1392
Comments (235)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
48
crazyjackel 48 points ago +49 / -1

Really, they didn’t clean text on text fields allowing them to be read as code? That is basic stuff.

But, no... the hackers should be sued. It is one thing to expose vulnerabilities and inform the website of those vulnerabilities. It is another to steal customer data and try and sell/give it out to legit everyone. The hackers are evil evil people.

24
honk_hogan 24 points ago +24 / -0

Really, they didn’t clean text on text fields allowing them to be read as code?

Is that really what happened? I would have at least assumed comp'ed cloud or data center people. So tired of our side taking L's due to our own retardation.

2
FluhanWu 2 points ago +2 / -0

This has happened to many leftists companies too. They can learn from this and improve.

3
negrosIaveIabor 3 points ago +3 / -0

That's crazy. Salting passwords and shit is literally some of the easiest shit you can do that makes shit like this impossible

1
CucksForTheDonald 1 point ago +1 / -0

Looks like it was just that. From OP's comment:

"According to DDoSecrets' Best, the hacker says that they pulled out Gab's data via a SQL injection vulnerability in the site—a common web bug in which a text field on a site doesn't differentiate between a user's input and commands in the site's code, allowing a hacker to reach in and meddle with its backend SQL database."

3
honk_hogan 3 points ago +3 / -0

WTF year is it? 2000? Did they write this shit in PHP?

1
Newuser9 1 point ago +1 / -0

PHP runs most websites. It's easy to sanitize user input. Whoever wrote gab is an idiot.

1
deleted 1 point ago +1 / -0
12
BurtMcGirt 12 points ago +12 / -0

Maybe they dropped a garage door pull while committing the crime.

5
Libertas_Vel_Mors 5 points ago +5 / -0

Pretty sure they sanitize their inputs - that's base 101-level stuff these days.

2
deleted 2 points ago +2 / -0
1
deleted 1 point ago +2 / -1
1
deleted 1 point ago +1 / -0
2
deleted 2 points ago +2 / -0
5
47urOFH3d 5 points ago +5 / -0

Wouldn't it be a better catch-all solution to use prepared statements, rather than trying to think of the ways in which you need to clean the text?

2
DiscoverAFire 2 points ago +2 / -0

"Please select a username from this list" "Please select a comment from this list" would be a pretty terrible social network.

2
deleted 2 points ago +2 / -0
1
FluhanWu 1 point ago +1 / -0

“Please select a username could work if it went like this: A row of alphanumeric drop-downs, like 12 of them with an option to add more by pressing the + button to the right. Then username gets chosen a single letter at a time. This concept would not be too popular for posting content in a forum or sending messages.

1
deleted 1 point ago +1 / -0