Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Not even the NSA can get it right |
|---|---|
| Date: | Thu, 26 May 2005 20:59:51 -0700 |
Have Fun, Sends Steve
Have Fun, Sends Steve
Valdis.Kletnieks@vt.edu wrote:
On Wed, 25 May 2005 12:58:37 EDT, Dan Margolis said:
Right, but why is XSS interesting? Why would they *want* a "suspected
script kiddie" list? Honeypots are good for learning about what sorts of
attacks are in the wild, *not* for learning who the attackers are.
So watching the console logs on a tempting target like www.nsa.gov for a month isn't going to give a *really* good idea of what's out there?
Consider - of those who went and tried the XSS that got posted, what percent probably tried some *other* tricks to see what *else* they could get it to do?
Yes, the NSA crew almost certainly know the attacks themselves - but by keeping an eye on what tricks have made it out to the script kiddies, they can measure how fast the tricks propagate. Any attack they see on *that* server they can safely conclude that it's part of the script kiddie canon (as it's very unlikely that a black hat would blow a 0-day attacking that server when everybody *knows* there's probably nothing worthwhile on there...)
Remember - we're talking about the organization that provided guidance on the design of DES's S-boxes, which made *no* sense at the time. Many years later, we find out that the NSA knew about differential cryptanalysis, the IBM crew independently discovered it, but kept quiet at the NSA's urging, and then when differential cryptanalysis came out in the open literature, the S-boxes made sense. This gave the NSA a *very* good measure of how far ahead they were at the time.
Or the public website is just maintained by low-pay civil servants (after all, there's no need for a security clearance for any of those pages ;)
Granted, we don't know everything the NSA does, but I see little to gain
from a public XSS hole, however insignificant. Occam's razor, folks; why
should I buy into such a twisted conspiracy theory?
I never said you should. I merely implied that immediately concluding that
it was a stupid mistake might in itself be stupid. Remember - we *know* that
many black hats try to stay under the radar by leaving tracks that look like
common script kiddies (so all the recon probes disappear in the noise). Why
shouldn't the world leader in spreading and recognizing disinformation do the
same once in a while? ;)
------------------------------------------------------------------------
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| Previous by Date: | [Full-disclosure] Re: alpha numeric exploitation, Kristian Hermansen |
|---|---|
| Next by Date: | [Full-disclosure] [USN-114-2] Fixed packages for USN-114-1, Martin Pitt |
| Previous by Thread: | Re: [Full-disclosure] Not even the NSA can get it right, Valdis . Kletnieks |
| Next by Thread: | Re: [Full-disclosure] Not even the NSA can get it right, Paul Kurczaba |
| Indexes: | [Date] [Thread] [Top] [All Lists] |