Уровень 0 · материалов: 3
В кластер входят документы об обнаружении конкретных технических уязвимостей в устройствах, играх или сервисах, и не входят документы, не связанные с поиском ошибок в безопасности.
Общие признаки: уязвимости в ПО и оборудовании, поиск ошибок безопасности, эксплуатация брешей в защите
Группа выше: Обнаружение уязвимостей и взломы систем
Смысл: The main idea is that a young child accidentally discovered a major authentication bypass vulnerability in Xbox Live, demonstrating that security flaws can be found through simple experimentation and should be reported responsibly to the manufacturer.
A five-year-old boy discovered a security flaw in Xbox Live that allowed access via a space character, earning him a reward from Microsoft.
Смысл: A 10-year-old girl discovered that many mobile games are vulnerable to simple time-manipulation hacks, which she presented at DefCon, illustrating that security flaws can be found by curious beginners.
A 10-year-old girl named CyFi presented a discovery at DefCon showing how changing device time can bypass progression timers in iOS and Android games.
Смысл: The text alerts Yota Egg users to a security flaw where a hidden manufacturer's administration panel remains accessible via default credentials, allowing unauthorized users on the network to control the device.
Yota Egg routers have a hidden manufacturer's admin panel accessible via default 'admin/admin' credentials, posing a security risk to users.