3 ms·
Sadly this is why one must notify vendors anonymously, and tell them up front they have 30/60/90 days to fix it before the information will be made public. Thi
by evilDagmar 3y ago
Sadly this is why one must notify vendors anonymously, and tell them up front they have 30/60/90 days to fix it before the information will be made public.
This vendor was abysmally irresponsible by storing static credentials in the application with apparently full read access to the databases. Stored procedures exist for a reason and they're not even remotely new.
If a "bad guy" had dug this out first, things would have been much, much worse for everyone involved, including the vendor. Trying to shoot the messenger makes me wish they'd mentioned which vendor so that their customers could be encouraged to go with someone who takes security even a little bit seriously.