberry PI, Wemos D1 Mini, Zwave, Shelly Humidity and Temperature sensors
Media:Chromecast v2, ATV4 4k, ATV4, HDHomeRun Dual
Server
Host Plex Server 3x3TB, 4x4TB using MergerFS, Samsung 850 evo 512 GB SSD, Proxmox Server with 1xW10, 2xUbuntu 22.04 LTS, Backblaze Backups, usenetprime.com fastmail.com Sharesies Trakt.TV Sharesight 


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.