3 ms·
I used to be very into the hacking, software cracking and reverse engineering scenes when I was a teen – spending my nights discussing Softice cracking methodol
by sp4rki 12y ago
I used to be very into the hacking, software cracking and reverse engineering scenes when I was a teen – spending my nights discussing Softice cracking methodologies, scripting telnet fingerprinting utilities, and other trivialities in IRC while taking care of FXPing releases all night.
One day my mom's email stopped working, so I contacted a CSR for the ISP. After 2 hours of being passed around to their highest level of tech support and explaining that she signed up for some shitty extra antivirus service some time before and that her actual email was probably aliased to an account on the special antivirus server, they kept insisting the account didn't exist and that I was lying. I tried to explain that it was almost a given that the alias just got deleted by someone doing clean-up too many times and I lost all patience. I dedicated all night to gaining access to their mail servers and getting my moms account back up.
I documented everything and the next day I went over and talked to their head engineer. I explained everything while sitting in a computer in his office proving the hack. I got a free lunch and 3 months of free internet service out of it. I was also called in a month later to corroborate the vulnerability was patched.
Two or three weeks later I got suspended from school for stealing some exams from the teachers shares in their "private" network. I covered my tracks, but a girl in the computer room at the time accused me of doing "something fishy" and I was caught with a floppy that contained the exams. That drama took the better part of the month and included my lawyer (my uncle doing me a favor) making incredible legal threats. I almost failed that quarter, but I did get off mostly unpunished.
I do development and specialize in security and risk assessment these days. It's nowhere as fun as it used to be in the early 90's.
- tptacek 12y agoWow, strongest possible disagree. In the mid-to-late 1990s, you could download any project's tarball, grep it for "strcpy", and have an exploitable stack overflow within an hour. Nobody needed any depth in compiler theory, in constraint solvers, or in cryptography. About the only good thing I can say for the 1990s is that you sometimes got to work in SPARC and MIPS assembly. Software security is harder in 2014, definitely. But that's a good thing.
- tedunangst 12y agoAlso a good choice for some time: grep printf * | grep -v '"'
- nate_mcfeters 12y agoAgreed. Even when you find trivial to exploit bugs, there's quite often not trivial to bypass protections in place. Certainly ways around them, but developing an exploit used to be paint by numbers in comparison.
- sp4rki 12y agoOh don't get me wrong. I agree with you. Software security — actually scratch that — security in general is harder in 2014 and by correlation more challenging to boot. I meant that security research used to be more fun before Assange, Snowden, and the NSA came along. I still love security and have become better at it throughout the years, but the ambience of conspiracy and the out of touch with reality legal ramifications and obstacles make me long for the days when "security was fun". Or maybe I'm just old now and I'm just reminiscing the good ol days.