Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Breach case could curtail Web flaw finders
Robert Lemos, SecurityFocus 2006-04-26

Security researchers and legal experts have voiced concern this week over the prosecution of an information-technology professional for computer intrusion after he allegedly breached a university's online application system while researching a flaw without the school's permission.

Comments Mode:
In other words, shoot the messenger 2006-04-26
Anonymous (1 replies)
So he finds that USC has deployed vulnerable web code, and they take their site down to fix it, and he is responsible for the downtime of the website?

Let's see, we wouldn't want to blame the web programmer for writing insecure code. Or the USC Information Security Team for allowing the code to be put into production on an Internet-facing web server. Seems to me that a bunch of incompetent IT people are trying to shift blame off of themselves.

Since USC has shifted the blame so efficiently, I'm sure that the same sloppy code is likely being deployed on other parts of their network. However, since we know how they treat an honest person who wants to cooperate with them, next time it won't be an honest person who is looking for the flaw(s). USC students beware! Your personal data is likely at risk and the only people looking for it are going to misuse it when they find it.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11389/33750#33750
FreeMcCarty.com 2006-04-26
Anonymous (2 replies)
Re: FreeMcCarty.com 2006-04-27
carl
Re: FreeMcCarty.com 2006-04-28
Bilz
In other words don't steal data? 2006-04-27
Anonymous (1 replies)
Imagine a world... 2006-04-27
jvf (1 replies)
Re: Imagine a world... 2006-09-26
Dve
as expected... 2006-04-27
infamous41md (2 replies)
Re: as expected... 2006-04-27
BXLE
Re: as expected... 2006-04-28
Anonymous
appearance today 2006-04-29
mv
He Should be Prosecuted 2006-05-01
Anonymous (2 replies)
Re: He Should be Prosecuted 2006-05-01
Anonymous
Re: He Should be Prosecuted 2006-05-23
Anonymous
Breach case could curtail Web flaw finders 2006-05-18
Spider Jerusalem







 

Privacy Statement
Copyright 2008, SecurityFocus