ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်
Authorization (written permission) မရှိဘဲ system တစ်ခုကို scan/test/access လုပ်ခြင်းသည် နိုင်ငံအများစုရဲ့ ဥပဒေအရ ရာဇဝတ်မှု ဖြစ်ပါတယ် — 'ငါ ကူညီပေးချင်လို့ scan လုပ်တာပါ' ဆိုတဲ့ ရည်ရွယ်ချက်ကောင်းတောင် ဥပဒေအရ ခွင့်လွှတ်ခြင်း မရှိပါ။ Scope (ဘယ် system/IP range ကို test လုပ်ခွင့်ရှိလဲ, ဘယ်အချိန်ကာလ) ကို client/employer နဲ့ written agreement ချုပ်ရပါတယ် (Rules of Engagement, RoE)။ Responsible Disclosure ကတော့ vulnerability တွေ့ရင် public မထုတ်ဖော်ခင် vendor/organization ဆီ အရင် အသိပေးပြီး ပြင်ဆင်ချိန် ပေးတဲ့ practice ပါ.
လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်
Company တစ်ခုက pentest ငှားရမ်းချင်ရင် — 'Statement of Work' (SOW) ထဲမှာ scope (IP range, domain, ဘယ် system ကို test မလုပ်ရ), timeline, emergency contact ကို ရေးထားရပါတယ် — scope ပြင်ပက system တစ်ခုကို 'အမှတ်တမဲ့' scan မိရင်တောင် legal liability ဖြစ်နိုင်ပါတယ်။ Bug Bounty program (HackerOne, Bugcrowd) တွေကတော့ company ကနေ public authorization ကို ကြိုတင် ပေးထားပြီးသားလို့ scope ထဲမှာပဲ test လုပ်ရင် legal ပါ.
အတူတူ ကြည့်မယ်
Before ANY security testing, confirm you have:
[ ] Written authorization from the system owner
[ ] Defined scope (which IPs/domains, what's off-limits)
[ ] Agreed testing window (dates/times)
[ ] Emergency contact in case something breaks
[ ] Legal sign-off if working for a client/employer
No checklist item ticked = do not proceed.Authorization/Scope/Responsible Disclosure ရဲ့ အရေးကြီးပုံကို ရှင်းပြနိုင်မည်။၅ မိနစ် စမ်းကြည့်
Bug Bounty platform (HackerOne ဒါမှမဟုတ် Bugcrowd) ကို ဖွင့်ကြည့်ပြီး, public program တစ်ခုရဲ့ scope document ကို ဖတ်ကြည့်ပါ — scope ထဲပါ/မပါ ဆုံးဖြတ်ရခက်တဲ့ scenario တစ်ခု ရေးကြည့်ပါ။
သတိလေးတစ်ချက်
ဒီ tutorial ရဲ့ hands-on lesson အားလုံးကို ကိုယ်ပိုင် lab (Basic lesson 4) ထဲမှာသာ practice လုပ်ပါ — ဘယ်လိုမှ authorization မရှိတဲ့ real-world system ကို scan/test မလုပ်ပါနှင့်, CTF platform (HackTheBox, TryHackMe) တွေကတော့ practice ဖို့ တရားဝင် ခွင့်ပြုချက်ရထားတဲ့ platform ဖြစ်ပါတယ်.