Hacker News new | ask | show | jobs
by mikeve 349 days ago
I love how run DOOM is listed first, over the possibility of customer data being stolen.
1 comments

I'm taking

>run DOOM

as the new

>cat /etc/passwd

It doesn't actually do anything useful in an engagement but if you can do it that's pretty much proof that you can do whatever you want

To be fair (or pedantic), in this post they didn't have root, so cat'ing etc/passwd would not have been possible, whereas installing a doom apk is trivial.
/etc/passwd is world readable by default.
To be even more pedantic, it's also not present on Android.
Good points, I've been out pedantic-ed!
not if you fork an open source os and add /etc/passwd you haven't been
Popping Calc!

(I'm showing my age here, aren't I?)