5 ms·
It's actually very easy: If you are in a server, you report it. You don't go digging for more, because once you're in, you can easily do more damage.
by boredpudding 10y ago
It's actually very easy: If you are in a server, you report it. You don't go digging for more, because once you're in, you can easily do more damage.
- baby 10y agoAgree with this, getting in is enough, going further is malicious at best.
- lern_too_spel 10y agoUnder those rules, it's not possible to verify reginaldo's claim that this machine is cut off from more valuable data.
- baby 10y agoYou don't need to verify these claims. You found a critical vulnerability, you are not the only one.
- frostymarvelous 10y agoHow then do we assess the extent of the vulnerability? As Wes proved, a simple looking RCE can lead to a huge breach of security due to failures in other areas. I agree that limits must be established, but also, these must not end research so abruptly as they can lead to further information. One might argue this is unethical, but a black hat doesn't care either way.
- baby 10y ago> How then do we assess the extent of the vulnerability? It's already a critical vulnerability. Unless you want to assign numbers to the infinity, which is ridiculous.
- frostymarvelous 10y agoYet we know not all critical vulnerabilities are created equal. That's why some get a 10k payout and others get a 2.5k.
- mamon 10y agoThis is assessed based on how hard it was to elevate your access rights (whether it requires physical access, user cooperation, etc.), not on how much damage you can do - because once you elevated your rights the possible damage is unlimited.
- frostymarvelous 10y agoExcept in that case, he unearthed another completely unrelated vuln. I agree that some actions are u ethical, but does that really matter so much when a black hat is unethical anyways? The fact that he reported meant he was harbored no malicious intent. How is collecting logins better than that? Seriously? This is completely malicious if you ask me. Moreover, we must not judge each case strictly to the same rule, but with a measure of consideration of the circumstances as well.
- Dr_tldr 10y agoBut in this case, they specifically said that the researchers were unable to escalate. How does he know? Either the researchers violated the rules by trying and failing, or they didn't try and he's simply lying to make himself look better. By your reasoning and their policy, those are the only two possibilities. What are we supposed to conclude from this? Under the current rules and assuming the description of what happened is accurate, it would seem you'll potentially be punished for establishing the full extent of a breach, unless it's not so bad, in which case you're rewarded for failing. In addition to being illogical and unfair, it also incentivizes OpSec to delude themselves and everyone else about their true security risks.
- frostymarvelous 10y agoAccurate. In the other case, they threatened because he proved the vuln was much much greater, infact I call it a billion dollar bug,and wanted to cover it up. This time they're proudly telling us because the attempts failed or were not made at all.