|
Microsoft is notoriously slow at patching security holes in their OS:es (they're not the only ones). They can be aware of flaws in their implementations (the "good" hackers report their findings directly to the software companies) for months that they don't patch. After a while some of the security entusiasts release proof-of-concept code that demonstrates how the hole might be (ab)used to force the affected software companies to address the issue.
This behaviour actually benefits all of us, since the malicious hackers (emphasis on malicious) would roam free and do hell of a lot more damage if the companies weren't forced to patch holes (And, we all know that some software companies is only in it for the dough).
While this somewhat childish prank might seem totally unnecessary it exposed a flaw that could have been used to, for instance, change the URL to point to something really malicious, and the "hole(s)" is(are) forced to be patched.
It might have been the wrong way of doing it, but if no serious damage was done (except to the trust of the server admin/site from the public), he made life for us, the users, more secure, and if he go around bragging about it or simply feels smug, I say: no serious harm done.
__________________
- Be Kind.
- Have fun.
|