https://ze3tar.github.io/post-zcrx.html #LinuxKernel #Exploit #RootAccess #CyberSecurity #StackOverflow #AdminAccess #HackerNews #ngated
Type Juggling 0==Admin Grants 847 Users ADMIN ACCESS?!
TYPE JUGGLING DISASTER! 0=='admin' returns TRUE! Password check BYPASSED! 847 users got admin access! Downloaded 2.3M customer records! $12.3M data breach lawsuit! CTO FIRED!
#php #phpdisaster #typejuggling #authenticationbypass #securitybreach #adminaccess #productionbug #phpshorts #phpwtf #0equalsadmin #careerending #databreach

Decorator Order Executes Route BEFORE Auth Check?!
DECORATOR DISASTER! Apply bottom-to-top! Route runs BEFORE auth! Non-admin deletes 847 users! Cannot recover! $4.7M data loss! €2.7M GDPR fine! Security team FIRED!
#python #pythondisaster #decoratororder #authenticationbypass #routesecurity #productionbug #pythonshorts #pythonwtf #adminaccess #careerending #gdpr #flask

Encountering a fatal error in WordPress can prevent you from accessing the admin area, making it difficult to manage or troubleshoot your site. However, there
"... I learned a lot on that job - mostly by making mistakes."
Mefites are weighing in on an Ask Metafilter question about the likelihood of admin login rights creating a major security risk on a work computer.
https://ask.metafilter.com/378147/Is-this-uni-claim-reasonable-it-doesnt-sound-so-to-me
#admin #AdminAccess #AdminLogin #computer #IT #login #security