Brian Martin and B K DeLong Lessons Learned From attrition org
Brian Martin, attrition.org
B.K. DeLong, attrition.org
Mirror::Image
The Attrition Web Defacement Mirror began as a small collection of mostly high profile Web defacement mirrors and quickly grew into the largest archive of its kind on the Net. In less than two years it moved from a few dozen mirrors to over fifteen thousand. The process of identifying, confirming and recording a mirror of a defaced site began as a simple set of commands and quickly morphed into a thousand-line custom application handling more tasks than we ever had imagined.
From start to finish, the mirror brought on more challenges and unique obstacles than we were prepared for. In retrospect, the lessons learned and insight gained from the world of Web defacing is staggering. This presentation will cover many of those aspects and begin to explain the ins and outs of running such a mirror hopefully giving insight to future developers who decide to create their own and to computer security experts who will use such mirrors.
Defacement Notifications
who, how, where and more
Administrative Response to our notifications
* hostility, threats, mistrust and a bit of thanks
What else is being hacked/defaced, not displayed on the mirror
Journalism (mostly at its worst)
'hacker site' to 'security site' in two years
Cashing in on the mirror
* we didn't
* ambulence chasers sure tried
Tracking Hackers
* we didn't
* good thing for them
Automation (limits to everything)
Brian Martin (aka Jericho) is a founder and staff member of Attrition.org. His day job includes a wide variety of security consulting provided to commercial and government outfits. When not working, he devotes a lot of time to the maintenance and updating of the Attrition.org security resource. He has three cats.
B.K. DeLong (aka McIntyre) is a staff member of Attrition.org and a researcher, writer and editor by day as well as a common face in the Web standards and development community.
Black Hat - USA - 2001 Hacking conference
#hacking, #hackers, #infosec, #opsec, #IT, #security