4 ms·
Interesting to see this come up. About 2 years ago I found a similar exploit in blackboard (XSS that could lead to session hijacking) and found that there was a
by Conlectus 7y ago
Interesting to see this come up. About 2 years ago I found a similar exploit in blackboard (XSS that could lead to session hijacking) and found that there was absolutely no way to report the vulnerability except through their help-and-support chat.
After reporting it, they thanked me and said they would be in touch when they addressed it. I never heard from them again, and it seems they didn't take security much more seriously.
- save_ferris 7y agoHad a similar issue with Southwest Airlines a while back. I wound up emailing a VP directly with screenshots and repro steps by looking up other SW email addresses to figure out their work email format, and then getting the VP's name from LinkedIn. The VP responded pretty quickly, forwarded my email on his people, and I wound up getting some free miles. I was kinda surprised to learn how easy it is to get most corporate email addresses through this experience.
- rtkwe 7y agoThe public disclosure part is really important as it's basically the main stick forcing companies to actually fix things in a timely manner in any case where there's not a direct threat of financial loss to the company.
- non-entity 7y agoI once reported a similar XSS session hijacking bug in the LMS our district used in highschool. The response? Something along the lines of "hmm, maybe you just shouldn't do that"