This is illegal! Most people seem to be missing this.
If you're going to break the law at your own University at least cover your tracks.
Don't annoy the crap out of them(Rightly or wrongly) then go on to black hat them.
81–90 of 308 posts
This is illegal! Most people seem to be missing this.
If you're going to break the law at your own University at least cover your tracks.
Don't annoy the crap out of them(Rightly or wrongly) then go on to black hat them.
shall we all assume it was an sql injection? does anyone know what the actual vulnerability was?
Sensationalist journalism is what it is. After a little bit of research, I discovered it's written by someone who used to be in Dawson's Student Union, so I guess he has a teeth against the administration.
"Ethan Cox is a 28-year-old political organizer and writer from Montreal. He cut his political teeth accrediting the Dawson Student Union against ferocious opposition from the college administration and has worked as a union organizer for the Public Service Alliance of Canada."
The title is misleading. He wasn't actually expelled for finding the flaw; he was expelled because, after reporting the flaw, he ran an exploit program on the school's server without permission, allegedly to see if it had been fixed. Had he only reported it, he would not have been subject to any disciplinary action.
"Ethan Cox is a 28-year-old political organizer and writer from Montreal. He cut his political teeth accrediting the Dawson Student Union against ferocious opposition from the college administration and has worked as a union organizer for the Public Service Alliance of Canada."
The title is misleading. He wasn't actually expelled for finding the flaw; he was expelled because, after reporting the flaw, he ran an exploit program on the school's server without permission, allegedly to see if it had been fixed. Had he only reported it, he would not have been subject to any disciplinary action.
He ran an exploit FINDER. He did not put exploit programs on the server.
ie: http://security.stackexchange.com/questions/14978/is-scannin...
I've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institu…
Go sign the petition here: http://hamedhelped.com/petition/