RE: Threaded Mode | Linear Mode open redirect vulnerability In Cristiano Ronaldo website 07-06-2014, 11:18 AM
#11
(07-06-2014, 11:12 AM)Geoff Wrote:(07-06-2014, 02:15 AM)BroZix Wrote:(07-05-2014, 02:37 PM)Geoff Wrote:(07-05-2014, 12:38 PM)XrpmX13 Wrote: Personally, I'd use this to break into their website and completely destroy it in order for them to realize the intensity of this threat, since nowadays people don't give any rewards or even a simple email saying "thanks" for your efforts.
This bugs me. You're suggesting you/he/people should be a fucking prick because you assume the person isnt going to be appreciative or reward you.
and even if they arent appreciative, or do not reward you - why does this necessitate being an asshole in return? If you want to get paid to pen test, find a job in that field.
This concept of ethics you have is akin to robbing someones house if they left the window open - suggesting you did it to prove the the intensity of the issue because they probably wouldnt be appreciative of you sneaking around their house trying to break in.
Your just using poor logic to justify an unethical action.
Don't want to get into the middle of so called war but I will say few words regarding that problem. Some day I found vulnerable device which was just "out there" on the internet of course I have investigated it and it appeard that some company could lose their money because of it. I had reported this right away to them but well ... After like 3 or 5 months after the report they didn't even care to respond to me and this still works...
I also in the message described what's the problem is and how to resolve it but they simply don't care ....
Anyway I don't defend or approve XrpmX13 behaviour in any way and just speak about my experience which I had when I was playing around some weekend for fun. Tho I must agree on some parts with XrpmX13 because some companies don't care even if you report it to them and spoonfed them how to repair it which is very sad in my opinion ┐('~`;)┌
I think you missed my point.
I am well aware that some companies dont care, dont react quickly, and/or are not appreciative. That doesnt excuse being a cunt though, especially if you havent even attempted to address the vulnerability with the vendor/company.
We can say that we had some misunderstanding here :troll:. Well yeah true but as they saying that's where does Black Hat Hackers coming into game tho.
![[Image: Facepalm-GIFS-1.gif]](http://gifsec.com/wp-content/uploads/GIF/2014/03/Facepalm-GIFS-1.gif)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
