-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Date sent: Tue, 19 Oct 1999 20:24:00 +0200
Send reply to: Krzysztof Dabrowski <brush_at_POL.PL>
From: Krzysztof Dabrowski <brush_at_POL.PL>
Subject: Re: Need help cracking wwwboard passwd.txt
Originally to: VULN-DEV_at_SECURITYFOCUS.COM
To: VULN-DEV_at_SECURITYFOCUS.COM
> >Just to let you know, it uses the same encryption scheme that can be
> >crack by progs the like of jack the ripper and cracker jack . It just
> >requires that you format the text correctly in the standard unix
> >format.
> >
> >But you definitely don't have the right to ask for payment, That's just
> >whack!
>
> Let's just forget about this particular case and concentrate on the
> meritum.
>
> What is wrong in calling a company , saying: "Your network is preety
> vulnerable to every exploit around. Script kiddies are probably hacking
> you 3 times a day. If you pay me well, i can tell you what's wrong and
> even fix it, if you don't , then bye bye and i'm not gonna waste my
> time".
>
> 1. It's not a black mail of any kind cause when they don't cooperate,
> you just forget about them. 2. Everything looks legal 3. Maybe it looks
> a bit like tele marketing, but it MAY work (aspecialy when you speak
> with management , not the technical staff).
>
> Just my 2 cents.
>
> Brush
Hi all.
Unfortunately, the majority of people will still see it as
extortion/blackmail. Maybe a better approach would be to say "hey, I
was doing some security testing or whatever for 'x' company and found
their network was full of holes. You appear to be running a similar
system. If you would like me to test your network and maybe make it
more secure here is my number. Give me a call". If they call, negotiate
a contract. If they don't, tough.
Catchya,
-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1 -- QDPGP 2.60
Comment: http://pgpkeys.mit.edu:11371/pks/lookup?op=get&search=0x6FD78581
iQA/AwUBOBISkAiK90dv14WBEQKDWgCg/gl3Ac85Udj6kop3jjNWJPLYTRQAoPfZ
4ou7X/B0XcwYjYTqRLsSPFYZ
=0rPc
-----END PGP SIGNATURE-----
Brad Griffin
Infotech undergrad & e-mail addict
CQU Rockhampton, Australia
Useful links:
http://www.pgpi.org/
http://spamcop.net/
http://www.avp.ru/
Received on Oct 24 1999