538
top 11 comments
sorted by: hot top controversial new old
[-] voodooattack@lemmy.world 21 points 6 months ago

You think this is funny, but a codebase I once inherited did exactly this. Up until that point in my life, I never imagined I’d ever have such a violent urge to strangle someone.

Bonus: the system had two types of accounts for signups: one for employers and one for employees. Naturally, it would set the role of the created account during the signup process, but the issue was that anyone could submit a signup request with a custom payload and set themselves as the third account type: administrator.

Bonus #2: during a self-update request (avatar change, etc), users were able to change their own IDs in the database.

It was 100% vibe-coded by two imbeciles in two months. We had to rebuild 80% of that codebase.

[-] AlecSadler 9 points 6 months ago

Pro tip: A lot of websites that don't let you update certain fields about your profile or other things actually do let you, because it's a full payload patch on the backend. You just need to modify the fields in dev tools.

Note: I did this on a hotel website to change my email address and then ended up creating a bad scenario where my login account email didn't match my hotel profile email...they fixed it for me and said, "we aren't sure what happened". I didn't say anything.

[-] Bonus@sh.itjust.works 16 points 6 months ago

So have you hacked into starboy98's mainframe yet?

[-] fascicle@leminal.space 7 points 6 months ago

Never seen someone so excited to talk to jigsaw

[-] Bonus@sh.itjust.works 4 points 6 months ago

Thanks for reminding me. Jigsaw is a plagiarist‽

[-] Miralyn@lemmy.dbzer0.com 12 points 6 months ago

I once worked a place that required me to have access to a very confidential database. To "protect against hackers", they changed the (collective) password every week and sent me the new one in open text to my webmail account. 😳

[-] bagelberger@lemmy.world 10 points 6 months ago

all this time video game computer security was based on reality

[-] mech@feddit.org 6 points 6 months ago* (last edited 6 months ago)

Except the corporations are the tutorial level, and the final boss is the home server of an anime-obsessed girl who wears Unix socks and owns an oscilloscope for some reason.

[-] TomMasz@piefed.social 7 points 6 months ago

TAP
TAP
TAP
"I'm in."

[-] BunScientist@lemmy.zip 6 points 6 months ago

Not the same but I ordered some electronics from a local store recently and the "forgot your password" link sent me a mail with my password.

[-] voytrekk@sopuli.xyz 1 points 5 months ago

They are just trying to remind you to keep all of your passwords unique.

this post was submitted on 26 Nov 2025
538 points (100.0% liked)

Funny

15104 readers
129 users here now

General rules:

Exceptions may be made at the discretion of the mods.

founded 3 years ago
MODERATORS