Live data from Hacker News

The Beirut Bank Job (2017)

darknetdiaries.com

31–40 of 44 posts

Re: The Beirut Bank Job (2017)

#31
post #29
post #10

Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…

> We did the report and that whole aspect got swept under the carpet and I was never asked back to that clients site ever again. You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.

Here’s a contra view.

If you had a back bone as a consultant your period 2 report would start with “unresolved issues from last time”, so you would very quickly have to resign due to your ethical baseline not being met. Therefore same outcome.

Re: The Beirut Bank Job (2017)

#33

It's quite possible in pentesting to end up hitting the wrong target unless you're careful. Not as extreme as this case but, I've had cases where customers gave me the wrong IP address range for external work in the past, or where the customer had been told they had a dedicated server, when their web hosting company had actually put them on a shared host.

[deleted]

Re: The Beirut Bank Job (2017)

#35
Much less impressive when you know the guy works for the cousin of the bank owner, which is part of a mafioso family. This was staged as a PR move for the security firm of the cousin of the bankowner.

Re: The Beirut Bank Job (2017)

#36
post #28

I loved this one especially because of the foreshadowing where he almost targets the wrong bank the first day. Tons of great episodes on this podcast. It's really a treasure.

I listen to a lot of podcasts, but this may be the one I get most excited about when a new episode comes out.

Same here. When my finances stabilise I’m going to contribute to his Patreon account.

Re: The Beirut Bank Job (2017)

#37
post #29

Earlier quoted context omitted.

> We did the report and that whole aspect got swept under the carpet and I was never asked back to that clients site ever again. You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.

Here’s a contra view. If you had a back bone as a consultant your period 2 report would start with “unresolved issues from last time”, so you would very quickly have to resign due to your ethical baseline not being met. Therefore same outcome.

>have to resign due to your ethical baseline not being met

Huh? Your job is to point to issues, not to ensure they're resolved.

Re: The Beirut Bank Job (2017)

#39

Much less impressive when you know the guy works for the cousin of the bank owner, which is part of a mafioso family. This was staged as a PR move for the security firm of the cousin of the bankowner.

Do you have a source for this? I'm genuinely curious

Re: The Beirut Bank Job (2017)

#40
In this video https://youtu.be/UpX70KxGiVo The running theme seems to be: omg its so easy to just walk in these places and rob them, the employees just let me in.

That seems an unremarkable assertion to me.

Do these corporations want all their employees to act as their private security force and secret police? I think most employees (rightly) dont give a shit if the company suffers. When it does well they dont get rewarded. They just gotta work somewhere so they can pay the rent and get food.

Your employer has the power to make you do all sorts of things. But they cant make you care.

Post reply on HN