Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

111–120 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#111

It's fascinating to know all this stuff from his perspective but the moral attacks by others in the comments truly suck. What is the point of AMA if all they do is attack the one sharing information.

Especially downvoting his comments. Like he cares about karma points. All it does is push all his responses to the bottom or hide them. Then what's the point of an AMA?

Re: IAmA a malware coder and botnet operator, AMA

#112
post #59

Earlier quoted context omitted.

but he says, only because it is not much common, and different distros are too diverse to justify an "investment"

Yes, the reasons are not very impressive ones, but nonetheless.

http://en.wikipedia.org/wiki/Security_through_obscurity

Re: IAmA a malware coder and botnet operator, AMA

#113
post #3

Well, clearly this guy's moral compass is a bit out of whack, but the IAmA does offer some fascinating insights into this world...

It was quite interesting to me how he rationalised his behaviour; Yes, it's a bad thing to do, but at the same time the world is full of bad actors, unscrupulous politicians and out of control corrupt financial institutions, so really I'm just acting in accordance with the established order.

I think people don't consider how the blatant and endemic corruption in society affects the moral codes of ordinary people very often, but this is a good case in point.

Re: IAmA a malware coder and botnet operator, AMA

#114

Earlier quoted context omitted.

When I see claims like this, why is it there's never any additional information about this company so I can avoid the hell out of it?

The company was probably Moveable Online. http://www.linkedin.com/pub/joshua-kelly/12/105/140

[deleted]

Re: IAmA a malware coder and botnet operator, AMA

#115
post #56

I very much enjoyed the reading of his comments - I pulled a few of his that others may find interesting. [polymorphism code - to hide virus signature] Randomness is your friend, make your own crypter and make it so fucking random on every compile, that AV reverse engineers kill themselfs (HINT: randomize the crypters sourcecode using perl scripts) [polymorphism code - to hide virus signature] I started coding about…

the statement about GMER is not true. I've seen GMER miss MANY rootkits/etc. As far as catching and removing rootkits that other most av's tend to misss i've had by far the most success with combofix(which includes a GMER scan). Nothing will catch 0day rootkits 100% of the time, once a system is compromised it's best to format and start from scratch (or restore from backup if you're positive it's clean, but make sure you replace the mbr too). Theres just no other way to be completely certain. I lost track of the times that I thought I got everything on a windows machine, then google for something like malwarebytes as a test only to be redirected.

Re: IAmA a malware coder and botnet operator, AMA

#116
post #51

Earlier quoted context omitted.

You'd be surprised how many vendors and merchants simply do not care. I was employed with an e-commerce vendor that indefinitely stored CVV2 in plaintext (among other numbers).

When I see claims like this, why is it there's never any additional information about this company so I can avoid the hell out of it?

[deleted]

Re: IAmA a malware coder and botnet operator, AMA

#117
post #49

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?

I had this pop up today, the wording was pretty misleading.

In my case not activating Secure By Visa let me proceed with the transaction normally, but they certainly tried to imply it was necessary.

Re: IAmA a malware coder and botnet operator, AMA

#118
post #32

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue late…

The only merchant that I've ever seen this used at is Newegg and they make it mandatory for Visa.

Re: IAmA a malware coder and botnet operator, AMA

#119

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

Verified by Visa is a fucking joke. In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net . If that's not by the book appearance of a phishing site, I don't know what is.

Really? Because SecureServer.net is a domain used in GoDaddy's webmail:

https://login.secureserver.net/

Post reply on HN