Skip to main content

Are you obligated to point out security flaws if you’re just hired for a small job?

posted onMay 13, 2013
by l33tdawg

Dokkat was contracted to do a small job on a website for a large corporation. After giving the project a once over, he realized the code base was full of security risks:

"Lots of PHP files throwing user get/post input directly into mysql requests and system commands." Dokkat says the programmer responsible has a family and children, and he doesn't want to be the one to put this employee's job in jeopardy. How should he proceed without throwing someone under the bus?

Source

Tags

Security Software-Programming

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th