Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Blaming the Good Samaritan
Houston Carr, 2008-09-26

In the early 90's, I attended an academic conference in Hawaii. At one presentation, a colleague from the University of California at Berkeley whom I'll refer to as "the supervisor," told a story of young hackers, who he referred to as the Urchins.

Comments Mode:
Blaming the Good Samaritan 2008-09-26
Anonymous (1 replies)
Re: Blaming the Good Samaritan 2008-10-01
Anonymous (3 replies)
Re: Re: Blaming the Good Samaritan 2008-10-01
Anonymous
Well, I haven't done pen testing in about 6 years or so, but I started doing them in 1994 as a firewall admin in college. Later did security research/testing at Bell Labs until 2002.

So I kind of understand the concept of running a pen test. One of the things that was crucial with doing pen testing on someone's network was _getting_permission_. You just can't compromise a network and then say "I was trying to help you fix your issues!" when caught.

>>>>>
This student was clearly not as stupid as you seem to think he was. I'd like to see you try and fix the security holes he found, without referencing his report.
>>>>>

I think you're mistaking outcome vs. intent. I'd expect better reading comprehension skills from someone who suggested I brush up on _my_ reading to understand security.

>>>>>
Did you read the article? How likely do you think this university would be to give someone like him, permission to "test" their security? Why don't you try asking at *your* local university, and see what they say? I'll be happy to visit you in jail.
>>>>>

I'm missing your logic here - I'd go to jail for asking my university to all me to run a test? Well, I graduated years ago, but they'd probably say no and no crime is committed.

But you're suggesting it's okay to run the test without their knowledge?

Do me a favor, save your note, and read it again long after you graduated and been working in the industry, provided you have the analytical skills to be employable. You'll see the foolishness of your ways.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/481/35182#35182
Re: Re: Blaming the Good Samaritan 2008-10-14
The Better Samaritan
disagree with premise 2008-09-27
Anonymous (3 replies)
Re: disagree with premise 2008-10-01
Anonymous
Re: disagree with premise 2008-10-04
Anonymous
Re: disagree with premise 2008-10-10
Anonymous
Blaming the Good Samaritan 2008-09-27
Anonymous
Blaming the Good Samaritan 2008-09-28
RU_Trustified
Where to draw the line 2008-09-29
Daniel Thomas (1 replies)
Re: Where to draw the line 2008-10-01
Anonymous
Blaming the Good Samaritan 2008-09-29
Anonymous (2 replies)
Re: Blaming the Good Samaritan 2008-10-01
Anonymous (2 replies)
Re: Blaming the Good Samaritan 2008-10-01
Anonymous
Blaming the Good Samaritan 2008-09-30
Darin (4 replies)
Re: Blaming the Good Samaritan 2008-09-30
Anonymous
Re: Blaming the Good Samaritan 2008-09-30
RU_Trustified (2 replies)
Re: Re: Blaming the Good Samaritan 2008-10-01
Anonymous (1 replies)
Re: Blaming the Good Samaritan 2008-10-01
Anonymous
Re: Blaming the Good Samaritan 2008-10-03
Anonymous
Blaming the Good Samaritan 2008-09-30
Anonymous
Blaming the Good Samaritan 2008-09-30
Brandon (1 replies)
Re: Blaming the Good Samaritan 2008-10-01
Teknohazard
Blaming the Good Samaritan 2008-09-30
Mr. Mike (1 replies)
Re: Blaming the Good Samaritan 2008-10-01
R... (1 replies)
Thin Skull Rule 2008-10-17
Anonymous
Blaming the "Cracker" 2008-10-11
Anonymous
Time to grow up 2008-10-11
Anonymous
Tresspassing 2008-10-28
Jake Brodsky







 

Privacy Statement
Copyright 2009, SecurityFocus