TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Infosec ethics in zero days, exploits and attribution

4 点作者 santaragolabs将近 8 年前

1 comment

cody8295将近 8 年前
I was working for a tech support&#x2F;student financial aid support center for a couple months and was fired for finding and using an exploit.<p>It was getting close to Thanksgiving and all the employees had to do state mandated online ethics training (this was a Connecticut state job).<p>The online ethics training was honestly bullshit, it was poorly designed and even more poorly implemented. Some slides wouldn&#x27;t load fully and others would be buggy. I had to restart it about 3 times.<p>In my frustration I looked into the source code for shortcuts and found a javascript file which included a function called SetScore(min,max,val).<p>After opening Chrome dev console and trying the function, I exited the training and refreshed to see a score of 100!<p>I immediately emailed my managers, and the admin of the site where the training was being hosted. 2 weeks later I got a call that I was terminated.