Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Bad Raps for Non-Hacks
Mark Rasch, 2003-06-16

A few odd cases show that you don't have be a digital desparado to be accused of a cybercrime... particularly if you embarrass the wrong bureaucrats.

Comments Mode:
the girl next door 2003-06-16
Kees Huyser
Bad Raps for Non-Hacks 2003-06-16
blacklight
Pen-testing own (hosted) domain 2003-06-17
Andy (1 replies)
Pen-testing own (hosted) domain 2003-06-18
Anonymous
Bad Raps for Non-Hacks 2003-06-17
Anonymous (3 replies)
Inadvertent Straying While Pen Testing 2003-06-17
Mark Rasch (1 replies)
Inadvertent Straying While Pen Testing 2003-06-23
Anonymous
Marc, in your latest message you bring up a very good anaology. The idea of a car not being locked is a good point. If I'm in the car with you and happen to notice your car not locked as you head to your local retail outlet, I say, hey, your car door is unlocked!.

You turn and say it's locked, I just locked it.

If I look at your car and pull the handle of the door, am I not doing the same as a ping sweep or a port scan?

If the door opens I've penetrated the system (car).

The point is in this case as a passenger (employee) I am concerned over the contents of the system (car). I bring that issue to your attention. Because I've pulled the handle of the door (port scan) should I now be arrested, tried and subjected to civil or criminal procesuction?

What if I don't say anything and the car is stolen because of the unlocked doors? As your employee am I guilty of aiding and abeting?

Why are employees awarded for bringing up issues of economic value for saving a few hundred dollars on coffee cups? Is there no economic value to information security?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/167/20547#20547
Bad Raps for Non-Hacks 2003-06-19
blacklight
Bad Raps for Non-Hacks 2003-06-19
Elc0chin0 (1 replies)
Bad Raps for Non-Hacks 2003-06-23
Ferg (1 replies)
Bad Raps for Non-Hacks 2003-06-24
blacklight
Bad Raps for Non-Hacks 2003-06-18
Elc0chin0
Bad Raps for Non-Hacks 2003-06-20
Hamster1







 

Privacy Statement
Copyright 2009, SecurityFocus