4 ms·
I love reading write ups like this. It's an extremely empowering feeling to realize that all these opaque software and cryptic errors are ultimately also writte
by CornCobs 5y ago
I love reading write ups like this. It's an extremely empowering feeling to realize that all these opaque software and cryptic errors are ultimately also written by fellow programmers. You CAN understand it, you CAN take matters into your own hands.
I remember once, a few years back, there was this website where I was supposed to submit something, only that the submission page couldn't load. My friend thought that that was the end of it, but I decided to try to poke around.
Back then I was quite unacquainted with http but I started with what I knew, downloading the page source, figuring out what was the link or call that was failing, then testing it with curl. I eventually managed to figure out that the problem was caused by a missing header in the http request so I installed some random browser extension that patched http requests and voila, it worked!
Still remember the amazing feeling when the page loaded. My friend thought I was a wizard
- gleenn 5y agoI remember applying for a visa on a country's government website and their Javascript was broken. I "hacked" the HTML just to finish the application. I think it was a Firefox compatibility issue.
- aaronbrethorst 5y agoHopefully not to live in Missouri.
- renewiltord 5y agoThe problem isn’t the “hack”. They’re too dumb to notice. The problem is thinking they’re smart enough to be worth telling.
- kbelder 5y agoI think you were downvoted because somebody didn't catch your reference.
- aaronbrethorst 5y agoI think you're right. I got a good chuckle out of it :)
- ethbr0 5y agoAt one point, I managing some servers for a project at a large company. There was an internal web app via which one could modify and change the update / patch schedule for servers. Only it was behaving like I wasn't authorized to use it (despite being the registered owner of the servers), and I couldn't find any documentation on what groups it wanted me in. Take a quick glance at the js, and it's doing AD lookups from my client, via an unofficial AD-REST endpoint everyone used, and then using the result. So easy enough to just return what it's looking for and change my server's schedules as desired. But hmm... I wonder if it works for the admin-looking group? Yup. Of course it does. Ping it over to a friend who works in appsec, they poke it for awhile, and figure out (a) with admin permissions this tool can change the patch schedule of everything (e.g. AD domain controllers) & (b) the same pattern of client-checks was used on a lot of other tools that team built. So I threw some poor team's roadmap into disarray, but a little curiosity on my part helped improve our security posture.