3 ms·
Based on the text of the post, it seems like OP stopped "probing the API" as soon as they had enough information to know that there was a security hole. So is y
by c1ccccc1 5y ago
Based on the text of the post, it seems like OP stopped "probing the API" as soon as they had enough information to know that there was a security hole. So is your proposal that any kind of probing of APIs in general should be considered malicious? Like if someone has an image conversion API and I submit a gif, or a 1x1 image to see what happens, that makes me a malicious hacker?
That position seems wrong to me, and the strained physical-world analogies you give don't justify it. Often, testing something directly is the only way to find out how it actually works. Which is necessary in plenty of non-hacking situations.