Security Basics mailing list archives

RE: application for an employment


From: "Craig Wright" <cwright () bdosyd com au>
Date: Sat, 1 Apr 2006 09:14:56 +1100


Hi,

"Putting a box with a public IP on a public net offering public services is  like presenting products in a Walmart or 
an Aldi respectively. I'm neither obliged to know what I'll buy before visiting the store, nor to only buy products 
that have been advertised. I look at different places, and search, to see what's available, and touch. This is all 
legal."

To go into this, I will assume web as "most" other services do not apply to this. A site that "sells" is a site that 
has an open (based on terms) offer to treat. A site that is just has 

 

brochure-ware  is just like a billboard. An advert. Other sites are more like a library. What is being offered and any 
terms on the site will apply to the reasoning.

 

See -

 

http://www.amazon.com/exec/obidos/tg/browse/-/508088/103-5987069-3709428

 

For example terms.

 

 Illegality starts when you breach the terms of the site. These are either the express terms – see above as example or 
the implied terms associated with the use of WWW systems on the Internet. There are RFC’s and Standards galore to help 
here as well as the local rules associated with fair use, contracting etc.

 

Even though a store for your example is public, there are rules to the use – i.e. conditions, associated with it. You 
may have to agree to have your bags searched for example. You can not look in locked draws, You have no rights to go 
behind the counter etc.

 

And as to the final part. If I was hiring a systems admin. I would not be looking to their pen. Testing skills. I would 
be hiring a person who could first and foremost run the server to the standards and policy of my organisation. 
Patching, disk monitoring, change control etc. All the “fun” things that port scanning has nothing to do with that make 
a server run well.

 

Regards

Craig

 


 
 
 
 

Liability limited by a scheme approved under Professional Standards Legislation in respect of matters arising within 
those States and Territories of Australia where such legislation exists.

DISCLAIMER
The information contained in this email and any attachments is confidential. If you are not the intended recipient, you 
must not use or disclose the information. If you have received this email in error, please inform us promptly by reply 
email or by telephoning +61 2 9286 5555. Please delete the email and destroy any printed copy.  

Any views expressed in this message are those of the individual sender. You may not rely on this message as advice 
unless it has been electronically signed by a Partner of BDO or it is subsequently confirmed by letter or fax signed by 
a Partner of BDO.

BDO accepts no liability for any damage caused by this email or its attachments due to viruses, interference, 
interception, corruption or unauthorised access.

Current thread: