3 ms·
These guys (hackers) were not very ethical at all. They found an open Jenkins server and then compromised it. That’s illegal. You don’t do that to “find out wha
by bitexploder 8y ago
These guys (hackers) were not very ethical at all. They found an open Jenkins server and then compromised it. That’s illegal. You don’t do that to “find out what is going on”. The rest of the article is pretty accurate regarding vulnerability disclosure to smaller companies. My team faces problems similar to this all the time.
- mrguyorama 8y agoMy interpretation is that they were attempting to figure out the owner to disclose to. Is there a legal way to do so that doesn't involve leveraging a vulnerability and indeed "hacking" a system?
- bitexploder 8y agoNot always. You start with the IP and try to work from there. My general rule is you (1) never attempt to authenticate to a system. (2) use only publicly available information. Think GET verb only or equivalent. Don’t modify state on purpose. You could do a lot with Jenkins to find an over. Morally, what these guys did is acceptable IMO, but, ethically, no good.