<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: &#8216;Security Consultant&#8217; Caught for Running Large Botnet</title>
	<atom:link href="http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 04 Dec 2008 21:23:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: James C</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-117790</link>
		<dc:creator>James C</dc:creator>
		<pubDate>Tue, 11 Mar 2008 20:18:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-117790</guid>
		<description>@ Sir Henry
I use torture to do my background checks on staff I hire, probably the reason I don’t have any at the moment.</description>
		<content:encoded><![CDATA[<p>@ Sir Henry<br />
I use torture to do my background checks on staff I hire, probably the reason I don’t have any at the moment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dirty</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-117493</link>
		<dc:creator>dirty</dc:creator>
		<pubDate>Mon, 10 Mar 2008 20:11:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-117493</guid>
		<description>No, no one is required to sign anything unless they have certs like CISSP, etc.

It just paints a negative image for people in our field</description>
		<content:encoded><![CDATA[<p>No, no one is required to sign anything unless they have certs like CISSP, etc.</p>
<p>It just paints a negative image for people in our field</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Lion</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-116719</link>
		<dc:creator>J. Lion</dc:creator>
		<pubDate>Thu, 06 Mar 2008 15:58:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-116719</guid>
		<description>Does all security consultant need to sign an official document saying that I will do ethical stuff only before working as a security consultant?

What's to stop a security consultant from saying "Pay me Protection Money or else..."?</description>
		<content:encoded><![CDATA[<p>Does all security consultant need to sign an official document saying that I will do ethical stuff only before working as a security consultant?</p>
<p>What&#8217;s to stop a security consultant from saying &#8220;Pay me Protection Money or else&#8230;&#8221;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-83565</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Fri, 14 Dec 2007 18:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-83565</guid>
		<description>@CG:

I am in agreement with Dirty on this.  Background checks are only as efficient as the technical abilities of the person performing them.  In any environment, people will hire someone who has technical expertise  unrivaled by anyone else in the environment.  That leads to situations like this.  Not sure what the solution is other than to beef up the technical knowledge of those hiring and those performing the background checks.</description>
		<content:encoded><![CDATA[<p>@CG:</p>
<p>I am in agreement with Dirty on this.  Background checks are only as efficient as the technical abilities of the person performing them.  In any environment, people will hire someone who has technical expertise  unrivaled by anyone else in the environment.  That leads to situations like this.  Not sure what the solution is other than to beef up the technical knowledge of those hiring and those performing the background checks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goodpeople</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74410</link>
		<dc:creator>Goodpeople</dc:creator>
		<pubDate>Mon, 19 Nov 2007 22:41:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74410</guid>
		<description>&#62; On another note, I use this nick waaaaay too much. I dont have
&#62; any others… I should go fix that some time.

which is why I started using Goodpeople.. :-)</description>
		<content:encoded><![CDATA[<p>&gt; On another note, I use this nick waaaaay too much. I dont have<br />
&gt; any others… I should go fix that some time.</p>
<p>which is why I started using Goodpeople.. <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74367</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Mon, 19 Nov 2007 19:45:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74367</guid>
		<description>Thats kind of a bad thing... because people would check and would find you have no history, and say "hm, he must be hiding something"

On another note, I use this nick waaaaay too much. I dont have any others... I should go fix that some time.</description>
		<content:encoded><![CDATA[<p>Thats kind of a bad thing&#8230; because people would check and would find you have no history, and say &#8220;hm, he must be hiding something&#8221;</p>
<p>On another note, I use this nick waaaaay too much. I dont have any others&#8230; I should go fix that some time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goodpeople</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74044</link>
		<dc:creator>Goodpeople</dc:creator>
		<pubDate>Sun, 18 Nov 2007 18:26:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-74044</guid>
		<description>Checking people's online behavior is a good place to start. But then again.. I use different nicknames on different sites. The name Goodpeople is only a few months old...</description>
		<content:encoded><![CDATA[<p>Checking people&#8217;s online behavior is a good place to start. But then again.. I use different nicknames on different sites. The name Goodpeople is only a few months old&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dirty</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73577</link>
		<dc:creator>dirty</dc:creator>
		<pubDate>Fri, 16 Nov 2007 20:00:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73577</guid>
		<description>&lt;strong&gt;CG:&lt;/strong&gt;
Background checks will only reveal if theyve been caught before.  Even NSA's and CIA's checks and security clearances miss some people.  Think of all the spies that are found out.</description>
		<content:encoded><![CDATA[<p><strong>CG:</strong><br />
Background checks will only reveal if theyve been caught before.  Even NSA&#8217;s and CIA&#8217;s checks and security clearances miss some people.  Think of all the spies that are found out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73544</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Fri, 16 Nov 2007 17:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73544</guid>
		<description>I have the dodgy philosophy of not having a problem if its yet another hole in a microsuck program, but getting pissed off if they do shit like this against open-source stuff. I do want them to get owned by a vuln they themselves sell at some point, mind...</description>
		<content:encoded><![CDATA[<p>I have the dodgy philosophy of not having a problem if its yet another hole in a microsuck program, but getting pissed off if they do shit like this against open-source stuff. I do want them to get owned by a vuln they themselves sell at some point, mind&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73363</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Fri, 16 Nov 2007 05:28:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/#comment-73363</guid>
		<description>i'm actually a supporter of 0day and full-disclosure (but not really a supporter of their business model).  0days keep sysadmins, network admins, security consultants, people that write exploits, security companies, AV, etc in business, busy, and getting paid.  it also keeps the technoidiots in fear mode which is also good for the above.

Now, if i was actively writing 0day i might feel different but since i am in the "i wish people would release more exploits for these vulns" camp i like people releasing exploits but not necessarily selling them (that's a whole other issue)</description>
		<content:encoded><![CDATA[<p>i&#8217;m actually a supporter of 0day and full-disclosure (but not really a supporter of their business model).  0days keep sysadmins, network admins, security consultants, people that write exploits, security companies, AV, etc in business, busy, and getting paid.  it also keeps the technoidiots in fear mode which is also good for the above.</p>
<p>Now, if i was actively writing 0day i might feel different but since i am in the &#8220;i wish people would release more exploits for these vulns&#8221; camp i like people releasing exploits but not necessarily selling them (that&#8217;s a whole other issue)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
