funsec mailing list archives

Re: Youth expelled from Montreal college after finding "sloppy coding" that compromised security of 250, 000 students personal data


From: Rich Kulawiec <rsk () gsp org>
Date: Wed, 23 Jan 2013 03:44:06 -0500

On Tue, Jan 22, 2013 at 01:50:10PM -0500, Valdis.Kletnieks () vt edu wrote:
Yeah, I liked how they didn't know they had gotten probed till the kid
*told* them, but were immediately able to verify that they didn't have
any other un-noticed exploits of the hole.  (Sure, you can easily grep
for the scanning tool's footprint, but it takes a lot longer to verify
there's no disguised attacks with a different footprint).

        "In a world where owning a radio was strictly forbidden,
        one man found a way to bring good news to his people.

        He made it up."

Security holes usually don't travel alone.

---rsk

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: