Publicly admitting to having committed a "computer crime"? That's a different story.
I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.
Publicly admitting to having committed a "computer crime"? That's a different story.
I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.
After berating one of the "d00ds" involved on Twitter, it looks to me like he told his friend how to exploit the problem, and his friend (or his friend's friend) made the site and exploited the hole.
If I show someone how to break into your house, and that person tells someone else "hey, nbpoole's house is open, let me show you," and your house gets broken into am I completely innocent of the crime? Security knowledge is the kind of knowledge that gets things broken into, so security people need necessarily be cautious with who they tell about security problems.