Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Bad Raps for Non-Hacks
Mark Rasch, 2003-06-16

A few odd cases show that you don't have be a digital desparado to be accused of a cybercrime... particularly if you embarrass the wrong bureaucrats.

Comments Mode:
the girl next door 2003-06-16
Kees Huyser
Bad Raps for Non-Hacks 2003-06-16
blacklight
Pen-testing own (hosted) domain 2003-06-17
Andy (1 replies)
Pen-testing own (hosted) domain 2003-06-18
Anonymous
Bad Raps for Non-Hacks 2003-06-17
Anonymous (3 replies)
Inadvertent Straying While Pen Testing 2003-06-17
Mark Rasch (1 replies)
Bad Raps for Non-Hacks 2003-06-19
blacklight
Thanks for the compliment.

I will add that them short-sighted idiots happen to be the ones who have the ultimate authority to approve the expenditures that pay your bills and mine as security people. The world can be cruel, ugly and unfair in that way, but that's the way things are.

You are right that reporting security holes is no pot of roses, as the net admins and net engineers who manage their op on a daily basis can get SUPER defensive - And they don't forgive and forget either. Those would-be security professionals who have no flair for diplomacy should really stay out of this business. And all the good will in the world will not protect you from coming to a bad end in this business if you don't watch your surroundings.

Finally, I am a great believer in not doing anything until we start receiving money from the client, as in "Show me the money!" Actually getting the money is the ultimate proof that the client's liaison person really has the authority to get the security testing approved, and that we interfaced with the client using the proper channels. CYA!

I am a security guy, because I love dealing and interacting with people. This does not mean that I am not unaware that I could end up with sharp objects sticking out my back, if I don't look over my shoulder systematically. CYA!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/167/20519#20519
Bad Raps for Non-Hacks 2003-06-19
Elc0chin0 (1 replies)
Bad Raps for Non-Hacks 2003-06-23
Ferg (1 replies)
Bad Raps for Non-Hacks 2003-06-24
blacklight
Bad Raps for Non-Hacks 2003-06-18
Elc0chin0
Bad Raps for Non-Hacks 2003-06-20
Hamster1







 

Privacy Statement
Copyright 2009, SecurityFocus