Earlier quoted context omitted.
> Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Sometimes these discoveries aren't intentional. Let's say I lean against a door and it's not locked. Well, I never meant to open it up, but since I can't prove I didn't intend to, and since the business can't distinguish peo…
The articled states that the kid used SQL injection techniques to access the site and gauge the vulnerability.
Teen Reported to Police After Finding Security Hole in Website
51–60 of 123 posts
Re: Teen Reported to Police After Finding Security Hole in Website
#52Suppose while you were away from your house someone came to your front door and found it unlocked. Assume he entered your house and had a look around, but didn't take anything. He then later notified you that you had left your house unlocked. Did he do anything wrong?
Physical metaphors DO NOT WORK in this scenario. This is not a house or a car or commercial warehouse or anything else... it's a website. There are far too many relevant differences between physical locations and web sites for metaphorical reasoning to work.
Well, we need to know more about the particulars. It says it was SQL injection. It's entirely possible, given the limited information, that he just sent a correctly crafted GET request. In that case, a more apt analogy would be a warehouse where stepping on a particular part of the sidewalk unlocks the door.
Re: Teen Reported to Police After Finding Security Hole in Website
#53I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police.
You never know if they're going to involve the police anyway after you spill the beans, and if they do, you'd rather they do it without already having a confession from you.
Re: Teen Reported to Police After Finding Security Hole in Website
#54I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
> Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me. The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police. You never know if they're going to involve the police anyway after you s…
I was definitely worried about this, but I figured that if anything, I've not lied to anybody, so I'd be happy with myself.
Re: Teen Reported to Police After Finding Security Hole in Website
#55A 30c3(30th Chaos Communication Congress) talk by Nate Cardozo(a lawyer) of EFF.
https://www.youtube.com/watch?v=oSi6PxVBOx4
My take on it? Don't do it, You will gain nothing and can loose everything.
Re: Teen Reported to Police After Finding Security Hole in Website
#56Earlier quoted context omitted.
> Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me. The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police. You never know if they're going to involve the police anyway after you s…
> You never know if they're going to involve the police anyway after you spill the beans, and if they do, you'd rather they do it without already having a confession from you. I was definitely worried about this, but I figured that if anything, I've not lied to anybody, so I'd be happy with myself.
Unfortunately, that's not the way police encounters work in practice. Even if you've done nothing wrong, talking to the police can really only hurt you. For example, this re-enactment is based on a true story in which an old lady in Baltimore was convicted of drug possession because some neighborhood children had left a dime bag under her sofa (which she didn't even know about) https://www.youtube.com/watch?v=s7RYH8Py6lY[0]
Just because you think you've done nothing wrong doesn't mean others will agree, especially when it's their job to think you're guilty.
[0] This is part of an hour-long video which shows several more cases like this, but for some reason I can't find the full version anymore.
Re: Teen Reported to Police After Finding Security Hole in Website
#57Earlier quoted context omitted.
> Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Sometimes these discoveries aren't intentional. Let's say I lean against a door and it's not locked. Well, I never meant to open it up, but since I can't prove I didn't intend to, and since the business can't distinguish peo…
The articled states that the kid used SQL injection techniques to access the site and gauge the vulnerability.
E.g. my street address growing up was 1901 Mayor's Road.
Re: Teen Reported to Police After Finding Security Hole in Website
#58In high school I was blacklisted from an admin position for demonstrating that you could write in Digital Command Language a program that simulated the login environment, stored login attempts, and then after three tries exited to the real login environment to let the user in. In college I was nearly expelled for just mentioning to the IT guys that they didn't have a password on some database, and I could get in with…
I also figured out how to access the middle school's library database without a login. [That wasn't secured, nor did it require a password]
Also, nearly got in trouble with the IT administrators at my high school because I found out how to send Novell messages.
I was a very bored kid.
Re: Teen Reported to Police After Finding Security Hole in Website
#59Earlier quoted context omitted.
> Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Sometimes these discoveries aren't intentional. Let's say I lean against a door and it's not locked. Well, I never meant to open it up, but since I can't prove I didn't intend to, and since the business can't distinguish peo…
The articled states that the kid used SQL injection techniques to access the site and gauge the vulnerability.
Re: Teen Reported to Police After Finding Security Hole in Website
#60Earlier quoted context omitted.
"It should never be a crime to report something to the police." I am not sure about that: http://www.wired.com/politics/law/news/2008/02/blind_hacker?...
False reporting is already a crime, and I think it's fair to assume that by 'something' (parent (parent)) meant 'a crime', rather than assuming that he meant false reporting should be made lawful.