Page 1 of 3

Attention, Legacycontinues. You, are an idiot.

Posted: Thu Mar 31, 2005 10:52 pm
by gen2600
I'm really quite sorry I couldn't respond to you in "DDDDDaaaaammmmmmnnnnnn!!! *That had to hurt*" thread. But it became locked a bit to quickly for me to respond.

So, please, allow me now - before this thread gets locked too.
legacycontinues wrote:Do you know a Travis Ogden?

Does he have a brother named Tim?
:idea: I do! I do! In fact, I AM Travis Ogden! Yay you found me! So, since you were asking this question of "rallitektech" I assume that YOU must first know who I am. Right? I would not imagine you'd ask such a thing without yourself knowing in fact who you were talking about - that'd be idiotic! Of course HE knows me, we're good friends!

Yes, I am a reformed hacker myself appearing in three books (genocide@Genocide2600.com), wired, laptop magazine, a slew of other texts/magazines etc and writing for the 2600 magazine (some years back). Yes I used to work for the Department of Defense for four years firewalling and doing intrustion detection and yes I worked with the FBI on tracking down child pornographers. Finally, yes I work at a major unix shop doing computer security... But you already knew all that!

Oh, uh, who the hell is Tim? My brothers name is pretty easy to figure out, if you actually read the website and it's no where close to Tim. That one is just odd - I'll need you to explain that to me.

In case you are wondering, I am the guy who runs the website rallyrabbit.com which you apparently found in his signature file. Before you said:
legacycontinues wrote:I'm your worst nightmare you piece of shit. Try me and see!! I'll wipe that sorry excuse for a website clean and then sell the domian out from under you guys.

I can do this all fucking day! You want to talk shit and open your big mouth thats fine...
You can do what all day, make a fool of yourself and make idle threats? I'm confuzed.

I must admit I did find that to be rather amuzing and I did utilize that statement to break the dull repetitious monotony of what I refer to as "a real job" - it made me laugh and I brought some friends over so they too could be amuzed as well. Thanks! You've brightened mine and others days!

So tell me! PM if you must, where might you start on your elite haxoring of my server? I admit, this could be great fun for everyone involved! Please allow me to be the first to say, let me "try and see"!

I am a little disheartened that you'd call it a sorry excuse, I did spend a whole 20 minutes with a simple text editor on it. :cry: ...oh well.

Before you launch into your elite haxoring of my server and apparently "wipe that sorry excuse for a website clean and then sell the domian out from under you guys" I was wondering if you'd allow me to give you some pointers to assist you in your quest and furtherment of your goals. Oh, once on the server you'll need to know where the site resides, here ya go: /usr/home/traviso/public_html/rally/rabbit/ - hope that helps!

First off, if I were you, I'd want to perform some "recon" of the target! In this case, my domain. Hmm, this might be a tough one if you aren't used to it. I'll save you a little time and point you to the primary host of the domain: infohammer.net.

Ok, lets go! A port scan won't show you much other then the very few open ports I have open through my firewall (I run ipfilter if you are curious) like ssh2 and apache on port 80. But wait! There is a snag! Dang! While you'd be portscanning me (and I can suggest some great portscanners if you are interested, personally, I use NMap which even has a stealth scan - which I detect) you've just been finger printed by my IDS (intrusion detection software) that was running transparent to you or your connection (meaning you wouldn't notice it during your attack). Woops, now I have your mac address and IP :(. Uh oh, I know where you live and who your ISP is. Which is bad, because the people I get my service from in my colocation are going to be angry, I will be bemused and the people you subscribe to will drop you like a hot potatoe! Uh oh! no more midget fisting porn! Personally, I think midgets in porn are just creepy.

So, actually I might suggest trying to spoof your mac address first and or possibly try your recon from a different node other then your pc where you apparently make all of your brilliant and enlightening posts from.

Probably during this first stage of your "attack" you'd like to do an OS finger print so you can find out what type of system I run before you wipe it off the planet so you can find 0-day exploits for that OS! Woops, another gotcha. Nevermind, I wouldn't try that, it's going to misrepresent my OS (display something not real)! Doh, you'll spend hours trying to figure out why your elite 0-day exploits just don't work! Man, that sucks! Oh well.

Second, you'd probably want to take the 0-day exploits (actually, if you can't find any, pm me - I'll send you to some websites) you've found and engage in the attack! Awman! So cool! Oh wait, crap, Travis Ogden has patched ssh2 and apache as well as bind on port 53. Awnuts. Another gotcha, crap - remember, don't get caught by my IDS (by the way, I run Snort which you can get or read about at http://www.snort.org. It's pretty sweet, I wrote about 600 of the rules it uses to profile attacks!). ...AND you got logged by the firewall, doh.

That sucks, oh well, at least you can probably (I should hope so anyway) launch a DoS (Denial of Service) attack! Whoa! That's elite! Wait, crap, if you are just going to do a DoS - you can't wipe my server out. Crap. You can at least point the software at your desired host "infohammer.net", hit go and just watch as the website is brought to it's knees because you are blasting so many packets to that host so fast that the computer just can't keep up! WHOA! SWEET! Now those 3, maybe 4 people who might have visited my website today MIGHT NOT GET THERE. AWYEA! You are rollin' now! Lol :wink: ...oh wait.

Damn, you got logged by my firewall AND fingerprinted by my IDS and probably black holed (i run portsentry - by psionic software - which writes a null route for portscanners and with some modification - DoS'ers, like mine!). Damn, so - actually probably none of your packets even made it to my site to bring it to it's knees after the first couple, and - CRAP - you can't even talk to my server anymore. Whoa, that's a buzzkill. See why you should do this from another machine?

Lastly, you'll probably realize there isn't much you can do without physical access, if you would like to fly cross country - I'll give you the physical address of where the server is, including which floor and suite the colocation is located at. Hell, just for fun and something to laugh about, I'll give you a place to stay while you try (I have a spare bedroom and a big BBQ!).

In the end you'd probably have given up your physical location by being finger printed by snort and being logged by ipfilter. Your mac address is specific to your network device (modem, ethernet card, wireless card etc). Since your silly tries have been cross state lines you're probably in trouble with the feds. Since you've wasted bandwidth that I pay for, you'll probably end up paying restitution, my internet provider will probably have you removed and black balled (yea, you are used to that!) from ISPs in your area, hair will grow on your palms and your pets will be ugly, if you do end up in prison it'll most likely be a federal pound me in the ass prison. Let me know how the tits tatt'd on your back work out!

So, in finality, I guess, if you think you have the shoes princess, please, lets dance :)

Travis Ogden
traviso@Infohammer.net
Genocide@Genocide2600.com

Posted: Thu Mar 31, 2005 10:55 pm
by BAC5.2
Who want's some popcorn?

*sits in the front row*

Posted: Thu Mar 31, 2005 11:23 pm
by Nomake Wan
BAC5.2 wrote:Who want's some popcorn?

*sits in the front row*
*sits right next to you and takes some popcorn* Oh man, this is gonna be da shiznit! I laughed my arse off, and this is only the opening!

Posted: Thu Mar 31, 2005 11:29 pm
by gen2600
I'll post attempt logs from him just to keep everyone in the know :)

Travis

Posted: Thu Mar 31, 2005 11:30 pm
by 206er
hey Ive got some jelly beans, trade you for some popcorn.
this ought to be good...

Posted: Thu Mar 31, 2005 11:36 pm
by BAC5.2
I hate Jelly Beans, sorry :(

Posted: Thu Mar 31, 2005 11:37 pm
by Kelly
<---cracks open a beer.

Posted: Thu Mar 31, 2005 11:48 pm
by jamal
WARNING: YOU ARE BROADCASTING AN IP ADDRESS!

Posted: Fri Apr 01, 2005 12:29 am
by corsair
I happen to like jelly beans.

Mr. Odgen you know your stuff, how does one go about persuing a career path like yours?

Posted: Fri Apr 01, 2005 12:34 am
by THAWA
Does anyone honestly think anything is going to come of this?

Posted: Fri Apr 01, 2005 12:51 am
by Nomake Wan
THAWA wrote:Does anyone honestly think anything is going to come of this?
Not really. After being shot down like that, I doubt anybody's gonna get up and continue... no pun intended, I swear.

...but I think what we're all hoping for is a reason for Travis to post something like he did again. After all, it was a wonderful read. :)

If something really did happen, it'd be like an unexpected sweetness.

Posted: Fri Apr 01, 2005 12:52 am
by Binford
God, I hope so! I'd hate to have missed the first thread until it was edited "slightly", I'm sure, then read through all that^ only for it to come to halt now. I'm up for some entertainment! I'll be optimistic and snatch some of that popcorn from you guys, if you don't mind!

Posted: Fri Apr 01, 2005 1:14 am
by gen2600
jamal wrote:WARNING: YOU ARE BROADCASTING AN IP ADDRESS!
Pleasantly so, actually, if he likes, I'd be glad to provide my home ip, the ip of my server in South Dakota, the colocation ip that is connected to the server in question and even my work ip :) - anything that would help...
corsair wrote:I happen to like jelly beans.

Mr. Odgen you know your stuff, how does one go about persuing a career path like yours?
Why thank you, actually, I'd seriously suggest against going about it the way I went about it. If you are really curious, then I'd suggest reading this book:

http://www.amazon.com/exec/obidos/ASIN/ ... 43-6982405

...which they talk about sort of how I got into hacking then into computer security. Although, I must point out - when I got into computer security things were different, laws were different and people in high places were far more ignorant then even today (yes, it IS possible). If you were to do what I did - you'd be in jail for a very very long time. I did not apply to work for the DoD, I was pressed into service for four years on a "contract". It was a great thing that led to a pretty solid career though that path would be near impossible to follow today.

Today, I'd suggest getting into an OS other then Windows, Linux or Freebsd (a personal favorite) or maybe even solaris, build the box and learn how it works. Security is really an extension best left for stepping to after one knows "how the systems work" at a very intimate level.

Linux, FreeBSD and Solaris 10 can be came by for free. If you want more info, feel free to pm me and I'll submit some sources for you to go through.

Travis

Posted: Fri Apr 01, 2005 1:24 am
by scottzg
I find this terribly funny.

Posted: Fri Apr 01, 2005 1:26 am
by dscoobydoo
OK, even though I did not understand all of the internet security lingo, that was a well written rebuttal. And I have gummi bears to add to the jelly beans and popcorn.

(grabs an open seat)

Posted: Fri Apr 01, 2005 1:28 am
by J-MoNeY
BAC5.2 wrote:Who want's some popcorn?

*sits in the front row*
Image

Posted: Fri Apr 01, 2005 1:49 am
by legacy92ej22t
I like popcorn, gummies and jelly beans. Hell, I think I'll stay just for the food!

Posted: Fri Apr 01, 2005 1:54 am
by dscoobydoo
OK, and correct me if I am wrong, but was he not booted from another forum for something similar to this??

Posted: Fri Apr 01, 2005 1:56 am
by Yukonart
Travis. . . hat's off to you. It's not a Blackhat, but it's a hat, nonetheless. ;)

Posted: Fri Apr 01, 2005 1:58 am
by J-MoNeY
This used to be such a drama free place. That makes baby J cry. :_(

Posted: Fri Apr 01, 2005 2:05 am
by corsair
I use Fedora about 33% of the time, this summer I figure I'll sit down and fully get to learning it.

That book looks pretty good, yay for Amazon account.

as to Thawa's question

what's this mean

legacycontinues
Voluntarily Dismissed

<---- over there where he posts

Posted: Fri Apr 01, 2005 2:38 am
by AWD_addict
I'll grab drinks for all the food.

Posted: Fri Apr 01, 2005 3:14 am
by 91White-T
Oh no, dont tell me this is now gonna become drama central like every other damn forum out there. Say it ain't so.

Posted: Fri Apr 01, 2005 3:38 am
by azn2nr
whats up guys. anyone like milk duds and m&m's (pulls up a seat)

Posted: Fri Apr 01, 2005 4:01 am
by corsair
I think we need a favorite junk food thread.