lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20061005003422.89140.qmail@web51014.mail.yahoo.com>
Date: Wed, 4 Oct 2006 17:34:22 -0700 (PDT)
From: Wolf Halton <saphil@...oo.com>
To: bugtraq@...security.net, joe@...rnsecurityonline.com
Cc: bugtraq@...urityfocus.com
Subject: RE: Informing Companies about security vulnerabilities...

Robert,

It is not illegal to pen-test web applications on your classroom
servers, and then as an exercise, check for web sites running the
vulnerable apps and send emails telling them of the vulnerability. 
This is not like pen-testing the company's web site without permission,
and your students will be thrilled to have something useful to do with
their fledgling skills.

Giving a talk on the vulnerability at the Black Hat convention might
get you fired from ISS though.  

Wolf Halton
http://www.networkdefense-dot-biz

> -----Original Message-----
> From: bugtraq@...security.net [mailto:bugtraq@...security.net] 
> Sent: Wednesday, October 04, 2006 3:15 PM
> To: joe@...rnsecurityonline.com; pen-test@...urityfocus.com
> Cc: bugtraq@...urityfocus.com
> Subject: RE: Informing Companies about security vulnerabilities...
> 
> So you are admitting publicly that you and a class of students that
> you
> teach are illegally testing random public 
> websites for the purpose of learning about security vulnerabilities?
> Sounds like you/your company need to speak
> with a lawyer.  
> 
> - Robert 
> http://www.cgisecurity.com/ Application Security news and more
> http://www.cgisecurity.com/index.rss [RSS Security Feed]
> 
> -----Original Message-----
> From: listbounce@...urityfocus.com
> [mailto:listbounce@...urityfocus.com]
> On Behalf Of Joseph McCray
> Sent: Wednesday, October 04, 2006 3:07 AM
> To: pen-test@...urityfocus.com
> Subject: Informing Companies about security vulnerabilities...
> 
> This probably won't sound like that big of a deal, but it still
> bothered
> me so I figured I'd ask the list. I was teaching a Web Application
> Security class last week and we were performing simple XXS, SQL
> Injection, etc on the vulnerable web apps I use for class.
> 
> 

ht

--
Summer Special - Make Money on Your Phone Bill  Arrowstars.com 
Computer support network: http://tech.groups.yahoo.com/group/Tech_Answers/?yguid=11909323
Eggs from Happy Chickens!  Catwood Farms - 1960 Hightower Trail, Conyers GA 30012-1822 - 678-384-4930


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ