Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Breach case could curtail Web flaw finders
Robert Lemos, SecurityFocus 2006-04-26

Security researchers and legal experts have voiced concern this week over the prosecution of an information-technology professional for computer intrusion after he allegedly breached a university's online application system while researching a flaw without the school's permission.

Comments Mode:
In other words, shoot the messenger 2006-04-26
Anonymous (1 replies)
Re: In other words, shoot the messenger 2006-04-26
Anonymous (5 replies)
Re: Re: In other words, shoot the messenger 2006-04-27
Anonymous
Yes, never take pre-emptive action to protect the people, or your fellow student for that matter. It is the DA's opinion by filing the case that these actions are against the law. In reality you cannot tell if a website is vulnerable without running a test. Would you put your social security number in a school website after all the bad press on school sites preceeding this incident? If you had the know-how, would you test it before you did? There was an apparent discrepency in terms of how many records the site would produce with the exploit upon proxy communication with USC, he then produced more. So, in effect, if your bank's website only produced your credit card number with an exploit run against it, this means they are secure?

Yep, "no grey area", & "cut and dry". "No pre-emptive action", & "Screw the people" it is the only legal way.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11389/33760#33760
Re: Re: In other words, shoot the messenger 2006-05-18
Spider Jerusalem
FreeMcCarty.com 2006-04-26
Anonymous (2 replies)
Re: FreeMcCarty.com 2006-04-27
carl
Re: FreeMcCarty.com 2006-04-28
Bilz
In other words don't steal data? 2006-04-27
Anonymous (1 replies)
Imagine a world... 2006-04-27
jvf (1 replies)
Re: Imagine a world... 2006-09-26
Dve
as expected... 2006-04-27
infamous41md (2 replies)
Re: as expected... 2006-04-27
BXLE
Re: as expected... 2006-04-28
Anonymous
appearance today 2006-04-29
mv
He Should be Prosecuted 2006-05-01
Anonymous (2 replies)
Re: He Should be Prosecuted 2006-05-01
Anonymous
Re: He Should be Prosecuted 2006-05-23
Anonymous
Breach case could curtail Web flaw finders 2006-05-18
Spider Jerusalem







 

Privacy Statement
Copyright 2009, SecurityFocus