Hello IndieHackers community,
I am a new born in this community, about ~2 days old (signed up).I don't have the right mindset to be an entrepreneur yet but I learn fast.
I know in every forum or community the most important aspects are: information, friends and respect.That's why I make a big "pro bono" to all users that have a website in production: free web application security testing. Just send me an email.
What are my expectations from you:
- the subject of the email must start with [IH] followed by your IH user name, eg: "[IH] Retronym"
- the sender domain name must match with the domain of the site that you want to test,
- the website must be in production,
- if I need to log in, please give me a temporary active account (user/pass),
- if you will have any questions to my response, please reply me,
- make a post to this thread if you will be happy with my work,
- if you have more that one website, send me another email (number 2).
What will be your expectations from me:
- long time without response, it depends how many emails I will get, but I will read it and constantly check for new emails every day,
- I will respond in a freestyle writing, because to make a report it's time consuming ,
- if your website is static, without some user interaction don't expect me to find something,
The more complex is your site the higher is the change to find something.
- maybe I will give you some tips and trick to empower your front-end security.
- my methodology is common sense without tools, because tools may trigger the WAF, like dirbuster.
My free time is very limited, I work 2 days, each day in a 12 hours shift and 2 days free (salesman at a gas station).
This "pro bono" is not related to my future project (online classified ads website).I really don't know how many days I will keep this "pro bono" open, just drop me an email to see.
Thank you for your attention!
I strongly recommend against participating in this, for all parties.
One excellent measure you can take to improve your app's security: don't hand over credentials to random strangers on the internet.
Even assuming Retronym's intentions are good, there are plenty of ways that a penetration test on your website can cause serious, unanticipated damage. You shouldn't engage in security testing unless you're confident that the tester is competent and conscientious about respecting the limits of the test. It's a big red flag when a tester demands to test against a production server (as Retronym has) rather than an independent testing environment. Also, if Retronym's intentions are nefarious, they could potentially plant backdoors into your app.
@Retronym: how are you protected legally if you cause serious damage? You don't have a contract saying who's liable. Having an email from someone at the domain is not enough. If I'm a secretary with a bankofamerica.com email address, that doesn't give me the authority to order attacks on the Bank of America website.
[I'm a former penetration tester who specialized in web apps. I worked for NCC Group, one of the largest security consultancies.]
Thank your for your great reply @mtlynch
One excellent measure you can take to improve your app's security: don't hand over credentials to random strangers on the internet.
That's was my fault, I mean a random generated username with normal or restricted user privilege. In the "bug bounty culture" is normal to ask for a username. If you log in with that username you know that you may be restricted or your activity logged.
Facebook has it's own adaption : https://www.facebook.com/whitehat/accounts/ with custom db, this account cannot interact with real facebook profiles, this will be also my feature for my project.Or do you mean platform leak? Like in the bugmenot.com db?
I respect your opinion and don't search for counterarguments because you are wiser that me and I am inferior to your knowledge because I am self taught, but those mentions in my profile description I didn't get in a short time.
It's a big red flag when a tester demands to test against a production server (as Retronym has)
Let's say I browse something on a random website about cats with less that 50 active users, I start testing common mistakes because this is how I contribute to their website and then search their email or feedback form. If they agree to test more detailed, then I will ask for "out-of-scope" methods and maybe a username. I don't ask anything in exchange.
Also, if Retronym's intentions are nefarious, they could potentially plant backdoors into your app.
I don't know what you mean? If I can then everybody can, that's the point of this pro-bono, to test the webapp and to give feedback.
Retronym: how are you protected legally if you cause serious damage? You don't have a contract saying who's liable.
I am not. I do this for about ~6 years now, this is how bug bounty platform ticks. If you don't know what you do, don't do it!
Having an email from someone at the domain is not enough. If I'm a secretary with a bankofamerica.com email address, that doesn't give me the authority to order attacks on the Bank of America website.
Common sense , country's CERT and this: https://hackerone.com/bofa .
Thanks for your response @Retronym.
It seems like you see this as equivalent to bug bounty programs. There's a critical difference between your proposal and bug bounty programs.
Companies create bug bounty programs in conjunction with their internal experts on software security and law. The program rules define liability and parameters for acceptable behavior by the pen tester.
People who request your pro bono services are likely not experts in law or software security. They don't know what precautions they need to take when working with a pen tester and ensure that both parties are protected.
Yes I know that, that's why I test only the common mistakes and give remediations. I don't conduct RCE or SQLi test. I don't know anything else with what I can help this community.
Thank you @Retronym - I'll actually take you up on it :-) Sent!
Update #1
Resume: one informativ email.
Welcome to the community! Thank you for this awesome offer.
Thank you, mate!
For now it seems nobody it's interested.