Thuta Learning
ရှာဖွေရန်
BasicSecurityintermediate

Legal & Ethical Boundaries

စိတ်လျှော့ပါ။ ဒီခန်းကို စာအုပ်လိုမဟုတ်ဘဲ စကားပြောသလိုပဲ၊ နားလည်လွယ်အောင် ရှင်းပါမယ်။

ဒီခန်းပြီးရင် ဘာတတ်သွားမလဲ

  • Legal & Ethical Boundaries ကို ကြောက်စရာမလိုအောင် နားလည်မယ်
  • ကိုယ်တိုင် authorized lab environment ထဲမှာ tool ကို run ကြည့်တတ်မယ်
  • Real assessment/report ထဲမှာ ဒီ concept ကို ချက်ချင်း အသုံးချတတ်မယ်

ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်

Authorization (written permission) မရှိဘဲ system တစ်ခုကို scan/test/access လုပ်ခြင်းသည် နိုင်ငံအများစုရဲ့ ဥပဒေအရ ရာဇဝတ်မှု ဖြစ်ပါတယ် — 'ငါ ကူညီပေးချင်လို့ scan လုပ်တာပါ' ဆိုတဲ့ ရည်ရွယ်ချက်ကောင်းတောင် ဥပဒေအရ ခွင့်လွှတ်ခြင်း မရှိပါ။ Scope (ဘယ် system/IP range ကို test လုပ်ခွင့်ရှိလဲ, ဘယ်အချိန်ကာလ) ကို client/employer နဲ့ written agreement ချုပ်ရပါတယ် (Rules of Engagement, RoE)။ Responsible Disclosure ကတော့ vulnerability တွေ့ရင် public မထုတ်ဖော်ခင် vendor/organization ဆီ အရင် အသိပေးပြီး ပြင်ဆင်ချိန် ပေးတဲ့ practice ပါ.

လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်

Company တစ်ခုက pentest ငှားရမ်းချင်ရင် — 'Statement of Work' (SOW) ထဲမှာ scope (IP range, domain, ဘယ် system ကို test မလုပ်ရ), timeline, emergency contact ကို ရေးထားရပါတယ် — scope ပြင်ပက system တစ်ခုကို 'အမှတ်တမဲ့' scan မိရင်တောင် legal liability ဖြစ်နိုင်ပါတယ်။ Bug Bounty program (HackerOne, Bugcrowd) တွေကတော့ company ကနေ public authorization ကို ကြိုတင် ပေးထားပြီးသားလို့ scope ထဲမှာပဲ test လုပ်ရင် legal ပါ.

အတူတူ ကြည့်မယ်

text
Before ANY security testing, confirm you have:

[ ] Written authorization from the system owner
[ ] Defined scope (which IPs/domains, what's off-limits)
[ ] Agreed testing window (dates/times)
[ ] Emergency contact in case something breaks
[ ] Legal sign-off if working for a client/employer

No checklist item ticked = do not proceed.
You should see
Authorization/Scope/Responsible Disclosure ရဲ့ အရေးကြီးပုံကို ရှင်းပြနိုင်မည်။

၅ မိနစ် စမ်းကြည့်

Bug Bounty platform (HackerOne ဒါမှမဟုတ် Bugcrowd) ကို ဖွင့်ကြည့်ပြီး, public program တစ်ခုရဲ့ scope document ကို ဖတ်ကြည့်ပါ — scope ထဲပါ/မပါ ဆုံးဖြတ်ရခက်တဲ့ scenario တစ်ခု ရေးကြည့်ပါ။

သတိလေးတစ်ချက်

ဒီ tutorial ရဲ့ hands-on lesson အားလုံးကို ကိုယ်ပိုင် lab (Basic lesson 4) ထဲမှာသာ practice လုပ်ပါ — ဘယ်လိုမှ authorization မရှိတဲ့ real-world system ကို scan/test မလုပ်ပါနှင့်, CTF platform (HackTheBox, TryHackMe) တွေကတော့ practice ဖို့ တရားဝင် ခွင့်ပြုချက်ရထားတဲ့ platform ဖြစ်ပါတယ်.

ဒီနေရာမှာ လူအများမှားတတ်တယ်

  • 'ကိုယ့် ကုမ္ပဏီပိုင် network ပဲ' ဆိုပြီး internal policy approval မရှိဘဲ scan လုပ်ခြင်း — company internal ဆိုတောင် IT/security team ရဲ့ approval လိုအပ်ပါတယ်
  • Bug bounty program ရဲ့ scope ပြင်ပက (ဥပမာ - third-party vendor domain) test လုပ်မိခြင်း — scope document ကို သေချာဖတ်ရန် အရေးကြီးပါတယ်

အခု ကိုယ်တိုင် စမ်းကြည့်

Bug Bounty platform (HackerOne ဒါမှမဟုတ် Bugcrowd) ကို ဖွင့်ကြည့်ပြီး, public program တစ်ခုရဲ့ scope document ကို ဖတ်ကြည့်ပါ — scope ထဲပါ/မပါ ဆုံးဖြတ်ရခက်တဲ့ scenario တစ်ခု ရေးကြည့်ပါ။

You'll know it worked when: Authorization/Scope/Responsible Disclosure ရဲ့ အရေးကြီးပုံကို ရှင်းပြနိုင်မည်။

Legal & Ethical Boundaries | Thuta Learning