Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

1–10 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#3
post #2

If you (like me) didn't know what a Shodan safari is, you're in for a fun ride: https://techcrunch.com/2019/01/21/shodan-safari/

It is unbelievable what, to this day, is still directly connected to the Internet. Everything from pharmacy prescription systems, to large cargo ships in the middle of the pacific, to dam control systems.

Shodan is an awesome tool.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#4
With articles like this, I often to take out the horrible thing that the company is doing and post the quote to Hacker News, to give a sense of the scale of the issue; in this case me trying to do so would require including the majority of the article. It’s that bad. And yes, apparently the company thought it was ok for the COO to physically assault security researchers at a conference.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#6
post #2

If you (like me) didn't know what a Shodan safari is, you're in for a fun ride: https://techcrunch.com/2019/01/21/shodan-safari/

It is unbelievable what, to this day, is still directly connected to the Internet. Everything from pharmacy prescription systems, to large cargo ships in the middle of the pacific, to dam control systems. Shodan is an awesome tool.

Also they have a free plan for anyone with an edu email, great way to kill a few hours in between studying!

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#9
I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#10
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Edit: the vulnerability still exists on many online exam styled pages.
Post reply on HN