4 ms·
Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, th
by twentysix 14y ago
Its certainly a grey area and covering all your bases legally before embarking on a penetration test would be good idea. Even with all the legal formalities, there needs to be a good level of trust between the client and the auditor for things to go smoothly.
Two days later, Mr. Al-Khabaz decided to run a software program called Acunetix, designed to test for vulnerabilities in websites, to ensure that the issues he and Mija had identified had been corrected.
If you find a security flaw in a system and report it, receiving positive feedback doesn't automatically imply that you have permission to conduct further tests. A web application vulnerability scanner can cause damage to production systems.
Almost anyone can just download a scanner and run a wild test using default settings. But its illegal to do it without prior authorization.
While his intentions were good, I think it was a bit naive of him to take upon himself the responsibility to make sure the flaws were fixed and conduct a test. Even when you have permission to conduct a test you stick to the scope and limits of the agreement. You cant just keep leapfrogging networks as you find holes.
Manually finding holes/bugs accidentally and reporting them is different from running a vulnerability scanner.
I dont think he should have been expelled without giving a chance to explain his story and the way they did it was not ethical. The management over reacted, especially considering there was no damages mentioned in this case.
http://testlab.sit.fraunhofer.de/downloads/Publications/tuerpe_eichler_Testing_production_systems_safely_-_Common_precautions_in_penetration_testing_TAIC_PART_2009.pdf http://testlab.sit.fraunhofer.de/downloads/Publications/tuer...
http://www.coresecurity.com/content/under-attack http://www.coresecurity.com/content/under-attack
https://en.wikipedia.org/wiki/Randal_L._Schwartz#Intel_case https://en.wikipedia.org/wiki/Randal_L._Schwartz#Intel_case
- kibwen 14y ago> While his intentions were good, I think it was a bit > naive of him to take upon himself the responsibility to > make sure the flaws were fixed and conduct a test. Given that his own personal information could have been exposed by this exploit, it's just as likely that he was acting out of self-preservation rather than merely due to feelings of personal responsibility. The only naive bit here is that he obliterated his plausible deniability via 1) not allowing more time between submitting the report and attempting the scan, and 2) not masking his IP behind seven proxies.
- jonny_eh 14y agoIt sounds like he may have been trying to find more flaws.
- thefreeman 14y agoAgreed. While he may say he was trying to verify the flaw was fixed, that just doesn't coincide with running a general purpose vulnerability scanner against their network. While I doubt his intentions were malicious, it certainly seems like he got curious / excited from his first find and went looking for more. With that being said, I definitely feel for the guy. I can certainly understand the intrigue and curiosity that would lead him to continue his exploration. It sucks that they decided to bring the hammer down so hard.
- JasonFruit 14y agoYes, it was naïve, and maybe unwise, but the curiosity would be hard to resist. I might have done the same thing in the same situation, at one time. (Now I'm old and soulless.)