Elektrine lite

← Feed

@hexamander@infosec.exchange

Post #4203781

2026-07-29 15:38 UTC

Thinking back to my consultant pentester days and the importance of scope. We used automated tools, spiders and scanners, trying to cover an entire web application in (usually) a very short test period. I made sure my scope was set before doing anything more than reading, but some systems (and some maintainers) treat even active scanning as a hostile action. If the tool went out of bounds, especially if it went so far out of bounds as to take hostile action against at least two out-of-scope systems, I would have been personally at risk for litigation. I also would have faced professional consequences, and rightly so. But do it with a liability laundering machine, and somehow it's fine.

Replies (1)

  • @Lemniscate@infosec.exchange 2026-07-29 15:56

    @hexamander@infosec.exchange Excellent points. They’re up to, what, two companies known to have been attacked in this situation? Have both of them said they aren’t going to pursue anything legally? I admit most all of what I’ve read about so far has been focused on the technical side.

    Open ##4203778