Phrack Issue 70
phrack.org
phrack.org
These security zines add so much value. Smashing the stack for fun and profit is taught in CS programs, for instance. I'd love to see this style of security research culture with the personality that it has return/grow outside of Project 0 blogs.
> currently: Google (IT security engineer)
but idk his rank there.
Especially the one for HTTP request smuggling was really helpful in making a C-staff member understand the attack vector more easily [2]
[1] https://securityzines.com/
[2] https://securityzines.com/assets/img/flyers/downloads/HRS.jp...
I also had to disable ASLR (echo 0|/proc/sys/kernel/randomize_va_space) and the executable was 32-bit. A lot has changed since those days :)
I expect failure for me.
https://www.2600.com/node/37570
Which lost them a bit of support (although perhaps gained some as well?).
2600 is also pretty good at never missing an issue (quarterly), and also runs actual prints.
http://phrack.org/issues/1/7.html
So it has it's counter culture roots.
Edit: Which I actually just noticed is from 2600 so I guess the point stands?
I directed a short film in the late 90s and we used this as an 'event' at a party (minus the floating part). We removed the glass from a light bulb to act as a remote fuse. Acetylene was perfect, as it gives this wonderful 'crack,' much better than the LPG we first tried. It was Tim's idea.
Please do not try this!
There's also still a local meeting in Raleigh, although I understand it's somewhat lightly attended these days.
- Setup a new zine and get one free editor from every intelligence agency in the world. - Organize a conference and have a fed do the keynote speech for you. Oh, wait...
But seriously, people are indeed "moving" but for other reasons. The community and culture is dying because it is under attack by several highly advanced actors.
It was definitely not associated with the military or govt. at the time though. That really came about with the founding of Blackhat and the open wooing of the Feds.
I should also say that almost no "hacker" conference, even back then, was primarily attended by hackers. We used to joke back then that Defcon was a "retarded fashion show" (sorry for the offensive terminology). There were always more journalists, narcs, and hangers-on at cons back then than people who were actually hacking anything.
The reality is simply that there aren't that many people seriously criming, and there weren't that many before. Attendance at these events has always been driven primarily from enthusiasts and spectators; you couldn't even fill a bar with the number of meaningfully active people, even in 1995.
(Obviously, this is a private-sector and America/Europe-centric observation).
Flat out, not being aware of what people are capable of is a threat, and so they make sure they are aware.
In my experience, and I have some that is a good parallel but is also not software / hacking related, these things happen in layers. There is a core layer, call it the actor guild, who are three letter lifers, let's say. They are insular, not having broad contact outside trusted peers.
These people won't be doing the work directly.
They will seek others who have various inclinations and or liabilities who can do that work, or even more insidiously, they know who will do the work due to those inclinations or simply being misguided. These people may be almost entirely removed from the actors guild, or if associated, it's murky. They will be directed by people who clearly are of the guild, but also are not core. There are layers of these people who actually do the work and are in contact more generally and who also lack knowledge and or may well be unaware of the real purpose behind their actions.
A good look at what was done, and frankly is still being done in various civil rights, environmental and political activist groups would hint very strongly at what I would be shocked to find is not being attempted (with some degrees of success) in these more technical circles.
Life has taken me well into territory exposed to this stuff, and is currently taking me well out of it for now. Good opportunities tend to work that way, so this is largely a matter of curiosity for me and maybe more should I return to a closer place one day.
In terms of things like activist collectives, I've seen the following:
Promotion of people inclined to favor established interests, who then influence the potential of the group toward low value actions.
Division. Basically, start shit among key players and watch the thing dissolve into uselessness meta.
Pollution. Increase group size and or decrease coherency with a combination of people and misinformation.
Dilution. Impact vital players in ways that reduce their agency and zeal to participate.
The underground these days is to be found on 4chan and other related (or not) subcultures, just like the_uT wrote more than 12 years ago, but certainly not in infosec.
Blacklisted411 was another zine you may be interested in hunting down if you enjoyed the genre.
Always nice to see that proper old skool textfile ascii art mag format. Had copies stored on floppy disks back in the day! Gives me such a early-mid 90s vibe and demoscene vibe also
I'm sorry if it disappoints you that people 'sold out' and it might feel like something of the original 'underground' scene has been lost---I genuinely get that. But experts who put in the time deserve to be compensated and making computing more secure is something that benefits society.
This is an e-zine of public content. Sure, "SoMeOnE cOuLd InTeRcEpT", but why bother? Even with encrypted sockets, logs would still show your IP going to the site. What information are we trying to protect or malicious activity are we trying to stop by using SSL?
... And is it worth the unfortunate webmasters having to deal with bullshit like LetsEncrypt's root certificate expiration and all the main of keystores and PKI management so random "Very Serious People on the Internet" can say "ah, they follow The Standard on security."
Controversial statement in 2021, I'm sure, but I think a use case for simple HTML over HTTP websites still exists. Your personal page with pictures of cats and your resume probably doesn't need to be some bastion of cybersecurity.
https://security.stackexchange.com/questions/157828/my-isp-b...
https://superuser.com/questions/902635/isp-is-inserting-ads-...
https://old.reddit.com/r/india/comments/8ry1k4/does_your_isp...
https://blog.mozilla.org/security/2020/11/17/firefox-83-intr...
EDIT oh shit, just revealed I use a password manager, please fire me if I ever reveal which one.
The world is more antagonistic to the Black Hat ethos now. Those in the West that have gotten fat off of bug bounties and infosec contracting may not have anything to do with "real hacking" now. They probably assume the hacker community will always be anglo-centric. But I'm sure Russia and China is rife with underground wares, as is probably Brazil and large swaths of Eastern Europe. Many hackers are probably inspired more by religion or nationalistic fervor than a bug bounty, yet they still need to research to perform epic feats and compromise national defenses.
Who knows what communities lie outside the domain of a 36 year old text periodical? The net is vast and infinite.
China,Russia,Brazil think of exploits and exploitation techniques as wares to keep or use as weapons.There is not much sharing or exchange of ideas.
The Chinese, Russian, and Brazilian states see exploits mainly as weapons. As does the US state....
The question is whether a hacker culture apart from state control exists, of hackers interested in ideas for their own sake/the challenge/the lulz. Without being in those scenes or even speaking those languages, I couldn't say. (But maybe you have knowledge?)
As in above parts of these comments, threads where people wonder if the corresponding cultures in the USA have been entirely "neutered" by state and corporate involvement, the question is not irrelevant to the US or European or English-speaking worlds either.
The scene is motivated by self interest and is afraid to lose exploits/techniques that they can trade for $$$ and power.
It's the one place where you can get clean, good Adobe CC shit conveniently packaged in a good old Master Collection format.
Torrent forums without the ridiculous ads and popups.
The only place I could find firmware hacks for various hardware including some brilliant mods for SFP routers and washing machines.
There still seems to be a sense of solidarity although I don't really like it since it's the old "fuck them all western shits".
Chinese net pops up every now and then. It's just hard to navigate, hence it's very much unknown to western users. But I know there's troves of cool stuff there.