If you're very lucky, the place you are in won't honor their demands for extradition on the hacking charges.
If you're very lucky, the place you are in won't honor their demands for extradition on the hacking charges.
Here's the mail I sent:
Hi there,
It appears that you have some pretty severe security problems on your site. This is a heads up so you can get it fixed. I would recommend doing so ASAP.
Your site has been posted to hacker news (which is a friendly programming site for start-up people and nerds) as an example of bad security practices. The link is here: http://news.ycombinator.com/item?id=2383857
It has also been posted to Reddit, which might be more of a problem since that site has a lot of 14 year old bored teens hanging around that know just enough about programming to do a lot of damage... Link: http://www.reddit.com/r/programming/comments/gdviz/how_not_t...
It appears that your site is easy to compromise, which might lead to anything from defacement to someone stealing all your content, usernames, passwords, etc.
I have nothing to do with these postings, I just don't like to see innocent sites get in trouble, hence this mail. Feel free to contact me if you need anything or have questions.
Hope you get it fixed before someone breaks it.
Yours,
Max
Oh, I understand the word hacker in all its culturally and context relevant forms, and you understand the word hacker, but they do not understand the word hacker. :-(
If we, as hackers of the sort that inhabit hacker news, have a post like this on the frontpage and noone cares to actually write them and tell them they have a security problem that may cause them serious damage we don't deserve better.
Edit: But your email is very amiable and clear, so I think you're probably safe.
I lost a lot of my faith in humanity that day.
In fact, a security consultant was convicted[1] for using ../../ in a URL after he thought a site had been hacked.