3 ms·
> There is _zero_ reason for you to _use_ exposed credentials if you find them. It adds nothing to the "security research" you may be doing. Bullshit. For one
by evilDagmar 3y ago
> There is _zero_ reason for you to _use_ exposed credentials if you find them. It adds nothing to the "security research" you may be doing.
Bullshit. For one thing, he wasn't doing "security research" he was trying to fix a problem his client was asking him to fix that directly involved the MySQL database in question. He literally stumbled across the security problem by accident. For the other, the vendor should be facing an investigation into exactly why they thought it was a good idea to have thousands of customers and millions of euros "protected" by one single password that was stored in plaintext on thousands of customer's machines. In a number of places that could easily result in criminal liability on their part--which is probably exactly why they contacted the authorities.
...and I'll point out that he didn't actually even have to know what these credentials were. With elevated privs on the local system, one can merrily let the application connect to the database server and then snatch that socket up and do with it whatever they wish and then the same information would have been revealed--that every one of MS's customers could quite readily access all the data of every other customer.