Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  DON'T USE IT
This site has a serious security flaw: every registered user can change the email and password of every account.

Edit: I've sent the site op an email



Fixed


If it's fixed, care to describe what the bug was if it was interesting?


When you visited a profile, there was a "edit" button so that you could just change email and password of every user. The kind of bug my grandma would find just by clicking around.


It's a side project (and given the setup doomed to fail anyway). Super big (US) IT-companies struggel with how to being profitable, whilest IT is capital/work intensive (to avoid these embarassing bugs).

There is a long-tail, but it's not for you.


do you know lobste.rs? Have you considered using it, it seems quite mature, can be white labeled and also is an rails app.


There's also http://telesc.pe :)


Recommended as is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: