PaulDotCom mailing list archives

party trick to shut up the non-believers


From: strandjs at gmail.com (John Strand)
Date: Mon, 3 May 2010 15:09:18 -0600

Videos man, videos.

http://www.youtube.com/user/strandjsgmail

A few months back my dad asked me the same thing.  For the past few years I
gave the vague answer "computer security."   However, he was persistent, so
I showed him a video about bypassing AV with Metasploit.

Then, he got it.  He forwarded that link to some of his friends. They, then,
repeated the process...

After a few weeks I get an email from my mother where AOL as deemed a new
virus a CRITICAL!!! There is nothing they can do about it, etc...

Do you guys get this?  I mean, who gets their Internet virus news from AOL?


Anyway, it says "here is video to prove it!!!"

http://www.youtube.com/watch?v=ScTCJ88rplU

I open my sandbox and click the link.

Crap..  It's the video I sent my dad..

Now, when I visit my mom at work there are lots of uncomfortable looks,
people pull their coffee in a little closer..  And there's pointing..  Dear
God, the pointing.

But on the flip side..  I don't get asked to fix personal computers much
anymore.

You could also do this:

C:\>sort "%x %x %x %x %x"

Nice 504 trick.  Spend ten min talking about what a format string attack is
and they will leave you the hell alone.





On Mon, May 3, 2010 at 1:26 PM, Ali Alhebshi <alialhebshi at gmail.com> wrote:

ARP poison them. Sniff some images and passwords and let them wow!


On Mon, May 3, 2010 at 6:54 PM, Robin Wood <robin at digininja.org> wrote:

Hi
At a party the other day I was asked the normal question of what do I
do for a living. I said security and kept it a bit vague but was
pressed so explained what pen-testing is and roughly what I do. I then
got the challenge, prove it, prove you can hack a company.

People would say to a dentist, prove you can do a filling but this
person insisted they wanted a demo. I explained the legalities and
finally fobbed them off and got away but it got me thinking, has
anyone got any good party tricks that they can pull in this kind of
situation that give an instant wow but are easy to do and legal? Not
quite legal but I was thinking if I knew any big sites with XSS I
could rewrite but none came to mind at that time.

Robin
_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




--
Ali Al-Hebshi

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20100503/f42f2c36/attachment.htm 


Current thread: