| I was at my first real software job and we had an in-house system to provide automated installers for common open-source applications for our end-users. After I started getting familiar with it I had a dream one night that certain input fields (which were very common) could be rather easily exploited to inject shell commands with root access. I woke up convinced that it was a real bug, went to work the next day, and proved it. It was exactly as I dreamed. I never had access to our internal codebase, but had seen enough of the front-end and what we stored on disk to piece it together in my dream. While it made me popular with some folks, it was a strange lesson indeed to discover that not everyone was as thrilled to have an up-start from tech support make such a discovery. Fast forward almost 20 years later and I've never had anything even remotely close happen again. |
It was a completely random series of notes.