Hacker News new | ask | show | jobs
by thefreeman 3968 days ago
they also brute forced employee accounts (likely the sql injection was in the employee facing section of the site)