Joakim Tauren
I have been running Bug bounty programs since 2016 and hacking on them myself since. 150+ M&A Security Due Diligence evaluations, ~40 per year.
Head of Security Testing at Visma.
Session
08-17
16:00
45min
Ethical hacking, good intentions and questionable outcomes
Joakim Tauren
We've all been there, we knocked a company offline while doing some well intended security testing. How many requests per second is considered ethical? How deep into a system can you go, dump the database or not? Reverse shell or touch /tmp/pwned? What are YOUR ethical boundaries?
What is ethical? and why? Is buying credentials of the dark web ethical? Is fuzzing a server in a broom closet with millions of requests ethical? Did you know it was a raspberry pie in a broom closet?
Milliways
Milliways