Re: Will the real hacker please stand up and raise their hand
- From: "Thor (Hammer of God)" <thor@xxxxxxxxxxxxxxx>
- Date: Fri, 14 Jul 2006 13:59:18 -0700
What, the trainers aren't good enough? ;)
T
---
New Blackhat Vegas 2006 Training Offered!
ISA Ninjitsu:
Designing, Building, and Maintaining Enterprise Firewall
and DMZ Topologies with Microsoft ISA Server 2004
http://www.blackhat.com/html/bh-usa-06/train-bh-us-06-tm-isa.html
On 7/14/06 12:46 PM, "Mark Teicher" <mht3@xxxxxxxxxxxxx> spoketh to all:
Anyone on the speaker circuit.. :)----------------------------------------------------------------------------->>
-----Original Message-----
From: "Arian J. Evans" <arian.evans@xxxxxxxxxxxxxx>
Sent: Jul 14, 2006 1:29 PM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: RE: Will the real hacker please stand up and raise their hand
I'm sorry, there's good & bad people out there, and I've worked
for the bad kinds of folks Terry described, and while I could
fill pages with sadly amusing anecdotes: that's life.
There's also good folks out there to work for/with, and you
simply have to look a little harder to find them.
Yes, shameless self-promotion and over-committal BS wins most
of the time; you should hear my friends in the pharmaceutical
industry rant about this *same* subject. Except, they have
a heck of a lot more Riding on their management's mistakes
than an unfixed XSS or CSRF.
Nothing unique about our industry vs. say accounting, except
maybe about 600 years of formalized practice.
I've gotten to sit beside PHD's who talk all day about network
security concepts, but cannot run a sniffer to save their life,
and I've worked with folks who would pick the PHD over the
experienced professional to run the sniffer every time. </shrug>
So if it bugs you, go get a PHD and be both.
Mark: I am curious though, I'm headed to BlackHat next month,
and who is it that you recommend I should be trying to meet?
Arian J. Evans
+1.913.378.3571 [mobile]
"See? That was nothing.
But that's how it always begins.
Very small." -Egg Shen
-----Original Message-----
From: Mark Teicher [mailto:mht3@xxxxxxxxxxxxx]
Sent: Thursday, July 13, 2006 3:36 PM
To: Terry; pen-test@xxxxxxxxxxxxxxxxx
Subject: RE: Will the real hacker please stand up and raise their hand
But why one doubt a Ph.D. (CISSP, IAM, CCNP, CCDA, CCNA, ACE,
CCSA, CCSE, and MCSE) who gained access to a database at
Roswell in the early 90's Almost like a person who spent
over 10 years with the Federal Government perfecting the
skills which enable him to be called "one of the first
CYBERSPACE private investigators".
Makes you want to attend BlackHat and actually meet and greet
a real bonafide grey/black hat hacker. :)
-----Original Message-----
From: Terry <tvernon24@xxxxxxxxxxx>their hand
Sent: Jul 13, 2006 3:56 PM
To: 'Mark Teicher' <mht3@xxxxxxxxxxxxx>, pen-test@xxxxxxxxxxxxxxxxx
Subject: RE: Will the real hacker please stand up and raise
the DoD. When I
Just recently, I worked at a company whose main client was
was being scouted I heard many promises and things thatpeaked the interest
of an ex-mischief maker. When I got the job I soon realizedthat the man
running the show was a huge fraud who claimed many accoladesabove my own.
Everything he said about his technical past was a lie and tomake things
worse, whenever he talked about me openly he hyped me up tobe something I'm
not from my past reputation. In the end he stoppedpretending to be my ally
and I got railroaded but it didn't come without a price tothem. When I
think about the whole mess now all I see is how shamelessself promotion and
lies can get you anywhere, even a contract with the upperrungs of our
government. Today I surely think the agents in which wereinvolved have
smartened up to this pretend company.typical black hat.
My example here is I've made myself a bad name being your
When I turn it all around into a useful thing for societynobody wants to
hire me except liars and frauds. The things many of us onthis list know can
save a company millions, the sad part is we get picked up by bull***saddened when I
artists that cheapen the art in which we're skilled. I am
think about all the huge liars and morons that put "Network Securityresume aren't
Engineer" on their business card. Most people who look at my
qualified enough to read it, so I get overlooked because oftheir ignorance
in my field and they pick based on who went to the bestschool. I'm probably
not alone in this plight.just doesn't add
/end rant
/dance
-Terry
-----Original Message-----
From: Mark Teicher [mailto:mht3@xxxxxxxxxxxxx]
Sent: Thursday, July 13, 2006 7:23 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Will the real hacker please stand up and raise their hand
Every once in a while, I read a story on the Internet, that
up, as listed below, it appears most organization,enterprise type companies
have policies preventing the hiring of known or identifiedcomputer security
type people, other companies hire them openly or make upsome impressive
press statements stating they have hired one with rootfu orsome sort of
skillz, whatever they might be..least as projected
You be the judge after the reading the attached article..
-------- Original Message --------
Subject: [ISN] Hackers and Employment
Date: Thu, 13 Jul 2006 03:15:11 -0500 (CDT)
From: InfoSec News <alerts@xxxxxxxxxxxxxxx>
Organization: InfoSec News - http://www.infosecnews.org/
To: isn@xxxxxxxxxxxxxxx
http://www.line56.com/articles/default.asp?ArticleID=7766
By Demir Barlas
Line56
July 12, 2006
The reason many of us who grew up outside America found this country
charming and worthy of emulation was its principles, at
on the movie screen. You can argue about their politics, but theaccording to a
characters portrayed by John Wayne, for instance, operated
fixed code of ethics. They stood for what they considered right; theynative-born Americans
never cheapened or sold themselves; and they lived (and died) with
integrity.
I encountered this America before I actually came here.
Perhaps this is why it is so easy for me to see what
cannot understand about that their own country: that it israpidly falling
into decadence. When I say this, I'm not referring to some decliningthemselves, and the
standard of collective religious morality, but rather to personal
morality. All too many Americans stand ready to pimp
system is now designed to reward rather than discouragethem. This is an
arrangement that the rest of the world rightly considershypocritical and,
despite all talk of globalism, will never emulate.one of whose
Let me give an example. I recently got an e-mail from Avaya,
employees, Tom Porter, was leading a security team at theWorld Cup. The
e-mail proudly advertises Porter as a "a former hacker [who]got into the
U.S. government database on Roswell in the early 90s." Nowhe has been
able to have a highly visible and well-paying job as chiefof Internet
security for FIFA and Avaya.Abagnale, Jr.,
As soon as I got this e-mail, I recalled the case of Frank
the fraudster whose life was made into the movie Catch Me If You Can.hackers. I
And, I admit, I got angry. I want to tell you why.
Some of my friends in the ninth grade were aspiring computer
suppose it was a natural impulse for a bunch of intelligentboys cooped up
in an otherwise boring programming class. We tried a fewexploits but, in
the end, got caught. We were never that good in the first place, notof the ethos
because we lacked intelligence but because, I am convinced,
that had survived into Denver even into the 1980s. The ethostold us that
hacking was bad. We couldn't shrug this off our conscience, and soThere is, in the
conducted our exploits rather half-heartedly.
I've kept up with many of my classmates over the years.
group with which I am familiar, no one who has committed afelony, gone to
jail, or refused to pay taxes. Everyone has walked the line. And ouroccupations, trying to
reward? Most of us struggle along at meaningless
make ends meet -- punished, I maintain, by our consciences.someone, you will be
For America no longer rewards conscience. If you kill
offered a book deal. If you impersonate a doctor and nearly cause themovie about
death of a baby [like Abagnale], someone will make a comedic
you. If you become a hacker and endanger our government, youwill become a
consultant. If you sink a company, you will find a highposition in that
very government. Only competence at criminality andself-promotion are
rewarded. The more vicious, heartless, and inept you are, the furtheronce animated
you'll go.
If you want to talk about anti-Americanism, you can't find a better
example. The culture of merit, sincerity, and principle that
this country is gone, and that impacts everyone from left to right.character
Have you seen The Man Who Shot Liberty Valance? John Wayne's
refuses to take the credit for an act that would, in thatday and age,
have made him famous. His principles dictate that he cannot engage inlove; Wayne
self-promotion, which he leaves to Jimmy Stewart's character. Stewart
becomes a senator and marries a woman with whom Wayne was in
retires from public life and dies alone.gotten a publicity
Oh, but today! After shooting Valance, Wayne would have
agent, launched a blog, and gone on talk shows. He wouldhave done the
lecture circuit, opened a consultancy on how to shootoutlaws, and sold
his "life rights" to a Hollywood studio.post-Wayne America
I'm sorry to say it, but I hate what you might call the
(and I say this despite having radically different politicsfrom Wayne
himself). It's an upside-down country in which criminals becomeon dollars a
celebrities while good, hard-working people struggle along
day. There is no longer any act divorced from its promotion. The onlyprostituting
principle is to gather as much money and fame as possible,
yourself all the way, until you die.or such acts
I do not feel that a country can long endure such principles
of decadence. They constitute a kind of rot that will, some day, turncountries of Western
America into the equivalent of the moribund, cynical
Europe. Moreover, they are a gleeful betrayal of everyprinciple on which
this country stood for the first two centuries of its existence.people who have
I suppose this article will be met by incomprehension from
absorbed their values from the post-Wayne moment in Americanhistory. As a
historian, I am a professional pessimist, but I can't helpbut feel that
these very people are only the tip of the iceberg; that, asin the movie
15 Minutes (or, more apocalyptically, Death Race 2000),crime will pay
even more than it does today.answer is yes, I
It is worth concluding with a passage from Henry Miller's The
Air-Conditioned Nightmare, which captures the spirit of the changed
America to which I allude:
As to whether I have been deceived, disillusioned...The
suppose. I had the misfortune to be nourished by the dreamsand visions of
great Americans. Some other breed of man has won out. Theworld which is
in the making fills me with dread....It is a world clutteredwith useless
objects which men and women, in order to be exploited anddegraded, are
taught to regard as useful....Whatever does not lend itself to beinganathema, the
bought and sold...is debarred. In this world the poet is
thinker a fool, and the man of vision a criminal.---------------
Copyright 2000-2006 Line56.com
_________________________________
Attend the Black Hat Briefings and
Training, Las Vegas July 29 - August 3
2,500+ international security experts from 40 nations,
10 tracks, no vendor pitches.
www.blackhat.com
-------------------------------------------------------------
--win the Analyst's
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to
Choice Award from eWeek. As attacks through web applicationscontinue to
rise,hackers. Cenzic has
you need to proactively protect your applications from
thesecurity penetration
most comprehensive solutions to meet your application
testing and vulnerability management needs. You have anoption to go with a
managed service (Cenzic ClickToSecure) or an enterprise softwaremanaged service can
(Cenzic Hailstorm). Download FREE whitepaper on how a
help you: http://www.cenzic.com/news_events/wpappsec.phpto confirm your
And, now for a limited time we can do a FREE audit for you
results from other product. Contact us at request@xxxxxxxxxxfor details.
----------------------------------------------------------------------------
--
--------------------------------------------------------------
----------------
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win
the Analyst's
Choice Award from eWeek. As attacks through web applications
continue to rise,
you need to proactively protect your applications from
hackers. Cenzic has the
most comprehensive solutions to meet your application
security penetration
testing and vulnerability management needs. You have an
option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed
service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to
confirm your
results from other product. Contact us at request@xxxxxxxxxx
for details.
--------------------------------------------------------------
----------------
-
----------------------------------------------------------------------------->>This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to
rise,
you need to proactively protect your applications from hackers. Cenzic has
the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
-
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------
- References:
- RE: Will the real hacker please stand up and raise their hand
- From: Mark Teicher
- RE: Will the real hacker please stand up and raise their hand
- Prev by Date: RE: nikto, n-stealth can crash the web-server?
- Next by Date: RE: nikto, n-stealth can crash the web-server?
- Previous by thread: RE: Will the real hacker please stand up and raise their hand
- Next by thread: Re: Will the real hacker please stand up and raise their hand
- Index(es):