Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 104 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow At what point is communication with a company illegal?
EH-Net
May 26, 2012, 11:19:26 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: At what point is communication with a company illegal?  (Read 1087 times)
0 Members and 1 Guest are viewing this topic.
Eleven
Jr. Member
**
Offline Offline

Posts: 64


View Profile
« on: November 21, 2011, 07:41:03 AM »

I know even attempts at attacking a site is illegal, but what about simply doing recon like downloading publicly available documents from their site and looking at metadata, gathering email addresses, URLs, business partners etc., without the intentions of using that data.  To me, it seems like OSINT is similar to someone in physical security walking into a store and looking at its physical security without any intentions of robbing it.
« Last Edit: November 21, 2011, 07:54:32 AM by Eleven » Logged
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #1 on: November 21, 2011, 09:47:33 AM »

There are probably no laws against it.  If you do not need to alter or exploit the code in the site to obtain the information then you are probably not doing anything illegal.  However you may be doing something unethical if you have not been given permission to browse the site.  If there is some monitoring of the site and it is noted that there are some strange directory traversals, they may take that as hostile and begin investingating.  Its a fine line I think, a gray area and is really based on your judgement.  If you find something that could be exploited and decide to tell them about it, you may get some negative responses.  Tread lightly sir.

The question then arises, what were you planning to do with the information?  You still gathered it so why?  That would be questions that I may ask if I came across your activity.  The otherside of the coin is "well they put it out there so its their fault" that's where you need to walk the ethical line I think.
Logged

Certs: GCWN
Eleven
Jr. Member
**
Offline Offline

Posts: 64


View Profile
« Reply #2 on: November 21, 2011, 10:06:43 AM »

I'd want to do it simply to try out some recon tools.

You raise a good point on ethics.  However, maybe it wouldn't be so unethical if someone were to do recon on a company who collects and sells information on us (e.g. Intelius).  If companies can collect information on me AND sell it, why shouldn't I be able to collect information on them?  Heck, I would just be collecting it, not profiting from it like they are.
Logged
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #3 on: November 21, 2011, 10:11:54 AM »

Can't argue with the logic Cheesy  Then again if the company collects the information because they are well defined as a "Partner" with a site that you gave your information to and agreed in one way or another that you allowed them to share your information with their "Partners" then they have the right do such data collection and you could still be found in the wrong, no matter your intentions or their business practices. 

Its the gray line similar to the idea of attacking back when defending your network.  One would like it would make sense but there are laws that protect the bad folks as well as the good folks and depending on where the originate, you may be crossing some international lines.  Best bet for testing tools is to try and build yourself a web app lab of such.  I'm sure you can get some sample sites that can quickly be thrown in for use, or you can test against sites like hackthissite.org.
Logged

Certs: GCWN
Eleven
Jr. Member
**
Offline Offline

Posts: 64


View Profile
« Reply #4 on: November 21, 2011, 10:25:33 AM »

hackthissite.org looks like fun.  Signing up now, thanks! Smiley
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.189 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.