Hacker News new | ask | show | jobs
by madmod 1365 days ago
In high school I was trying to make an app to scrape my grading system Skyward and ended up finding a trivial auth bypass that let me see anyones grades. Knew the school would turn me into a villain if I was discovered even though I was on student council and an honor student so I emailed the principal and got a meeting with him. For some unknown reason my poc didn't work in the meeting so during the meeting I found a second auth bypass. They paid me $75 for finding the issue and told me to try to hack the teachers side of the system next. Lots more to the story if anyones interested.
2 comments

I'd interested to hear more about the story! Would be cool if you wrote a blog post or something about it.
Definitely interested. Would you mind if we had a call or discuss over email and I can post it as blog or podcast