Laws surrounding Database search engines ?
by earflaps - Monday July 1, 2024 at 02:35 AM
#1
If you were to make a database search engine, does anyone know the precautions needed to stay within the law (Considering the servers would be physical), would you need to hide passwords, would you be able to upload the databases themselves, would owning the databases be illegal?

I'd assume it's a sort of grey zone but if anyone is familiar with the law then please inform me, thanks <3
Tongue
Reply
#2
I found an interesting thread on the law stack exchange that seems to answer your questions: https://law.stackexchange.com/questions/...s-and-guid

TLDR: Unless it contains anything fraud related (ccs and maybe unhashed passwords(?)) you'll be good. There's many database search engines that are ran by legitimate companies for a profit so I'd assume it's currently a legal grey area at least in the United States

EDIT: Also forgot to mention that you may need to worry about how your ISP handles it compared to the law, you should probably read over their ToS and decide how you should host the search engine afterwards. I'd suggest running it through some type of reverse proxy to avoid any suspicions from your ISP.
Reply
#3
(Jul 01, 2024, 02:40 AM)Nuko Wrote: I found an interesting thread on the law stack exchange that seems to answer your questions: https://law.stackexchange.com/questions/...s-and-guid

TLDR: Unless it contains anything fraud related (ccs and maybe unhashed passwords(?)) you'll be good. There's many database search engines that are ran by legitimate companies for a profit so I'd assume it's currently a legal grey area at least in the United States

Wouldn't possession of the databases alone be illegal due to it being stolen goods though. Thanks for the response anyways, I'll do some more research and try find out
Tongue
Reply
#4
(Jul 01, 2024, 02:43 AM)earflaps Wrote:
(Jul 01, 2024, 02:40 AM)Nuko Wrote: I found an interesting thread on the law stack exchange that seems to answer your questions: https://law.stackexchange.com/questions/...s-and-guid

TLDR: Unless it contains anything fraud related (ccs and maybe unhashed passwords(?)) you'll be good. There's many database search engines that are ran by legitimate companies for a profit so I'd assume it's currently a legal grey area at least in the United States

Wouldn't possession of the databases alone be illegal due to it being stolen goods though. Thanks for the response anyways, I'll do some more research and try find out

Apparently the only thing that matters is what exactly the database contains and how you obtained it. If it's a publicly leaked database for example it wouldn't necessarily be considered a violation of the Computer Misuse Act since you didn't exactly obtain it through hacking, if it were a database that's not yet public that would probably come into question since it MIGHT mean that you breached it yourself at least to the feds. So as long as it doesn't contain anything illegal (fraud, cp) and is a publicly accessible data breach you probably won't come onto much suspicion. This doesn't mean that it couldn't be used as evidence on the off chance you end up being arrested for anything cybercrime related however.

Source: https://law.stackexchange.com/questions/...-in-the-us
Reply
#5
(Jul 01, 2024, 02:50 AM)Nuko Wrote:
(Jul 01, 2024, 02:43 AM)earflaps Wrote:
(Jul 01, 2024, 02:40 AM)Nuko Wrote: I found an interesting thread on the law stack exchange that seems to answer your questions: https://law.stackexchange.com/questions/...s-and-guid

TLDR: Unless it contains anything fraud related (ccs and maybe unhashed passwords(?)) you'll be good. There's many database search engines that are ran by legitimate companies for a profit so I'd assume it's currently a legal grey area at least in the United States

Wouldn't possession of the databases alone be illegal due to it being stolen goods though. Thanks for the response anyways, I'll do some more research and try find out

Apparently the only thing that matters is what exactly the database contains and how you obtained it. If it's a publicly leaked database for example it wouldn't necessarily be considered a violation of the Computer Misuse Act since you didn't exactly obtain it through hacking, if it were a database that's not yet public that would probably come into question since it MIGHT mean that you breached it yourself at least to the feds. So as long as it doesn't contain anything illegal (fraud, cp) and is a publicly accessible data breach you probably won't come onto much suspicion. This doesn't mean that it couldn't be used as evidence on the off chance you end up being arrested for anything cybercrime related however.

Source: https://law.stackexchange.com/questions/...-in-the-us
Thanks, tbh I think it's just one big grey area. If HIBP and 0t rocks + Many other companies can get away with it then I think it's safe to do but it's always good to double check
Tongue
Reply
#6
(Jul 01, 2024, 03:00 AM)earflaps Wrote:
(Jul 01, 2024, 02:50 AM)Nuko Wrote:
(Jul 01, 2024, 02:43 AM)earflaps Wrote:
(Jul 01, 2024, 02:40 AM)Nuko Wrote: I found an interesting thread on the law stack exchange that seems to answer your questions: https://law.stackexchange.com/questions/...s-and-guid

TLDR: Unless it contains anything fraud related (ccs and maybe unhashed passwords(?)) you'll be good. There's many database search engines that are ran by legitimate companies for a profit so I'd assume it's currently a legal grey area at least in the United States

Wouldn't possession of the databases alone be illegal due to it being stolen goods though. Thanks for the response anyways, I'll do some more research and try find out

Apparently the only thing that matters is what exactly the database contains and how you obtained it. If it's a publicly leaked database for example it wouldn't necessarily be considered a violation of the Computer Misuse Act since you didn't exactly obtain it through hacking, if it were a database that's not yet public that would probably come into question since it MIGHT mean that you breached it yourself at least to the feds. So as long as it doesn't contain anything illegal (fraud, cp) and is a publicly accessible data breach you probably won't come onto much suspicion. This doesn't mean that it couldn't be used as evidence on the off chance you end up being arrested for anything cybercrime related however.

Source: https://law.stackexchange.com/questions/...-in-the-us
Thanks, tbh I think it's just one big grey area. If HIBP and 0t rocks + Many other companies can get away with it then I think it's safe to do but it's always good to double check

Yeah, if shitty companies that make you pay to search other companies data for PII (*cough cough* Intelligence X) are still in business in the United States then it's likely you won't have much trouble with the law because you hosted your own. Stay safe out there though.
Reply
#7
If you are going to host it at home just use NGINX. It shouldn't be illegal, but ISP is the main problem here. Just use VPN, NGINX and you are good to go.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] Database Searcher Telegram odanbtw 1,021 86,611 1 hour ago
Last Post: hexaagent00
  ✅ Top 10 Google Dorks For SQL Injections NextSoftGroup 12 430 Yesterday, 01:54 PM
Last Post: V1nh
  Amex 5.07.2024 SCAMPAGE WITH ADMIN PANEL xls 15 1,901 Yesterday, 10:04 AM
Last Post: Isolatedforsex
  Bypassing Modern AV (Metasploit Method) godco99 8 478 May 05, 2026, 07:54 PM
Last Post: manguberdi
  ✨ [TUTORIAL] MAKE A PHISHING PAGE⚡STEAL LOGIN CREDENTIALS FROM ANY WEBSITE ✨ MINDHUNTER 274 19,610 May 05, 2026, 06:20 PM
Last Post: pddemerde

Forum Jump:


 Users browsing this forum: 1 Guest(s)