4 ms·
Permission is the enemy of a hacker. Us enthusiasts don't mean any harm and almost never perform tests that break the software (or network). There's a reason wh
by hamhamed 11y ago
Permission is the enemy of a hacker. Us enthusiasts don't mean any harm and almost never perform tests that break the software (or network). There's a reason why bounty programs exist.
- jacquesm 11y agoUs enthusiasts might end up in court and/or trouble for that. Do not do pen-testing on systems you don't own or have explicit permission to work on (such permission might be a bug bounty program or something to that effect). Yes, there is a reason why bounty programs exist, they make it plain that testing is 'ok'. In absence of a bounty program or a relationship with the company you can't claim that you 'don't mean harm' and that your tests would never break the software or the network. It's going to be lumped in with actual attacks.
- homakov 11y agoOne caveat: client side attacks like XSS that don't execute or break backend part are rather ok 100% of time
- tptacek 11y agoNot even close to true.
- homakov 11y agoAt least non-admin XSS is much harder to define as "hacking" by a judge. Otherwise, writing something like "Send your password to ha@ck.er plz!" would be considered severe hacking attempt too.
- tptacek 11y agoI don't know what country you're referring to, but in US criminal law, there is no such thing as "hacking". There is only unauthorized use. Cases will turn on whether you should have known that your use of the site while testing for security bugs was unauthorized (short answer: yes, you should have known), and whether it caused damage. But that's criminal law. That's a real concern, but the bigger concern is tort law. If you blow up someone's site by getting an XSS input cached and replayed to all its users (or, heck, even if you just cause an alarm that they have spend money responding to), you are going to be liable.
- homakov 11y agoThat's true. I myself would never poke around some corp. website w/o a bounty program
- jacquesm 11y agoThen please don't indirectly tell others it is ok to do so. You could cause a lot of trouble for someone who sees you as an authority figure. Of course 'homakov said it was ok' is not a very good defense, but still, better not to encourage dumb/bad behavior.
- MichaelGG 11y agoSimple example that this isn't true: an admin portal that shows requests and doesn't escape properly. Bam, you just broke their whole backoffice.
- tptacek 11y agoSimple refxss testing can easily fuck sites up; all the site has to do is stash a query input somewhere that gets rendered back out in JS to all users later (extremely common example: search results). All the sudden every user on the site is getting alert popups. A lot of these sites can calculate down to the second and the dollar how much they lose if their site goes down. Guess who's liable if the cause of that downtime is you?
- ultramancool 11y agoNot going to lie, every time I'm on a website with some sort of ID in the URL, particularly more obscure ones, I can't help but tamper with it. Try putting quotes in it, try making it a negative value or changing it to nearby values. I've found a disturbing number of SQL injection and XSS attacks like this, just messing around on obscure sites. I run a small business and have noticed our customers try to do the same sometimes, their user ID is visible in the URL at some points. I see the error logs saying they tried to load something they didn't have permission for at least a few times a month. Do you think there's a serious legal risk here, assuming I don't perform any bad queries on the DB but just see an error message from it and assuming I don't give anyone an XSS'd link, just from plain toying with URLs?