did I ever mention that project I worked on where I discovered we had a dedicated public API which returned the root password for one of our production servers
Normally the URL was generated by the web server, passed to the web UI, and then silently passed back when the user clicked a certain button in the web UI. But a user could have manufactured a request using any other URL there. Any IP address or port, whatever
-
-
Of course, having inspected their traffic to find this out, the user already knew the IP address of at least one of our internal servers
Show this thread -
None of this amounted to anything in the end because the product, as you might expect from having been built by the same fine engineers who made these security decisions, flat-out didn't work, and therefore had no users
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.