Okay, I'll bite.
Quote:
In my opinion, what you are suggesting is worse then anything I've seen posted here so far (and as a senior member I hope to god you're joking) and on par with writing viruses and distributing them.
No, I was not joking. And the reason I "Set aside" the ethics discussion was because it had already been covered multiple times in the entire thread, obviously. There was no reason to repeat it.
Quote:
Ethics and morals can never be 'set aside.'
Agreed. But that doesn't mean I'm going to post something that repeats what the previous four posters have said.
Quote:
I understand where you are coming from but you have no way of targeting script kiddies when doing something like that you're just doing a blanket attack against anyone that downloads the exploit. Some of you MUST understand the 'educational prupopses' and know its not a bunch of BS. I have some tutorials written on coding and compiling exploits and they are on their way.... Tutorials on the useage IDA, hailstorm, and other black-box testing utilities are coming as well. I am in discussion with the authors of 'Exploiting software: How to break code' in regards to using some of their content.
What in the name of Tao are you talking about? It was a humorous warning because many of us have seen instances identical to that. Calm down and see that I never said I was going to do that example, but explained that it is quite possible. I don't care who you work with or what you have done, nor how long you have been here. What does matter to me is how you present your opinion. I am completely fine with it being an "educational site" with downloads based upon exploits, but there is a rather large difference between educating someone and merely handing them a shotgun. Proof of Concept does not mean "free to all, don't ask don't tell". I respect that you want to "educate" people on it, but don't think for a second I don't see how it can be misused. You can't ignore it.
Quote:
My point is the 'educational purposes' stance is not just a 'way out of trouble'. The whole point of the site is to educate those willing to stick around and learn. Provide tools and infomation to make it fun and easy, and "lessons" to provide some sort of direction. Some of you DO get that.. I see it in the webtraffic logs. People are coming to the 'Tutorials' section [some of which are republished from here with authors concent - thanks guys! ] and reading! I'm thrilled to see 25% of the visitors stay for an hour... you're reading! You're really reading! hehe
And that's fine :) Welcome to AO. But don't mistake all of us here for whitehats, because I'm most certainly not. I'm a greyhat by all curiosity means, and thus if I find it funny that people are posting compiled (read: ready to use) and people download them for shits and giggles. This means that I'm 100% about security through curiosity and the betterment of the internet through oldschool hacking means (security testing without permission to fix/improve/safeguard). This also means that the moment someone tries to run a precompiled exploit (or any attack on me for that matter) and I catch them, I burn their fscking OS into the ground.
Instead of posting precompiled binaries (which I would never trust regardless of content, because exploits simply are not precompiled for sane people, even securityfocus and packetstorm knows this), post how to compile something. Teach them compiling methods and the basics of compiling.
Quote:
It is unfortunate - and my own fault, that you've seen the site now and not after completion because it is not my intention to create a 'script kiddie' download site.
It looks good so far. Just don't mistake us all for people who are so young that we can't remember that when exploits were released, it wasn't ever working code and binary files certainly weren't going to ever be released for the masses. The first step to lessen the impact of script kiddies was to make their lives more difficult. If you precompile it for them, you've just included the mass amount of people who don't know how to compile and thus wouldn't have been able to run it in the first place.
edit Don't think we are attacking you, demeaning you, insulting your work or project. Seriously, may the Tao bring wisdom and progress upon the path of your project. Just be ready for a difference of opinion on AO, and that it is okay to have one.