Phrack Magazine (1985-2016)
phrack.org
phrack.org
If it weren't for a timely late night phone call from Craig needing some more content for an issue, the Conscience of a Hacker would probably not have been written.
I hope life is finding you well!
Thank you :)
I printed it and carried it with me to school and read it over and over.
When I was a senior in college studying Anthropology and subcultures (specifically hacker culture), several of my roommates who were engineers and CS majors told me I absolutely needed to read your essay.
To this day, it's still one of the most influential essays I read about the culture and understanding the ethos of an ethical hacker. After getting involved in the scene in the late 90's, I found out reading your essay was almost a rite of passage.
It's an amazing work that is timeless and still resonates to this day.
Little did I know at the time that I was in the presence of greatness and driving with a legend. He was Ward Christensen. I was so totally ignorant of his awesomeness that I'm ashamed. And so embarrassed now thinking about how vain I was talking to him about my barely getting my feet wet with Android application development. :$
That was my only encounter with Ward. I think I connected the dots a few months later when I read about him in 2600. (@Ward - If you are reading this, hi!! And my apologies for my ignorance).
I would speculate it's likely it made for a much more interesting conversation for both of you than if you had been aware of his accomplishments. You also got a much more interesting anecdote as a result of that.
FWIW I hadn't heard of him until your comment. I suspect for every one person I have heard of there's at least a hundred I haven't heard of whose accomplishments are no less great.
Unless you are a narcissist, it must really suck to be so famous that you can never have a conversation with anybody in a symmetric fashion.
One day on my way back from a trade show about the future of technology (1992?), I get picked up by this chain smoking hippy guy in an old beat up Ford Escort.
We had a pleasant conversation. And then it suddenly hit me that I was talking to a famous (in my country) radio comedian.
And that’s where the conversation stopped.
It was exactly as you described: I just felt embarrassed talking about mundane stuff like the full color flat LCD panels that were so cool.
What do you say to somebody like that?
Little did I know that he was writing his seminal paper in a terminal on the side .. "Smashing the Stack for Fun and Profit" has gone on to be one of the most famous of Phrack articles .. if only I'd known, I would've asked to proof-read it first. ;)
(Likewise: hi @AlephOne!)
Oh the golden days of #phrack and #2600 in the 90's. Was a teenager armed with a dialup to a BBS with an IRC gateway. The modem so slow I would type lines and wait for the characters to catch up on the screen.
[0] - https://tuts4you.com/e107_plugins/download/download.php?list...
[1] - http://www.phrack.org/issues/65/10.html
[2] - https://www.exploit-db.com/ezines/kr5hou2zh4qtebqk.onion/ART...
One night I came across an e-zine that shared a BBS phone number for my city. I made several attempts before giving up. An hour later cops showed up at my door. It turned out I was phoning a secondary number for 911. I got pranked pretty good!
Example ... about halfway through Issue 0x02 it is casually mentioned, "You will find by running ‘qemu-system-i386 -fda pocorgtfo02.pdf’ that the PDF file you are reading is also a bootable disk image." o_O !
I was doing software security semi-professionally before the 8lgm Sendmail 8.6.12 vulnerability that set off the modern buffer overflow craze, and worked with a bunch of people frantically reconstructing that exploit (which wasn't published) --- the authors of the first x86 stack overflow vulnerability included my future business partner at Matasano, Dave Goldsmith.
It was light night and day! Before overflows, there was a whole variety of different "kinds" of exploits (you got some command injection with metacharacters, for instance with SunRPC services calling popen and system, but you also got "overwrite a file" or "leak a file" or things like that). Afterwards, it was just: every machine on the Internet had remote code execution via overflows.
It used to be feasible to calibrate an stack exploit for a remote service, for which you didn't even have source, in an hour or two of tinkering. It's crazy to think of how far things have gone since then.
[1] http://www.phrack.org/papers/escaping_the_java_sandbox.html
1. clone https://github.com/fdiskyou/Zines
2. go offline for a week
(or longer) and enjoy the read!FILE HIT LIST: {HEX}perl.ircbot.Arabhack.47 : /home/$USER/Zines/ZF0/zf0 4.txt {HEX}php.cmdshell.avi.209 : /home/$USER/Zines/ZF0/zf0 5.txt {CAV}Win.Worm.SomeFool-32 : /home/$USER/Zines/h0no/h0no.txt {HEX}php.pktflood.oey.671 : /home/$USER/Zines/owned and exposed/2.txt {YARA}php_backdoor_php : /home/$USER/Zines/29a/29a-3.zip {CAV}Win.Trojan.U-83 : /home/$USER/Zines/29a/29a-5.zip {CAV}Win.Trojan.Flatei-3 : /home/$USER/Zines/29a/29a-7fe.zip {CAV}Win.Trojan.P98M-1 : /home/$USER/Zines/29a/29a-4s.zip {CAV}Win.Worm.rb2-1 : /home/$USER/Zines/29a/29a-8.zip {CAV}Win.Trojan.VirTools-1 : /home/$USER/Zines/29a/29a-1.zip {CAV}Win.Trojan.Flatei-3 : /home/$USER/Zines/29a/29a-7.zip {CAV}Win.Trojan.U-78 : /home/$USER/Zines/29a/29a-6.zip {CAV}Win.Trojan.VirTools-2 : /home/$USER/Zines/29a/29a-2.zip {YARA}telnet_cgi : /home/$USER/Zines/uninformed/3.6.txt {CAV}Win.Trojan.Rootkit-133 : /home/$USER/Zines/uninformed/code.3.6.tgz {CAV}Win.Downloader.51998-1 : /home/$USER/Zines/phrack/65/10.txt {HEX}exp.linux.setuid.6 : /home/$USER/Zines/phrack/61/3.txt {HEX}php.malware.magento.578 : /home/$USER/Zines/phrack/62/6.txt {CAV}Html.Trojan.Shellcode-19 : /home/$USER/Zines/HITB/HITB-Ezine-Issue-001.pdf ===============================================
Makes for a splendid email sig.
If you want excellent detection rates, you might consider this string: <script type="text/javascript" src="http://web.nba1001.net:8888/tj/tongji.js"></script>
Lots of AVs will detect this even if you put the string into an image file.
For anybody who wasn't around back then, a "beige box" wasn't actually a "box" involving tone generation like a blue box or a red box. It just meant clipping onto the red and green wires in the demarc box and connecting to an RJ-14 plug to plug into a phone. It worked well with COCOT's (Customer Owned Coin Operated Telephones) because the phone line for a COCOT was just a regular line that you could make long distance calls on. The mechanism that made it a pay-phone was all contained inside the phone itself, as opposed to a "telephone company payphone" where the actual line itself was special. Thos were the ones you could use a red-box on, to simulate dropping quarters into the phone.
Just found out they also have a website. Enjoy it: http://www.set-ezine.org/
Thank you phrack, could not have done it without you! (i mean the first thing, Phrack was good but not that good!)
First time I've read one was 1995 on some BBS.
My /first/ modem though was a "Lightspeed 1200" from some company who's name I forget. You can guess how many bps that one could sling...
I think he used on of them on his FIDO BBS (Arkham Asylum)
I picked up a secondhand 300 baud modem for my Commodore 64 when I went to someone's house to buy some games. It was like some kind of mysterious magic when I actually connected to a BBS.
Later my parents got the long-distance phone bill... And my fun was somewhat dampened.
Is there an equivalent today to Phrack?
Thank you Phrack.
It's funny how time (and life) changes people... from the outside.