6
Apr

Twitter sues spammers. But to what effect?

As a heavy twitter user I commend twitter for there fight against spam. News hit the webs that they “filed suit in federal court in San Francisco against five of the most aggressive tool providers and spammers.” As any regular user would tell you that if you use key words or popular hashtags you will get inundated with replies from bots with 1 or 2 followers with a link that most the time is completely unrelated or sexual in nature. I hate spam. I think I’m a bit more adept to not clicking on shit but as we all know the general users don’t do that and never will. My shity blog suffers from spam to the degree I turned off commenting. (hit me up on twitter @ciphersson for your thought on this…irony) Needless to say I’m left with a few questions….

I have had a bit of fun in my personal time fucking around with twitter and know of a few of these tools such as tweet attack, the yahoo pipes deal, looping tweets and so on. It is what it is, using a system for purposes unintended by the creators. Whats the fun of anything if you can’t break it? However what worries me is suing “aggressive tool providers.” Correct me if I’m wrong but could this set a president? THE PROVERBIAL SLIPPERY SLOPE!!!” (had to use at least one catch phrase lulz.)

typical stock photo
In 2007 Germany banned “hacking tools” and in 2010 Fedora was criticized for removing SQLninja from there repos. With twitter now suing tool makers why couldn’t Oracle sue the backtrack devs for releasing sqlmap or wordpress suing the coders of wpscan? As you can see the list can go on and on. As I noted earlier my blog/s have suffered from spam and I have used “tools” to test for vulnerabilities. So whats the option? Sue people were only the baddies can have the tools? Buy them from Vupan? Or hang out with Tux and see how the junk works?

I dig the multi front assault against spam but it leaves me with a bad taste in my mouth. For one if twitter thinks suing five companies is going to stop spam there sadly mistaken. More will pop up and probably more so because A. it’s profitable and B. people like the challenge to circumvent there tech. What will and dose happen is it will move to a underground sites thus making it a bit more, but not much more harder for twitter to analyze the “tools” and it’s going to cost twitter more because now they have devs and lawyers trying to stop it. Ethical people who need to use tools will be scared to do so under threat of law and unethical folks won’t give a shit and continue on. I personally think the lawyer monies should go to the dev dept to combat this never ending problem.

I understand this is a we bit different (spammers vs things like burp suite) but I think its in the same club, going back to the catch phrase “slippery slope ala Germany’s ban. If twitter dose win these cases people not in to security may look at it very differently than someone testing stuff.

I love twitter but in my humble opinion I think they should figure out how the tool works and then implement stronger measures to deter those methods rather than hiring a team of lawyers. The knowledge of how to spam is not going to go away. Twitter is a huge platform. Those “five” companies will be but blip on there spam problem. But I am glad there trying….

I keep thinking of the novel “Demon” were the dead IT millionaire triggered robots to go out and kill all the spammers with lasers from a demon that monitored the news for his death. However enjoyable that would be to witness (attn: authorities that was sarcasm) we live in a world were I think suing people for creating a tool will not have much effect.

But what do i know I’m just a janitor.

7
Mar

Sabu, Redundancy, The Cake is a lie & the effected.

I try to be deadly honest and objective as possible. It’s my shtick. Devils’ advocate. So here go’s.

Ok because the statue of limitations are up i’ll talk about this. A long long time ago I use to run with a bad crowd. We did ALOT of stupid stuff. One was rob houses. As a rule you got in you got out. Don’t brag just do it. I now work a brainless job at a good place with good folks and pay the bills to keep a roof over my boys head. That’s all i do.

I read that conversation between mike virus and sabu and obviously people never heed the rules of stealth being of the utmost importance. Moreover the back and forth of calling out each others skills, skrid, script kiddy, auto tool user and so on is trivial in my oupuion. Chest beating.

Think of braking in to a house. Do you break out a laptop with some super hand written prog with some super cool device plugged in to the security system then preform some fancy ass hat trick strait out of CSI: “New Jersey” or “Swordfish.” Do you get a master lock picker on you team with hundreds of dollars worth of tools? Or do you look under the dam mat grab the key an walk right in by your self?  (I’m not condoning doing any thing illegal i just don’t understand some methods at times) The cake is a lie. Anonymity is only as good as your will to stay anonymous and completely isolated to your goal. Inherently that contradicts human behavior. People go insane in isolation all the time. Your senses will dull and you will make a mistake.

Of course  you will garner more respect from your peers if you refine your skills and actually understand how the tool works or how to do it manually but it dose not matter. The key is under the mat, it works. Beat your chest or do what you came for. Don’t get caught or do the latter most likely the latter. human nature.

Seems to me it was more about the ego than it was about popping a box. I speculate there is quiet a few people out there tonight having the realization that some guy in New York knows a little to much about them and there shitting there self’s.

If your goal is to break in, logically you would do it the quickest and stealthiest way possible. People who join teams with uber sweet 31337 names (Still waiting for Team Origami to hack all the paper folding sites) and brag on twitter or pastebin about there shenanigans with bravado are doomed from the get go. Not only the likelihood of them getting busted theirs also politicians who will use it as ammo to only make stricter laws. The one bad apple rule.

Army of one: Get in collect ye bounty, get out and STFU. Don’t tell your wife, don’t tell your mom, don’t tell you best bro and ffs don’t tweet or brag about it in IRC. Reduce every possible way you could get exposed. Joining a “team” or “group” dose just that. Logic.

I think the hole new antisec, anonymous and the like is not bearing any fruit. There is other legal ways to try and change the world. @ciphersson me on twitter if you think there is a positive side to all this?

If you have a twitter account called “anon0u812″ that’s the levy’s first crack. Your no longer anonymous from there on out. What’s the psychosis behind that? Recognition? Political statement? That’s for another blog post but needless to say IMO it’s all so counter intuitive. If you think your anonymous then by default one of your main objectives is to be ANONYMOUS!!

I swear it reminds me of that cable show “the first 48″ were guilty ass hats never ask for a lawyer! IMO people need to read spiderman comics more. “With great powers com great responsibility.”

There was a great interview on isdpodcast a few weeks back with the devs of i2p. One of them made an analogy that I to have made many times in a bit of a different way.

My version go’s like this.

Guns are legal to own. The majority  of gun owners don’t go around killing people. If you take a shotgun and start shooting in the air near a police station, The likely hood of a officer dropping a bead on you and killing you is high. Just cause you understand how to exploit shit doesn’t mean ya should. If you are going to I would guess that obfuscating your identity should not even be on the list of things to do because you shouldn’t have a identity. The only person that should ever know is yourself. But is it worth the risks? Is it a drug for some people?

I fucked up recently…. Like I said. I type this here to face my own demons. Brutal honesty. Not to mention its public record but who cares eh? Any how I left a greasy spoon bar and grill after eating a burger and fries and drinking a beer. I burnt out of the parking lot with a nice buzz. I was doing over 100 mph down a old Nebraska road in my 1970 Chevelle and long story short, the law caught up with me. The officer asked me if i new how fast I was going and I replied “really…………. really fast, i had it buried.” Then he asked why was I going so fast. I replied that “this was the first time I really took it out for a good drive on the back roads and i wanted to see how fast it could go.” You may think that’s stupid but i thought “what the hell.” I was caught red handed. Then he asked how many beers i had drank. I said three in the past two and a half to three hours. Thing was I had been partying at a good clip the night before. They gave me a field sobriety test and i past them all (practice makes prefect) and as he was about to let me go on my way with a rather serious ticket for doing 65 over the limit up pulls some young buck and he happen to have a breathalyzer. I failed and off to the clink i went.

Why am i talking about this here you may ask? First i’m not bragging. It’s shameful. I haven’t done something this stupid in ages. In retrospect i repeatedly ask my self what the hell was I thinking. I go to work at a dead end job (good place but it is what it is) and drudge away to make sure my boys have a roof, warm bed and food. At that moment I obviously didn’t care for any one. This point I have been struggling with night and day. I have put there welfare in danger and for what? A joyride. The thought of some one doing what i was doing flying down the road and the thought of my wife driving with my kids on those roads is reprehensible. One little mistake and i could have hit some family. I read all these books on computers and books on SiFi. I’m continuously learning.. I’m not the sharpest tool in the shed but i sure ain’t the dumbest yet that day I was a complete idiot. Do I continue to be one or do i try to recover.. mitigate? I may have lost all notions of common scene that day but I’m going to get back up and try harder to posses it a we bit more often.

But why am I telling random people this?

Because I committed a crime and now i have to face the music. If you play with fire eventually your going to get burnt. Sabu new the extreme risk he was taking. Moreover he did it over and over again obviously with out remorse. Add recruiting young impressionable kids to the mix that have know idea of the implications of there action it’s not hard not to fill any sympathy for the guy. I’m trying to fill some for my self but it’s just not there and it sure as hell isn’t there for him.

I fill bad for his children. His family. I thought I was facing some hard times because of my stupidity but dam… that dude is in for a ride if he’s not in the witness protection program already.

Trust no one. No one is really your friend and no one really will give a rats ass about you when the shit hits the fan. At the end of the day if your lucky to have family and you didn’t burn all the bridges you have that’s all you have. If Sabu go’s to prison who do you think is going to write to him? Who will put money on his books were he can buy a 3.00 tiny bag of chips? It sure as hell wont be the “idea” or any “anonymous” person. It will be the ones he took for granted but still care about him. Still love him.

I’m no hacker. black, white grey… So wtf do I know? I got in to this hobby cause I was a gamer geek, then a Linux nerd then made the natural progression…I dug security. Reading 2600 on an off for years i found it interesting. Getting free AOL internet by continually canceling it cause I was broke. War dialing then war driving cause it was fun to discover what was out there learning more an more the hole way. Not to hurt people just a bit curious. My slow  growth in to infosec makes me respect Boris’s screen name “JadedSecurity.”

I like tools I dig sweet new hacks. I find it all utterly fascinating and I want to lean and understand more. As for the daily drama it’s all so redundant.

Another one got caught today, it's all over the papers.  "Teenager Arrested in Computer Crime Scandal", "Hacker Arrested after Bank Tampering"...         Damn kids.  They're all alike.          But did you, in your three-piece psychology and 1950's technobrain, ever take a look behind the eyes of the hacker?  Did you ever wonder what made him tick, what forces shaped him, what may have molded him?         I am a hacker, enter my world...         Mine is a world that begins with school... I'm smarter than most of the other kids, this crap they teach us bores me...         Damn underachiever.  They're all alike.          I'm in junior high or high school.  I've listened to teachers explain for the fifteenth time how to reduce a fraction.  I understand it.  "No, Ms. Smith, I didn't show my work.  I did it in my head..."         Damn kid.  Probably copied it.  They're all alike.          I made a discovery today.  I found a computer.  Wait a second, this is cool.  It does what I want it to.  If it makes a mistake, it's because I screwed it up.  Not because it doesn't like me...                 Or feels threatened by me...                 Or thinks I'm a smart ass...                 Or doesn't like teaching and shouldn't be here...         Damn kid.  All he does is play games.  They're all alike.          And then it happened... a door opened to a world... rushing through the phone line like heroin through an addict's veins, an electronic pulse is sent out, a refuge from the day-to-day incompetencies is sought... a board is found.         "This is it... this is where I belong..."         I know everyone here... even if I've never met them, never talked to them, may never hear from them again... I know you all...         Damn kid.  Tying up the phone line again.  They're all alike...          You bet your ass we're all alike... we've been spoon-fed baby food at school when we hungered for steak... the bits of meat that you did let slip through were pre-chewed and tasteless.  We've been dominated by sadists, or ignored by the apathetic.  The few that had something to teach found us will- ing pupils, but those few are like drops of water in the desert.          This is our world now... the world of the electron and the switch, the beauty of the baud.  We make use of a service already existing without paying for what could be dirt-cheap if it wasn't run by profiteering gluttons, and you call us criminals.  We explore... and you call us criminals.  We seek after knowledge... and you call us criminals.  We exist without skin color, without nationality, without religious bias... and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it's for our own good, yet we're the criminals.          Yes, I am a criminal.  My crime is that of curiosity.  My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.          I am a hacker, and this is my manifesto.  You may stop this individual, but you can't stop us all... after all, we're all alike.                                 +++The Mentor+++

Like computers, houses are easy as shit to break in to. Fact. Who’s fault? Well people shouldn’t leave the windows open and as for incompetent security practitioners there to blame to. In the end it comes down to criminals with malicious intent.  They will always be there in one form or another.

Iraq: The U.S. Tried to win the people over by visiting villages an interacting with the people. That’s what the Feds should do with the “hacking” scene. Not turn people, create more draconian fascist laws selling the very freedom there trying to protect. But alas there will always be the road side bomb. The kid who’s pissed at the world and reads a book on sqlmap and the idiot driving 130 plus miles per hour down a country road. Bad judgments.

( fuck…. this blog is totally getting flagged)

Anonymous is far from dead. Think of it like this is a Kracken with thousands of appendages that think for there self but adhere to a central idea. That’s the Krackens heart or hive mind or wtf ever you want to call it. Sabu busted? A blip on the radar of the infosec/hacker/absurd scene. Cut off a arm another one grows back.  Phrack… Another got busted..

I’m a father I try to stay out of trouble… Back then what happened was a dude in are group  dropped the dime and a biker went to his house an talked to his father on my behalf. Do I ever want my kids to do such thing? No. Some one who didn’t have a biker friend wasn’t so lucky that day. Yea i read as i wrote there there has been retaliation against panda anti virus. and? So what. People are angry. Sad. happy but me… same shit new day.

 

I don’t even know what this post is about any more except some innocent people get really hurt when unproductive stupid asses do idiotic worthless meaningless shit….
Another day, another one arrested… Goodbye Sabu hello anon0u812 read about you soon….

29
Dec

What i got from focusing on security in 2011

True to form, i am attempting to keep this blog orientated towards information security. I haven’t posted as often as i had hoped but i thought i make one last post before 2011 ends and share my experiences.

Recently i introduced a person to Linux. He digs it. Likes all the concepts that i have espoused redundantly, yet i have grown frustrated with him for asking me questions that i find to be the simplest of things and have tried to subtly express his need to type the very questions he ask me in to google first. Afterwards i go home from work and fire up some vm’s and attempt to break stuff and allot of times I’m at a loss as to what to do. I have told the guy like a million times how powerful the command line is and in retrospect i can correlate his frustrations with mine. To him i know so much of what he wants to know and to me i have met and read the works of people i want to know what they know. To him i can see his thirst for wanting to understand and put in practice certain things but again like me some times complex knowledge, be it programing or actually understanding how a exploit works rather than what it dose seems daunting. With this i realize that’s just life. Every one is in there area of of learning be it a seasoned vet who reminisces about computers that weighed 80lbs or a kids running an outdated version of metasploit on there iPhone just cause they can. Freshman, seniors what ever, i think what is most important is a person loves what there doing and want to lean how to do it to the best of there ability.

A little over a year ago i decided to focus exclusivity on security, i thought it was the pinnacle but now i think it is that combined with programing. In short i have always been a techie. At first mostly gaming form the 2600 on up to the PC. I started building PCs to make a few extra bucks then repairing coworkers PCs for some more change. i like to understand why i was fixing it instead of just hit and run fixes. then i discovered the Linux. I had an old PC that was shit cause i sold my p3 dell laptop to pay rent for a crappy house in the country because i was going to get married soon. Being in the country in Kansas i could only get dailup. I was broke so i returned to a crappy hustle from times passed and had perpetually free AOL access buy calling a different help desk person and canceling every time the free trial ran out, thus them extending it indefinitely.  I swear i must have had 3 years free on and off. SO any how i read about Linux and decided to give it a go. I Downloaded  Dam small Linux and when i tried to install, per the directions for a dual boot system i accidentally wiped the hole box and was stuck with DSL like it sat. It took me a bit to figure out how to get online with it. From then till now i have grown to love Linux and still have dam near every distro from then till now siting in draws in my basement somewhere. All this time i have still been fixing computers for beer change and i cant count the times that people told me i need to be doing it for a living.

Then came the kids. The hole time i have been messing with computers i never really thought of it the sense of a disciplined learning endeavor. I just thought of it as to how to get the second hand crap i hustled to work the way i wanted. I never thought of cracking my neighbors wep as a security thing i just needed some Internet and play a few games and troll some chat rooms for some lulz. Its just been an on an off hobby. Before i met my wife i traveled around allot, no strings attached to any one or any thing but now i settled down and had more time to focus. i upgraded my boxes and sold my massive collection of gaming consoles and started playing mmo’s all the wile fixing peoples computers for every one i new, the proverbial shade tree computer guy. But like most humans i happened to like to breed and next thing you know there two little boys shitting them self’s and crying for food at three am. Were eating mac and cheese and deciding witch bill not to pay wile every one that i know keeps telling me to work in computers. Knowing that computers pay more than what i currently make i started considering this in a hole new light ala how the hell am i going to give these guys a half ass decent life?

So i thought if I’m going to attempt to get paid to mess with this shit and knowing that there a hundred different areas to work in then “hacking computers” would be the funnest. Naive, i know. Now this compounded with my joy of Linux and the extreme boredom rural Kansas brings, i thought i needed to get to know people in real life to see what it takes. ( all ways found “IRL” acronym a bit odd. WTF i didn’t type this in real life? A IRC chat is not real life?) I decided to look in to attending a con. So i started looking and looking for a Linux con in my area but to no avail. So then i started looking in to security cons and theirs like a 1000. I started fallowing the hastags #security and a few other and seen a few people mention derbycon. I cant quiet recall the description that was on the home page but it was along the lines of “You like Linux? you a security pro? are you a hobbyist? this is the con for you.” Now from reading news from many RSS feeds over the years i looked at the speaker list and a few names jumped out at me. Irongeek’s was one cause i remember doing the U3 hack and reading his site here and there. Mitnicks jumped out well because i have been subbing to 2600 for almost a decade. Even funnier is that i started loading up my ipod with EVERY podcast there was when searching “security” in iTunes i herd some of the speakers. Before this i predominately listened to Linux related podcasts. Slowly buy surely i was listening to ruffly 15 to 20 podcast a week on the topic of security. Pretty soon a week wasn’t enough because my RSS feeds were rolling out with info that couldn’t be kept up with just weekly. I was in a full on 24 hour news cycle of infosec. Around that time i downloaded “InfoSec daily podcast” a few times.

During this time i was in to YouTube a bit more than i would like to admit. YouTube randomly removed my entire channel because people abused the DMCA because they didn’t like my views on politics and religion. I rechristened my screen name as ciphersson for several reasons. One CiphersSon is an anagram for censorship. Two i always liked ciphers and the son was a homage to all the people who pioneered that technology, both reason I’m still learning that the depths of both subjects is super deep. And like security i haven’t scratched the surface.

But the podcasting thing started over shadowing the youtube thing. In retrospect some of my “tutorial” videos i made over the past three or four years were the most n00bish shit ever. But i liked the new direction i was going. And i still longed to go to a con because i thought i could learn more there and meet people. I finally decided that Derbycon had to be the one to go to. I also started listing to ISD almost everyday. Just download it right before i went to work and my day was 100% 8hours of a pud blue collar brainless job, but the audio phones was 8 hours of 100% security news and topics. At this point i started to frequent the IRC rooms of more security related folks. I found twitter to indispensable place for information if used correctly.

What amazed me to a degree was that there were people i have herd and have respected for quiet sometime just bullshitting with each and me from time to time. Purely in my head i guess. A great example is Dave. When i finally went to buy my derbycon ticket i prepared ahead of time. If i was going to attempt to make it to a con, i could only afford to go to one (more on that later) so i got all my computers fired up because i thought it was going to sell out in minutes. One computer for buying the ticket, one for irc and another to fallow the #derbycon hash in real time with tweet deck. So then it came i left work early and started bullshiting with folks in IRC and then finally the ticket went on sell and the ticket server crashed…..and still crashed and still crashed. IT was like down for 20 to 30 minutes. I was clocked out as if i was on my break and it was turning in to a long break, so i was going to need to call my boss early to try to explain what the hell i was up to that night. Then the worst thing possible happened. The ticket server was working and quickly i went to purchase my ticket and O NO! paypay wouldn’t go thu. Paypal said i needed a verified account and my crap was tied to a prepaid debit card. FML!!!! So in frustration and utterly dejected i turned to the IRC to vent and vent i did. “omg this sucks sucks suck ass fail this really sucks bad.” Folks were like whats up man? so i attempted to explain and as i was doing so i get this BEEPbeep… here it was Dave like “whats wrong man?” so i explained and hes like “don’t worry about it i can take of your order over the phone.”

Now let me explain something here because my next statement is going to sound super fanboyish groopie noob or what ever you may call it. But from my perspective here i am a fucking peon janitor who has listened to podcasts non stop, heard about these folks on an off for a good wile so i created the hole rockstar thingy untouchable psychology deal in my head.

Any how next thing you know Dave’s on the phone. and I’m like uh uh uh yea uhhhhh Hi Dave, hows it going. I recall him saying something like “well I’m trying to keep these servers going” or something like that. Then he says with a quizzical inflection “Well do you mind giving me your cc number?” Me not really realizing how some folks in the security community guard there shit so hard i say “naw man not at all” hell i think i recited my ss# address mothers maiden name and that my cats name was Linux hahaha jokes jokes… but i was like hell yea your awesome. He says no problem man i know how much you have been in wanting to go to derbycon.” Ok at this point i’m thinking whaaaaa? I have never talked to this guy even in chats but maybe a “hey whats up” or “howdy” and he knows that i been gunning to go to derby?  Security folks go figure :-) Any how he fixed that right up and i had the first ticket ever made for derbycon in my inbox in a mater of minutes.

Work with me here because im getting to my main point.

I guess this would be a good part to mention isd. Like i mentioned earlier i started hanging in #isdpodcast and stopped downloading the cast and started listening to them live stream at seven pm every day for my lunch break. I cant count the times my coworkers looked at me like i was crazy because i was laughing so hard because of the lulz passed around with these guys in the irc and the guys talking. After a bit here is this group of people you listen to every day but really don’t know, never met IRL or really talked about any thing other than computers and computer security. I for one can sometime tell who’s had a long day or is not in the greatest of mood or is in a good mood cause it’s Friday. There is the irc at 3am that is some times quiet as a mouse or filled with all kinds of topics. Or there is folks on twitter and theirs been a few bumps between the crew but they have remedied it. And (hanging my head a bit low) i have a time or two or three or eight were  made a complete ass out of my self after consuming a bit to much of the drink on Friday night. Also being able to vent to certain people when i was haveing some very hard times personally. Needless to say you got to give props to any group that day in day out talks for 30-40 min sharing there thoughts and knowledge with people they do and don’t know every were.

I wasn’t able to make it to Derbycon due to financial reasons. Boris and Karthik of ISD got wind of this and Karthik was going to help me get there. Varun and Enlight2k were going to let me crash on there hotel room floor. Unbelievably freaking cool. Like Dave helping with the ticket it all just dumbfounded me. I think i sabotaged that subconsciously because i felt like i was being to needy or something. I have a sister… she lives off my mom, who has been a widow scene i was ten. Gave every thing for us kids and my sister nickles and dimes here every day. I ask my mom for 20-30 bucks maybe every 3 years for a quick loan for gas or something but other wise i have been doing shit my self scene i was 16 and i don’t know why but i felt like a charity case and i just didn’t like that. I had to pay some bills so as the saying gos shit happens. I have watched every derby video and hack3rcon vid to boot but it dose suck i couldn’t go.

I could look back like a bunch of folks in my RSS feeds have done for all of the biggest shit thats happen in 2011… RSA, Sony, LulzSec (funny as hell till they posted peoples family pics) OWS, more draconian laws fucking up the freedom on the Internet.I’m positive there will some eventful happenings for 2012 because i have come to the conclusion that like Nurses and Truckers there will always be need security folks. Sure i could blog about what happen and what will, but its a bit redundant, at this point, at least in the 50+ feeds i check 20 times a day. But for me theres something else and i don’t want to be mushy and a sentimental ass hat but it is what it is.

ISD and crew donating to EFF to score free tickets to defcon for Geordy. RAD. Mubix, bugbear, Spridell, Baconzombie joining the group i was trying to get together to have a 24/7 hfc telethon. RAD.(never give up ha) Every one at Derby donating a rather large amount of doe to keep Johnny afloat. RAD. Boris and Karthik trying to help me get to derby. RAD. rapid7 hooking HFC up. RAD. Pauldotcom hooking HFC up. RAD. Dave helping me with a ticket. RAD. Varun offering me a place to crash for derby. RAD.  And most recently Logan @ http://www.social-engineer.org/brad-smith-updates/ (go check that out) and many other helping out Brad Smith. Fregin RAD!!!!!

Community.

I never realized theirs such a cool bunch of people. From my standpoint its a bunch of really smart people i hope to one day learn from. I know full well the Internet and any community has there pricks and stuck up people that are completely unapproachable and to be honest i expected that to be the majority of folks but to the country there is tons of people just sharing in there passion ad to the occasional few with a hair up there ass i hope they find some tweezers and chill. I know  were i stand and for 2012 i endeavor to get a bit more disciplined and lean more instead of obsessively reading the news. The one time i was on ISD i choked, witch is odd because i usely can talk for hours about stuff like that. I was ill prepared and i know full well the crew is out of my league. Frankly i didn’t know were to start. Um Nikto… ok yea that one haha. Never the less they were welcoming.  I talked to Karthik one night and he told me i need to think like a pentester when preparing for my bit on the cast that time but i realized in the seance of pentesting as a profession i have know idea what that is like. I’m a janitor. However buy listening to ISD and Exotic Liability, Pauldotcom, Risky Business, Social Engineering Podcast, OWASP Security podcast, SecuraBit, Social Media Security, Hacker Public Radio, Spy Gear Radio, LinuxOutLaws, Linux 4 the rest of us, FLOSS weekly to name a few……. i have learned much more and hope to continue on learning.

So if i have something to take away from the security community for 2011 it’s just that, it’s a great community. I’m humbled to have so many cool people fallow little ol me on twitter and even give me the time of day. To all i say thanks and i hope to meet more people. My only regret is i didn’t attempt to meet people sooner.

As for 2012…. My plans are  to buckle down an go get my GED, spend a minimum of an hour every night breaking something, work on projects in my ideas list and lay off the dam beer haha. O yea and get some more sleep.

Till next time rock on.

P.S. I’m planing ahead for next the derbycon….what’s that that offsec says? Try Harder…

#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj
$/=unpack('H*',$_);$_=`echo 16dio\U$k"SK$/SM$n\EsN0p[lN*1
lK[d2%Sa2/d0$^Ixp"|dc`;s/\W//g;$_=pack('H*',/((..)*)$/)
17
Dec

guest post:Tyler Wall’s (a.k.a. Red_Rail) Thoughts on #sopa

 

red>

 

A bill nicknamed “SOPA” was introduced and supported by many of our *lovely* politicians that would ultimately give the government the power to censor the internet. Imagine the government, in the land of the free might I add, having the ability to control what websites you are allowed to visit. Imagine the government deeming Twitter, Facebook or LinkedIn “detrimental to the American way” and forbidding American citizens from visiting these websites. Sound familiar? This is what China does.

Thanks to the Electronic Frontier Foundation and many of us who contacted our representatives telling them to recognize that we value our privacy and freedom on the internet, the bill died in the house today. However the bill is still active and it is pending review by an ‘internet expert’ of their choosing. It will rear its ugly head again and this time it will likely have more support.

The result of this bill passing could be devastating to the very concepts of freedom of speech, freedom of press and freedom of information. If you are an internet user of any level… if this bill is passed it WILL impact your daily life.

It will only take only a single minute of your time to email your representative (jump to and see the link at the end of this post now), and then you can go on living your life knowing that you did something to combat this country from turning into a tyranny. Tyranny is a strong word but I feel it is not used without justification.

I have to admit that personally, I have always been an apolitical type of person publically. However I do have opinions and I voice them by voting in every election I can. I read about each politician and their views on issues that are important to me and find the candidate who I believe will represent me the best. I come from a family that when the entire family gets together for a thanksgiving dinner, politics are always the topic of discussion. I grew up observing my family of strong politically opinionated people and how wherever they go, they just cannot hold back their comments. Sometimes resulting in hours of heated debates with some random stranger we walked by on the side of the street! After my experiences with this I have just come to the conclusion that some people are so very passionate about a political party or a particular issue, that it is just tantalizing and a waste of time to try to engage in a debate where the opposing view is unable to approach the subject with an open mind. Furthermore, this is why political debates have always seemed a bit childish to me. They are filled with politicians taking a ‘firm’ stance on a particular issue simply because it is beneficial to their campaign. These feeble attempts to gain votes of a particular demographic are an insult to me and it speaks something about how politicians really perceive the intelligence of the American voters. To get to the point, the first time I heard of what this bill proposes I was shocked by something political for the first time. After learning more I decided I could not just sit back and let something like this happen without knowing that I, Tyler Wall, did not do what I could to stand against such an injustice.

I encourage you to spend just a few minutes of your time at the EFF website (link below) to read a little about this bill and take the time to email your representative from the website. If you’re curious as to how the bill got so far to begin with and look into it, you will hear the familiar tale of how immense the power of a lobbyist with a large bankroll is. You will see how it’s money that talks and manages to introduce, gain support and potentially pass a bill into law… even if the bill is so blatantly opposed to the basic principles that we covet in our United States Constitution.

These types of laws take away our freedom slowly bit by bit and happen more frequently than even the law makers seem to realize. It has happened at an alarming rate over the last 10 years, and for me… the line has been crossed now. I WILL choose to stand up, fight against, voice my beliefs and contact my representatives whenever I see such a law being proposed that has zero consideration for the rights we have as American citizens. I will continue to persistently prod at my representatives and law makers until I know that I have been heard, noticed and not just conveniently overlooked. If you’re still reading this (may the force be with you LOL), then I strongly urge you to take action as soon as possible. If you take the time to learn more about the potential consequences of this bill, I am confident that you too will be dumbfounded that something like this could ever even get to the point of being drafted on a piece of paper… much less have the support of so many of our current ‘leaders’. But it’s real and is gaining support.

The internet to me is more than just something to waste time on. I use it to learn. I use it to do research. I use it to expand my mind beyond my small little world. I use it to see how other people think. I use it to meet people from around the world to gain an understanding and appreciation for various cultures and beliefs. Finally, the internet over the years has become more than just a hobby… it is the sole reason that many of us have a career that provides for our families. Don’t let anyone take away the rights to our privacy and freedom on the internet, because it will undoubtedly have a profound impact on our kids, our neighbors, our friends and our lives personally.

Essentially, giving the Government the power to control our gateway to knowledge, information, or line of communication is a TERRIBLE idea. It is only supported by those would could directly benefit and profit from such madness.

If you are thinking, “What’s the big deal, it’s just the internet!” Please come to the reality that our society is now reliant and functions on the benefits that the internet has to offer. It has impacted the world in so many ways that internet access is now even classified by the U.N. as a “basic human right.” Seriously! Its importance is right up there with food, water and shelter! This might sound like some people are over doing it, but classifying internet access as a human right comes not without great logic and reason. The U.N. Secretary General Frank La Rue states that the internet is, “an indispensable tool for realizing a range of human rights, combating inequality, and accelerating development and human progress.”

And how I do concur Mr. Rue! The power of mass communication can never be overestimated. Furthermore, I believe that a society’s progression out of poverty is directly related to the standard of education it offers to its people. The internet offers people virtually instant, unlimited access to the world’s knowledge. Knowledge IS most certainly power… and the human mind should never be limited in what it can explore and learn. It is counterproductive to the advancement of civilization as a whole. I can, and have, debated this viewpoint very convincingly with supporting ideas and facts; however that is not what this post is about.

The day the Government passes and enforces this bill will be the day Americans are limited and possibly told what we can or cannot learn, who we can and cannot communicate with, and what we can and cannot do to harmlessly entertain ourselves online. This will also be the day we will have to finally accept that the ideas of our four-fathers and the very concept of freedom as we understand it have been lost. If this bill passes we can point fingers and blame the politicians who have been influenced by the greed and personal interests of corporate lobbyists, but at the end of the day we will have just watched yet another one of our freedoms be bastardized and destroyed.

We, the people, are the ones who will have to live with giving up one more of our freedoms that we enjoy as a citizen of the United States of America. I am terrified to think that while in this country, the country that I love so dearly, I will one day become a grumpy old man who just complains about what went wrong and spends his golden years preaching and reminiscing about “the good ole days” when this country actually used to value the privacy and freedom of its people. If anything that I have said upsets you in any way, the question is… what will you do about it? I encourage you to start by reading more about this bill and deciding how you feel about such a power in the hands of the politicians historically known to take a mile when given just an inch.

If this is not the future you want for you and your kids please visit the website below to learn more and take action:

https://action.eff.org/o/9042/p/dia/action/public/?action_KEY=8173

Tyler Wall (a.k.a. Red_Rail)

16
Nov

SOPA Rant

There’s been allot of reporting on SOPA well at least online there has been… (Justin Timberlake taking a lady on a date, however charming dose not merit the most substantive of news…in my opinion) The build up of support opposing SOPA or previous laws of the same ilk have had the same opposition an outrage voiced over and over again. This seems as if it’s a never ending battle between the voice of the people and the power brokers of the old media spending millions of dollars on lobbyist to swoon the lawmakers to do there will. Moreover there is added incentives for the lawmakers after there tenure as a “public servant” Chris Dodd is a prefect example. He has had a long career of yada yada yada and who hires him? yea

I ask my self… How many petitions have i signed? How many letters have i sent to my state legislators? For what? To prolong there concerted effort to impose not my nor the populaces will but the people who line there pockets?   http://www.opensecrets.org/  All the old adages sound true again an again…. “You give power away your most likely never to get it back” and so on.. Incremental change is very slick and keeps the people docile because they have other things to worry about. As long as we have MTV, comedy central, mcnbc or fox (depending on who you believe the most on tv derp) and a big mac were fine. Incremental change, slowly but surly the government is trying to push laws thu that is not in favor of peoples liberties but to give the government more and more control. Incremental change you can believe in.

I live in a rather small town in Kansas, theirs probably like five other registered democrats in my town an I’m being optimistic. But now a  days my disillusionment with both side have dam near gave me a sense of helplessness.  I always say i earnestly try to be objective and look at both sides of the coins. I stole this quote from  Neil deGrasse Tyson [1] he wrote on his facebook profile once because it rang true with me.. “I’m socially liberal and fiscally conservative” That’s my real life. The people in Washington don’t do none of that. They don’t represent any one, they pander for a popularity contest to the public then abide buy special interest athat are not in the public’s interest. The GOP is any thing but conservative with astronomical military budgets that have sent the country in to bankruptcy. And the the harbingers of change, the Dems come in to do what? The same dam shit off the hopes of the people wanting a change.

People say SOPA will create a great firewall of America like the one in place in China or the half ass one in Iran. Unlike China and Iran the culture here is a bit different so the polotrixters take a different approach to oppressing the people. They imply that there is this huge problem of piracy when the numbers contradict that stance at every turn.  There best tactic they can use in there arsenal and that is the rhetoric of fear.  Now they got to do it for the kids but all the wile its old media lining the pockets of these law makers and its not the lawmakers writing the legislation it the lobbyist and the mpaa and riaa “contributing” to the legislation.  So if the DMCA, COICA, ProtectIP, Patent reform, SOPA and what the heck else is next is here to protect people then why is it these arcane institutions the ones screaming chicken little the sky is falling? There plainly stifling innovation. Their plainly holding on to a dieing model that made a few filthy rich. There worst part is there still filthy rich and have had record profits and record pay hikes. They still hold the keys to the kingdom in what we rent on netflix and how its rated for are consumption. But they want more.

This is the tip of the iceberg. This is the double bladed sword. There using Washington for there agenda and Washington is using them for there agenda. Like all other laws that are past these days theirs always subsection 5 paragraph 3c line 18 with the small print under it that’s says “o yea there’s no due proses and if any one uses a vpn, proxy or ssh then they are a felon buy default that can be detained at the air port have there balls juggled and fried buy a rent a cop and promptly sent to Gitmo that were going to close in a few more weeks but trust us we would never abuse that power. Line 19 says some senator gets 20,000 million for a highway that leads to no were.” (ya sarcasm… i think)

They won’t need to enforce the laws them self, as is clearly demonstrated buy DMCA abuses. The DMCA is and was a terrible piece of legislation that is now looking good compared to SOPA. It not exactly hard to go to someones youtube account, find out they don’t jive with your world views and file a false DMCA claim against there account and have there voices muted out of existence. There is other examples of this that abound.. but the point is it is abused and SOPA is giving DMCA some brass knuckles to make the beat down even worse.

These so much that has been written on this that all you have to do is type this in to google “sopa site:www.techdirt.com”  and there is enough for any person to discover that this legislation is utterly hideous for the growth, innovation and freedom of the world wide web as we know it.

So now what? The petitions have been signed the stacked jury is in session and some shity law is going to be imposed on people one way or another even if its watered down. Till next years censorship day when this years censorship day seems like small potato’s?

The old cliché rings true yet again.

These so much to this its hard to wrap my head around. I could rant on this for hours and point it out in detail but like i said that’s been done. What we need is solutions. Like the occupy movement that’s been sweeping the nation i again try to see both sides. For one we have to have a stable banking system in America but also those banks and institutions need to be held accountable for there actions. I believe in capitalism hole hardly but not to the degree were every one but a few 1000 people are abusing the majority in to the ground. I have two little kids, I’m behind on bills and even overtime still leaves me broke. I have to rotate my insurance every year from eye to dental according to are needs and health insurance would cost me so much i wouldn’t be able to pay my rent.  Putting my kids thu collage one day is rotting my gut with worry because it looks like a hopeless situation. But i do know in order for me to make what i do make some one has to have a business to pay me and so on its a quagmire. So what am i to do? Well giving up is not a option. Camping in a park with signs held hi to be twitpic’d 1000 times i can’t do cause milk is really f-ing expensive and ill get evicted.  Writing my representatives don’t seem to be very effective. awww i got it….

We the people for the people buy the people

put your money were your mouth is

necessity is the mother of all invention

They occupy my country’s capitol. they occupy my dusty DVD player. They want to occupy the DNS server i connect to. They want The proverbial Justin Beiber to to occupy and overcrowded prison for singing on youtube and they want to still occupy my wallet. People have called the Internet alternative media well its my main media and they are the dieing media. I no longer want my entertainment from these info dictators. I agree the internet is a human right. So instead of the cliché “can’t beat them join them” i say Ta hell with them.

I suspect they will extend the copyright on music for the next 300 years but i will get my media form independent sources, Creative commons sources. Like http://www.jamendo.com/en/ http://soundcloud.com/ http://freemusicarchive.org/ and  http://ccmixter.org/ for music. http://librivox.org/ http://www.gutenberg.org/ and the Internet for literature and support folks like http://wiki.creativecommons.org/Case_Studies/Cory_Doctorow. And motion pictures outlets like http://vodo.net/ and indy artist on youtube.

Not because i want stuff for free, on the contrary, i gladly pay for the content i consume. The reason is obvious. I find the “industry” despicable for not adapting to the Internet ( i mean come on its 2011) and instead of adapting spending millions to oppress the very users who made them those millions. When i can, i will go to the concert of folks that are like minded and buy there swag, movie projects like vodo.net i will give what i can also, like wise with lit. They will get my money and places like the EFF will get my money instead of any politician campaign support. (goodby democrats hello unaffiliated)

The Internet is not owned buy the MPAA or RIAA or cox communications or even DARPA who created it. The Internet is held up by the consumers who buy computers and phones who pay there monthly bill and choose freely what to surf to…freely. The Internet adapts quicker than Washington and i honestly believe there is no laws other than repressive laws like Iran is trying to implement that will stop it. By far the Internet adapts quicker than the arcane broken logic of the studios in California. They can pay off politicians to kill and censor the Internet but buy doing so will spur alternatives to the shit there pushing off on people because its not them who occupy the Internet its the users.

-ciphersson

 

 

 

Hackers For Charity