if you know how your computer is beating inside, you are hard to foolIAmA a malware coder and botnet operator, AMA
161–170 of 203 posts
Re: IAmA a malware coder and botnet operator, AMA
#162Earlier quoted context omitted.
He says he is Polish.
A commenter on Reddit points out "I'm Polish and that's not how a Pole would spell Russian words. He's German."
Re: IAmA a malware coder and botnet operator, AMA
#163Earlier quoted context omitted.
It's because you can't do a charge-back with a UK card and get your money back.
Unless charge-back means something different to what I think it does, of course you can with a UK card. The terms and conditions may be different, but the usual fraud etc. is covered.
Anything under £100 and might be out of luck.
Take Mastercard's scheme
• The cover applies to Mastercard debit cards, prepaid cards and Maestro cards, and to purchases made on a Mastercard credit card which don't qualify for section 75 cover
• There is a minimum spend of £10 but no upper limit on spending
PS: Subsection (1) does not apply to a claim—
(a)under a non-commercial agreement, F1. . .
(b)so far as the claim relates to any single item to which the supplier has attached a cash price not exceeding [F2£100] or more than [F3£30,000][F4, or]
Re: IAmA a malware coder and botnet operator, AMA
#164Earlier quoted context omitted.
Yes, the reasons are not very impressive ones, but nonetheless.
http://en.wikipedia.org/wiki/Security_through_obscurity
Re: IAmA a malware coder and botnet operator, AMA
#165Earlier quoted context omitted.
I work in the financial industry and I'm very convinced that my work is not harmful by any stretch of the imagination. In the past I've left well paid positions out of moral issues, in different industries. For instance, when my algorithms were getting patented, or I was increasingly made to work in .NET. People have different views. However, stealing CCs and massively screwing over random people... you cannot possib…
> I work in the financial industry and I'm very convinced that my work is not harmful by any stretch of the imagination. Well duh? Of course you are. It's you working for the financial industry, after all. We could debate this all day without getting anywhere. It's easy for you to blow smoke up everyone's ass, pretending your work is beneficial because it provides "liquidity" or whatever. You can confuse us laymen wi…
Not-so-obviously, if I had qualms about my job I wouldn't be doing it. Some people are for sale, I'm not.
> But in case you're being sincere, here's something to peruse: http://maxkeiser.com/ and http://zerohedge.com
I know these sites. They're rather juvenile but sometimes there's stuff of real value there. There are crooks in finance, and everywhere else, which doesn't mean "finance is bad" by definition.
> You work for an industry whose raison d'être is making money with money. This is vastly different from producing something of value.
There is nothing bad about making money from financial services. If you stretch it a bit, you can call it "making money with money" the same as you can argue that the sole reason for any imaginable job is making money. It's not.
Re: IAmA a malware coder and botnet operator, AMA
#166Earlier quoted context omitted.
oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…
I really hope I never make enemies with anyone around here.
You have 17 bits left. Use them wisely.
Re: IAmA a malware coder and botnet operator, AMA
#167Earlier quoted context omitted.
Unless charge-back means something different to what I think it does, of course you can with a UK card. The terms and conditions may be different, but the usual fraud etc. is covered.
If you have a problem with a purchase made by credit card or via a credit agreement offered by a retailer, you may be protected under section 75 of the Consumer Credit Act. This makes the credit provider jointly liable with the retailer for anything you buy, provided the item costs between £100 and £30,000. ... Purchases made on debit or prepaid cards or chargecards are not covered by section 75. Neither are purchase…
Re: IAmA a malware coder and botnet operator, AMA
#168Earlier quoted context omitted.
A commenter on Reddit points out "I'm Polish and that's not how a Pole would spell Russian words. He's German."
User: rawrr69, on Reddit: "His writing style, long and nested sentences and use of commas are another hint. Plus he likes to laugh about and feel superior to other people and rectify their "mistakes" - 100% definitely German."
well, as a German, I'd like to point out that this might have something to do with the fact that he is kind of an asshole. There are nice and well-mannered people here too.
Re: IAmA a malware coder and botnet operator, AMA
#169I very much enjoyed the reading of his comments - I pulled a few of his that others may find interesting. [polymorphism code - to hide virus signature] Randomness is your friend, make your own crypter and make it so fucking random on every compile, that AV reverse engineers kill themselfs (HINT: randomize the crypters sourcecode using perl scripts) [polymorphism code - to hide virus signature] I started coding about…
the statement about GMER is not true. I've seen GMER miss MANY rootkits/etc. As far as catching and removing rootkits that other most av's tend to misss i've had by far the most success with combofix(which includes a GMER scan). Nothing will catch 0day rootkits 100% of the time, once a system is compromised it's best to format and start from scratch (or restore from backup if you're positive it's clean, but make sure…
Re: IAmA a malware coder and botnet operator, AMA
#170Earlier quoted context omitted.
Actually, signing the receipt has everything to do with fraud. If you use a credit card in a transaction you are required to pay regardless of whether you sign an agreement saying so. The difference is, if the merchant does not collect your signature, they are liable for any chargebacks AKA reports of fraud whereas the bank would be if the merchant did collect the signature. [1][2] My point in bringing up the signatu…
Because if you did not sign, there is no written contract for that transaction, so there is far less of a case that the charge is valid. Regardless of what the signature looks like, you are liable if it was you (or someone you authorized) who signed and you are not liable otherwise. You are even liable if you charged for the transaction but did not sign - there is just no written, signed contract, so you are presumed…
3DS attempts to create a 'cardholder present' situation, hence the shift of liability.