Full Disclosure mailing list archives
Re: Scandal: IT Security firm hires the author of Sasser worm
From: VX Dude <vxdude2003 () yahoo com>
Date: Tue, 21 Sep 2004 03:16:04 -0700 (PDT)
Note, this isn't addressed to the admin's or virus helpdesk folks, but to the whitehats trying to sell another product or service and try to pretend that they did it out of the "good of the community". ======================================================= Did everyone just sober up from defcon already? Where would the security industry be if it weren't for criminals? Who would write the books for you (or the research they're based on)? Who would make nice pretty power point slides for the next Blackhat Conference? Where would ISS be without TESO? Where would iDefense be without their "anonymous" tip program? Everything you guys know can be traced to evil criminals. Your whole industry is based on perception. They hire a virus writer, because now they can scare client's with him. Just like how you guys publish way too much information.... "to help out the admins". ha ha ha ha ha ha The "admins" dont need offsets, and your PoC's don't protect them. Your "full-disclosure" is "fear-disclosure". You guys scare the shit out of everyone in some twisted hope that vendors will make patches avialible faster, and admins will patch quicker. Its fear that drives this industry, and fear which makes your profits. In the recent Oracle debacle, why did Application Security Inc release information for 44 Oracle vulnerabilities. Was it to help with problems that the patch caused? Nope. It was to once again install fear. If they make you think there is a clear and present danger, perhaps you'll buy there products. And if there wasn't any present danger, they give other hackers a head start to manufacture the danger. You whitehats play the game, and you tell me you don't know the rules? Fear is Money. Thats why Application Security Inc did it, thats why Securepoint bought Sven Jaschan, thats why ISS X-Force creates 0day, thats why iDefense buys "intellegence", and thats why you bought Kevin Mitnick's latest book. If you're going to play the game, then learn to play it well. Who knows, you may put up a challenge. If you're going to whine that someone else figured out a better strategy, then you should either copy them or leave the industry. Stinny, Internet Sniper --- "Gregory A. Gilliss" <ggilliss () netpublishing com> wrote:
Mr. Thomas, Oh, do shut up! Three words: Robert Morris Junior! -- Greg On or about 2004.09.20 11:21:23 +0000, Feher Tamas (etomcat () freemail hu) said:Hello, The german IT security company "Securepoint" hashired SvenJaschan, who wrote and spread the Sasser Internetworm,which caused widespread and costly damages tolegions ofWindows computers. He will work as a developer for security softwaressuch asfirewalls. This is a scandal! Whether or not you like the250k USDhead-hunting bounty which Microsoft Corp. paid tohave Mr.Jaschan nailed, he is still a criminal. Hiringhim is ataboo. It is totally unacceptable to picture himas a modernage Robin Hood or freedom fighter. He is acriminal, similarto an arsonist, who sets a house alight and thefire spreadsto an entire city. I urge all to boycott the Securepoint and I urgethose whosuffered losses due to the Sasser worm to sueSecurepointand seek damages. VXing must end and we must senda strongmessage to teenagers that cracking is not hackingand willnot be tolerated. Securepoint website: http://www.securepoint.cc/ Info about Sven Jaschan's hiring: http://www.f-secure.com/weblog#00000296 Sincerely: Tamas Feher from Hungary. _______________________________________________ Full-Disclosure - We believe in it. Charter:http://lists.netsys.com/full-disclosure-charter.html -- Gregory A. Gilliss, CISSP E-mail: greg () gilliss com Computer Security WWW: http://www.gilliss.com/greg/ PGP Key fingerprint 2F 0B 70 AE 5F 8E 71 7A 2D 86 52 BA B7 83 D9 B4 14 0E 8C A3 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
__________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Scandal: IT Security firm hires the author of Sasser worm, (continued)
- Re: Scandal: IT Security firm hires the author of Sasser worm Georgi Guninski (Sep 20)
- Re: Scandal: IT Security firm hires the author of Sasser worm morning_wood (Sep 20)
- Re: Scandal: IT Security firm hires the author of Sasser worm Will Image (Sep 20)
- Re: Scandal: IT Security firm hires the author of Sasser worm Bruce Ediger (Sep 20)
- Re: Scandal: IT Security firm hires the author of Sasser worm Samir Kelekar (Sep 20)
- Re: Scandal: IT Security firm hires the author of Sasser worm Pavel Kankovsky (Sep 21)
- Re: Scandal: IT Security firm hires the author of Sasser worm ktabic (Sep 21)
- Re: IT Security firm hires the author of Sasser worm Peter Bruderer (Sep 21)
- Re: Re: IT Security firm hires the author of Sasser worm -just a thought- Frank de Wit (Sep 21)
- Re: Scandal: IT Security firm hires the author of Sasser worm VX Dude (Sep 21)
- Re: Scandal: IT Security firm hires the author of Sasser worm Ron DuFresne (Sep 21)
- Re: Scandal: IT Security firm hires the author of Sasser worm van Helsing (Sep 22)
- Re: Scandal: IT Security firm hires the author of Sasser worm Dries Robberechts (Sep 22)
- Re: Scandal: IT Security firm hires the author of Sasser worm Ron DuFresne (Sep 22)
- Re: Scandal: IT Security firm hires the author of Sasser worm Barrie Dempster (Sep 22)
- Re: Scandal: IT Security firm hires the author of Sasser worm Ron DuFresne (Sep 22)
- RE: Scandal: IT Security firm hires the author of Sasser worm Jonathan Rickman (Sep 20)
- RE: Scandal: IT Security firm hires... Harlan Carvey (Sep 20)
