Rule 1. NEVER trust user supplied data. Once that rule was broken, any other rules broken became clear to everyone
You'd think that client side security would be something that we'd gotten over by now.
Well, we have passkeys. /s
131–140 of 151 posts
Rule 1. NEVER trust user supplied data. Once that rule was broken, any other rules broken became clear to everyone
You'd think that client side security would be something that we'd gotten over by now.
Well, we have passkeys. /s
Earlier quoted context omitted.
Did you try adjusting price?
I am not malicious or willing to attempt theft. Academically though, in an official testing environment, that would be entertaining to attempt.
Earlier quoted context omitted.
(playing the devil's advocate here) But that's not the case- if you find someone's physical keys in the street, will try to open the neighbor's door with it? so why is it ok to use a password that you "found" to log into a site?
Curiosity. I once dropped my keys on the way to my leasing office. I searched the entire complex and office for my keys. Then I saw a guy at the mailboxes trying to open each one, one by one.* I asked if he needed help and he just said he found some keys on the ground and wanted to find out who they belonged to. They were mine. And my mailbox was in the other side of the complex so all bets were off for him anyway. I…
Earlier quoted context omitted.
Curiosity. I once dropped my keys on the way to my leasing office. I searched the entire complex and office for my keys. Then I saw a guy at the mailboxes trying to open each one, one by one.* I asked if he needed help and he just said he found some keys on the ground and wanted to find out who they belonged to. They were mine. And my mailbox was in the other side of the complex so all bets were off for him anyway. I…
that actually maybe super illegal if they are usps mailboxes.
Imagine being a world class F1 driver and (someone) still have to upload your CV somewhere.
I imagine the instructor "What could I teach Verstappen now..."
That's not just one vulnerability, that's a whole slew of failures. For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hope you got at least free tickets for life out of this.
> For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hate this kind of post-hoc finger pointing people do after security breaches. There are other concerns in life beyond security - youre naive to think differently. Is your house secure or could somebody break past your protectio…
How do you feel if that's also what your bank chooses for you?
Earlier quoted context omitted.
Lesson: instead of being the good guy and reporting shit, just sell it on black market.
(playing the devil's advocate here) But that's not the case- if you find someone's physical keys in the street, will try to open the neighbor's door with it? so why is it ok to use a password that you "found" to log into a site?
They took the website offline on the same day it was reported! That’s amazing!
Yeah I thought that was good. The fix wasn't that long either given how fast enterprises like this usually operate.
That's not just one vulnerability, that's a whole slew of failures. For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hope you got at least free tickets for life out of this.
> For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hate this kind of post-hoc finger pointing people do after security breaches. There are other concerns in life beyond security - youre naive to think differently. Is your house secure or could somebody break past your protectio…