Thursday, December 18, 2008

Case-Study of Malware drop servers

Hey,

Here's a document I've just read.

As for me, only the "result" part is worth reading.

Anyway, this is just another study where computer security researchers are playing with the black/white hat barrier. What will happen when the drop server will be a compromised machine from a botnet, without any open directory, and belonging to Mr. John Doe ?

Will they hack it too ?

Probably.

Tuesday, December 09, 2008

New SSH bruteforce attacks ?

This is actually a shitty title, because it is *NOTHING NEW*.

I see some people around yelling like looserz : "oh my goooooooood the bad guys are now using different IPs when trying to bruteforce some SSH server !"

Can you tell me, what is new in this ? Hell, botnets have been used for years already, for any kind of purposes : DDoS, malware propagation, spam, phishing, even distributed calculating, so WHY THE FUCK wouldn't it be used for something as TRIVIAL as SSH bruteforcing ?

Sometimes security researchers are making me laugh out loud. (Strange to see a "lol" written down, ain't it ?)

Link here some of the crap.

Monday, November 17, 2008

Monica

She looks perfect.
I love the perfume of her hair, of her skin, of her.
I have never been falling so much and so fast under a girl's charm.
Everything in her is beauty, charm, sensuality.
I love her laugh, and her smile.
I kissed every part of her skin, and enjoyed it so much...
We made love.
In this art, she was perfect too.
It's been unbelievably good.
I won't ever see her again.
Life sucks.

Sunday, November 16, 2008

McColo down

A great victory for all actors fighting cybercrime each day : the fraudulent hosting company McColo has been taken down.

While the whole anti-cybercrime community can be proud of it, is it really making things get better ?

Well it does...For two or three days. A week in the best case. Less spam, less malware, less childporn on the net... But the bad guys are moving. They're probably already somewhere else, pushing their malicious activities on the net once more.

The problem is only going somewhere else, nothing changes.

And while researchers are shutting things down, what are Law Enforcement dudes doing ? Blaming international laws. So silly...

Picking up chicks - SUIT UP !

Well there are at least two different schools related to picking up girls. The "Mystery" and the Venusian methods, and the "Barney Stinson" method.
While the first one is really well documented on Internet, maybe even too much, the second one is a bit less known, except for people like me who love watching "How I met your Mother".

Mystery would say that you don't need to dress too classy, or so. He'd say that you need to show you take care of yourself (DHV) but that you should be original, even using crazy stuff like strange hats or flashy clothes...
Barney believes girls are basing their first impression only by their perception of the "look" of the potential lover. That's why Barney *always* dresses in suits. Nice costume, great tie, he looks perfect, and therefore he manages to get laid in almost every episode of the serie.

I tried it. And while I'm sometimes a bit too shy with the Mystery methods, last night proved me Barney's point of view is interesting enough to re-experiment this : I got to talk with a 7 only because I was suited up. She tried to get in contact at first, she did the work, I had nothing to do. But while she was getting closer to me, it was interesting to still have Mystery's ideas in mind : her body language was quite readable.
A nice evening in disco, suited up, even if I didn't get laid this time. :-)

Wednesday, November 12, 2008

Tired of apocalypse

Hell yeah, I'm dead tired of hearing security researchers claiming they found a new vulnerability in blahblah protocol that could lead to the end of this fucking world, would it be used by cybercriminals...
This is not new. But lately it turned into becoming a silly habit. Dan Kaminski DNS stuff was still quite ok, but then, the fuss about the new TCP state table manipulation vulnerabilities was nothing but shit. Louis & Lee announced they would give infos at T2, but what the hell ? They didn't say anything !
What's the point in announcing weeks before that you found something, when you're finally not releasing your discovery ?
Drives me mad...
Or hilarious. So fucking stoopid.
*shhhhh* EOF

Saturday, November 08, 2008

ROCK !

I hear you brave young Jaybles,
You are hungry for the rock.
But to learn the ancient method,
Sacred doors you must unlock...
To find your fame and fortune,
Through the valley you must walk.
You will face your inner demons.
Now go my son and rock!"