6 ms·
The problem is that "attempted hacking" is kind of a fuzzy thing. To go with your example is it "attempted robbery" if they catch you on camera scoping out the
by orclev 12y ago
The problem is that "attempted hacking" is kind of a fuzzy thing. To go with your example is it "attempted robbery" if they catch you on camera scoping out the bank exits and camera angles? At what point does something go from looking around to "attempted hacking". He didn't actually succeed in anything he tried, so basically what they have him for is running a port map which shouldn't ever be illegal, and sending some garbage form data.
Because this is the law here and they'll always apply it as broadly and wrongly as they possibly can you have to consider the extremes on this. At what point do you draw the line? To go with the hypothetical worst case scenario, what if little bobby tables goes to sign up for a account somewhere, does he get charged with "attempted hacking"? This also puts grey and white hat hackers in a dangerous place as well (particularly grey hats which are already on shaky ground as is).
- Consultant32452 12y agoSomeone didn't just get bored and fill a form field with random garbage. We're talking about attempting a SQL injection attack which shows clear intent.
- Dylan16807 12y ago>Someone didn't just get bored and fill a form field with random garbage. Yes they do. >clear intent Intent of what, exactly? Intent to make the site do something it wasn't explicitly designed to do, yes, but that does not imply exceeding authorized bounds or causing any harm.
- Consultant32452 12y agoI'm not saying that people never put random garbage in a form field. We're talking about a specific incident where a person apparently made at least 44 requests attempting to perform SQL injection. The intent of unauthorized access or destruction of information. When you get caught trying to pick the lock at your bank you can argue you weren't trying to exceed authorized bounds or cause harm all you want but I doubt it will get you very far.
- Dylan16807 12y ago"SQL Injection" can be as simple as including an apostrophe. It depends on the details. Deliberately injecting "SELECT * FROM customers" can potentially exceed authorized bounds. (Even then the intent might not be there in all cases.) Injecting "SELECT 1=1" to see if the system is broken is clearly not exceeding authorized bounds.
- Consultant32452 12y agoWhile I may have disagreed with you, I felt your original position was a reasonable one. Now you're attacking the straw man of someone being brought up on charges for an apostrophe in a form field. When that happens I'll gladly join you in declaring the ludicrousness of those charges.
- Dylan16807 12y agoNo, I'm not making a straw man, I'm pointing out that "SQL Injection" is very vague, and attempted SQL injection even more so. There is a huge gulf between checking for access and abusing access.
- Consultant32452 12y agoAnd that's why we have DAs, grand juries, judges, and juries. If someone gets brought up on charges for literally putting an apostrophe in a form field on a website the system has failed because there's no clear intent to perform an attack of any kind in that case. When that happens, let's talk.
- Lawtonfogle 12y agoThe intent between Username: Lawtonfogle Password: hunter2' OR 1 = 1; and Username: admin Password: hunter2' OR 1 = 1; is quite different. Should these be treated equally as hacking?