1392
Comments (235)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
24
honk_hogan 24 points ago +24 / -0

Really, they didn’t clean text on text fields allowing them to be read as code?

Is that really what happened? I would have at least assumed comp'ed cloud or data center people. So tired of our side taking L's due to our own retardation.

2
FluhanWu 2 points ago +2 / -0

This has happened to many leftists companies too. They can learn from this and improve.

3
negrosIaveIabor 3 points ago +3 / -0

That's crazy. Salting passwords and shit is literally some of the easiest shit you can do that makes shit like this impossible

1
CucksForTheDonald 1 point ago +1 / -0

Looks like it was just that. From OP's comment:

"According to DDoSecrets' Best, the hacker says that they pulled out Gab's data via a SQL injection vulnerability in the site—a common web bug in which a text field on a site doesn't differentiate between a user's input and commands in the site's code, allowing a hacker to reach in and meddle with its backend SQL database."

3
honk_hogan 3 points ago +3 / -0

WTF year is it? 2000? Did they write this shit in PHP?

1
Newuser9 1 point ago +1 / -0

PHP runs most websites. It's easy to sanitize user input. Whoever wrote gab is an idiot.

1
deleted 1 point ago +1 / -0