Earlier quoted context omitted.
If I was interviewing the author for a role their complete disregard for infosec ethics would be a hard "no" from me - no matter how good they might be at interviewing.
I think this depends somewhat on how old they were - young people do stupid things.
I compromised 300 stores and a “Spanish consultancy”
31–40 of 49 posts
Re: I compromised 300 stores and a “Spanish consultancy”
#32"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.
Re: I compromised 300 stores and a “Spanish consultancy”
#33How legal is what this guy did in Spain?
Re: I compromised 300 stores and a “Spanish consultancy”
#34I don’t think HN should be a place for “company shaming”… unless the author contacted the company and they denied/rejected/threaten him instead of fixing the issues. I guess it did not happen. I see HN as a place for collective learning. I don’t see what we can learn from this post.
Which company is shamed in this post?
Re: I compromised 300 stores and a “Spanish consultancy”
#35Re: I compromised 300 stores and a “Spanish consultancy”
#36Umm this guy should tread lightly. Whats up with the prodding? This is some straight up blackhat hacking.
Yes, this crosses all the lines. You can debate the finer points of the SQL injection bit, but the moment he got into Rocket Chat admin and started gratuitously stealing employee cookies, there's just no way to paint that any color other than black. As his bio states, he's a software engineer - clearly not a security professional, because he's steamrolling right through all infosec ethics. A quick Google search for h…
Re: I compromised 300 stores and a “Spanish consultancy”
#37"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.
Once he found the SQL injection, downloading the tables was too far IMO. On the other hand if he had stopped at this point, the company would have no idea about the weak admin credentials that could lead to real data breach and internal compromise at a later date.
Re: I compromised 300 stores and a “Spanish consultancy”
#38Re: I compromised 300 stores and a “Spanish consultancy”
#39"I thought about writing an email to these people, let them know about the vulnerabilities in their code, and the bad practices they have, but I didn’t at this point. I felt like I was able to find more things regarding this company." Oof, that's bad behavior. I wouldn't be proudly blogging about this.
Re: I compromised 300 stores and a “Spanish consultancy”
#40How legal is what this guy did in Spain?
But, the cyber security professionals working in the consultancy firm can gather easily the small pieces of information left behind and sue him if they find out data extraction, for example.
Keep in mind that he claims he extracted sensitive data, but he could be lying just to be in the HN front page. Who knows.
Unethical, risky… and very stupid.