funsec mailing list archives

Re: Is RCE of malware illegal?


From: Dude VanWinkle <dudevanwinkle () gmail com>
Date: Sat, 5 Nov 2005 18:35:52 -0600

On 11/5/05, Blue Boar <BlueBoar () thievco com> wrote:
Oliver Schneider wrote:
In response to "is RCE legal?" I'd like to raise a funny question with a
serious background: is RCE of malware illegal?

Possibly.

But, there is always the assumption that it is unlikely that the
copyright holder will bring civil suit.  At least with the older kinds
of malware...

Imagine the spyware distributor has a EULA explicitly restricting RCE.
Assume furthermore the spyware uses rootkit techniques.

If you reverse-engineer it, you break the EULA (and you are not part of the
legal system while doing this).
From my understanding the reverser of the malware (or suspected malware)
does something illegal, no?

Some spyware is a bit harder, because the producers are sometimes very
unrepentant, have money on the line, and are willing to use all stalling
& legal tactics.

Well then they definitely wouldnt spend money suing the reverse engineer

Most EULA's are unenforcable anyways. Can someone who doesnt own the
bandwidth, hardware, or software,  agree to a contract for that setup
(read: employee)?

Some of them have forced AV companies to take them out of the spyware
detection.

and some of them pay the company directly for non-detection

http://slashdot.org/article.pl?sid=04/11/02/2032247

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: