|
|||||||
| Pentesting Specific topics related to legal penetration testing |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
Quote:
__________________
dd if=/dev/swc666 of=/dev/wyze |
|
||||
|
Quote:
Just remember the BT starting logo and the litle text that is writen there. Regards
__________________
If you wait to do everything until you are sure it`s right, you`ll probably never do much of anything. |
|
||||
|
Quote:
Quote:
Quote:
sociopathichaze, You may be "right" in that, technically, some or all of these things should be corrected. However, you were dead wrong in even attempting to find these issues in the first place. You did NOT do a "security audit" no matter how you rationalize it in your own mind. A security audit is done by professionals, under contract, using standardized procedures, within a specified scope. On top of that, those professionals adhere to ethical standards. So far, what you've done is at best, unauthorized poking around in areas you had no right or authority to be near, and what are by my count, at least three felonies, and something on the order of 5-20 counts of each felony, depending on the jurisdiction and how the police and prosecutor see each felony. Also, you've broken just about every ethical standard adhered to by professional pen testers. Quote:
If you insist that you "post all the info [you] have obtained, email the Dean and explain why he should fire these idiots, email everyone in the student/faculty directory telling them their data isn't safe", or continue with any other action along those same lines, you're going to force their hand. What will happen is that you won't be the good guy, you will be the "Temp Worker Charged with Hacking Local College. Details on the 6 O'clock Report." If you don't let this die, then your next step should be to get a competent defense attorney. You'll need one.
__________________
Thorn “Never try to teach a pig to sing; it wastes your time and it annoys the pig.” - Robert Heinlein |
|
||||
|
Quote:
My guess, he's thinking that he'll get hired as an admin and be able to leave helldesk by submitting this information to management.
__________________
A 3rd Party Security Audit is the IT equivalent of a Colonoscopy, it's long, intrusive, and when it's done you'll have seen a lot of things you really didn't want to see, and you'd definitely remember that you had it done. I ♣ baby harp seals. |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|