![]() |
|
Philosophical question about vulnerability - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Philosophical question about vulnerability (/Thread-Philosophical-question-about-vulnerability) Pages:
1
2
|
Philosophical question about vulnerability - mig4ng - 05-15-2015 Hello, I've not been very active on the forum, when I come here I just see the new posts and I don't even comment anymore, I guess I got to restart my active duty in the forums, but bullshit aside I have a philosophical question about "hacking" if I can call it that. Lets hypothetical say that I found a glitch or a fail in security of a payment system in a website like ebay, that allows me to purchase things that cost $30 for about $0.60 because they didn't configured their paypal and credit card payment properly (it's not via SQLi and no I'm not using others people money) and I can just underpay a lot for any product in that store. My question isn't if it is correct to use it, of course it isn't, the real question here is, if I hypothetically found a bug like this, is it a crime/illegal to purchase items using this "bug/glitch". Share your opinion. RE: Philosophical question about vulnerability - Nyx - 05-15-2015 Hm. I think it wouldn't go against law because you used the website and paid the price that the website demanded from you, but they might try and call you on theft. RE: Philosophical question about vulnerability - Rye123 - 05-15-2015 Should not be illegal, the owners scripted it that way, it's their fault. RE: Philosophical question about vulnerability - Inori - 05-15-2015 I'd wouldn't say that it's illegal, but I'd report it to the site's owners after using it a few times in case they find it on their own later and see that you've been using it RE: Philosophical question about vulnerability - Crypt - 05-15-2015 (05-15-2015, 12:19 AM)Rye123 Wrote: Should not be illegal, the owners scripted it that way, it's their fault. That's an idiotic and flawed logic. That's like saying it's not illegal to hack a website because the person who coded it had an vulnerability in the way he coded it. @OP if it requires any sort of tampering with the website or requests, it's illegal. Otherwise SQLi, RCE, XSS, CSRF, and everything else would be legal. RE: Philosophical question about vulnerability - roger_smith - 05-15-2015 (05-15-2015, 12:04 AM)mig4ng Wrote: Hello, @Nothing.nobody beat me to it, but yes it's completely illegal. At minimum I'm sure you could be charged under the CFAA of '86 http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act RE: Philosophical question about vulnerability - mig4ng - 05-15-2015 Thanks for the answers I guess I'll just warn the webmaster about the bug then, maybe he gets me some voucher or something to buy stuff on their site
RE: Philosophical question about vulnerability - roger_smith - 05-15-2015 (05-15-2015, 01:48 AM)ねこまっしぐら Wrote: Hey man, you're right. I never even thought of it like that. You have a good point. You should go take a bike that's not locked up. It was their fault that they didn't lock it up, right? I mean now that I think about it, what were they expecting? They probably left it there unlocked in case someone wanted to take it and use it. What a wonderful and caring person to leave their bike like that. RE: Philosophical question about vulnerability - Th3PonyWizard - 05-15-2015 how stoopid can people be if you malform input and gain any favor from it = it is illegal RE: Philosophical question about vulnerability - ねこまっしぐら - 05-15-2015 (05-15-2015, 04:55 PM)Th3PonyWizard Wrote: how stoopid can people be Nicely said. Well put. |