@[email protected] to Programmer [email protected]English • edit-22 months agoSQL Injectionlemmy.mlimagemessage-square18fedilinkarrow-up1268arrow-down15file-textcross-posted to: [email protected]
arrow-up1263arrow-down1imageSQL Injectionlemmy.ml@[email protected] to Programmer [email protected]English • edit-22 months agomessage-square18fedilinkfile-textcross-posted to: [email protected]
minus-square@[email protected]linkfedilink4•2 months agoSo does that imply they already knew the candidate they were hiring, and were just checking if this is the guy?
minus-square@[email protected]OPlinkfedilinkEnglish3•2 months agoIDK I didn’t think that much into it lol
minus-square@[email protected]linkfedilinkEnglish1•2 months agoYeah, this seems like an exploit for those cases.
minus-square@[email protected]linkfedilinkEnglish1•1 month agoNo the interviewer is personification of the naive backend that checks only that a specific row is present in the DB, or that’s how I read it.
minus-square@[email protected]linkfedilink1•1 month agoSo I guess the interview is handled by a non-vulnerable intermediate process, which adds the hire to the the main table of employees when at some point in a successful interview, and then calls a notification process that just searches it?
minus-square@[email protected]linkfedilinkEnglish2•1 month agoyeah something like “if new candidate in employee DB == hired”
So does that imply they already knew the candidate they were hiring, and were just checking if this is the guy?
IDK I didn’t think that much into it lol
Yeah, this seems like an exploit for those cases.
No the interviewer is personification of the naive backend that checks only that a specific row is present in the DB, or that’s how I read it.
So I guess the interview is handled by a non-vulnerable intermediate process, which adds the hire to the the main table of employees when at some point in a successful interview, and then calls a notification process that just searches it?
yeah something like “if new candidate in employee DB == hired”