4 ms·
In my opinion this is a bit like finding a exploit in a site and contacting the company and publishing it later. It certainly is more flashier then reading a .t
by bittersweet 17y ago
In my opinion this is a bit like finding a exploit in a site and contacting the company and publishing it later. It certainly is more flashier then reading a .txt.
He uses a sort of scare tactic to let people see how easy it is to get into some of the sites, it might work well. I bet Cloudkick has this as their top priority now.
On the other hand, I don't know how many companies would want to hire him if he didn't take the time to contact Cloudkick.
- iuguy 17y agoI work in the industry and if what has happened is that the site requested a test from them and was happy for them to publish this then yes I guess it's appropriate, but I wouldn't really do it as it associates the firm with hacking live sites. To put it another way, to demonstrate the exploit you have to actually conduct the attack. To find the exploit you have to do a PoC. If this was done without explicit permission from the site owner it's legally shaky ground at best and certainly (at least as far as I'm concerned) unethical.