A former curriculum writer at an ed-tech company recounts discovering severe security vulnerabilities in a C-interpreter product used by K-12 schools. A locally-installed daemon ran an unauthenticated websocket server bound to 0.0.0.0 that accepted arbitrary C code for execution, enabling remote code execution from any website or any device on the same network. The company also had a server-side eval() code injection exposing plaintext credit card data, plus a default-credential router. The founder patched some issues quietly without notifying schools, and the company remains in business and has been recognized in an industry ranking.

4m read timeFrom thedailywtf.com
Post cover image
401 Impressions