top | item 7920564

(no title)

stackcollision | 11 years ago

I recall a case where the courts did not agree with you. I can't remember names or many details, but the gist was that some guy realized that one of the pages was taking an fdat argument that was his userid, and by simply incrementing that number he could retrieve the data of any user he wanted. He presented his findings to the company (something major, like AT&T maybe), and they immediately sued him. He fought in court saying he wasn't malicious and was "white hat" as you say, but I believe he was convicted.

Does anyone remember this case?

discuss

order

danielweber|11 years ago

Weev. Search HN, there are hundreds of conversations about that case.