3 ms·
But in this particular case, it sounds like it wasn't known to him that it was an exposed credential. He thought it would just access his own data, so there wou
by andersa 3y ago
But in this particular case, it sounds like it wasn't known to him that it was an exposed credential. He thought it would just access his own data, so there would have been no reason to report anything to the vendor at that point. The access to protected data here was accidental.
- akira2501 3y agoHe thought the credentials, which were hard coded into the app, for an mysql server, somehow accessed only his data? That's hard to believe. Which seems like the defense understood, because they offered that the "name of the remote database" seemed like it could be related to his customer that he was contracted to. In the end, he's going to pay 3,000 euro, and made an example of. He could have received 3 years in prison. So slightly unfair to everyone but hardly worth stretching credulity to defend.
- andersa 3y agoHm, I think I misread the article. It just says it was accessing a database named after the client, not that the user/password suggested being specific to the client. So you're right, it being hard coded then suggests it can likely access all of them. He should have stopped there and reported the issue. While paying a fine of 3000€ is likely without consequence for most programmers, that's not the only thing that happens. It now shows up on his criminal record and would be considered in any future case against him.