HN2new | past | comments | ask | show | jobs | submitlogin

In high school I was trying to make an app to scrape my grading system Skyward and ended up finding a trivial auth bypass that let me see anyones grades. Knew the school would turn me into a villain if I was discovered even though I was on student council and an honor student so I emailed the principal and got a meeting with him. For some unknown reason my poc didn't work in the meeting so during the meeting I found a second auth bypass. They paid me $75 for finding the issue and told me to try to hack the teachers side of the system next. Lots more to the story if anyones interested.


I'd interested to hear more about the story! Would be cool if you wrote a blog post or something about it.


Definitely interested. Would you mind if we had a call or discuss over email and I can post it as blog or podcast




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: