Re: [fw-wiz] Legal Release for Security Work

From: Steven M. Bellovin (smb_at_cs.columbia.edu)
Date: 10/26/05

  • Next message: WarrenPaul_at_russellcorp.com: "[fw-wiz] EDI (AS2) Configuration"
    To: "Jay Archibald" <jay.archibald@comcast.net>
    Date: Wed, 26 Oct 2005 16:35:20 -0400
    
    

    In message <001801c5d372$27a11dd0$0212aa80@csw.l3com.com>, "Jay Archibald" writ
    es:
    >Here is a sample PENETRATION TESTING CONTRACT. This same contract is found
    >in EC-Council's Ethical Hacker Course resource kit.
    >
    >http://www.pwcrack.com/penetration_contract.shtml
    >

    One problem with this contract: it does not state clearly the sorts of
    actions the provider is allowed to perform, including what machines can
    be attacked. This is not a trivial point. For example, suppose that
    Department A within a company hires a penetration tester; the attack
    goal is to obtain access to a login account within that department.
    One very plausible way to do that is to hack a machine in Department B
    that is used by someone in Department A, and get in from there. Is
    that permissible or not? Before you answer, remember the Randal
    Schwartz case.

    More generically -- the laws against hacking bar *unauthorized* access
    to computer systems. What is authorized in this case? Is breaking and
    entering permitted? Do you have suitable evidence to show the local
    prosecutor in case you're caught?

                    --Steven M. Bellovin, http://www.cs.columbia.edu/~smb

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: WarrenPaul_at_russellcorp.com: "[fw-wiz] EDI (AS2) Configuration"

    Relevant Pages

    • Suddenly unable to start KDE...
      ... On one of my machines w/ Red Hat 9 that I've been using for some time, ... This communication is for use by the intended recipient and contains ... this e-mail does not constitute a contract offer, a contract amendment, ...
      (RedHat)
    • Re: Somthing else for the spelling police!!!
      ... I suggested you drop an entirely _separate_ issue, ... you're suggesting that I drop the issue of you lying about what I've ... serious harm or injury, and as a result of the attack, the attackee was ... didn't _have_ a contract, which is clearly untrue, ...
      (uk.people.gothic)
    • Re: MD5CRK is now LIVE
      ... My reasoning on why SSL certificates would be ... > Michael Wiener's attack, or simple extensions thereof. ... I proposed a contract from Homer Simpson to Bart ...
      (sci.crypt)
    • Re: Why vitzivanu lehadlik ner?
      ... >attack, it's merely an observation. ... this "deconstruction" thing seems to be closely ... >associated with the type of analysis / thought that Jacko is talking about. ... Thus a contract that's been "mesora'd" to a beit din - that ...
      (soc.culture.jewish.moderated)
    • Re: Question relating to power factors and old welder
      ... No, that's an old wives tale, AC will contract your muscles just as well ... Both machines are fed from a 60Amp ELCB (All the garage sockets are fed from ...
      (uk.rec.models.engineering)