When are they publishing the report Squishy
Whatever you do, cover your ass.
You cannot be too open with law enforcement, too anal with written pentesting contracts or record too much information in your conversations (online and off) when discussing ANY pentesting operation.
There is nothing on that hard drive worth the potential years in prison that it may get you.
If you want a challenge, challenge your pentesting friends to a friendly contest by setting up a virtual network and pentesting each other's best work.
If you want a real world challenge, donate your pentesting skills to non-profits to help keep them safe.
When are they publishing the report Squishy
Sometimes I try to fit a 16-character string into an 8–byte space, on purpose.
Be sensitive in choosing where you ask your question. You are likely to be ignored, or written off as a loser, if you:
* post your question to a forum where it's off topic
* post a very elementary question to a forum where advanced technical questions are expected, or vice-versa
* cross-post to too many different newsgroups
* post a personal e-mail to somebody who is neither an acquaintance of yours nor personally responsible for solving your problem
A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.
Not to mention that the size of the coconut would be of interest to the swallow in question..
But despite that,
Shame that the execution of the plan left quite a bit wanting.
Its not a bad idea, however as I am sure is clear, the set up and preparation of such an idea needs better prior planning and thought.
I have another idea.
This one will DEFINITELY get the attention of law enforcement and the businesses.
I have to speak with our local DA first, but I'll talk about it in a little more detail once I have.
If you don't hear from me for a while (like more than a week). It was probably illegal, and I'm probably somewhere cooling my heels.
<raises glass> Here's to pushing the envelope and hoping it doesn't rip.
Hopefully you will be able to tell us about your idea soon and how it went.
Tiocfaidh ár lá
This idea is quite a bit more confrontational than the others and goes a bit farther in actually showing a business owner that his/her wifi is insecure.
I think that it is still legal, but I need to talk to some people first. In fact, I won't even consider doing it unless I also get the go ahead from local feds too.
Federal laws are something that I had overlooked in the past - and something that others should take into consideration.
When attempting something that may be questionable as far as legality, you need to check city, county, state AND federal laws.
It's a lot to do. But, your freedom is worth it.