Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
@100110111 Why. It is government website so legal risk is low and I havent used any reverse shells(though I probably can) so I am pretty safe
-
Look for a security contact on their website, or ask for a security contact at their main contact. I doubt they implemented security.txt
-
Just don't. Government is usually incompetent, and if you notify them, they still won't act on it. Now when they get hacked, then guess where they will send the police to do a raid at 4AM in the morning. Guess also whose complete electronics will be confiscated and who will never see them again.
-
Don't do it mate! If they get exploited and they notice, chances are high, that you are the first one they will go after.
Probably !dev
How should I inform a government website that one of their user password combinations is in a short metasploit password list. The list name is tomcat_mgr_default_userpass
The top exploit db vulnerabilities for tomcat verison did not work so kudos to them on that. I am just a script kiddie
Edit :- Forgot to mention I am an Indian citiizen
question