Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Disclosure of vulns and its legal aspects... |
|---|---|
| Date: | 30 May 2007 18:50:24 -0000 |
First, I fully agree that you should dump them the information anonymously and then walk away. But...yup, there's a but. If you were reporting this to me, I'd likely be just a teeny tiny bit curious about you. And chances are pretty good that you've left some tracks in my logs, especially if you were making interesting page calls or posts. Or some manager may ask his team, "Can we check to see if this has been exploited and track them down?" Your hits will be part of that investigation. While I agree, anonymous is great, if you've not maintained that anonymity in your testing, at least be aware you can still get into some trouble. This is one of those cases I might suggest tabling your findings and chalking it up as a learning experience on multiple levels. <- snip -> On Wed, May 30, 2007 at 09:14:39AM +0100, Lee Lawson wrote:
I would personally create an anoymous email account and send them some information stating that you are a penetration tester that 'happened' upon a possible security flaw in their website, but because of the state of fear that some unenlightened organisations have about this type of situation, you wish to remain anonymous at this point. Then explain that if they are open to increasing the security of their website, you will gladly analyse the security flaw further and give them full disclosure, on the basis that you will be given written permission prior to continuing further.
------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Citrix Pen Test,, Sat Jagat Singh |
|---|---|
| Next by Date: | Re: Disclosure of vulns and its legal aspects..., Sat Jagat Singh |
| Previous by Thread: | RE: Disclosure of vulns and its legal aspects..., Craig Wright |
| Next by Thread: | RE: Disclosure of vulns and its legal aspects..., Craig Wright |
| Indexes: | [Date] [Thread] [Top] [All Lists] |