| |
| ▲ | iancarroll 3 hours ago | parent [-] | | How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs? | | |
| ▲ | xmodem an hour ago | parent | next [-] | | Maybe i'm old fashioned, but personally I think the onus should be on the person sending out unauthorized malicious requests to figure out how to not do that. Any responsible bug bounty researcher reviewing the DNS zone by hand would spot the CNAME and remove it from the target list. You don't get to wash your hands of that because your chatbot did it. | |
| ▲ | toomuchtodo an hour ago | parent | prev | next [-] | | When I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope beyond your intended target. Dump the subdomains, resolve them, and review where they resolve to in order to understand the footprint and attack surface boundaries before engaging scanning or agentic red team harnesses. Automate as much as possible for building the state graph of the target, but a human must remain in the loop to sanity check. To not do this means you could be attacking hyperscaler object storage, a CDN, a partner SaaS frontend, ticketing systems, mail systems, etc (ie anything someone may CNAME off the root domain but that is outside of their organization’s control). | |
| ▲ | saghm 2 hours ago | parent | prev | next [-] | | Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS. | | |
| ▲ | iancarroll 2 hours ago | parent [-] | | The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second? | | |
| ▲ | saghm 2 hours ago | parent [-] | | You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening? | | |
| ▲ | iancarroll 2 hours ago | parent [-] | | I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all. | | |
| ▲ | saghm 2 hours ago | parent [-] | | Okay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners. | | |
| ▲ | iancarroll 2 hours ago | parent [-] | | Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive. | | |
| ▲ | saghm an hour ago | parent [-] | | > Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think it's pretty disingenuous to compare viewing a couple of pages once a day with running scripting tools against over 400 websites. > I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive. Oh good, no one has ever claimed "it's for your own good" when doing something selfish without consent. |
|
|
|
|
|
| |
| ▲ | natebc 3 hours ago | parent | prev [-] | | [dead] |
|
|