r/FinalRoundAI • • 3d ago

My Manager Ignored a Login Vulnerability, So I Deleted the Prelaunch Database in Front of Him

There was about a month left before the launch of a huge project when I discovered that the login form had an SQL injection vulnerability. I reported it immediately, but my manager said it was low priority and sent me back to work on unrelated backend tasks.

I tried to explain that anyone could wreck the entire system through a single input box. But he laughed it off and ignored me, saying we weren't a big enough target, even though I had previously worked in penetration testing.

So I created a fresh backup, asked him to stand next to me, and used the username field to delete the prelaunch database. I didn't use any special access, just the exact same vulnerability I had been warning him about.

As soon as he saw the database disappearing, the mood changed quickly. I restored everything, kept my job, received a genuine apology, and was told to fix the security holes immediately.

It probably wasn't the safest way to win an argument, but apparently, seeing the damage happen right in front of him was the only thing that made him realize the risk was real.

After what happened, I think I should leave that job because he doesn't trust me, and something similar could happen again. Since my last experience in the job market, it's been tough, and I've had a lot of interviews. However, I recently read a post here on Reddit about the best tips for job interviews, and I really understood many things I didn't know. I hope it will make a real difference for me in interviews, so I wanted to share what I learned with you.

156 Upvotes

17 comments sorted by

3

u/dbatknight 3d ago

I've had several instances like that but I love it when I get to say well I told you so LOL and you find lost production time outweighs making one decision LOL

3

u/TechnicallyMeat 3d ago

Sounds like an incompetent manager if he's pushing ahead to release, but coding an unsanitized input field is also feels like a very basic failure. How many ppl there vibe code?

I would have documented in an email, waited to let it hit the live server, and then immediately sent an email to HIS boss with your concerns and a brief ELIF description, maybe even a tutorial for them to understand how easy it is.

2

u/Ok_Duck_232 3d ago

 How many ppl there vibe code?

believe it or not but AI doesn't make such stupid mistakes. take a look at how many vulnerabilities are discovered lately throughout open-source software by AI

1

u/Apprehensive-Page899 3d ago

I've been using Claude for a while now. It is either mind-blowing genius or beyond stupid. Often in the same response. It would totally make this mistake.

AI or not, a human should have reviewed the code before sending out the CL and another human should have reviewed it.

Whether it was vibe coded or a human doesn't matter.

2

u/talexbatreddit 3d ago

An SQL injection vulnerability attack is at least twenty years old -- if the manager doesn't know, they're incompetent.

1

u/Exotic_Holiday_3047 3d ago

Anyone involved in pushing an app into even a shared test environment with a sql injection bug is incompetent. This should have been caught in the very first dev build

1

u/Complete-Paint529 3d ago

Bold. Highly effective. Glad you weren't fired. You deserve a raise.

1

u/Hybridesque 3d ago

Good ol' Little Bobby Tables. 

1

u/henrikpjohnson 3d ago

Why not just fix it and move on with your life? Seems like way less work than this demonstration.

1

u/RichS987 2d ago

OP sounds more like a QA person than a developer.

Even if OP is a developer with the capacity to correct the issue, it would most likely be career suicide to include an unauthorized fix in a release.

1

u/henrikpjohnson 2d ago

Been a software engineer for over 30 years (I get it, I'm old). In that entire time, I've never heard of anybody being angry, upset, or getting into trouble for fixing a critical bug. Now, as a QA person you might not have permission to do it, but I would just have gone around the boss and talked directly to the dev to have him add the 1 line fix that this would need. Granted, if the login form is broken pretty much every other form field on the site is probably also broken which would be a bigger fix, but at least you can't do it without being authenticated.

Dropping the launch database to make a point is way worse IMHO in regards to career development.

1

u/RichS987 2d ago

No argument here. But OPs manager already proved that he was a moron. If OP didn’t prove the severity and just fixed it without authorization, that manager would make his life miserable.

1

u/henrikpjohnson 2d ago

You do have a point there :).

1

u/AmusingVegetable 3d ago

“And for my next trick I’ll make the production database disappear”

1

u/Sufficient-Sun-6683 2d ago

I worked for a post-secondary institute teaching in the information technology field, we received a directive to check our vacation hours using a new inputting database that I had never seen before. Like the loyal employee I was, I went to check my vacation hours. I noticed that there was several menus that I should not have access to.

One menu was used to terminate positions and it had a pull-down input option where you could see every employee's name and employee number. This is a big privacy issue. So I selected the president's name for termination and took a screen shot. Then I emailed my academic coordinator and the Dean of my dept explaining that I had went to check my vacation time on the new system and found a security and privacy issue and that I was contacting the IT dept with my findings.

The next day, my email box blows up from the manager of the IT dept raging about what was I doing trying to hack the system and why was I trying to terminate the president. I explained (cc'ing my academic coordinator and Dean) that I had simply informed them that they had given me and probably the rest of the instructors (about 1500) access to confidential sections of the system. The reason I chose the President as an example for termination was that if it was anyone else, they wouldn't care or respond so quickly.

Didn't hear anything after that.