Slashdot Mirror


Startup Prepares Cracker Attack Emulator

Startup.Blog writes "A startup company MuSecurity is shipping a product that emulates multitude of known attacks and integrates the security checks into quality assurance processes. The company 'will soon begin selling a new vulnerability assessment product that lets technology vendors and enterprise developers test their products with known hacker techniques, allowing them to fix bugs before products are put into use.'"

106 comments

  1. So what? by komodo9 · · Score: 4, Insightful

    How is this anything new? There is open source (and closed) that has been available for a while that does this.
    --
    United Bimmer - BMW Enthusiast Community

    1. Re:So what? by komodo9 · · Score: 1

      Erm, I mean open and closed source software. Nessus for example.
      --
      United Bimmer - BMW Enthusiast Community

    2. Re:So what? by Fred_A · · Score: 5, Funny

      We people in the industry even have a name for this technology. It is called a user.

      --

      May contain traces of nut.
      Made from the freshest electrons.
    3. Re:So what? by HermanAB · · Score: 3, Funny

      For a Windoze box, it is called 'Plug Into Teh Interweb'. This test runs for about 20 minutes.

      --
      Oh well, what the hell...
    4. Re:So what? by gbobeck · · Score: 4, Funny

      Your testing tool must be outdated. With a new Windows XP box the test now takes 10 minutes or less.

      --
      Navicula hydraulica plena anguilarum est. Omnes castelli tuus nostri sunt. Ed elli avea del cul fatto trombetta.
    5. Re:So what? by Anonymous Coward · · Score: 0

      Links to homepages & other misc crap belong in sigs where I can ignore them. What has a BMW website got to do with penetration testing? Goatse would have been more appropriate.

    6. Re:So what? by cp.tar · · Score: 2, Interesting

      I'm sorry to say, but it takes less.

      It takes less than is necessary to download a firewall and an anti-virus program, which was something I had to do recently. Unimaginable fun.

      --
      Ignore this signature. By order.
    7. Re:So what? by Anonymous Coward · · Score: 0

      So another company is going to scan my network with nessus. Wonderful. Because, you know, VeriSign and the three dozen other companies which already provide this service don't run nessus quite as well as these new guys will.

    8. Re:So what? by 42Penguins · · Score: 1

      As funny as it is, it just doesn't seem realistic to me. Maybe I'm at the wrong intraweb...
      In the last 5 years on Windoze 2000 + xp, I've been pwned exactly 0 times, same as my BSD box. Of course, the firewall, firefox, and not being a dumbass certainly help.

    9. Re:So what? by Rahszhul · · Score: 1

      firewall, firefox

      ... No doubt that the two fire's are creating enough light to scare away any slightly tanned hacker's hide.

    10. Re:So what? by HermanAB · · Score: 1

      Your firewall/router/little blue box, typically runs Linux. Have you considered that this firewall doesn't have a firewall to hide behind?

      I'll believe in Microsoft security once Cisco/HP/Whoever starts to sell Windows based firewall appliances.

      --
      Oh well, what the hell...
    11. Re:So what? by plover · · Score: 3, Funny

      Could you be thinking of ... hmm ... I don't know, maybe ... SATAN??!!?!

      --
      John
  2. A karma whore is me. by heinousjay · · Score: 1, Funny

    So if you hook this up to a Windows box, does it blow up like the androids on the old Star Trek?

    --
    Slashdot - where whining about luck is the new way to make the world you want.
    1. Re:A karma whore is me. by Crazyscottie · · Score: 1, Informative

      So if you hook this up to a Windows box, does it blow up like the androids on the old Star Trek?

      If by "blow up," you mean BSOD, then I'd say your chances are pretty good. Then again, who knows... with Vista's Red SOD and all, we might uncover new levels of crashing. ;-)

      --
      Just because it can't be explained doesn't mean it isn't true. Science fits into reality... not the other way around.
  3. REALLY, REALLY important /sarcasm by AKAImBatman · · Score: 5, Insightful

    Mu Security would not say whether the product will be hardware- or software-based, but more details will be revealed in March, Furgerson said.

    That's not very helpful. If we're talking a tool to check for security flaws already patched against, what good is that? Just keep your systems up to date. On the other hand, if we're talking about things like buffer-overflow checkers, then why not use an existing product?

    This thing is going to have to be pretty darn impressive to actually find a niche other than people who don't know any better.

    1. Re:REALLY, REALLY important /sarcasm by antifoidulus · · Score: 3, Insightful

      It seems as if they are trying to automate what companies pay experts a lot of money to do already: attack software from every concievable angle. The experts hired to do that can get quite creative, so of course the software is going to have to be quite good to get companies to consider replacing their experts, and I personally doubt they can do it. If it's worth anything, it will probably just end up becoming another tool of the trade. Though, as always, time will tell.

    2. Re:REALLY, REALLY important /sarcasm by Tim+C · · Score: 4, Funny

      This thing is going to have to be pretty darn impressive to actually find a niche other than people who don't know any better.

      In my experience, that's still a pretty big niche.

    3. Re:REALLY, REALLY important /sarcasm by onedotzero · · Score: 1

      True, but how many companies can afford these experts? Assuming they charge (partly) by time spent on trying to crack a site, presumably not many small to medium-sized companies will pay for a full range of techniques.

      In which case, an updateable boxed package may be something they would find value in. If they pass that and still get cracked, then perhaps it would be time to call in the big boys.

      Presumably this kind of tool is also part of the toolset of security experts? I don't know, but it seems like it would be a logical starting point.

      --
      onedotzero
      thedigitalfeed.co.uk

    4. Re:REALLY, REALLY important /sarcasm by vux984 · · Score: 2, Interesting

      So pay the experts for the really creative stuff and get the robot to do the 'basic' drudge work. Once your product has passed the robot then have the experts look at it.

      If it doesn't get passed the robot then you just saved a bunch of money by not bothering the expensive experts. If it does get passed the robot, then hopefully the so-called experts will no what its already passed and will focus their expensive time on being 'creative'.

      We generally let our compilers proof-read our code for errors before we have it peer-reviewed. This could be the same thing. No point in wasting someones time to find flaws that the machine can find on its own.

    5. Re:REALLY, REALLY important /sarcasm by jayloden · · Score: 1
      The experts hired to do that can get quite creative, so of course the software is going to have to be quite good to get companies to consider replacing their experts [...]
      ...or just cheaper.
    6. Re:REALLY, REALLY important /sarcasm by charlesnw · · Score: 1

      And I just saved a bunch of money by switching to Geico... uh I mean using
      Flawfinder.

      --
      Charles Wyble System Engineer
    7. Re:REALLY, REALLY important /sarcasm by netnull · · Score: 1

      I've seen the technology and it's impressive. It's intended for vendors to detect break points in their products. The fuzzing and mutation engine can really be relentless. The reporting is nice, particularly if you tie the console of the ToE into the mu box so that you can see any error messages side by side with their cause. Those vendors serious about securing their products should give this a look. You allude to the fact that experts do this type of testing, but once user-friendly automated tools come onto the market we will both an improvement in security, as well as a rise in attacks. Another difference is that this technology breaks boxes without finese. Finding exploitable logic errors without trashing the box will still be in the realm of experts.

  4. Satan/Santa by fatphil · · Score: 5, Insightful

    ... and several other ones already axist.

    I'd say that the only interesting thing about this announcement is an opportunity for geeks to analyse this new product and see if it contains any ripped off GPL'ed code.

    FP.

    --
    Also FatPhil on SoylentNews, id 863
    1. Re:Satan/Santa by ABCC · · Score: 0

      Virii and cracks are often released as GPLed code, so anything that includes a neutered version of those would be a GPL violation. Sounds a bit like a publicity disaster waiting to happen, and it's proof that the GPL is a viral license :P

    2. Re:Satan/Santa by fatphil · · Score: 1

      The publicity disaster will be when some crackers hack this company's website, and pw|\|x0R (is that how you spell it?) it.

      (Or just some good old fashioned DNS poisoning at the root servers - if that's good enough for RSA.com, it's good enough for these guys.)

      --
      Also FatPhil on SoylentNews, id 863
    3. Re:Satan/Santa by ABCC · · Score: 0

      well, publicity means reaching the general public imho. i was thinking of something along the lines of open-sores/gpl=filthy red commies licence/windows>linux stories you see on pcworld.

  5. In other news... by Anonymous Coward · · Score: 5, Funny

    cracker sues Startup over piracy of cracker's trade secrets via emulation.

    1. Re:In other news... by Anonymous Coward · · Score: 0

      Don't you really mean... .... we now can use enterprise cracker software stolen from crackers that sponge off hackers that steal information from systems that are allegedly protected by the anti-virus companies that intentionally miss rootkits that are placed by intellectual property companies that fight to allow Betamax to copy movies then create DRM hardware to fight piracy with technology as does government to fight terrorists by spying on our computers to protect your interests which includes information that is supposedly private but breaks the 4th since information is not property except to the RIAA and friends that argue you are stealing their property unless you buy from Itunes and when fill your 40 GB Ipod that would never be realistically used for any other reason but bootleg music that you downloaded using Bitorrent that's open source but Bram says shouldn't be used for illegal downloading though RMS wrote GNU and suggests information should be free.

      Com'mon that made complete sense.

  6. This is nothing new by possible · · Score: 4, Informative

    I read about this a couple days ago and spent some time on the company's site looking for an explanation of what they are doing that is so new. The answer I came up with is "Nothing". There is no information on their websites about specifc products or services. Looks like another snake-oil security startup.

    There are other companies and even some academic groups (PROTOS from the University of Oulu, to name one) who have been doing real things in this area for years. There are also companies that take a source-code centric approach.

    For several years now, there have been products that check for whole classes of vulnerabilities in applications. Such approaches are not limited to just known vulnerabilities in existing apps -- they check for common programming or configuration errors in custom applications as well. They are making it sound like checking for these things before systems go into production is a new concept. That's the whole point of security auditing.

    1. Re:This is nothing new by zopf · · Score: 1

      Yeah, this all sounds suspiciously (or at least auspiciously) similar to EEye's Retina scanner, etc. It's all been done before.

      --
      Did you see the pool? They flipped the bitch!
  7. No, but a couple of red-shirts will die trying... by Anonymous Coward · · Score: 0
    ... followed by the words, "He's dead, Jim."

    Sorry, that was too easy. :)

  8. Tip: by DrEldarion · · Score: 4, Funny

    While most crackers are pretty harmless, saltines are going to give you the most problem. Keep an eye out for Ritz as well, as I've personally had issues with keeping those out of my system.

    1. Re:Tip: by LordPhantom · · Score: 2, Funny

      Hmm.... Chris Rock might have a few things to say about "crackers". Now back to your regularly scheduled topic.

    2. Re:Tip: by gbobeck · · Score: 1

      Graham Crackers can be a real bitch too.

      --
      Navicula hydraulica plena anguilarum est. Omnes castelli tuus nostri sunt. Ed elli avea del cul fatto trombetta.
  9. What about their site... by bassgoonist · · Score: 0, Offtopic

    If we all go visit their site at once will they see it as a DDOS? :-p This is a cool idea, doesn't seem terribly novel to me though.

    --
    You can tell I'm an aries because of my ram.
  10. They spelt the name wrong! by oztiks · · Score: 0, Offtopic

    How the hell are crackers and skiddies going to know what the company is about if they dont spell it ... mU53ur1+y

  11. What about.. by SocialEngineer · · Score: 4, Insightful

    Does it call fed up employees who are just looking for someone to talk to, exploiting the conversation and getting valuable information necessary to break into the network? :)

    Cool concept, but I wonder about how effective it'll be without good admins who know how to watch logs, set up honeypots when necessary, and train employees to shut up. Still, it could have it's uses.

    --
    "Better to be vulgar than non-existent" -Bev Henson
  12. It's just a company making a product by Morgaine · · Score: 1, Interesting

    They are making it sound like checking for these things before systems go into production is a new concept.

    You make it sound like hyperbole in marketting is something outrageous and previously unheard of.

    It's a company, fer crissake. If it were an academic research group making out that they had invented a new concept, then that would be different and your criticism would be more valid.

    If their product has no technical novelty, then your remarks should be directed at Slasdot editors for accepting it as News For Nerds. The company seems to be offering another competing product in this market. And that surely is A Good Thing.

    --
    "The question of whether machines can think is no more interesting than [] whether submarines can swim" - Dijkstra
  13. MuSecurity.. by JWSmythe · · Score: 5, Funny


        "MuSecurity. We hack you first, so the hackers don't have to."

        "Pre-root your box for only $19.95"

        "Want a bot net? Have you own today!"

        Oh, testing for exploits, not actually exploiting the box.. hehe.

    --
    Serious? Seriousness is well above my pay grade.
    1. Re:MuSecurity.. by ozmanjusri · · Score: 5, Funny

      "MuSecurity. We hack you first, so the hackers don't have to."

      So they're a division of Sony, are they?

      --
      "I've got more toys than Teruhisa Kitahara."
  14. Oh great, more "red queen"... by venomkid · · Score: 4, Insightful

    More "keeping up with the hackers" nonsense. How about we just leave nothing permitted that we don't already know is legit?

    There's money to be made in treating cancer, but not curing it. And this is the IT equivalent.

    --
    vk.
    1. Re:Oh great, more "red queen"... by Anonymous Coward · · Score: 0

      Only on Slashdot could something like this be considered "insightful."

      You don't understand the first thing about security. Sad.

  15. Wheel v3.0 stable by theelemur · · Score: 0, Offtopic

    Sounds like a vuln scanner. y0 spoonm :)

  16. When crackers attack by Bill_Royle · · Score: 2, Funny

    For those of you that want to emulate a cracker attack, I cannot recommended highly enough any of the ABBA albums out there. Turn that on amongst any non-crackers, and you will know rapidly how well things will hold up.

    There are limits to this type of stress-testing, though - playing any "Rocky" movie will likely cause excessive bleeding from your ears. There's no reason to go overboard when cracker-testing.

  17. Other news by Anonymous Coward · · Score: 1, Funny

    In other news, the shares of the security company raised after it was leaked that Microsoft ordered dozens of vulnerability checkers.

  18. Hot off the press.. by js92647 · · Score: 1

    Man beats MuSecurity by throwing his computer out of the office window, successfuly proving it cannot stop hackers against completely breaking the security. Movie clip at 11.

  19. Juniper Staff by Anonymous Coward · · Score: 3, Interesting

    Almost all the staff is ex-Juniper. Talk about running off with corporate assets

  20. Known attacks by MichaelSmith · · Score: 3, Insightful

    Its the unknown ones you really have to worry about.

    1. Re:Known attacks by mmjb · · Score: 1

      Well, as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns -- the ones we don't know we don't know

  21. Did anybody else... by Anonymous Coward · · Score: 0

    ...read the title as: 'Startup Prepares Cracker Jack Emulator'?

  22. Just another module.... by Bananatree3 · · Score: 1

    for the RoboAdmin! Yes! You can have your very own fully automated system administrator, and now New and IMPROVED with automated security checks! If you ever need help with your IT issues, simply chat with the RoboAdmin chat bot and you will start feeling better in no time!

  23. This proves that... by Tune · · Score: 1

    ...crackers' IP cannot be properly protected by law (DMCA) and patents.
    The *only* way to protect virusses, spyware and other malware effectively from these kind of companies is through trusted computing, people. Go figure!

    1. Re:This proves that... by cp.tar · · Score: 1

      Wait...

      Are you saying I can prevent a virus from getting on antivirus programs' lists?

      --
      Ignore this signature. By order.
    2. Re:This proves that... by Tune · · Score: 1

      Hmm. My comment was actually intended as a joke.
      But seriously, if trusted computing ever takes off, in that it completely and ultimately limits users from peeking inside software (which I personally doubt) even malicious software will be below the radar. That's like a rootkit that a user cannot technically (or legally) detect, modify, remove, etc.

      Now your question basically translates as: will anti-virus companies behave as "user", or will they force, reverse-engineer or bypass TC layers in the OS?

    3. Re:This proves that... by cp.tar · · Score: 1

      Well, whatever happens, when 'trusted computing' takes off, I will most certainly not trust it.

      --
      Ignore this signature. By order.
  24. Obligatory... by kvonk · · Score: 1

    In Soviet Russia, product emulates YOU!!

  25. Maybe it's Da Fuzz? by PGillingwater · · Score: 4, Informative
    Without bothering to RTFA, it seems to me that they're not really talking about a library of known attacks like Nessus or EEye, but rather are discussing something like an automated tool that generates hundreds of thousands or even millions of potential attack vectors, similar to Spike or Scratch. For a nice roundup of Fuzzing links, check here. Note that Mu security is already listed.


    N.B. mu is a nice Japanese Zen word which means emptiness of mind, or literally "nothing."

       

    --
    Paul Gillingwater
    MBA, CISSP, CISM
    1. Re:Maybe it's Da Fuzz? by Slashcrap · · Score: 2, Insightful

      N.B. mu is a nice Japanese Zen word which means emptiness of mind, or literally "nothing."

      It's also a nice letter from the ancient Greek alphabet which means literally "mu".

    2. Re:Maybe it's Da Fuzz? by Cally · · Score: 1

      Woof! Woof!

      --
      "None are more hopelessly enslaved than those who falsely believe they are free." -- Goethe
  26. crackers by Anonymous Coward · · Score: 0

    damn white people, always hacking computers. we black folk, don't have none.

  27. Story Sez "Hacker;" Submitter Summary sez "Hacker" by RobotRunAmok · · Score: 1, Troll

    So what's with this "cracker" in the headline? And "cracker-in-a-box" is a Saltine.

    Please stop trying to kidnap the English language. C'mon, Geeks are supposed to be efficient: "Cracker" already means too many other things to effectively assume a new mantle, especially one already being served in the global media with "hacker." Yes, we're all sad that we benign computer hobbyists have to call ourselves "benign computer hobbyists" instead of the far more edgy-danger-cool "hacker" as we could for about a week-and-a-half in 1994, but time -- and language -- marches on.

    Seriously. Get over it. You're embarrassing the rest of us.

  28. Need... More... Sleeep..... by Stephen+Maturin · · Score: 1

    When I read the headline I thought this had something to do with saltines.

    --
    Non tam praeclarum est scire Latine, quam turpe nescire
    -- Cicero
  29. Biggest threat^D^D^Dcustomer ? by Anonymous Coward · · Score: 0

    And I bet their biggest customer is .ro eh ? Does it also come with a copy protection ?

  30. Headline should read: by EVil+Lawyer · · Score: 3, Funny

    Slashdot Editor Duped by Guerilla Marketer

  31. Is this new? by harris+s+newman · · Score: 0

    I thought there were a variety of products out there, some GPL'd that will do this same thing. Think nagios...

  32. QUICK! HOW DO I GIVE THEM MY MONEY? by Rogerborg · · Score: 1

    I demand that you provide more details of this revolutionary software product so that I may purchase 10,000 copies forthwith.

    Lesson to Slashdot advertisers: why buy an ad, when you can just keep submitting stories about some blog entry that promotes your product until eventually one of them sticks?

    --
    If you were blocking sigs, you wouldn't have to read this.
  33. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  34. Emulator or the real thing? by noidentity · · Score: 1

    If this carries out attacks just as the real thing, isn't this the real thing and not an emulator? (I haven't RTFA of course)

    1. Re:Emulator or the real thing? by fatphil · · Score: 3, Informative

      It's a good question, however there is a simple answer.

      There are at least 2 parts to each exploit. One is the route in (a buffer overrun, for example), and the other is the payload. You can test vulnerability by using the same route in, but with a harmless, or simply information-gathering payload. Other alternatives can include a patching payload.

      FP.

      --
      Also FatPhil on SoylentNews, id 863
  35. Ripped off Google Maps by Hextreme · · Score: 1

    Anyone else notice the ripped off Google Maps image on the 'Contact Us' page without credit?

    A company that doesn't give credit where credit is due doesn't deserve money.

    1. Re:Ripped off Google Maps by Anonymous Coward · · Score: 0

      Note the link on the page ' Map' points to http://maps.google.com/maps?q=1153+Bordeaux+Drive, +sunnyvale,+ca&spn=0.030960,0.060176&hl=en

      Hardly covert
      Don't you have any more noteworthy to critique?

  36. pump & dump by Anonymous Coward · · Score: 0

    looks like a pump & dump.

  37. Re:Story Sez "Hacker;" Submitter Summary sez "Hack by Anonymous Coward · · Score: 0

    100% agreed. In this headline it is particularly moronic, as one is misled to believe this is a tool for people developing copy protection.

  38. Funny Company Name by dozer · · Score: 2, Interesting

    MuSecurity looks like MicroSecurity (picture the little-mu greek character in front). Or, in ISO units, "very little security". Strange choice for a name.

  39. How about this thought? by Anonymous Coward · · Score: 0

    The staff are the most important assets a corporation can have. Sadly (for the corporation), staff has free will, rights to exist, rights to apply their skills..

        - AND -

    the right to start working other places.

    1. Re:How about this thought? by Anonymous Coward · · Score: 0

      Your post is confrontational, and yet you don't disagree.

  40. pffft... by p_cyde · · Score: 1

    we don't need emulators to crack... Signed, a Cracka (aka "user")

  41. They've had cracker attack emulators for years... by IronChefMorimoto · · Score: 1

    NASCAR race post-race fights between fans (crackers) of different drivers. 'nuff said.

    IronChefMorimoto

  42. Please people by Anonymous Coward · · Score: 0

    I'd prefer the term "Caucasian" or "White person." The term "cracker" is so insensitive. You clods.

  43. Good article on source code inspectors by hal9000(jr) · · Score: 1

    Jeff Forristal did a really good analysis of source code instection tools at Secure Enteprise Magazine.

  44. Re:A chair flew by... by Anonymous Coward · · Score: 0

    Enough of the fucking ballmer chair jokes.

    Im no Microsoft fan but for fuck sake give it a rest.
    It was funny at first but god damn it its so lame.

    moron

  45. Please RTFA by powers_722 · · Score: 1

    "Instead, Mu Security's product performs a thorough and methodical analysis along the many lines of inter-dependencies that exist among protocols. Understanding how to create the right type and set of mutations needed to systematically expose potential vulnerabilities in highly interconnected applications and systems - identifying both existing and "day zero" threats - is a key part of Mu Security's breakthrough in determining the security readiness of such a wide range of systems. Marrying such capabilities to a platform approach allows such analysis to be comprehensive, efficient, and repeatable. The net result is that Mu Security's solution has already uncovered multiple day zero vulnerabilities in every system analyzed."

    http://www.musecurity.com/

  46. ISEAGE project by Bender0x7D1 · · Score: 2, Informative

    As mentioned previously, this sort of thing is being/has been done. One project I am familiar with is the Internet-scale Event and Attack Generation Environment (ISEAGE) project at Iowa State University.

    Its webpage, has an overview of the project and documentation on its architecture and implementation. I think one of the key aspects of the project can be found in the overview: "Unlike computer-based simulations, real attacks will be played out against real equipment."

    ISEAGE is approaching security from a real-world perspective, using real world devices. Sure, your software/hardware might be secure when the attacks are played against it; but is it secure when those attacks when there are dozens of attacks occuring simultaneously? What about when it is being hit by thousands of requests, or is under a DDoS attack? What happens when devices decide to start breaking the protocols, or the rules? What happens if a device physically fails? What is the effect of a device overheating during a DDoS attack? How do you simulate this/test for this other than hooking it up and hammering it with a DDoS attack?

    This is the kind of information that is needed to prevent or mitigate an attack, but can't be found by reading code or running a scanner. How did the US figure out how to build rockets? We built some, they blew up, and better ones got built. The real world isn't the same as a lab.

    --
    Reading code is like reading the dictionary - you have to read half of it before you can go back and understand it.
    1. Re:ISEAGE project by Anonymous Coward · · Score: 0
      ---> Insert response containing castle/swamp/fire/monty python here <---
  47. Hacker, not cracker by hkb · · Score: 1

    Why does Slashdot continue with fruitless attempts to revise history by using the term "cracker"? It's not "cracker" and never has been. NEVER.

    Just face it, there are criminal hackers, and there are ethical hackers. The same as there are criminal locksmiths (eg thieves) and ethical locksmiths.

    If you want to try and change the term, at least don't lie about it and flame people when they quite rightly correct you.

    --
    /* Moderating all non-anonymous trolls up since 2004 */
    1. Re:Hacker, not cracker by Lxy · · Score: 1

      Why does Slashdot continue with fruitless attempts to revise history by using the term "cracker"? It's not "cracker" and never has been. NEVER.

      I think you're confused. In the beginning, there were "hackers" and there were "crackers". "Hackers" were geeks who built, tested, used, and otherwise understood the inner workings of things. Linus is a hacker. He wanted an OS for the PC that didn't suck, and used his knowledge to build a true hacker OS.

      "Cracker" refers to someone who breaks into things, usually with malicious intent. If an attacker installs a rootkit on your webserver, you have been cracked, not hacked.

      In the recent years the mass media morons have blurred the line, and the word "cracker" virtually doesn't exist. Now there's good (white hat) hackers and bad (black hat) hackers. Even that is starting to change, with words like "penetration testing" starting to redefine the white hats.

      Back to your original point, I agree with you that it's not worth fighting over anymore. The word "cracker" is pretty much gone forever, and eventually the word hacker will mean only "bad guy", with the good guys using the new terminology to distinguish themselves from hackers.

      --

      There is no reasonable defense against an idiot with an agenda
      :wq
    2. Re:Hacker, not cracker by dick+johnson · · Score: 1

      I for one prefer Saltines (though cheesits are pretty good too).

      --
      - dj
    3. Re:Hacker, not cracker by checkitout · · Score: 1

      Actually, cracker used to only refer to people who "cracked" games and other software. Hacker has always had dual meaning.

      It's simple: You hack systems, you crack software. Try and find old references to "cracking a system" vs. "cracking software", you won't.

    4. Re:Hacker, not cracker by hkb · · Score: 2, Insightful

      No, you are confused. Crackers are/were people who break software copy protection. This is how it's always been. I guess you weren't around "back then", or you were living in some other reality different from the planet Earth's.

      This is why 2600 is called the hacker quarterly, why Defcon is a hacker convention, why Phrack is called Phrack (Phreaking/hacking), and so on.

      It has never been the way you describe, never.

      --
      /* Moderating all non-anonymous trolls up since 2004 */
  48. Sounds to me like what they did... by foxtrot · · Score: 1

    ...was took a script kiddie, and then replaced the kiddie part with more script.

  49. Re:Story Sez "Hacker;" Submitter Summary sez "Hack by Anonymous Coward · · Score: 0

    The term has been around at least since the sixties.
    Some of us remember past the 90s.

    Before challenging an etymology, learn it.

    If you're confused by the multiple meaning of phrases or words then you must have a hell of a time coding. And if you don't code, we don't care.

    (score this as bait taken)

  50. Will it protect you against top posting? by Anonymous Coward · · Score: 0

    new security tool protects against top-posting on mailing lists.

    http://goodluv.diaryland.com/bottompost.html the bottom post enforcer

  51. Top 20 attacks on Windows? by Anonymous Coward · · Score: 0

    Does this have anything to do with OpenBSD or Trustix Linux?

    Windows, windows, windows ... oh you make me cry!

  52. I drove the cofounder to the airport by Anonymous Coward · · Score: 0

    I guess you gotta see it and talk to them. I spent a couple hours last week with Kowsik (CTO/Cofounder of Mu) and one of my engineers and I was fairly impressed. They intend it's use only in a lab environment and for the depth and speed the box has its uses. It also packages some features and reporting that are well thought out and actually mirror operational realities and convenience.

  53. Where? by Anonymous Coward · · Score: 0

    What open source software does this? Mu is selling a security appliance which does object based protocol fuzzing. What could you possibly think holds a candle to it? Spike? Peachfuzz? Ya, right. These people have power relays for automated restarting, they have target monitoring, they can play man in the middle, and it's plug and play right out of the box. It's powered by XML for god's sake. A company can buy this thing, hook their device into it, tell it which protocol it speaks, and get canned protocol stressing out of the box by pressing a button. You know what else in the world does this? nothing. Nothing Open Source, nothing closed.

    You're full of shit. Post one link to an open source fuzzer which treats protocols as object encapsulations, fuzzes them, and does so with zero configuration and full target monitoring.

    What were you going to say? Nmap? Nessus? Do you even know the difference between protocol stressing and vulnerability assessment?

    Fucking idiots on Slashdot getting moderated up for talking out of their assholes. It never fails. Solved the "noise problem" my ass.

  54. NO NO NO YOU ARE COMPLETELY WRONG by Anonymous Coward · · Score: 0

    Despite being moderated to the lofty score of 5 INSIGHTFUL, you couldn't be more full of shit if you spent an entire weekend eating helpings of creamy poop.

    Nessus, Satan, and Nmap are tools used in vulnerability assessment. The first two use security signatures to look for known software bugs and either report or exploit them.

    Mu is selling a security appliance which performs protocol stressing (aka fuzzing) on a known bunch of protocols. Other products in this category are Dave Aitel's (Immunity) Spike, Peachfuzz, a bunch of secret shit by HB Gary, well... there are a whole lot of them, but the important thing is this: they all suck dick.

    Now these moo clowns, they've got a nice front end, a gui, a smart fuzzing engine... the whole nine yards. There is nothing like this on the market. Nothing open, nothing closed.

    Now, I've used enough profanity to get myself moderated down, and keep you moderated up. And what's awesome is that you're totally wrong, and by being wrong you've totally warped everyone's perceptions of what's actually going on here. You've created anti-news.

    And it's wonderful, really, to see the moderation system in action - creating fiction, promoting lies.