While this is all fun and games, I am curious if DOSing someone else’s server, even if it’s being used to run a phishing scam, is legal.
I seriously doubt it is legal in the United States. Seems like a pretty clear abuse of a computer network.
Stopping phishing campaigns with Bash
11–20 of 169 posts
Re: Stopping phishing campaigns with Bash
#12Re: Stopping phishing campaigns with Bash
#13As much as I think things like this can be fun, depending on your jurisdiction (and tbh the US loves extraditing people for silly computer crimes), it might not be advisable. This is all but certainly illegal at least within the US. I’m sure most competent security experts have been tempted to do things like this, or SQLi a scammer’s form and nuke their DB, and usually bad things won’t happen to you, you might find t…
Re: Stopping phishing campaigns with Bash
#14All banks in the EU are required to use 2FA, I'm curious how these hackers get around that.
I'm asking because my (German) bank only very recently changed to requiring 2FA every X days for login. I'm very curious if they are actually compliant, since I used to be able to log in just with 1 factor to see my current balance (but not conduct any transactions).
Re: Stopping phishing campaigns with Bash
#15All banks in the EU are required to use 2FA, I'm curious how these hackers get around that.
Re: Stopping phishing campaigns with Bash
#16While this is all fun and games, I am curious if DOSing someone else’s server, even if it’s being used to run a phishing scam, is legal.
Re: Stopping phishing campaigns with Bash
#17As much as I think things like this can be fun, depending on your jurisdiction (and tbh the US loves extraditing people for silly computer crimes), it might not be advisable. This is all but certainly illegal at least within the US. I’m sure most competent security experts have been tempted to do things like this, or SQLi a scammer’s form and nuke their DB, and usually bad things won’t happen to you, you might find t…
How can it be illegal sending a few fake data to a website? And anyway I doubt they will ever sue you, at most you could be targeted for some revenge attack if they are really pissed off and you don't hide your traces.
Re: Stopping phishing campaigns with Bash
#18Nice! If you are required to write an email address, it would be cool to use a canary, and see if it shows up on haveibeenpwned.com.
Re: Stopping phishing campaigns with Bash
#19As much as I think things like this can be fun, depending on your jurisdiction (and tbh the US loves extraditing people for silly computer crimes), it might not be advisable. This is all but certainly illegal at least within the US. I’m sure most competent security experts have been tempted to do things like this, or SQLi a scammer’s form and nuke their DB, and usually bad things won’t happen to you, you might find t…
How can it be illegal sending a few fake data to a website? And anyway I doubt they will ever sue you, at most you could be targeted for some revenge attack if they are really pissed off and you don't hide your traces.
This is what I expect the relevant text in the CFAA is...
knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;