JamieTheMashMan

23 Followers
40 Following
105 Posts
I’m aMechanical engineer who learnt to code
WorkFounder @ Mashoom
WorkCTO @ Loanpad
FunI own ~190 actual CDs, and listen to them loads 🙂

Hello Mastodon! I haven't really posted anything here since I'm socially awkward but I come with a cry for help.

I am not a security professional (although I strive to be), just an engineer so I need some advice. I found an unprotected endpoint on one of the sites I use daily for my business that allows read access to all documents, regardless of who they belong to. I disclosed the vulnerability with the company that owns the platform and their dev team is already working on a fix. The thing is, their OpSec is pretty much non-existent and I lack the knowledge to know what to do here. Is this something that should be disclosed to the public after it's patched? I also want to recommend they check their logs to see if someone has exploited this before, but I lack the confidence lol.

Could anyone tell me how I should recommend they handle this? Is this maybe something I should NOT do?

Thank you lovely people :)
#opsec #redteam #vulnerability #disclosure #infosec

FWIW I still hope Elon succeeds with Twitter. Why wish failure on anyone? But for me, not letting people post links to their other accounts was just too much.
This hit me different… here’a to creating real value… 🙂

I've decided to release my own Christmas single called "Duvet Know It's Christmas?"

It's a cover version.

It’s fennel. Or is it bok choy? Or is it the climax of my latte art career?
An HTTP Request in the Queens English.
Mercator size vs. true country size
by Neil Kaye
If it makes you feel better, because environment as well
GitHub - hakluke/how-to-exit-vim: Below are some simple methods for exiting vim.

Below are some simple methods for exiting vim. Contribute to hakluke/how-to-exit-vim development by creating an account on GitHub.

GitHub
I mean, it's a good album, but...