Discovered a major security vulnerability at a Chinese factory - how do I report it safely?
一位研究人员在网上发现一家中国汽车厂的生产系统完全暴露于互联网,并通过一个被遗忘的技术服务账户成功登录。该系统包含实时生产数据和操作员信息,存在严重安全隐患。研究人员希望负责任地披露这一漏洞,但担心使用真实身份可能引发麻烦或被视为垃圾邮件。 2025-7-9 21:0:11 Author: www.reddit.com(查看原文) 阅读量:14 收藏

While researching manufacturing software online, I found a Chinese automotive factory with their production system completely exposed to the internet. This should NEVER happen - manufacturing execution systems should stay on internal networks only.

Out of curiosity (and 10 years experience with this software), I tried logging in. Default passwords were changed, but there's a forgotten technical service account that admins always overlook. Got right in and could see live production, work orders, operators working - basically could shut down their entire factory.

Now I'm torn. I want to tell them about this massive security hole, but I'm scared to use my real email. Should I make a throwaway email to contact them? What if they think it's spam or get me in trouble somehow?

How do you responsibly disclose something like this while staying anonymous? This is a serious vulnerability that could destroy their business if the wrong person finds it.

TL;DR: Found Chinese factory's production system wide open on the internet, got in easily, want to warn them but don't know how to do it safely.


文章来源: https://www.reddit.com/r/blackhat/comments/1lvu6w1/discovered_a_major_security_vulnerability_at_a/
如有侵权请联系:admin#unsafe.sh