Done properly, an injection like this probably could have been done with no change to default behaviour,
Interesting.
So the sloppiness was in the implementation and not the social engineering.
But then of course, people tend to be not good at both, fooling people and fooling programmers/computers at the same time. In this case, the chap turned out to be better at fooling people than programmers/computers.
And I am being sloppy for not trying to learn enough about exploits even though I should have a good enough programming base to start it.
Interesting.
So the sloppiness was in the implementation and not the social engineering.
But then of course, people tend to be not good at both, fooling people and fooling programmers/computers at the same time. In this case, the chap turned out to be better at fooling people than programmers/computers.
And I am being sloppy for not trying to learn enough about exploits even though I should have a good enough programming base to start it.