Akula Posted June 1, 2011 Report Share Posted June 1, 2011 I have talked to less than 10 organizations that have good - focused, security teams. I have talked to less than 2 banks that focus on security, and do it well. Most of the IT Security people at organizations you actually do business with, have IT Security titles but are project managers. I cannot unlearn how poorly security is treated, even after the Sony breach hit the market. If you bank, use credit cards for anything, use any social networking, you will be losing your PII, I promise. PII has about 15x the value of a single credit card number now, it isn't about credit cards anymore. On the flip side, exploits are easier. BackTrack anyone? Quote Link to comment Share on other sites More sharing options...
thorne Posted June 1, 2011 Report Share Posted June 1, 2011 This is so true. You have shops that have been running the same set of engineers for 6 or more years and they are stuck in there ways. Quote Link to comment Share on other sites More sharing options...
Guest Hal Posted June 1, 2011 Report Share Posted June 1, 2011 Off topic-ish, do know a guy named Bruce Schneier? He's a security guy that parlayed his experiences into other areas away from IT. Quote Link to comment Share on other sites More sharing options...
AWW$HEEET Posted June 1, 2011 Report Share Posted June 1, 2011 Im in security. I agree, no one knows what the fuck they are doing. I do more sustainment of our security tools than analysis of useful data. Id like to get into writing signatures and checking out incidents. Quote Link to comment Share on other sites More sharing options...
jeffro Posted June 1, 2011 Report Share Posted June 1, 2011 what is PII? this topic interests me Quote Link to comment Share on other sites More sharing options...
AWW$HEEET Posted June 1, 2011 Report Share Posted June 1, 2011 what is PII? this topic interests me personally identifiable information. sets of data that can be used in combination to steal identity, etc. Quote Link to comment Share on other sites More sharing options...
jeffro Posted June 1, 2011 Report Share Posted June 1, 2011 so i should withdraw all of my money and move to Australia? Quote Link to comment Share on other sites More sharing options...
Akula Posted June 1, 2011 Author Report Share Posted June 1, 2011 Off topic-ish, do know a guy named Bruce Schneier? He's a security guy that parlayed his experiences into other areas away from IT. I know of him, read some of his stuff. I attend these little meetings like B-Sides and stuff at the HackerDojo with guys like Billy Rios or Ivan Ristic. I am teaching classes again at Black Hat this year but even Black Hat has become a CIO road-show like RSA. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 1, 2011 Author Report Share Posted June 1, 2011 Im in security. I agree, no one knows what the fuck they are doing. I do more sustainment of our security tools than analysis of useful data. Id like to get into writing signatures and checking out incidents. Fuzzing is like Nascar, you only do it for the crashes. We have 11000+ signatures, no point in reinventing the wheel. Most of our R&D guys fuzz, write an exploit, publish to our KB, repeat. Seems kinda boring really. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 1, 2011 Author Report Share Posted June 1, 2011 so i should withdraw all of my money and move to Australia? Your money is safe-ish. I don't know about withdrawing it all, but you should avoid using your credit card at momNpop places. You should never, EVER use the same password for facebook as you do for your bank. Stop using tabbed browsing, in fact use more than one browser and use one for surfing and one for banking. host files for credit cards, etrade and banks log out for crying out loud, LOG OUT, don't just close the tab. Quote Link to comment Share on other sites More sharing options...
Supplicium Posted June 1, 2011 Report Share Posted June 1, 2011 BackTrack is fun Quote Link to comment Share on other sites More sharing options...
zeitgeist57 Posted June 1, 2011 Report Share Posted June 1, 2011 Wow, you're a geek. Quote Link to comment Share on other sites More sharing options...
Ramsey Posted June 1, 2011 Report Share Posted June 1, 2011 Your money is safe-ish. I don't know about withdrawing it all, but you should avoid using your credit card at momNpop places. You should never, EVER use the same password for facebook as you do for your bank. Stop using tabbed browsing, in fact use more than one browser and use one for surfing and one for banking. host files for credit cards, etrade and banks log out for crying out loud, LOG OUT, don't just close the tab. You mean like ie for pron, and firefox for paying for fleshlite? p.s. serious question muddled by played internet humor. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 1, 2011 Author Report Share Posted June 1, 2011 I would never use IE, but you get the idea. You never want to have your bank website up, and any other website up on the same browser or a session hijack can occur. then you need to LOG OUT of your bank's site. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 1, 2011 Author Report Share Posted June 1, 2011 Wow, you're a geek. Thanks. I am also concerned with the bad things that happen out there. 350% increase in security incidents in the last year. Sony's pay service down for a month, seriously a freaking month!!!!? It is so easy to exploit systems now that I don't think you even need to understand the underlying technology. Attack and Defense Labs makes this great toy called Shell of the Future that should scare the crap out of everyone. Quote Link to comment Share on other sites More sharing options...
AWW$HEEET Posted June 2, 2011 Report Share Posted June 2, 2011 where do you work at? pm me. Quote Link to comment Share on other sites More sharing options...
motozachl Posted June 2, 2011 Report Share Posted June 2, 2011 Someone can HAVE my id, I owe lots of people lots of $ Quote Link to comment Share on other sites More sharing options...
TTQ B4U Posted June 2, 2011 Report Share Posted June 2, 2011 Note to self, never piss off Jason. He can fuck up your world. Good info man. Quote Link to comment Share on other sites More sharing options...
RedRocket1647545505 Posted June 2, 2011 Report Share Posted June 2, 2011 I know absolutely NOTHING about IT stuff, so forgive me when I ask a dumb question like: Is it possible to track down the people that do this shit? They aught to hang them by the balls. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 2, 2011 Author Report Share Posted June 2, 2011 I know absolutely NOTHING about IT stuff, so forgive me when I ask a dumb question like: Is it possible to track down the people that do this shit? They aught to hang them by the balls. Yes, the ones that aren't good at it are easy to find. The good ones use open proxies to hide their identity. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 2, 2011 Author Report Share Posted June 2, 2011 where do you work at? pm me. I work for a small Silicon Valley startup called Qualys. Hacking as a service. Quote Link to comment Share on other sites More sharing options...
Akula Posted June 2, 2011 Author Report Share Posted June 2, 2011 Note to self, never piss off Jason. He can fuck up your world. Good info man. Most of the guys I work with are Blackhats in some way, if you piss me off I just have them work on it. They are bored most days. Quote Link to comment Share on other sites More sharing options...
04silvrz Posted June 2, 2011 Report Share Posted June 2, 2011 good info, wasn't so much aware of the vulnerabilities in xss or much about that in general. these are some pretty cool tools... http://www.andlabs.org/tools.html#sotf Quote Link to comment Share on other sites More sharing options...
JaSSon Posted June 2, 2011 Report Share Posted June 2, 2011 Attack and Defense Labs makes this great toy called Shell of the Future that should scare the crap out of everyone. I googled, read, did not understand. Can you give me cliffs in layman's terms? Quote Link to comment Share on other sites More sharing options...
Akula Posted June 3, 2011 Author Report Share Posted June 3, 2011 I googled, read, did not understand. Can you give me cliffs in layman's terms? I put some malicious code on a web page, say on a forum that is allowing script tagging. Your browser executes the code and your computer pops up on my console I have running as a new target. I then copy your hard-drive to mine, or watch you log into your bank and capture the HTTP headers so I get your passwords, or what have you. if you want some good "hacking" tools, go to http://www.getmantra.com/tools/ or just download Backtrack. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.