[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Found an sqli vulnerability in a major movie production company

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 32
Thread images: 3

File: IMG_0035.jpg (55KB, 600x535px) Image search: [Google]
IMG_0035.jpg
55KB, 600x535px
Found an sqli vulnerability in a major movie production company
, what the hell can i even do with that?
>>
>>58390017
leak info, grab some logins and change their sites; sell the info on the dark web or something
>>
>>58390017
dump admin details and 301 it to goatse.cx
>>
copy all the info you can, change nothing, gradually """leak""" out info to """news""" groups
>>
>>58390017
>tell them
>maybe get appreciation for it
>>
File: tfw.jpg (23KB, 385x385px) Image search: [Google]
tfw.jpg
23KB, 385x385px
>>58390408
>tfw goatse was deleted from the .cx domain so long ago
>>
>>58390421
>tell them
>get sued
Yeah, nope
>>
>>58390017
try to find a way to get a shell login, try to see what other servers are visible & repeat until you find a server with unreleased movies
>>
>>58390464
>implying
any not complete retarded company would appreciate it, if you don't make it public instantly
>>
>>58390464
Check if they have a bug bounty program
>>
sneak tranny porn scenes into movies right before they're released to theaters
>>
File: 1483791191797.jpg (141KB, 1500x1500px) Image search: [Google]
1483791191797.jpg
141KB, 1500x1500px
>>58390496
>film companies
>not completely retarded
>>
>>58390557
You know that they rely on they're reputation, nigger?
>>
>>58390696
>they're reputation
IDIOT
>>
Depends. If the company approved or is okay with this, they should provide some kind of credit or compensation for the vulnerability. Otherwise, they could press charges for unauthorization. For your safety, consider reporting the vulnerability anonymously without providing your information. I've been in a situation where I reported a bug and the company did not authorize it and tried to press charges. The charges were dropped after I told them I would provide a fix for the vulnerability at no charge and did so at the cost of my time and efforts. Be careful.
>>
>>58390718
Your the idiot, because you think that companies are evil.
>>
>>58390765
>Your the idiot
IDIOT
>>
>>58390765
You're *
>>
>>58390908
How do you know this is correct?
Fact is: you don't.
>>
>>58390718
>>58390820
>>58390908
Newfags
>>
>>58390765
Here's an example for you - A Vulnerability Timeline for an exploit in some PwC software:

19.08.2016 PwC contacted
22.08.2016 Meeting with PwC, informed them about the impact and the details of the vulnerability and responsible disclosure
05.09.2016 Asked PwC about updates and whether a patch is available
13.09.2016 Received a Cease & Desist letter from PwC lawyers
18.11.2016 Informed that 90 days have passed and ESNC is planning to release a security advisory; asked for any details PwC can share about this matter including risk, affected versions, how to obtain a patch
22.11.2016 Received another Cease & Desist letter from PwC lawyers
07.12.2016 Public disclosure
>>
>>58391177
hail PwC

I am only workin' for kpmg though
>>
>>58391177
>>58391199
What does PwC and kpmg have to do with movie production?
>>
>>58391216
Heavily depends on you're mom.
>>
>>58391216
Just an example of the sort of response you'll get if you tell a big corp about a security hole.
>>
>>58391229
>you're mom
IDIOT

>>58391231
Oh yeah.
>>
>>58391231
find directors emails and contact info..

ill buy a bunk of movie directors info op.

let me know if you find any..
>>
>>58391216

The timeline the guy above you posted was about an SAP auditing tool PwC uses. They load it up at a customer site and it pulls a bunch of data from an SAP system that they use to compare to the financial data the company provides to Wall Street to help locate any discrepancies. So in this case, any publicly-traded company that runs SAP and uses PwC for their auditing firm could be vulnerable to that exploit.
>>
>>58391312
That's huge.
>>
>>58391312
inb4 op gets suicided by 6 shots on the back of the head while drowed in the toilet while he was taking a piss
>>
>>58391312
its happening

https://www.youtube.com/watch?v=sEBG3KqxGhw
>>
>>58391536
>2011
Whatever this was, it already happened
Thread posts: 32
Thread images: 3


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.