Advertisement
Promo

Security threats Toolkit

Story: Tsunami appeal site 'hacker' found guilty

  • Previous comment

Posted by: Evil Wizard (Friday 14 October 2005, 7:12 PM)

  • Reply

John I dont believe in this case you can say there is no way that you can know what pages you are authorized to view and what aren't. This guy is a supposed infosec consultant. I know that if I go to a website and then purposely start doing some SQL insertion or trying to exploit some cross-site scripting vulnerability or trying and drill down into a root directory then I am doing something illegal by trying to break into the site. Its not that he was just trying to view another webpage, he was trying to view information he knew he shouldn't be accessing through the browser. (I can post code in a forum that when submitted shows me the SAM file from the server... or whatabout a little cut and paste of source code in an online shopping cart program that changes the listed price of something to a penny?) The browser is just the medium used to execute the attack. I also dislike all the references to looking for locked doors via wriggling handles because that is not what he was doing. He was attempting to break in via a known exploit. Had he broken in who knows that kind of damage (purposeful or not) he could have caused. That is in my opinion why he was busted. Now the severity of the penalty... is arguable.

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters