Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Panel Debates Hacker Amnesty
Kevin Poulsen, SecurityFocus 2002-03-25

Should hack-and-tell intruders who warn companies about security holes do time with hardened criminals? Security experts probe the ethics of hacking.

Comments Mode:
Panel Debates Hacker Amnesty 2002-03-26
Anonymous (2 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-26
Surreal (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-26
Robert P (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
Martin
Panel Debates Hacker Amnesty 2002-03-27
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
Ichinin (Ichinin (at) suespammers (dot) org [email concealed], TEXT messages only NO HTML)
Panel Debates Hacker Amnesty 2002-03-27
To the armchair sec analysts
Panel Debates Hacker Amnesty 2002-03-27
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
Andy Richmond
Panel Debates Hacker Amnesty 2002-03-27
Patrick
Panel Debates Hacker Amnesty 2002-03-28
Dimitri Sinchovich
Panel Debates Hacker Amnesty 2002-03-28
Anonymous
Panel Debates Hacker Amnesty 2002-03-28
Anonymous
Panel Debates Hacker Amnesty 2002-03-29
Snagnbytz
NYT Should Prosecute... 2002-03-29
Brian Powell (1 replies)
NYT Should Prosecute... 2002-04-01
Anonymous
Panel Debates Hacker Amnesty 2002-03-31
Anonymous
Panel Debates Hacker Amnesty 2002-03-31
Anonymous
Damn the man! 2002-04-01
RK2K
What else did he get in to? 2002-04-01
CrazyNetworkGuy
Panel Debates Hacker Amnesty 2002-04-02
Hamster1
Panel Debates Hacker Amnesty 2002-04-02
John in Virginia
After reading these posts... 2002-04-02
Robert Perriero (1 replies)
I agree completely 2002-04-02
Scorp
Panel Debates Hacker Amnesty 2002-04-02
John P.
Panel Debates Hacker Amnesty 2002-04-02
Anonymous Lady
Panel Debates Hacker Amnesty 2002-04-03
Anonymous
I've read about Lamo's activities before. As I understand it all he is doing is useing a web browser in a nonstandard way to explore the extent of what he can see. The NYT placed a computer on a public access point and invited the public in via http port 80 access, ie a standartd web browser. If anybody useing just a web broswer finds more access than the owner of the NYT's web site had intended to make available to the public that's a problem for the webmaster to correct. As I understand things, Lamo did not break any law. He was legitmatly accessing a public web site with nothing more than a web browser. He did not deface of alter any content on the web site. All he did was explore the web site better than anybody had done in the past. The NYT, and every web master, should get better security / configuration control over their publicly accessable web sites. As I see it, you put up the web site for the public to explore. You can't complain if someone in the public explores it better than you expect. of course I could be wrong.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/358/11606#11606







 

Privacy Statement
Copyright 2009, SecurityFocus