Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 55 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow would this be ethical?
EH-Net
May 25, 2012, 03:25:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: would this be ethical?  (Read 4443 times)
0 Members and 1 Guest are viewing this topic.
jinwald12
Jr. Member
**
Offline Offline

Posts: 50



View Profile
« on: January 02, 2010, 12:50:58 PM »

Now i know this may seem strange but bare with me. OK ,I'm wondering if this hypothetical situation would fall in the "ethical end of the spectrum". the scenario is this. your doing a pen test on a large network with a server devoted just to running a IDS. would it be considered ethical to run a Denial of Service Attack to buy time to do the pen test? i know this doesn't sound probable or smart but would it be ethical?
Logged

where did all the fun go?
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #1 on: January 02, 2010, 01:10:01 PM »

Why don't you ask your client? Though mostly DoS attacks are not welcomed.
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #2 on: January 02, 2010, 01:20:12 PM »

If this is a legitimate pentest, then its all about the rules of engagement that you should have clearly defined and agreed upon in advance. This kind of technical consideration has nothing to do about ethics. Its not "cheating" and if the IDS is vulnerable then its vulnerable and needs to be exposed as such by either you being allowed to attack it or at least identity the vulnerability in a well detailed report.

Most will not want you to take down a server if it disrupts the network so that's why we usually have to be careful when we are doing any kind of exploit.  If its just running IDS and you feel taking it down wont be disruptive and such an attack is defined in writing, then by all means. Btw, just having it written out is not enough. You need to sit down with the powers that be and go over each point to make sure they clearly know what you might do and the possible problems that might occur.  It really doesn't help you much after the fact to show the fine print in your agreement to the CEO, who never understood it any way, explaining your action if you accidentally knocked out the corporate network.
« Last Edit: January 02, 2010, 01:24:01 PM by Kev » Logged
jinwald12
Jr. Member
**
Offline Offline

Posts: 50



View Profile
« Reply #3 on: January 02, 2010, 09:13:49 PM »

thanks you guys and this wasn't for a pen test this was a hypothetical question
Logged

where did all the fun go?
bamed
Newbie
*
Offline Offline

Posts: 48


View Profile WWW
« Reply #4 on: January 13, 2010, 10:55:44 PM »

I think all of the answers above are technically correct, though I would throw in there that if you purposefully bring down a server simply to "buy time" than your motives make it unethical.  If you bring down the server to expose a vulnerability, that's a whole different situation.  Of course, the client most likely won't know your motives, and you'd probably get away with it, but it is still my opinion that in the scenario originally described, the pen-tester's motives were unethical, thus the act would be unethical.
Logged

chown -R bamed ./base
timmedin
Sr. Member
****
Offline Offline

Posts: 470



View Profile WWW
« Reply #5 on: January 31, 2010, 08:25:57 PM »

It all depends on the "rules of engagement".

From practical experience, I haven't seen an intentional DoS against productions systems be allowed.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.264 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.