Anyone know how to handle the legal/bueracratic aspects of pen-testing a web server which is not in-house, but property of a hosting company??
The hosting company may not take lightly to suggestions that it may be vulnerable, and may be afraid of damage caused by a test. Worse, if the server is not dedicated, but rather uses virtual hosts, other clients could be affected by the testing.
Any real-world advice, forms, paperwork, or legal info. would be appreciated.
Franklin DeMatto
franklin_at_qDefense.com
qDefense - DEFENDING THE ELECTRONIC FRONTIER
Received on May 22 2001