"One coder added at least two database entries that are visible on the live site and say “this is a joke of a .gov site” and “THESE ‘EXPERTS’ LEFT THEIR DATABASE OPEN -roro.” "

        • Yoddel_Hickory@lemmy.ca
          link
          fedilink
          English
          arrow-up
          69
          ·
          27 days ago

          If SQL injection is picking a lock, this is entering through an unlocked door.

          Not sophisticated at all, authentication on API routes is way earlier on the security checklist than SQL query sanitisation. This site is amateur work.

        • Fiestorra@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          31
          ·
          27 days ago

          Much much simpler, with a SQL injection at least you have to bypass the filters set, this is just submitting the changes through an API and the DB just eats it up.

          • otp@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            27
            ·
            27 days ago

            SQL injection is like picking a lock.

            This is like trying to open the door and finding out there’s no lock.

            The door isn’t necessarily obviously visible, but most buildings do tend to have doors.

            Borrowed and expanded upon another commenter’s metaphor

    • Mac@mander.xyz
      link
      fedilink
      English
      arrow-up
      22
      arrow-down
      2
      ·
      edit-2
      27 days ago

      Ah, unfortunately this is only accessible by master-level bitwizards in the discepline of hacking.
      Even more unfortunate is that discerning the ‘how’ is only accessible by those who are adept at reading the article.

  • JasonDJ@lemmy.zip
    link
    fedilink
    English
    arrow-up
    29
    ·
    edit-2
    27 days ago

    Oooh that’s juicy. I wonder how many holes they left in the important production systems that they’ve been touching.

    I also wonder, with how progressive and dissenting American programmers and cybersec experts are, if our l33t h4x0r sk1llz could be turned against DOGE?

    Not suggesting anything wildly destructive, just some friendly grey-hat trolling to slow them down and expose their flaws. Think of it as a complimentary pen-test.

    Part of me also thinks they are hoping some people will slip in some “proof” of fraud somewhere, like how people “proved” the COVID vaccine was killing people via VAERS.

    • andrew_bidlaw@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      ·
      27 days ago

      I also wonder, with how progressive and dissenting American programmers and cybersec experts are, if our l33t h4x0r sk1llz could be turned against DOGE?

      What can hurt Musk? These kids are nobodies, his co-conspirators all depend on his will, and the only thing I suspect is probable to crush him is either a lone gunner or an oil\tech barron who got too pissed of from his plans ruining their business prospects.