• tyler@programming.dev
    link
    fedilink
    arrow-up
    7
    ·
    14 days ago

    “Hack” is a very strong word here. They asked the website if they could be admin and the website happily said yes and made them admins.

      • tyler@programming.dev
        link
        fedilink
        arrow-up
        2
        ·
        14 days ago

        Oh definitely. They found a glaring vulnerability, it just doesn’t mean they hacked it. An equivalent would be somebody paying a pen testing team to see what they can do and the team finds an open window into the accounting office and they climb in, put a note on the desk stating that the pen testing team needs to get paid three times as much, and then accounting does it no questions asked after they find the note.