Full Disclosure mailing list archives
Re: Security breach database
From: Valdis.Kletnieks () vt edu
Date: Fri, 17 Dec 2004 11:28:29 -0500
On Tue, 14 Dec 2004 15:44:41 PST, n30 said:
Guys, Looking for few interesting security breach stories... Any database / sites that capture these??
Well, there's a problem - where do you get the stories? The black hats probably won't be sharing their version of the stories (at least until the statute of limitations expires ;). The white hats may be unable to share their version - or at least not in a worldwide public forum. As a result, they become things that get told over a pitcher of Guinness and a "You never heard this from me" disclaimer. A story that was interesting when I heard it in "When I was doing a pen test for <named the guilty large finacial institution>, we found a <description of totally stupid self-inflicted vulnerability>" becomes a lot less interesting when I tell it as "Somebody I know was doing a pen test and..." And since people are going to ask :) The guy was doing a pen test for one of the larger banks in NYC, and right at the start he was being watched by the VP-level guy who had hired him. So my friend is doing commentary as he's trying stuff, for the VP's benefit, and the *very first* thing comes out as "Well, we like to check this one first because it was popular years and years ago, but it *never* works anymore. It's a good test of the logging and alert system though, because somebody should notice that it got tried and.. umm.. HOLY <BLEEP> IT WORKED"... See? Somehow it loses something that way.. ;)
Attachment:
_bin
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: TCP Port 42 port scans? What the heck over..., (continued)
- Re: TCP Port 42 port scans? What the heck over... Dave Aitel (Dec 22)
- Re: TCP Port 42 port scans? What the heck over... Owned You (Dec 14)
- Re: TCP Port 42 port scans? What the heck over... Florian Weimer (Dec 14)
- Re: TCP Port 42 port scans? What the heck over... Niek (Dec 15)
- Re: TCP Port 42 port scans? What the heck over... Kevin Finisterre (Dec 15)
- Re: TCP Port 42 port scans? What the heck over... wastedimage (Dec 16)
- Re: TCP Port 42 port scans? What the heck over... Valdis . Kletnieks (Dec 22)
- Message not available
- Fwd: TCP Port 42 port scans? What the heck over... wastedimage (Dec 23)
- Security breach database n30 (Dec 16)
- Re: Security breach database Martin Mkrtchian (Dec 20)
- Re: Security breach database Valdis . Kletnieks (Dec 21)
- Re: Security breach database Willem Koenings (Dec 23)
- Re: Security breach database Barrie Dempster (Dec 23)
- Re: Security breach database Paul Laudanski (Dec 24)
- Re: TCP Port 42 port scans? What the heck over... Maxime Ducharme (Dec 22)
- Re: TCP Port 42 port scans? Scot Bryhan (Dec 23)