Hack Back – A DIY guide to those without the patience to wait for whistleblowers
11–20 of 62 posts
Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#12Every time I find or see an SQL injection issue I get angry. It's 2014, why are web developers still making the same basic mistakes? SQL injection is a fixed issue. There is no excuse. Same with XSS, although not as serious it's staggeringly common.
I believe it is essentially a function of the skill distribution and price of developers. There will always be a spectrum of skill level; there will always be very inexperienced, low-skilled developers just about able to knock together something that works, but is susceptible to SQL injection. These inexperienced developers will charge less, and will get work, so there will always be an endless supply of new develope…
Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#13Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#14This article was quite fascinating. It's impressive that a series of small security holes culminate with the release of sensitive software. It's equally interesting that all those security tips we roll our eyes at, as we've heard them one too many times, they really matter! Don't write crappy code: Don't trust user input. Don't do client-side only checks on any information being processed by the server. Etc. Etc. The…
How would you know for sure that it didn't dump the database to somewhere in Asia once "they" have your server under control? Serious question, because how can you trust the logs? (Mind you, I'm not that technical)
Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#15Not a good idea considering Bitcoin isn't anonymous and a sufficiently motivated state can back track to an electronic purchase of bitcoin tied to your identity.
Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#16Earlier quoted context omitted.
I believe it is essentially a function of the skill distribution and price of developers. There will always be a spectrum of skill level; there will always be very inexperienced, low-skilled developers just about able to knock together something that works, but is susceptible to SQL injection. These inexperienced developers will charge less, and will get work, so there will always be an endless supply of new develope…
No, it will stop. I think the tools and general lack of awareness are a big factor - those will both undoubtedly change.
Re: Hack Back – A DIY guide to those without the patience to wait for whistleblowers
#17"I recommend using servers you've hacked or a VPS paid with bitcoin to hack from." Not a good idea considering Bitcoin isn't anonymous and a sufficiently motivated state can back track to an electronic purchase of bitcoin tied to your identity.
purchase it using stolen bitcoin. :P