Chapter 73. In Denial of Your Services
Allen West
The attack of disclosure to discourage further snooping is somewhat of a tradition now within the cybersecurity world. Old-timers in the vulnerability research world can tell you that the ecosystem of getting paid for responsible disclosure of findings used to be much riskier than it is today. Bug bounty was designed for that. Without formal bug bounty programs, let alone bug bounty hosting platforms like we have today, it was often a toss-up of how an organization would react to the disclosure of vulnerabilities in their systems. Many times, companies that were unsure how to handle situations like this would often resort to legal action against the researcher, which inevitably led to fear of disclosure and community backlash to the responding company. A lose-lose scenario.
Over time, most companies have come to appreciate the contributions that freelance vulnerability hunters provide and have tried to formalize the process, laying out clear guidelines of what they do and do not want researchers to try when testing their applications. Some common off-limit items include brute forcing, social engineering, purchase of compromised credentials on the dark web, and commercial vulnerability scanners, just to name a few. Basically, anything that would incentivize misbehavior or interrupt actual business.
Security decisions are often ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access