Security Hack.... Who do I discuss this with ?
I have come across a "hack" that was done to a bulletin board (very recently),
that scares the bejeezus out of me.
I can see this happening pretty much on any bulletin board which uses any form of "sql" database.
In this specific case, they logged in, changed their session ID to "1", refreshed the page, then wreaked havoc all over the site.
I have the specific code used to perform this hack,
but do not want to merely display it here (for obvious reasons).
Who/How can I discuss this and what can/should I do to prevent it from happening on my site?
|