Microsoft Opens the Gates to Hack Their Web Services

Use Netsparker


It seems like Microsoft are starting to get serious about security, in a very progressive move they have said they are ok with ethical hackers finding security flaws in their online services.

It’s been fairly ok so far to hack away at software installed on your own hardware, but hitting remotely hosted applications has been a big no-no with individuals facing legal action even when they were just trying to help.

In a first for a major company, Microsoft has publicly pledged not to sue or press charges against ethical hackers who responsibly find security flaws in its online services.

The promise, extended Saturday at the ToorCon security conference in Seattle, is a bold and significant move. While researchers are generally free to attack legally acquired software running on their own hardware, they can face severe penalties for probing websites that run on servers belonging to others. In some cases, organizations have pursued legal action against researchers who did nothing more than discover and responsibly report serious online vulnerabilities.

Personally I welcome such a move and hope more companies act in a foreword thinking and ethically just manner. There are many good guys finding flaws, and sadly then don’t report them for fear or litigation. In turn the bad guys find the same flaws and exploit them for gain.

Actions by more big companies to ‘ok’ ethical hacking would make things a little more secure for everybody.

As things stand, researchers frequently turn a blind eye to gaping security holes on websites for fear of suffering a fate similar to that of Eric McCarty. The prospective student at the University of Southern California found a flaw in the school’s online application system that gave him access to other applicants’ records. In 2006, he was charged with computer intrusion after producing proof of his finding.

“There’s definitely a lot of trepidation among legitimate researchers to find flaws in public-facing web applications because you never know how [companies] are going to react,” said Alex Stamos, a founding partner at iSEC Partners, a firm that provides penetration-testing services. “That hurts us because the only people finding these flaws are the bad guys.”

For once I’m praising Microsoft, I know it’s an odd and rare occurrence but they are doing the right thing!

I’m sure you guys have a lot to say about this one..

Source: The Register

Posted in: Hacking News, Legal Issues, Web Hacking

, , , , , ,


Latest Posts:


Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.
Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.


3 Responses to Microsoft Opens the Gates to Hack Their Web Services

  1. Zinho April 21, 2008 at 9:48 am #

    Strange, I got very nice and kind regards from MS security response center when I found *remote* holes. Of course I followed responsible handling of the issue, this may be the reason

    I guess that that no-no is meant to scare and discourage hackers since by far the most targeted company in the universe

  2. fever April 21, 2008 at 5:40 pm #

    You went through proper channels instead of posting as an exploit againt them. that is why they thanked you instead of arresting you. that is the way it should be with all servers of big companies. they should have a forum or somthing where you can submit your work to them and show them their problems.

  3. Changlinn June 1, 2008 at 2:04 pm #

    I wonder if they have fixed up all their expired and incorrectly assigned SSL certificates all over the place. I’ll have to remember where I saw some of them.