Post #4203781
2026-07-29 15:38 UTC
Thinking back to my consultant pentester days and the importance of scope.
We used automated tools, spiders and scanners, trying to cover an entire web application in (usually) a very short test period. I made sure my scope was set before doing anything more than reading, but some systems (and some maintainers) treat even active scanning as a hostile action.
If the tool went out of bounds, especially if it went so far out of bounds as to take hostile action against at least two out-of-scope systems, I would have been personally at risk for litigation. I also would have faced professional consequences, and rightly so.
But do it with a liability laundering machine, and somehow it's fine.
Replies (1)
-
@Lemniscate@infosec.exchange 2026-07-29 15:56
@hexamander@infosec.exchange Excellent points. They’re up to, what, two companies known to have been attacked in this situation? Have both of them said they aren’t going to pursue anything legally? I admit most all of what I’ve read about so far has been focused on the technical side.