Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, that's what I understood too. The article seems to exaggerate some points, and this is one of them.

It's like creating an attack called "GOLDEN ADMIN". If you have admin credentials, you can log in as the admin and do anything you want! Wow!

(I know that letting attackers authenticate to anywhere without generating logs is bad, but still... i agree with the parent reply)



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: