GPEN · Question #422
You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary hold- harmless and…
The correct answer is D. Cracking password hashes on the corporate domain server. Under Singapore's Computer Misuse Act (CMA) Chapter 50A, the hold-harmless agreement is with the contracting company - it can authorize testing of company-owned systems, but it cannot extend authorization to individual employees' personal credentials. Cracking password hashes…
Question
You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary hold- harmless and nondisclosure agreements. Which action by your group can incur criminal liability under Chapter 50a, Computer Misuse Act?
Options
- AExploiting vulnerable web services on internal hosts
- BAttempts at social engineering employees via telephone calls
- CTesting denial-of-service tolerance of the communications provider
- DCracking password hashes on the corporate domain server
How the community answered
(27 responses)- A19% (5)
- B4% (1)
- C7% (2)
- D70% (19)
Explanation
Under Singapore's Computer Misuse Act (CMA) Chapter 50A, the hold-harmless agreement is with the contracting company - it can authorize testing of company-owned systems, but it cannot extend authorization to individual employees' personal credentials. Cracking password hashes on the corporate domain server reveals individual users' plaintext passwords, which are personal data belonging to those individuals, not just the company. Exposing those credentials may constitute unauthorized access to protected computer material beyond what the company alone can legally authorize, potentially incurring criminal liability under the CMA even within a signed engagement. Actions A, B, and D against internal company hosts are covered by the engagement scope, whereas D specifically crosses into accessing individual users' protected credential data that the company has no right to waive on their behalf.
Topics
Community Discussion
No community discussion yet for this question.