HN user

bbastian

25 karma
Posts4
Comments7
View on HN

This makes me wonder; how is it appropriate to handle vulnerabilities such as these?

A few months ago, I decided (as an experiment to see how common XSS actually is) to click on random HN links and type "<asdf '\"" into any search bars and look for weird rendering on the page or weird behaviour in the page source. After half an hour, I had five or so exploitable XSS vulnerabilities, two of the more prominent ones being CNN and Newegg. I sent emails to their security-related issue addresses, but they never responded or fixed the issue.

After sending them a couple more emails, I just gave up. But this article makes me wonder, could I have handled the situation better? The thought of releasing a benign-but-scary exploit crossed my mind, b ut I'm uncertain...

Well, with CouchDB, you have to pre-define all of your queries with "views". And the first time you call a view, it has to run your mapping function against -every- document in the database, which takes a ton of time.

Hmm. This is rather difficult. I'm under a lot of pressure from my parents to move out of the house and support myself. However, I have no experience doing anything else. I've applied to many jobs which require no skill, but have had no luck. Not really sure what to do... I don't dispute that building a portfolio, going to college and getting a degree would be a good idea, but I'm just trying to solve a difficult situation.