Earlier quoted context omitted.
Just saying, If he found the vulnerability without using Acunetix, why did he have to use Acunetix later to check if the same vulnerability has been fixed or not? Couldn't he re-check using the same way that he initially found the vulnerability?
Perhaps he was using a wider net to see if there were any other problems which, given the level of (in)competence displayed by the techs working for the college, was a distinct possibility.
Hamed Helped. Help Hamed.
51–52 of 52 posts
Re: Hamed Helped. Help Hamed.
#52Earlier quoted context omitted.
http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…
It sounds like he's being screwed over by the vendor, who forced him to sign an NDA. To be honest anyone using Acunetix isn't looking to hack into anything. It's an enterprise scanner that looks for general web app issues rather than something that's typically used to conduct actual attacks. You'd expect an actual attack to be conducted with a tool like Havij, Sqlmap, Burp or Zap proxy.
But that doesn't make the scanner any less stressful or detrimental to the system