Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 28 guests and 1 member online
You are here:
EH-Net
May 24, 2013, 06:16:38 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Features
>
Opinions
(Moderator:
don
) >
Security research and Black hats where does the bourder line
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Security research and Black hats where does the bourder line (Read 13882 times)
0 Members and 1 Guest are viewing this topic.
Jamie.R
Sr. Member
Offline
Posts: 429
Security research and Black hats where does the bourder line
«
on:
August 16, 2012, 07:48:00 AM »
I was just curious how does one do security research without breaking any laws?
You hear about new bugs being found in software but in order for someone to find that bug they must have been breaking a few rules.
Where does the line stop and start for security research? I have seen many articles about people finding sql injection on well know website but they must have been breaking the law so where can you draw the line from research to brkaing the law and being black hat ? What do people think ?
Logged
OSWP | Hackingdojo Nidan | eCPPT
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Security research and Black hats where does the bourder line
«
Reply #1 on:
August 16, 2012, 08:01:44 AM »
Following on from your SQLi example. I'd suggest it depends on the circumstances.
If you pick a random website you've got no authorisation to test and start throwing Burp/Nikto/etc. at it, not legal.
If you're legitimately using a site as a user, and your knowledge spots something that's a weakness, there should be no issue reporting this to the sec-ops guys. The difference is being professional enough not to 'just see'; for example error message pops up potentially indicating SQLi, don't then grab sqlmap.....
(I've reported issues a few times on different sites (sorry, NDAs....), and despite the urban horror stories my insight and suggestions has been both greatly recieved and rewarded by the effected site).
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
m0wgli
Full Member
Offline
Posts: 248
Re: Security research and Black hats where does the bourder line
«
Reply #2 on:
August 16, 2012, 08:17:43 AM »
As already mentioned it depends on the circumstances as well as the site. Companies such as
http://www.facebook.com/whitehat/bounty/
and
https://www.paypal.com/us/webapps/mpp/security/reporting-security-issues
for example have bug bounties in place provided the research stays within the terms of bounty program.
The EFF have a small guide:
https://www.eff.org/pages/grey-hat-guide
which is worth a quick read.
Logged
Security + | OSWP | eCPPT | CSTA
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #3 on:
August 16, 2012, 08:40:50 AM »
ok then so you spot somthing do you report it ? as someone ethical you should but most people wont becasue the hassel that is involved.
Logged
OSWP | Hackingdojo Nidan | eCPPT
cd1zz
Hero Member
Offline
Posts: 561
Re: Security research and Black hats where does the bourder line
«
Reply #4 on:
August 16, 2012, 08:42:48 AM »
Most large software companies have a way to report bugs and will not pursue legal action unless you're acting in a malicious way. There are times when the researcher doesn't think the software company is acting "fast enough" which is when things get a bit messy. But for the most part in stand alone software as long as you're professional and follow the companies disclosure policy or bug reporting policy you'll be fine.
If you're poking and prodding on live websites on which you don't have permission to do so, you could get yourself into some trouble.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #5 on:
August 16, 2012, 09:19:42 AM »
ok so here few senarios
you on site you enter your credit card details what get stored on the site. You then notice they being stored without puttin **** over the last 8 didgits do you report it ?
you using a website and your name is 0'neal this causing an sql injection do you report it ?
Your friend been messing with website trying hack it he tells you about a really bad bug would you report it ?
lets say you want do some research in orcel datasbe but they pretty expensive the only real way to do your research is to be a bit unethical what do you do ?
I also head that at defcon there was a presentation on hacking voip in hotel rooms how ethical is this ? trying hack voip phone in hotel to me is wrong you dont own it dont have permission but how many people would give you permission to do this sort of testing?
Logged
OSWP | Hackingdojo Nidan | eCPPT
cd1zz
Hero Member
Offline
Posts: 561
Re: Security research and Black hats where does the bourder line
«
Reply #6 on:
August 16, 2012, 09:31:46 AM »
Quote
you on site you enter your credit card details what get stored on the site. You then notice they being stored without puttin **** over the last 8 didgits do you report it ?
Sure, this is just an observation.
Quote
you using a website and your name is 0'neal this causing an sql injection do you report it ?
If your name is really O'neal... then I would probably play stupid and report the "error" not even calling it a SQLi.
Quote
lets say you want do some research in orcel datasbe but they pretty expensive the only real way to do your research is to be a bit unethical what do you do ?
Not true, you can download oracle and use it free:
http://www.oracle.com/technetwork/products/express-edition/overview/index.html
Also, I think you
really
know the answer to this if its unethical.
Quote
I also head that at defcon there was a presentation on hacking voip in hotel rooms how ethical is this ? trying hack voip phone in hotel to me is wrong you dont own it dont have permission but how many people would give you permission to do this sort of testing?
It's Defcon. Period.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #7 on:
August 16, 2012, 09:44:38 AM »
I do know the answer but I trying get people view what do they count as ethical and unethical. As I think sometimes when people are doing security reasearch they sometimes cross the line and maybe at night slip into a black hat.
Logged
OSWP | Hackingdojo Nidan | eCPPT
MrTuxracer
Newbie
Offline
Posts: 45
Re: Security research and Black hats where does the bourder line
«
Reply #8 on:
August 16, 2012, 01:50:37 PM »
I think this really depends on how you "research" and how professional you report your findings.
If it sounds like you try to extort the website owner -> you'll get in trouble.
If you send a mail from your
1337haxxor@steal-your-cc.com
mail account containing a responsible report, nobody would trust you -> you'll get in trouble.
If you provide the webmaster with his entire database -> you'll get in trouble.
I can say from my own experience that most webmasters are thankful for a responsible and professional reported vulnerability
Regards.
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #9 on:
August 16, 2012, 04:08:40 PM »
Yes I think I just trying to figure out how people do security research without breaking any rules. As I think sometimes it border line if you break the law or not of course there are some instances where its really obvious.
Logged
OSWP | Hackingdojo Nidan | eCPPT
m0wgli
Full Member
Offline
Posts: 248
Re: Security research and Black hats where does the bourder line
«
Reply #10 on:
August 17, 2012, 03:20:29 AM »
I saw an interesting talk at bsides London earlier in the year by Abraham Aranguren titled legal and efficient web app testing without permission:
http://blog.7-a.org/2012/05/legal-and-efficient-web-app-testing.html
According to the talk "At least 48.5% (32 out of 66) of the tests in the OWASP testing guide can be legally * performed at least partially without permission".
Note he does have caveats "* Except in Spain, where visiting a page can be illegal" and "* This is only my interpretation and not that of my employer + might not apply to your country!".
It's obviously advisable for anyone to establish their own legal position before following any of his advice should they wish to do so.
Logged
Security + | OSWP | eCPPT | CSTA
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #11 on:
August 17, 2012, 03:24:25 AM »
I sadly missed that talk as i was at the CV place bet it was intresting.
Logged
OSWP | Hackingdojo Nidan | eCPPT
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Security research and Black hats where does the bourder line
«
Reply #12 on:
August 17, 2012, 03:29:37 AM »
I found Abraham's talk quite enlightening, for me it was one of the more beneficial talks from BSides London this year. I'd also suggest taking a look at
OWTF
, the tool introduced and discussed during the talk.
For those not able to party with us, the BSidesLondon Youtube channel is where you need to be spending your Friday. Abraham's talk
here
.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Security research and Black hats where does the bourder line
«
Reply #13 on:
August 17, 2012, 03:36:22 AM »
Did you attend the talk on html 5 Andew? I enjoy that talk.
Logged
OSWP | Hackingdojo Nidan | eCPPT
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Security research and Black hats where does the bourder line
«
Reply #14 on:
August 17, 2012, 03:53:22 AM »
Missed that one (recording on my 'to watch' list); same reason, sat in CV clinic.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.