Re: [Full-disclosure] Setting the record straight on "The Return ofKoobface"




Absolutely you are correct, but if you check the blog there are further
references up to last Friday. It was a tremendous, jaw-dropping flood of
Kooberz proxies the last two weeks. And it's still coming.

The point is us Little Guys are paying attention, too. And sometimes we
catch this shit before the Big Boys like Dancho and Kaspersky wake up and
smell the coffee. Since February I've been wondering Why The Hell I hadn't
heard anything in the ITsec press on this new resurgence. Did they hold
back so Dancho could publish his "Ten Things You Didn't Know About The
Koobface Gang" article? Or so Microsoft could gloat over "taking down" the
Wimpy Waledac botnet? Is the Good News always published before the Bad News
in the security industry press release cycle?

The fact remains, Koobface marches on and the security industry can't stop
it. Period. I will be among the first to jump up and down and yell "RA!"
when someone takes it down, but it ain't going to happen soon. All I can do
is sit back and watch while the Big Boys get their headlines.

BTW, I don't consider myself "bitter". I'm what you might call "tangy".

Thanks for your support,

Hinky

----- Original Message -----
From: J Roger
To: full-disclosure@xxxxxxxxxxxxxxxxx
Sent: Saturday, March 20, 2010 3:28 PM
Subject: Re: [Full-disclosure] Setting the record straight on "The Return
ofKoobface"


This reads as "waaa i noticed this first and didn't think much of it but now
that someone else is making a big deal, i want my credit". Maybe you
reported on it first on your blog, with a single sentence that wasn't even
the primary focus of the post. Regardless if an up rise in koobface is
significantly news worthy or not, you apparently failed to draw enough
attention (or the right attention) to it at the time.

In other words, maybe you did it first, but someone else did it better.

What's more valuable to an enterprise, someone that quickly writes a risk
assessment that's so sloppy the management with authority to act on the
findings don't even bother to read it, or someone that takes the time to
write a report on the same findings that actually speaks to the business and
be able to make positive changes happen.

You talk about being bitter towards the security industry (which IS
understandable) but maybe it's time to reflect back a little on yourself.
Maybe it's not ALL the industries fault. Maybe the sources of your
bitterness have a little something to do with your inability to make enough
of the right things happen. Sure you're a "Big Time Security Professional",
but maybe your blog wasn't enough to get the word out. Maybe you felt it
wasn't even worth getting the word out or sounding any alarms. If that's the
case though, don't go back now and try to take credit.



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Non Sequitur vs. LICD
    ... So this blog does not act as anybody's full-time gig. ... No single blog will both originate and aggregate all the news anyone could want. ... As the traditional news media crumbles due to the loss of newspaper issue sales and subscriptions and advertising revenues decline, as more of the reporters are laid off, more blogs will spring up and start to originate news. ... Try this: Create an account at Google and then create a Google Reader page: ...
    (rec.arts.comics.strips)
  • Re: OT: Hoekstra responds to NYTimes
    ... you're reluctant to post links to blogs, you call me a hypocrite, then a ... website, which is, guess what, a blog. ... Had I linked to some opinion of Michelle Malkin on her site, ... for a news item in The Guardian weeks back. ...
    (rec.arts.theatre.musicals)
  • Re: OT: Hoekstra responds to NYTimes
    ... you're reluctant to post links to blogs, you call me a hypocrite, then a ... website, which is, guess what, a blog. ... for a news item in The Guardian weeks back. ... So in a supposed straight news item, an anonymous source is cited ...
    (rec.arts.theatre.musicals)
  • Readmine .91
    ... In around 15 minutes a day read news ... and blog articles that are interesting to you, ... Readmine learns what you like and what you don't and organises your ... Download and Explore the power of the Readmine RSS Reader. ...
    (comp.software.shareware.announce)
  • Comment on Marrs attack on the blogosphere....
    ... A comment on Richard North's blog says it all. ... Andrew Marr is bitter because he can see the end of the traditional ... free market news, ... opinions as Mr Marr for the same reasons about gossipy bloggers like ...
    (uk.politics.misc)