3 ms·
I may be completely wrong, but that seems a bit narrow a definition - attackers move laterally once they penetrate organizations. I can also imagine disgruntle
by Max-Ganz-II 2y ago
I may be completely wrong, but that seems a bit narrow a definition - attackers move laterally once they penetrate organizations.
I can also imagine disgruntled or malicious employees or contractors.
- codingdave 2y ago"once they penetrate organizations." Yep, that is the key. Crashing your own org hasn't done that. Unless I'm misunderstanding what you are claiming?
- Max-Ganz-II 2y agoNo. It's not a way to get in, but it is a way to crash a system (which should not be crashable) if you are in.
- codingdave 2y agoI think you are describing a bug, not a vulnerability. Is it bad? Sure. Is it a security vulnerability where you can impact anyone else? Doesn't sound like it.
- Max-Ganz-II 2y agoThis makes sense and I see it, but there is one matter which gives me pause; when I came to submit the issue, there's some kind of standard severity rating system, which you have to fill in. Questions like - can this issue be exploited over a network, or do you need local access? how many privileges are required? what's the consequence of the issue - degraded service, complete denial of service? questions like this. The issue here fitted into this framework of questions - there was no point where it didn't fit, and the severity rating system was evidently thinking in different terms.