11 ms·
I remember reading about this case around the time the charges were originally filed and those are pretty much the charges. The guy ran nmap (or equivalent) on
by orclev 12y ago
I remember reading about this case around the time the charges were originally filed and those are pretty much the charges. The guy ran nmap (or equivalent) on the website, and submitted some attempts at SQL injections in a few forms. That was pretty much the entirety of his "hacking". Honestly what he got on the plea bargain is at the far end of what I'd consider appropriate for what he did. Something like a small fine, say $500 and a "don't do that again" would probably be more appropriate honestly. Had he actually gotten somewhere with the SQL injection, or actually gained access to something I'd say more might be warrented.
FYI the 44 counts were arrived at by charging each form submission individually, so it was really just 1 charge, just counted 44 times.
- Consultant32452 12y agoThe 44 counts thing is kind of ludicrous unless he literally made 44 separate attempts at SQL injection at different times rather than 44 separate HTTP requests. Having said that, I think the punishment for "attempted hacking" should be fairly harsh in the way "attempted robbery" is. He was likely attempting to steal copies of information or perhaps even destroy information that could've cost thousands or perhaps even millions to recover depending on who he'd gone after.
- yebyen 12y agoOr (to present an alternative explanation for why one might try to see what ports are open and whether some rudimentary attacks can succeed) maybe he was trying to evaluate a potential vendor and decide whether or not to put his secure personal or company information into the system. You know, rudimentary attacks that should not succeed on any type of vendor system that has been through the most basic security audit or pen testing? I guess we should either trust the vendor or don't. No real reason why would anyone want to see if other hackers with basic knowledge can get access to a system? I'm sure there are plenty vendors with transparent public records of the authorized penetration tests that they have ordered which have been done, you can trust!
- Consultant32452 12y agoThere are a number of passive things you can do to gain some trust in an online vendor. You can, for example, look for certifications from a service like SiteLock. To maintain the brick and mortar analogy, you wouldn't try to pick the locks of a storefront after hours just to determine whether or not you should do business with them. And if you get caught doing that, I dare say you deserve to be charged with a crime.
- yebyen 12y agoSending packets with strings which are commonly known to cause serious problems if systems are vulnerable to well-known exploits should not be a crime. If your system solicits users to input their private data and is vulnerable to easy attack vectors or common exploits like basic SQL injection, you are the one who should be charged. So, the only problem left is how to establish your standing to sue the lazy vendor. It is a problem since you can't actually bring them up on negligence charges if you were not actually damaged. Well, if picking the lock is thus illegal per your analogy, then the only way to have standing would be to first submit yourself to potential unknown harm and wait for the day when a bad hacker comes! I think your analogy falls down too, because a brick-and-mortar storefront holds its own assets and is liable (or insured) for their own losses in the event of theft. You rarely store your own private things inside a brick and mortar storefront. If you did and they are stolen, the store would normally be liable and reimburse you. People store their private data "in the cloud" all the time, but because of arcana in law which does not correctly distinguish between pulling on the handle and picking the lock, they are not allowed to check and see if the cloud-monger actually locks the door when he goes home at night?
- Consultant32452 12y agoThere are ways to determine if a site is secure without attempting to gain unauthorized entry. You can look for third party certifications, a valid SSL certificate, etc. This is similar to the analogy of looking around at your bank to see they have a security person, locks, cameras, etc. protecting your safe deposit box. You don't go try to break into the bank to determine if it's reasonable to put your assets in the box there.
- orclev 12y agoThe problem is that "attempted hacking" is kind of a fuzzy thing. To go with your example is it "attempted robbery" if they catch you on camera scoping out the bank exits and camera angles? At what point does something go from looking around to "attempted hacking". He didn't actually succeed in anything he tried, so basically what they have him for is running a port map which shouldn't ever be illegal, and sending some garbage form data. Because this is the law here and they'll always apply it as broadly and wrongly as they possibly can you have to consider the extremes on this. At what point do you draw the line? To go with the hypothetical worst case scenario, what if little bobby tables goes to sign up for a account somewhere, does he get charged with "attempted hacking"? This also puts grey and white hat hackers in a dangerous place as well (particularly grey hats which are already on shaky ground as is).
- Consultant32452 12y agoSomeone didn't just get bored and fill a form field with random garbage. We're talking about attempting a SQL injection attack which shows clear intent.
- Dylan16807 12y ago>Someone didn't just get bored and fill a form field with random garbage. Yes they do. >clear intent Intent of what, exactly? Intent to make the site do something it wasn't explicitly designed to do, yes, but that does not imply exceeding authorized bounds or causing any harm.
- Consultant32452 12y agoI'm not saying that people never put random garbage in a form field. We're talking about a specific incident where a person apparently made at least 44 requests attempting to perform SQL injection. The intent of unauthorized access or destruction of information. When you get caught trying to pick the lock at your bank you can argue you weren't trying to exceed authorized bounds or cause harm all you want but I doubt it will get you very far.
- fivedogit 12y agoHaha. It's like stabbing someone 44 times and getting 44 counts of attempted murder.
- rayiner 12y agoI don't see any reason why attempting SQL injections on a few forms on the County website should be treated any differently than trying a few ways to pick the lock on a county building. Should the punishment for the latter depend on the sophistication of the lock-picking techniques the intruder uses? Web servers are other peoples' property, and there's no "right to tinker" with them. All you have is an implied license to use the site in the way the owner expects you to use it, the same as with a physical storefront.
- guelo 12y agoA better analogy than lock-picking: the door has a sign that says "turn knob to the right to enter", he was arrested for unsuccessfully turning the knob to the left to see if it would opened into another room.
- orclev 12y agoYes but there are degrees with these things. If you attempt to open a locked door they don't charge you with armed robbery, even if that door has a sign that says "employee's only". I'm not suggesting attempting a SQL injection should just be ignored, but it should clearly be at worst a misdemeanor and not a felony, about on par with trespassing in terms of severity. Now, if you then use that SQL injection to steal protected data, gain further access, or delete data, then yeah you're talking about moving into felony territory. Web servers are other peoples property, but they're also a public space when you open then up to the public by hosting public services on them. A private server is different from a public server in the same way private property is different from a public storefront. By making your server accessible to the public you lose some of the expectations of privacy and implicitly allow a certain degree of access.
- rayiner 12y agoIf you try to break into a building under the cover of darkness, you're going to get hit with more than a trespass charge.
- sillysaurus3 12y ago
- kw71 12y agoUh oh. I might be in trouble for finding out the entire list of people in the local jail by looking up Mr. %