3 ms·
I happen to know one of the authors of this post (hey Tom!). He's actually a really nice, down to earth guy. Helped out with our college cyber defense programs
by cipherboy 7y ago
I happen to know one of the authors of this post (hey Tom!). He's actually a really nice, down to earth guy. Helped out with our college cyber defense programs and is a killer red teamer. Very patient in explaining how he got in and defaced your website, time and time again.
Is this his best work? Nah, this is amateur hour on the part of Netgear. But am I glad it was him who found it? Definitely.
Keep in mind, there really wasn't anything _to_ this vulnerability other than copying and pasting from one website (and a firmware zip) to another. They just added a little pretty formating and saved you the trouble of extracting the firmware.
- ryanlol 7y agoI don’t doubt that the authors of this post are wonderful people. I just don’t think that there are too many people in this space working for free, only motivated by a desire to help people. I certainly don’t think that there’s anything wrong with dropping bugs to pad your résumé. To the contrary, I think it’s fundamentally unreasonable to expect that more than a couple of people would do this work for purely selfless reasons.
- CiPHPerCoder 7y agoPeople who do this kind of work for purely selfless reasons and don't end up starving or homeless are probably very privileged.