Hacker News new | ask | show | jobs
by _l219 877 days ago
After moving to the UK, it has been my policy to pretend to see nothing.

During my first week in university, I found a vulnerability in two of their servers allowing me to execute arbitrary code/commands + escalate to root due to a very outdated kernel.

I reported this to a lecturer and was immediately told that what I did was illegal and not to poke at any of their services. Last I checked, it still hasn’t been fixed.

3 comments

The ostrich approach to tech security.
If it ain't broke don't fix it ;)
> I reported this to a lecturer

I wonder if such reports would be taken more or less serious if it was made anonymously.

Yes it is illegal, wont stop someone. Fools.