Live data from Hacker News

Hamed Helped. Help Hamed.

hamedhelped.com

51–52 of 52 posts

Re: Hamed Helped. Help Hamed.

#51
post #37

Earlier quoted context omitted.

Just saying, If he found the vulnerability without using Acunetix, why did he have to use Acunetix later to check if the same vulnerability has been fixed or not? Couldn't he re-check using the same way that he initially found the vulnerability?

Perhaps he was using a wider net to see if there were any other problems which, given the level of (in)competence displayed by the techs working for the college, was a distinct possibility.

Exactly. Which is the definition of unauthorized penetration testing.

Re: Hamed Helped. Help Hamed.

#52
post #25

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

It sounds like he's being screwed over by the vendor, who forced him to sign an NDA. To be honest anyone using Acunetix isn't looking to hack into anything. It's an enterprise scanner that looks for general web app issues rather than something that's typically used to conduct actual attacks. You'd expect an actual attack to be conducted with a tool like Havij, Sqlmap, Burp or Zap proxy.

As I said in my post, I don't believe his intent was malicious (which is what I assume you mean by "hack into").

But that doesn't make the scanner any less stressful or detrimental to the system

Post reply on HN