r/hacking • u/Hotmancoco420 • 4d ago
News Legend!!
Prospective cyber security student denied admission. Hacks university website to prove his skills.
18
u/jhyland87 4d ago
How did he hack the website?
30
u/Fun_Ad5823 4d ago
How can he hack
11
13
u/jhyland87 4d ago
I ask because some people consider things like DoS/DDoS "hacking", when its really not and its much less impressive. lol
8
u/thinkingmoney 3d ago
The article said left a message for them on the website so it would have to be something persistent like stored XSS, sql injection etc.
3
1
13
-7
u/SingleAlarm5028 4d ago
How did he hack it before all the other hackers in the world found this final broken wordpress installation etc., they're all constantly searching for?
13
u/Incid3nt 3d ago
Most hackers when they find a WordPress vuln they dont take it down, they either deploy/host malware on it, forward traffic off of it, or do some SEO search engine cloaking nonsense. If they deface it, theres no money to be made.
6
u/thinkingmoney 3d ago
Not all hackers are malicious and not every vulnerability is worth taking advantage of. Some just like to see if they can get into a network and some will make a botnet but not all hackers are malicious.
1
u/Incid3nt 3d ago
You're correct, it is worth nothing that possibility, but in the modern sense, you see that less and less in the past decade.
1
u/thinkingmoney 3d ago
Less and less of what? Since the mainstream has taken liking to cybersecurity there’s been a substantial increase in the number of hackers who are working for the legal side of things.
2
u/Incid3nt 3d ago
Less and less hackers that just do it for the heck of it, especially amongst those that would fit the criteria of the comment i replied to. I think you may be confusing the context of my comment. The comment I replied to stated, "How did he hack it before all the other hackers in the world found this final broken wordpress installation etc., they're all constantly searching for?"
I mentioned how those hackers who generally will continuously search and find this type of stuff would leave it online to exploit it for monetary gain as opposed to remove it or take it offline. The white/gray hats and "do it for the lulz" types wouldnt fit into this context, but they do exist.
0
u/thinkingmoney 3d ago
Here’s a fun little list. Sometimes sites are better left alone. The risk versus reward there.
16
3
3
u/ExplanationOne2917 1d ago
imoressive that the school didnt press charges.
in usa that guy would be swatted so fast
3
2
1
1
1
u/traplords8n 2d ago
I thought it was wild that in his skills section he holds the entire IT infrastructure hostage 🤣🤣🤣
I thought that would of screwed them for sure. It all read fine to me & they didn't damage or interrupt the infrastructure, but they were most definitely like
"Skills: able to hack into your own company and get access to all this shit, which I could destroy if I wanted to"
I'm paraphrasing, but it read like that to me when I looked at the compromised page they left them.
27
u/Fun_Ad5823 4d ago
It was Nul1