Re: 0-day exploit..do i hear $1000?

From: rain forest puppy (rfp@wiretrip.net)
Date: 10/18/01


Date: Thu, 18 Oct 2001 14:23:20 -0500 (CDT)
From: rain forest puppy <rfp@wiretrip.net>
To: <roelof@sensepost.com>
Subject: Re: 0-day exploit..do i hear $1000?
Message-ID: <Pine.LNX.4.33.0110181359040.14110-100000@cailleach>


> Then someday, Hacker L33t and L4t3 decides that they are not in it for
> fame, but for money. So, they open a security firm (many examples e.g.
> L0pht, Max Vision, RFP, many more).

Um, excuse me? Open a security firm? Since when have I opened a security
firm?

I work for a company that was in business before I ever published anything
as RFP. I've been there for years now.

And in it for the money? What money? The money from writing a chapter in
Hack Proofing your Internetwork? That was donated to OpenBSD and Nessus.
The money for speaking at conferences? I haven't accepted one to date.
The money I've made from whisker? Well, whisker is free, so there's none
to be had.

I sit around an absorb myself in various security related challenges. In
the end, I have tools, research and information which I choose to share,
to promote further research.

If I was truly a sell-out, why the hell would I release my tools and
research to the world? It would be worth more to me as exclusive
proprietary intellectual property used as a service to paying customers.

Unfortunately, the world doesn't always work how everyone expects it to.

And in the end, why should people sacrifice their lives and free time just
to continuously pump 0day research into an industry where, if they don't
profit from it, everyone else will? Hell, sensepost.com is a security
services company...are you saying that *every* tool you use is 100%
developed by an employee of sensepost?

So I've sold out because I share my research with others, but
sensepost.com can take tools like nmap et al and use them to make a profit
as a security service, and that's ok?

Funny how that works.

- rfp

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: [fw-wiz] Re: Ethics, morality, and mental retardation
    ... decides to join the pool and start peeing in it - either ... But, if you go that route, suddenly society ... ask security professionals about their "hacker pasts" is ... That's money I was supposed to make!" ...
    (Firewall-Wizards)
  • [Full-Disclosure] Security Industry Under Scrutiny: Part Two
    ... Subject: Security Industry Under Scrutiny: Part Two ... > place to combat terrorism. ... > industry makes more money, but more people are at risk. ... > of script kiddies, and employs those exploits that have been known ...
    (Full-Disclosure)
  • Re: If Macs have no spyware....
    ... >>> fee and forfeit the money, lunch, and iPod should you lose. ... Tell me, why are you writing ... of shit with this dime store troll. ... security vs. XP security? ...
    (comp.sys.mac.advocacy)
  • Re: how can I make money off my ultimate security solution for servers
    ... Go to venture capitalists and try to convince them to give you money to set up a real live corporation and do the dev/marketing with that money and company's sales staff. ... You might have something but the likelihood or odds of you having the panacea of Windows security isn't very promising given the billions spent on R&D for it from so many different companies. ... This is not just my opinion, I have shared this design with my friends who are network admins and IT professionals and they have spent weeks trying find some flaw in my system. ... In my free time I have designed a bullet-proof solution that makes a windows server completely unhackable. ...
    (microsoft.public.windows.server.security)
  • Louisana Owes FEMA Misspent $30 Million
    ... Do officials in our Office of Homeland ... Security employees who oversaw the program are currently under federal ... The state says we don't owe the money back. ... Director of the East Baton Rouge Parish ...
    (alt.true-crime)