Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually it's reasonable that this person haven't given you the details. If he disclosed specific way he got in you'd probably patch it and carry on. Then he'd probably find another way to get in, disclosed it too, you'd patch it and it could turn into full-time (low/un)paid job for him. Not to mention that all of the holes found by him could earlier be exploited by someone else who could left something on your server.

By sending just the proof he forces you to reconsider your approach to security and start from clean state.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: