Thursday, August 20, 2009

so easy a 9 year old can do it

From time to time I get questions from my son about ethical hacking, penetration testing, lock picking and the like. It has always been important for me emphasize the "ethical" and legal components of these activities.

For example, one day the swimming pool was unexpectedly closed and locked with a padlock. He has seen me pick these types of locks for the better part of his life. However he respects the rules posted and knows the picking the lock to get in would likely be against the law. More importantly he knows that the lock provides little to no security against criminals or vandals.

I've recently began showing him how to spot simple web application vulnerabilities using test applications on a private network. He was able to perform his first authentication bypass using a forgot password function in the application. I'm proud of him but know I have a to continue re-enforcing his positive sense of ethics and concern for others.

No comments: