Hacker News new | ask | show | jobs
by fellerts 749 days ago
Great read, I loved following your thought process as you kept digging.

At what point did you inform Cox about your findings? It doesn't sound like you were ever given the green light to poke at their management platform. Isn't work like this legally dubious, even if it is done purely in white-hat fashion?

1 comments

Cox has a vulnerability disclosure program. https://www.cox.com/aboutus/policies/cox-security-responsibl...