58
Root
5y

I'm seeing people defending clearly-injectable code and I'm just stunned.

And this person in particular is supposed to be responsible (at least partially) for finding security flaws.

I don't know what to say.

Comments
  • 25
    "I am pretty sure we do this all over the place"

    That isn't helping my sanity, Mike!
  • 5
    For fun, make a script that goes through payload all the things, and if it hits anything, emails the CTO with a big red X in the subject line.
  • 0
    You should inject it as a "toldja so"?
  • 0
    he's defending his job security

    oh wait...
  • 3
    Nah, it's not about security. It's just supporting dependency injection by design! :]
  • 2
    @vorticalbox I made fun of them on slack in front of the dev and security teams. It got fixed. 😊
Add Comment