A former curriculum writer at an ed-tech company recounts discovering severe security vulnerabilities in a C-interpreter product used by K-12 schools. A locally-installed daemon ran an unauthenticated websocket server bound to 0.0.0.0 that accepted arbitrary C code for execution, enabling remote code execution from any website or any device on the same network. The company also had a server-side eval() code injection exposing plaintext credit card data, plus a default-credential router. The founder patched some issues quietly without notifying schools, and the company remains in business and has been recognized in an industry ranking.
401 Impressions