3 ms·
It's a very fine area. Once he had the database credentials, that's all he needed to tell the company to fix their code. Connecting to the database is what did
by magicmicah85 3y ago
It's a very fine area. Once he had the database credentials, that's all he needed to tell the company to fix their code. Connecting to the database is what did him in.
We need white hats that want to find vulnerabilities for good, but when you exploit a target and they aren't aware until after the fact, that's still a crime. I don't know what the safe way of doing this is other than only doing white hat hacking on systems you control. Any system outside of your control should not be exploited unless the company has an agreed upon contract that indemnifies you from any harm caused.
- fluoridation 3y agoAlternatively, reporting the vulnerability is what did him in. This seems to encourage an adversarial environment where no one will report any vulnerabilities they find for fear of repercussions. If their good faith efforts will be used against them, they may as well act in bad faith.
- raphman 3y agoThe developer claims that he assumed that he assumed that the database credentials were specific to the customer he was helping debug the problem. Once he realized that he could see other data, he closed the connection and notified the company. I'd argue that a customer who accesses their own data on a vendor's database via a client has also the right to access it via a different client.