Hacking and exploiting - How do you deal with any security holes you find?

前端 未结 8 2202
慢半拍i
慢半拍i 2021-01-30 04:26

Today online security is a very important factor. Many businesses are completely based online, and there is tons of sensitive data available to check out only by using your web

8条回答
  •  暖寄归人
    2021-01-30 05:15

    If it doesn't affect many users, then I think notifying the site administrators is the most you can be expected to do. If the exploit has widespread ramifications (like a Windows security exploit) then you should notify someone in a position to fix the problem, then give them time to fix it before you publish the exploit (if publishing it is your intention).

    A lot of people cry about exploit publication, but sometimes that's the only way to get a response. Keep in mind that if you found an exploit, there's a high likelihood that someone with less altruistic intentions has found it and has started exploiting it already.

    Edit: Consult a lawyer before you publish anything that could damage a company's reputation.

提交回复
热议问题