RE: How do you become a Cyber Bounty Hunter?

From: Rob Shein (shoten_at_starpower.net)
Date: 11/08/03

  • Next message: Peter Mercer: "RE: CEH and Intense School"
    To: "'C Ryll'" <carolynryll@hotmail.com>, <pen-test@securityfocus.com>
    Date: Fri, 7 Nov 2003 18:35:10 -0500
    
    

    I think you're adding too much power to what they had in mind. They aren't
    putting out a reward for freelancers to go hunt these guys down; they're
    putting out a reward for people who can provide evidence to law enforcement
    that gets them caught. In other words, "If you know these guys, and rat
    them out, we'll pay you big money."

    > -----Original Message-----
    > From: C Ryll [mailto:carolynryll@hotmail.com]
    > Sent: Thursday, November 06, 2003 6:10 PM
    > To: pen-test@securityfocus.com
    > Subject: How do you become a Cyber Bounty Hunter?
    >
    >
    > After a discussion with some people regarding Microsoft's two posted
    > bounties, I understand that cyber bounty hunters are actually
    > available for
    > hire by companies. I am curious what knowledge base, or
    > experience, this
    > type of independent position would require. Where would you
    > obtain this form
    > of security knowledge? Given that MAC and IP can both be
    > spoofed, and that
    > victim systems are often used to launch some attacks, how do
    > you actually
    > get back to the original source?
    >
    > Note that I am not talking about fundamental security
    > knowledge (I.e., how
    > to secure a system, or determining if/what was on the
    > system), but how to
    > trace back to the origin of the attack while knowing that the
    > IP and MAC are
    > most likely spoofed and/or attacks rerouted.
    >
    > Respectfully,
    > Carolyn.
    >
    > _________________________________________________________________
    > Frustrated with dial-up? Get high-speed for as low as $26.95.
    > https://broadband.msn.com (Prices may vary by service area.)
    >
    >
    > --------------------------------------------------------------
    > -------------
    > Network with over 10,000 of the brightest minds in
    > information security at the largest, most highly-anticipated
    > industry event of the year. Don't miss RSA Conference 2004!
    > Choose from over 200 class sessions and see demos from more
    > than 250 industry vendors. If your job touches security, you
    > need to be here. Learn more or register at
    > http://www.securityfocus.com/sponsor/RSA_pen-> test_031023
    > and
    > use priority code SF4.
    >
    > --------------------------------------------------------------
    > --------------
    >
    >
    >

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_pen-test_031023
    and use priority code SF4.
    ----------------------------------------------------------------------------


  • Next message: Peter Mercer: "RE: CEH and Intense School"

    Relevant Pages

    • Re: [fw-wiz] The home user problem returns
      ... Tina, if I didn't know better, I'd conclude that security is driven by ... I have an entirely different take on pain versus reward than this thread ... > as a reward system for proper configuration, ...
      (Firewall-Wizards)
    • RE: pricing model for Pen-test
      ... Institute for Security and Open Methodologies ... OPSA - OSSTMM Professional Security Analyst ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • Imam announces Rs 50,000 reward for =?utf-8?Q?Taslima=E2=80=99s_head?=
      ... Security for controversial Bangladeshi writer Taslima ... Nasreen has been tightened after a imam here announced a reward ...
      (uk.religion.islam)
    • RE: [Full-Disclosure] Scandal: IT Security firm hires the author of Sasser worm
      ... happens when he goes out and finds a job in the security industry? ... of the best minds out there and they could have done just as good of a job ... Saying that no teenager can be reformed is like saying you can't change your ... Good people do bad things sometime, it is a fact of life. ...
      (Full-Disclosure)
    • RE: Pen-testing remote VPN services over IP
      ... and a big new trend is the "SSL VPN" where SSL support is integral ... Is there a particular VPN you're looking ... > Institute for Security and Open Methodologies ... most highly-anticipated industry event of the year. ...
      (Pen-Test)