Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 914643
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 15, 20262026-05-15T17:45:03+00:00 2026-05-15T17:45:03+00:00

Is it possible to get into legal trouble for identifying vulnerabilities in a web

  • 0

Is it possible to get into legal trouble for identifying vulnerabilities in a web application even if you don’t exploit them?

I have considered using tools like NetSparker on occasion to see if a site has any vulnerabilities and I’d like to contact the owner of the site to see if they’d be interested in me fixing it. I suspect that some of these people might get angry or misinterpret my intentions and I’m curious if I could get into any trouble for simply finding these security issues.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-15T17:45:04+00:00Added an answer on May 15, 2026 at 5:45 pm

    If you are looking for vulnerabilities in open source software or commercially distributed software and you are a US citizen you are protected by the 1st amendment. It is legal for you to write exploit code and do whatever you want (as long as it isn’t selling it to terrorists/the mob). If you do find a flaw, report it to BugTraq and put it on your resume. I have racked up a lot of CVE numbers over the years and I actively write exploit code.

    In Germany and France the laws are a bit different, the possession of “hacking tools” like exploit code or even NMAP can land you in jail. You might also be interested in the laws of full disclosure.

    On the flip side, if you go around scanning people’s web sties looking for vulnerabilities you are breaking the law and the FBI will investigate you. Do not look for vulnerabilities in random websites without the owners permission.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Possible Duplicates: How to get kids into programming Suggestions on starting a child programming.
Possible Duplicate: Get image data in Javascript? Convert an image into binary data in
Is it possible to get in Visual Studio code intellisense into XSLT extension functions.
Is it possible to disable the option to get into Rename mode when clicking
For reasons that are too obscure to get into, I have a millisecond representation
I am looking for some code as I don't really wanna get into the
Is MySQL UPDATE incrementing operation transaction-safe? I mean could it possible to get into
I am developing an application using the wrong tools. I don't wish to get
does anyone know how to (if possible) get the owner of the tag on
I am trying to work out if it is possible get JPA to persist

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.