Is the constitutional issue here that exploiting a security hole (SQL injection, remote execution to dump the $_SERVER variable, what have you) constitutes an illegal search?
If so, is their any guidance from case law about the difference between some sort of legal poking and prodding vs illegal hacking?