CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Hacker Wargame Research Project - finding out how Hackers think image
Cyber Security
Anonymous writes "

The Hacker Wargame Research Project hackerwargame.org quietly sprang up with little publicity around the middle of April 2003. It is a Hacker Wargame just like hack.datafort.net or www.roothack.org, but that’s where the similarities end. Corporate Technologies USA, Inc (whose clients include government agencies) are looking for people who can compromise a fully patched Windows 2000 server from the Internet.

This is not typical / real world situation, leaving only two clear routes of attack.  Discover a new vulnerability, and subsequently produce a working exploit for it which is far fetched or go after server misconfigurations.  A social engineering based attack is pretty much ruled out by the fact it’s a lab environment.

The website gives off mixed messages, written in a light-hearted tone that would likely put of the more legitimate hackers / security professionals, unless that’s the intention of its *carefully* worded content with frequent mentions of the $250 you can get for successfully achieving a number of goals.  Corporate Technologies are a company who have both the experience and opportunity to run such a project, mainly in the form of their point man John A. "Cobras" Klein. Which leaves only the questions of why and what do they have to gain?  The faq page gives the answer to this question as

“In simplest terms, we are trying to figure out if we can spot the target of an attack based on the methods used so we can build a smarter IDS that thinks like a hacker does.  Of course, to make something think like a hacker, we have to know how hackers think, so we study them.”

However this does not really make sense.  They are willing to pay people $250 for finding / exploiting misconfigurations in their installs of Windows 2000 / IIS5 / MS SQL Server / Exchange server, or they are looking for people to find new zero day vulnerabilities in these Microsoft products, then exploit them?  If so first of all someone skilled enough, and with the resources to do this would likely have no reason to take part (certainly not a financial incentive), and even if they did the vulnerabilities would be found in the participants own time on their own systems beforehand.  Secondly anyone else with such knowledge would likely have a questionable background and therefore significantly value their privacy and have no reason to participate in a research project with the aim of finding out a whole lot of information personal to them.

Full Story
Rootsecure.net

"
Posted on Thursday, 01 May 2003 @ 08:59:43 UTC by cj (1937 reads)
[ Trackback ]
image

"Hacker Wargame Research Project - finding out how Hackers think" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· More about Cyber Security
· News by cj


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 3
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer