Hacker News new | ask | show | jobs
by rootuid 4574 days ago
Contact the vendor, give them time to fix it. Wtf are your contacting his customers?

Sam, you are truly a moron.

1 comments

It doesn't seem that he felt like taking any action since 2010
Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.
What's "responsible" about not telling the people who actually own the websites in question?
Maybe he was, maybe he wasn't, only he knows. But when you're running 100000 websites, you should Google yourself once in a while at least. Besides, this isn't some 0-day, it's some extremely basic SQL injection vulnerability. This company wasn't capable of doing extremely basic security, and should be out of business. This is the kind of company that stores your passwords in plaintext. He doesn't seem to have done anything since he was notified either (see Phil's comment)
Oh, I'm definitely not disagreeing that the company was irresponsible in their coding practices and having found the previously released notices on their own - they are certainly at fault for that negligence - and if they have indeed been notified before, then they are even worse of a company; but I still think the Sam didn't approach the disclosure properly, but that's just an opinion.
Yes, the company has had plenty of time to fix this amateurish error on their own, especially since it has been reported/detailed on exploit sites in the past.