Re: How do you become a Cyber Bounty Hunter?

From: Jimi Thompson (jimit_at_myrealbox.com)
Date: 11/15/03

  • Next message: dave_at_immunitysec.com: "Re: pricing model for Pen-test"
    Date: Sat, 15 Nov 2003 13:04:55 -0600
    To: pen-test@securityfocus.com
    
    

    All,

    Without access to the zombie carrying out the actual attack, you have
    exactly 0% chance of backtracking. Even with access to the zombie,
    you still need a LOT cooperation from the ISP that the zombie is
    living on and you had better hope that their logging, etc. is in
    order. In all probability, the zombie you are back-tracking from
    will just point back to another zombie, ad nauseam.

    Microsoft is exactly right in the approach. Most of the people brag
    about what they "accomplished", and this is precisely how they get
    caught. Offering a bounty will give financial incentive to those who
    have been bragged to, to make a phone call. I wonder how much gear
    you can buy with the bounty for Blaster?

    Jimi

    At 11:09 PM +0000 11/6/03, C Ryll wrote:
    >After a discussion with some people regarding Microsoft's two posted
    >bounties, I understand that cyber bounty hunters are actually
    >available for hire by companies. I am curious what knowledge base,
    >or experience, this type of independent position would require.
    >Where would you obtain this form of security knowledge? Given that
    >MAC and IP can both be spoofed, and that victim systems are often
    >used to launch some attacks, how do you actually get back to the
    >original source?
    >
    >Note that I am not talking about fundamental security knowledge
    >(I.e., how to secure a system, or determining if/what was on the
    >system), but how to trace back to the origin of the attack while
    >knowing that the IP and MAC are most likely spoofed and/or attacks
    >rerouted.
    >
    >Respectfully,
    >Carolyn.
    >
    >_________________________________________________________________
    >Frustrated with dial-up? Get high-speed for as low as $26.95.
    >https://broadband.msn.com (Prices may vary by service area.)
    >
    >
    >---------------------------------------------------------------------------
    >Network with over 10,000 of the brightest minds in information security
    >at the largest, most highly-anticipated industry event of the year.
    >Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    >see demos from more than 250 industry vendors. If your job touches
    >security, you need to be here. Learn more or register at
    >http://www.securityfocus.com/sponsor/RSA_pen-test_031023
    >and use priority code SF4.
    >----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_pen-test_031023
    and use priority code SF4.
    ----------------------------------------------------------------------------


  • Next message: dave_at_immunitysec.com: "Re: pricing model for Pen-test"

    Relevant Pages

    • RE: Cisco CTR
      ... hacker's program is, the state of the network, etc. I'd like to see the ... If this type of attack can succeed as I think it could, ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)
    • RE: Cisco CTR
      ... > vulnerability scan shows no vulnerability it does not mean an ... > attack was unsuccessful. ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)
    • =?windows-1252?Q?Re=3A_Lahore=2DTerror_Attacks=3A_RAW=92s_Guerilla_Warfare?=
      ... security forces have been martyred in foiling three separate terrorist ... attacks by killing 9 terrorists at FIA Building, ... suicide attack in Kohat. ... been waging a guerilla warfare in Pakistan through its well-trained ...
      (sci.military.naval)
    • [NT] DCE RPC Vulnerabilities New Attack Vectors Analysis
      ... Get your security news from a reliable source. ... These new attack methods were found while researching exploitation ... They might also apply to other vulnerabilities such as the DCE RPC DCOM ...
      (Securiteam)
    • << Small Biz Server news this week - June 18, 2004 >>>
      ... The monthly Executive Circle Security Webcast with Mike Nash, ... IP phones can create network security risk ... The biggest of the headaches was Tuesday's attack ... Akamai now says it was targeted by DDoS attack ...
      (microsoft.public.backoffice.smallbiz2000)

  • Quantcast