It's fascinating to know all this stuff from his perspective but the moral attacks by others in the comments truly suck. What is the point of AMA if all they do is attack the one sharing information.
IAmA a malware coder and botnet operator, AMA
111–120 of 203 posts
Re: IAmA a malware coder and botnet operator, AMA
#112Earlier quoted context omitted.
but he says, only because it is not much common, and different distros are too diverse to justify an "investment"
Yes, the reasons are not very impressive ones, but nonetheless.
Re: IAmA a malware coder and botnet operator, AMA
#113Well, clearly this guy's moral compass is a bit out of whack, but the IAmA does offer some fascinating insights into this world...
I think people don't consider how the blatant and endemic corruption in society affects the moral codes of ordinary people very often, but this is a good case in point.
Re: IAmA a malware coder and botnet operator, AMA
#114Re: IAmA a malware coder and botnet operator, AMA
#115I very much enjoyed the reading of his comments - I pulled a few of his that others may find interesting. [polymorphism code - to hide virus signature] Randomness is your friend, make your own crypter and make it so fucking random on every compile, that AV reverse engineers kill themselfs (HINT: randomize the crypters sourcecode using perl scripts) [polymorphism code - to hide virus signature] I started coding about…
Re: IAmA a malware coder and botnet operator, AMA
#116Earlier quoted context omitted.
You'd be surprised how many vendors and merchants simply do not care. I was employed with an e-commerce vendor that indefinitely stored CVV2 in plaintext (among other numbers).
When I see claims like this, why is it there's never any additional information about this company so I can avoid the hell out of it?
Re: IAmA a malware coder and botnet operator, AMA
#117Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?
In my case not activating Secure By Visa let me proceed with the transaction normally, but they certainly tried to imply it was necessary.
Re: IAmA a malware coder and botnet operator, AMA
#118Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue late…
Re: IAmA a malware coder and botnet operator, AMA
#119Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
Verified by Visa is a fucking joke. In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net . If that's not by the book appearance of a phishing site, I don't know what is.
Re: IAmA a malware coder and botnet operator, AMA
#120Great nugget: > a US credit card costs 2$ on the black market and a UK starts at 60$, americans are all in debt.