TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

What to do after discovering SQL Injection vulnerability in random websites?

3 点作者 mariocarvalho超过 11 年前
After playing a little with Vega - I'm newbie in web auditions, just trying to learning something new - and auditing some websites I can see that 8/10 websites have SQL Injection vulnerabilities classified by Vega as High. What should I do here? Email the website owner?

2 条评论

pktgen超过 11 年前
I would be very, very, very careful here. Not sure what country you're in, but you're setting yourself up for possible legal action, even though your intentions are good.
gk1超过 11 年前
You can email the owner with a few tips to fix the issue. You can even offer to do a deeper inspection for some fee.
评论 #7292232 未加载