We spoke to the overall owner of the sites and they did not object to myself or the magazine publishing this information.
We spoke to the overall owner of the sites and they did not object to myself or the magazine publishing this information.
From what I know vulnerability scanning (which is essentially what wpscan does) is a bit of a grey area under UK law.
It's been likened to someone "rattling the windows" of a house. They may be doing it with the intention of notifying the owner that he's left his house unlocked, or they may be doing it to attempt to gain unauthorised access..
The analogy isn't perfect but it's one I'd step carefully on.
I congratulate you for talking to the owners before publication, however.
That's...astonishing.
Sadly, it didn't transform into action.
What do you mean by this?
In the article you state:
> in many cases there is simply no way to contact the website owners
Do you simply refer to the owner of the parent domain name?
With some, we were able to contact the developers behind the sites. Others just didn't respond.
Basically - no one in the NHS or DoH knows who manages the thousands of .nhs.uk websites. We did our best to contact individual site owners and, where that was impossible, alerted the government directly.
Hope that clears it up.