Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Slashdot.org

Journal Journal: Slashdot Personals 3

Lately I'm beginning to see ads for "Slashdot Personals". Yay. I think I'd rather give homosexuality a try. Desperate OSDL marketeers ripping of desperate geeks on a site which is desperate for new "news". Woot!

User Journal

Journal Journal: The Mailbag 4

It came to my attention recently that my ongoing trouncing of CmdrTaco had been interrupted by having myself retired from Whatsbetter.com. Of course I had to do my best to rectify the situation, and the good folks at Whatsbetter.com were happy to oblige. Much to my dismay they had interpreted my lack of recent journal posting as a sign of my demise. While I admit I owe you all a status update on Slashcode (it's coming!) I will have to make do for now with some tidbits from the mailbag:

--

Hey sllort,

I've re-enabled the item... One of my admins must have retired it. Your /.
jounal has not been updated in the last 5 months. Spending your time at K5
these days? Or have you found new and better places to troll ;-)

Enjoy the site,
-chris

>hello, noticed that in the following pairing:
>
>http://www.whatsbetter.com/display.pyt?item=14198&item=14199
>
>one Slashdot user was retired as "old" and the other was not. Just wanted
>to let you know that neither user is old nor retired, we both write
>journals regularly, here are the links:
>
>http://slashdot.org/~cmdrtaco/journal/
>http://slashdot.org/~sllort/journal/
>
>I do not like being retired as "old", i'm only 27, i'm active on the site
>and i'm as active now as when i was added.
>
>let me know what you decide,
>
>-sllort.

Of course, I have no idea what he's talking about with this "trolling" nonsense, but he's re-activated my account for more Taco-crushing, and that's what's important. Thanks, Chris.

--

Hi,

as far as I am unknown, the best thing is to introduce myself.

Working in political sciences but interested by IT since I'm 15 (4 years
already), I just took some distant glances at /., so far. I just got
involved in the overall /. picture, until I got moderation points, too
quickly in my opinion.

I quickly realized that some deep trends where impairing the very spirit of
what was in my mind a quite flawless system. I posted various documented
posts questionning Apple's software, marketing policy, prices policy etc.
until I just went aware that they were plainly ignored, or modded down. I
just had the bad taste to say that, at last, Windows XP was a respectable
OS. I just had the foolish idea of defending Oracle.

Then I decided to make some researches about people in the same frustrating
state of mind as mine. And quite quickly I found this by now old story about
the troll survey. I found that many many clever people were relayed in the
remote electronical sphere of purgatory. And that maybe you were the boldest
one of these.

So my questions are naturally coming to you : what do you think of Slashdot
by now ? Did you improve to evaluate how many people were backing you ? Are
they any other sites as /., with other moderation/participation systems ? If
not, what about building an alternative one ?

It just looks like many of us stay frustrated by the current status of /.
And frankly this is sad.
If in any case you can't/don't want to respond, plz leave a blank message.
I'll keep looking for freedom advocates.

Regards,
Jdif

p.s : reading Top Ten ?

Wow. "remote electronical sphere of purgatory". Putting aside for a moment your... diction... yes, I've spent some time at k5 recently. K5 is what Taco would call "navel gazer's anonymous", what Seth Finkelstein would call "more writer fair", and what I would call "fractionally less fucked up". As far as being upset with /. - well, they've managed to stay "in business" for five years, and nobody's threatening their market niche yet, though God only knows if they're profitable. It's a sad thing that some real assmasters are in charge, but we can always hope that something better will come along - or as you point out, we can do something about it.

As far as reading goes, allow me to suggest the September and October edition of Trollback - the new editorial staff deserves plenty of praise.

-s.

User Journal

Journal Journal: More rantings and pornography!

Yes yes, it's that time again. Not really, I'm just bored at the moment and after reading this bit about some porn peddler being governor of California, I decided it was time to update this thingy again! So, move over Larry Flynt, you amateur! Make way for the professionals!

Remember, don't forget to mark me a foe so you never get too see my journal updates. Hmm. That didn't make sense, did it? Also, you people ought to be glad that there are individuals like me daring enough to filter out crappy pornography of really ugly women. That series might be bad enough to cause impotence, so be warned. I'm in favour of equeal oppurtunities but I say that girl's future is NOT in the porn business. Yuck.

User Journal

Journal Journal: Porn wants to be free!

And so it came to pass that pornography became free! Enjoy and stop before it starts chafing, that'd look mighty awkward in the emergency ward. Not a pleasant idea. Maybe the masochists among us are more interested in that. Sandpaper anyone?

That said; only 3 RPC calls from 3 different IP adresses... Now be a dear and mark me as a foe while I might or might not try to post a story about SCO being part of the Illuminati. Novus Ordo SCO!

User Journal

Journal Journal: Pornography for the people! 4

Yes yes, have to keep the masses happy, right? The latest harvest of thumbnail galleries has been pretty much catastrophic lately so I'm digging up older bookmarks. Thumbnail galleries can be quite good once you filter out all the popups, referral scripts, traffic trading scripts, animated gif banners and all that. Nothing a bit of PHP, some knowledge of coding/scripting and a hormone high can't solve. Anyways, you people most likely don't come here to read my rants, so onward, without hesitation!

Now get lost and make me your foe! Kudos to SlashChick btw :P

User Journal

Journal Journal: Argh! 9

Only 87 people hate me! Outrageous! I made fun of canadians, americans, dutch people, tourists and whatnot and still only 87 people. :( Come on people, you can do better! I'll use the patented, copyrighted and effective method by posting links to pornography with some unwitty text! Cheerios lads!

Now, go on minions, make me your foe! You know you hate me!

Censorship

Journal Journal: Think the RIAA is alone?

... Well, forget about it. The RIAA has got a nice and tiny and insignificant little ally, the Buma/Stemra, henceforth known as "those leeches who charge you extra per DVD.". Did you think all those scary stories about putting an extra charge on DVD/CD media (regardless of actual purpose) were just tales to frighten away John Doe from doing anything? Well, guess again.

All those stories are a reality here in the Netherlands. The store where I work nearly got sued by said organization. Why? We were playing music CDs on the showroom PCs. Want to buy a CD or DVD? Be prepared to fork over another 20% per item. (On top of the already 20% VAT. That's 40% wasted.) Thank God the Dutch law system is fcked up beyond belief to the point where USian lawsuits are impossible, or else I'd be certain the store where I work would be sued to death by now.

Then again, the extra money they charge per CD/DVD do make me feel a bit better. Sure, I download and copy stuff like C&C Generals and MOO3, more or less feeling bad about it. But those were HORRIBLE games and I'd feel worse AND 50 Euros poorer if I had bought them. Good games are an entirely different issue: I actually feel bad about not having a legal version of Vice City. Good games are worth the money. At least the money they now charge will ease my conscience a bit! ... Or at least make my wallet a bit lighter...

That said, I wonder if there are any other dutch people around here who know which companies support the current course of action our RIAA-clone is taking? It'd be nice to cough up a list of those companies and declare their goods to be freely copied. After all, we are being charged for something we haven't even done, so we might as well do it.

Carry on, minions!

Slashdot.org

Journal Journal: Krow Dead at 2 7

I just heard some sad news on talk radio - Slash Team icon Brian Aker's job at OSDN was found dead in the noncompetitive OSDN payroll ledger this morning. I'm sure trolls and /bots alike will miss him - even if you've been freaked by everyone, there's no denying that krow was the Slashcode contributor that didn't suck. Truly a Slashdot icon.

He will be missed.

Slashdot.org

Journal Journal: IRC Fun 18

Well, yesterday's IRC thing went off without me, though had I been there, my questions would have been dumped anyway, so no big deal. It's a pretty long log, so I took the liberty of snipping the good parts and adding some translations for those who don't speak Slash. Hope you enjoy, and I apologize in advance for any inaccuracies.

Question
Answer
Translation

<Questions> w00t asks: Will /. users ever be able to change the "look and feel" of Slashdot? Such as the colors, and general layout?

<CmdrTaco> Maybe a little, but not much. 20:04
It's computationally expensive.
<hemos> The new machines will be 2x P3 1.4 Ghz, with 2 gigs of RAM.
<CmdrTaco> It's programatically tricky.

Even removing images will increase our computational workload. We'll never change this, but patches are always welcome.

Patches are always welcome tho ;)

<Questions> reefer asks: Is there any system in place or a plan on developing some system to prevent duplicate posts?

<CmdrTaco> Whatever. 20:06
Next.
<hemos> Reefer: There is one.

We have a pretty good system that we copied from fark, but Rob still sneaks a couple through.

<Questions> jew asks: At LWCE 2000 NYC, you stated that you were considering developing alternate systems of accessing the site's content than HTTP/HTML. You mentioned NNTP. Have you considered or implemented any alternate means of accessing the site, such as RRS? If not, why?

<CmdrTaco> We don't have time to implement much in the way of other protocols.
<hemos> CmdrTaco: We did try the chat thing with whatever program that was.
Er, not chat. 20:07
Discussion thing.
<CmdrTaco> Yeah, we had an IRC bot.
That gated stories & discussions.
Salsa.
That was fun.
Worked really well.
Nobody used it :)

The trolls had a very popular IRC bot called Slashbot that gated stories, and we murdered comments.pl and banned about a hundred IPs to shut it down, but we shut down our version because no one used it.

<CmdrTaco>Karma isn't worth anything. Why would we change that? 20:09

Except for: how many posts you can make a day, your initial comment score, your ability to moderate or metamoderate, and almost any other interaction with the site, that is. We'll never change karma's fictitious worthlessness like we did before.

<Questions> OcelotLM asks: Have you considered changing the Games colour scheme to something less garish?

<hemos> Hahahaha
<CmdrTaco> Whateever.
Next.
<hemos> You should have seen the first round of it.

Ok, ya, it sucks. Get over it. Remember Slashdot succeeded because our HTML is the best.

<CmdrTaco> (I'm just skipping trolls btw ;)

I'm not going to tell you why moderation is anonymous and why we IP banned www.w3c.org from our site. This is because the answers are not for those among us who do not drink the gin with the tonic.

<Questions> limerickey asks: What happened to John Katz?

<CmdrTaco> We had to let him go during a round of layoffs last summer.
We miss him, and were sad to see him go. 20:15
He added a lot to Slashdot, and it was really unfortunate.
<hemos> the acerbic nature of some of the people also turned him off.

Realized that if he continued to pander his career for Matrix fans, he'd never work as a journalist again. Also the trolls.

<Questions> sebi asks: Did you ever consider adjusting the amount of moderator points based on Metamoderation results (like add a point for every 100 fair metamods, subtract one for every 5 unfair ones ore something like that)

<CmdrTaco>what you are asking is does M2 affect getting M1 points.
And yes, it does.
If you meta modearte, you will get more mod points. 20:17
It isn't 1 point for 100 fairs or anything.
But it's a lot.
If you moderate good, and meta moderate whenever it is offered to you, you can get mod points fairly quickly.

See, we created a discussion site, which by its very existence proves that people disagree, otherwise there'd be no need for discussion, and then we've implemented a moderation system based on the idea that disagreement over what "to moderate good" means is impossible. There exists, in this world, "absolute good" and "absolute bad", and we have written a system to detect it in Perl. Thank you. Thank you very much.

<Questions> TrollBridge asks: Despite the junk that trolls (as I myself once was) have posted in the past, is it a fair statement to say they have indirectly contributed to the polishing of the Slashcode?

<CmdrTaco> I'm sure there is no web discussion system that is harder to crapflood than Slashdot.
So thanks for making us have to waste our time writing that code.
We COULD have had RSS for subscribers or NNTP interfaces or something.
<hemos> I can say personally that the trolls have taken time away from my kids birthda's.
So, I hope you feel very proud of that.
<hemos> What I would say is the trolls have made it so that we haven't made features
<hemos> but instead have had to think of ways to stop people from accessing the site.
It sucks having to program stuff to prevent a crapflood when we COULD be adding cool fun new shit for folks.

We're not going to address what the trolls have done, but the crapflooders have really fucked with us. We blur the distinction; you should too. P.S. even though no one could crapflood Fark.com to save their life, we're even tougher. The routine, unchecked scripted crapflooding of sid=20721 is proof.

<Questions> mmh asks: Will there ever be a section dedicated to site issues and discussions? Stuff like Slashcode updates, hardware issues, suggestions, etc. Whenever things come up in regular stories, people posting about it are off topic. It would be nice to have a place for this (and a place that you guys read to get the suggestions).

<CmdrTaco> www.slashcode.com has some of that.
<CmdrTaco> My journal has some more of that.
<hemos> The problem with one section for discussing is that then no works gets done.
<CmdrTaco> I don't foresee a Slashdot section dedicated to Slashdot.
There are only so many hours in the day,
I can't spend all of them talking about what I do,
<hemos> Because it's navel gazing at its finest.
<CmdrTaco> and then still have time left to DO anything.
We're not 50 people here.
And I don't want to read a website about Slashdot.
I hate reading websites where half hte content is discussion about the website.
CNN isn't about CNN.
many community driven content sites are OBSESSED with themselves.
I'd rather not be.
A couple forums a year. A journal entry a week. A few hudnred emails a day.
Isn't that enough :)

If we'd had a META section, or listened to our users, we could have ripped off the early-story subscriber plum years earlier - same thing with CAPTCHA. And I don't think we were ready for that then. So, no, sounds like a bad idea.

<Questions> pwrlnkid asks: Have you given any thought to allowing subscribers to see the story queue and "moderate it". Seems to be an easy way on your parts to get rid of dupes or old news.

<CmdrTaco> FAQ!
FINALLY!
Next.

Mention K5 again and I'll kill you.

<CmdrTaco> Mmm. Scotch.
<hemos> Man, I'm getting a G&T.

We watch anime. We lease our BMW's. We drink gin & tonics. We solved the drivel problem. Excuse us.

<hemos> Yeah, the patch situation is a fun one.
Because the reality is that hardly anyone submits pathces.
<hemos> So, yeah, the code is open...but really that just means people donwload it and install it.
<CmdrTaco> We don't get many patches. Which is really unfortunate. 20:44
<hemos> Yeah, essentially we have all the costs of being OSS
without any of the benefits.
<CmdrTaco> We spend a lot of time making the system (relatively) easy to install for others, but we're not actively getting a lot of benefit back.
We do it more out of a labor of love than for business reasons.
We really WANT this thing to be open source. We think its cool. 20:45
<hemos> Because we end up supporting people using it, but get nothing back.
Frankly, if I were deciding it strictly on business merits, it's current status as open source is a lot of work without much back.
<CmdrTaco> There is no other open source CMS that will work on the scale of slash.
But most people just want a dinky little site.
They can use one of the *nuke clones.
They don't need a steak, they're cool with hamburger ;)

We don't know why people don't feel motivated to contribute. It annoys us how at K5 there's all these cool features added by users like those awesome Dynamic Comments, and we're stuck back here in the Stone Age with Nested Mode (I mean STEAK MODE). Oh well - pass the alcohol .

<Questions> erigol asks: Have you considered setting up a slashdot Wiki, since Wiki's are, like, the rage, and stuff.

<CmdrTaco> Wiki is silly. Not scalalble.
<hemos> Wiki's make me want to guage my eyes out.
gouge, even.

WE MAKE THE STEAK. THE STEAK IS THE BEST. KEEP YOUR MUTTON AWAY.

<CmdrTaco> Users in .d bitching that we post Microsoft Ads ;)
<hemos> Hah.
<CmdrTaco> I can't understand why that offends people. I find it hilarious.
<hemos> The irony of that is amazing.
<CmdrTaco> SCO shoudl advertise with us.

How can something be bad ironic when it pays for our single malt? That's good ironic. Bad ironic is when we IP-ban the W3C, because that doesn't pay for STEAK, BMW leases, or gin. Puh-lease.

<Questions> Cephalien asks: Out of curiosity: Do you think that the ever-growing popularity of Slashdot, and the occasionally negative publicity offered there towards certain companies (Microsoft comes to mind), do you think that those companies might intentionally seed people to post comments? If so, how often, and how much do you think that effects the overall 'feel' of the comments about a story?

<CmdrTaco> I'm sure it happens to some degree.
<Aaton> CmdrTaco: no problem
<CmdrTaco> But astrotrufing by a major corporation will never outnumber Slashdot's population.

Unless they get ahold of that script that routinely floods sid=20721... but we don't talk about that.

<CmdrTaco> Web petitions are stupid. I delete them all.

My IQ is not zero, and I can prove it.

<CmdrTaco> I don't want to say something will "Never" appear on Slashdot.
If someone could convince me, I'd do anything.
Moderation with names attached?
Open Submissions Queue?
But few people understand the scope of such changes.

These two features have been implemented at K5 already, dumbfuck. Do you really think we'd copy someone else's feature? We're the STEAK, they're navel-gazing hamburger. Sister puh-leaze.

<CmdrTaco>What's sad is that anonymous posting serves a very important purpose.
It exists so that you can say thigns that might be held against you.

Remember how earlier we said Carnivore was watching so anonymous posting wasn't really anonymous? Keep thinking about that while I fix another drink..

Slashdot.org

Journal Journal: Slashdot Interview Tonight 3

There's an IRC interview with Taco & Hemos tonight. I won't be there, I have plans tonight. There are millions of things that could be asked: why are messages now batched so we can't tell when we've been mass moderated, why are the moderation totals hidden so we can't tell when a comment has been mass moderated, why are comment numbers randomized instead of starting at 1, what percentage of editor moderation is "Over/Underrated" (we've been handed the editor's aggregate M2 stats forever, why not document the loophole?)

The way they run these interviews is usually that you submit to a question bot, but can't talk, and they pick questions off the bot. In short, none of the above has any chance of getting asked. Neither do the following three questions, though they are probably the three questions to which the answer is the most interesting:

  1. Why doesn't a Moderation Results message include the name of the Moderator?
  2. Why aren't we told when an editor moderates our posts?
  3. Why is the W3C HTML Validator at www.w3c.org IP banned from Slashdot?

Have fun folks, and remember, Never disturb a man.

Slashdot.org

Journal Journal: The Easy Way to W3C Approval!! 7

The absolute best way to to get the W3C to validate your site is to ban their IP address. Because, if your HTML doesn't check out, who's the wiser?

I'd like to take this opportunity to congratulate Rob & co on not having a gigantically flawed W3C validator page for the first time in their illustrious five-year history. Way to go, guys!

Security

Journal Journal: Fyodor Responds... Kinda 11

Well, Fyodor wrote a rather lengthy reponse today, collating a whole bunch of geocities pages in order to prove that any allegation made against him is false, and that he is not a terrorist.

I don't really know what to make of his response: it's weird, because he kind of denies hacking sdem's computer, but he doesn't deny posting screenshots of sdem's page to his website, and talks about "trolling trolls" and "rhetorical devices".

I honestly can't make heads or tails of it - I thought that his page on breaking into sdem's machine was a much better piece of writing on his part - but here's the link for you all to try to make sense of:

http://interviews.slashdot.org/comments.pl?sid=65960&cid=6080152

Interestingly he accuses me of slander and says that he would press charges if he weren't busy with an important project. That certainly would be interesting, considering I could haul at least ten witnesses into any courtroom that saw his "Troll Hunting 101" post.

Completely weird.

Slashdot.org

Journal Journal: Modbombing and Interview Control 18

Update: This comment by an AC claims that a user moderator, not an editor, was one party to the moderation attack on this comment. While an AC comment doesn't prove much, it is at this point pretty unlikely that editors were involved. I'd like to remind everyone reading that the name of the posting account isn't sufficient information to grade an entire post; in this case, the linked post is factual, polite and accurate, and fully deserving of the +5 Interesting score the users originally gave it.

--
Original journal entry:
--

Slashdot interviews send the best of the 5-rated user comments to an interview candidate. Users pick the best questions, and Slashdot sends the interview. Right?

Maybe.

Take a look at the Fyodor Interview. Scroll down to this comment which asks, in a polite fashion, whether Fyodor has ever chosen to use his hacking skills to break the law, and cites the Slashdot troll hacking incident detailed earlier in my journal. This question received a score of 5 from the users of Slashdot, and was therefore eligible to be part of Fyodor's interview.

Today, alert reader Gendou pointed out that four days after the story posted, a flurry of moderation activity had occurred in this posts's thread. The post was moderated down as a "Troll", heavily, till it reached threshold 3, and every comment in the thread which mentioned Fyodor's hacking incident also received large quantities of "Troll" moderation.

Now, who gets moderator points, opens up a four day old story, and starts using moderation to push an agenda? More than 5 points were used in the attack, which means that either a large group of users acting in concert attacked the thread, or a user who is gaming Slashdot's system attacked the thread, or an editor did it. Who was bent on removing any shred of legitimacy from complaints that this question was not forwarded to Fyodor?

The users of Slashdot gave this comment a score of 5.

Slashdot Moderation is unaccountable, and I don't know who did this. For now, I'd like anyone who saw that the users of Slashdot moderate this question to 5 to vouch for that fact in the comments, as I am vouching here. We may never find out who manipulated the comment scores, but we can set the record straight.

Security

Journal Journal: New Fyodor Evidence Released 16

Trollaxor.com has obtained a cache of Fyodor's "Troll Hunting 101", briefly posted to www.insecure.org/tmp/trolls in 2002 by Fyodor shortly after hacking the computer of a Slashdot prankster. I have been advised that the images and content in this cache have been modified to protect the name and personal information of Fyodor's hacking victim (SumDeusExMachina) which Fyodor initially saw fit to publish. The modifications appear in bold and are clearly marked as REDACTED.

I would like to invite anyone who witnessed this firsthand in 2002 to post a comment certifying that this content is accurate to the best of their recollection below in the comment section.

I personally certify that this content was posted to www.insecure.org in 2002, and that I personally loaded and witnessed it.

The Cache.

Security

Journal Journal: What Can Illegal Hacking Do For MY Business? 19

Slashdot has an interview with security legend Fyodor, admin of the famed insecure.org and author of the world's most affordable port scanner, nmap.

The best part of this interview is that Slashdot does not often interview criminals. Many Slashdot readers know that Fyodor used his tool to illegally attack a college student in 2002, for his personal amusement but also to the benefit of Slashdot's admins. For those that don't know the story, I will present a brief summary.

*Those individuals interested in independently verifying the facts presented in this article should skip to the "Verification" section near the end.

Sdem had created a hoax account entitled electricmonk, and used it to post this comment pronouncing that he was actually a cute Linux booth babe. "electricmonk" left an email at Yahoo and encouraged Slashdot readers to get in touch.

Fyodor proceeded to do so, boasting of his previous exploits with women he'd met online. He was even helpful enough to attach a picture.

This is where the story turns ugly. Sdem responded with a truthful email, in which he advised Fyodor that the whole thing was a hoax. After that, sdem posted a log of his exploits to sid=20721 (trolltalk), mentioning that he had tricked Fyodor and referring to many of the biters as "wankers". This apparently really set Fyodor off, and he began to plot criminal revenge.

First, Fyodor dug through insecure.org's referrer logs to find what IP address had requested the picture of Fyodor & his paramour. Using this information (and the logged User-Agent), Fyodor knew from the get-go Sdem's IP address and O/S. From this point, he launched nmap against Sdem's box and was greeted with the holy grail of sorts for BlackHats: an open X windows server on port 6000.

Sdem had been running an X-windows server for Windows on his Win2k box. Fyodor was able to bypass the authentication on the X-windows server and used the X-windows server to take complete screen captures of Sdem's machine whilst sniffing and recording keystrokes.

Fyodor proceeded to take hours worth of screen captures, including information on a "secret troll irc server" that sdem was using. Fyodor wrote a detailed writeup of what he observed, including an irc robot used on the server to detect new Slashdot stories for the purpose of early posting. Fyodor also mined and posted as much information about Sdem as he could find, including his real name and contact information. Jamie McCarthy used this illegally obtained information shortly after it was posted to log on to the irc server, monitor the bot, and modify Slashdot in order to break the story monitor.

Fyodor even submitted his "troll hunting" story to Slashdot, though it was rejected.

After he was done hacking Sdem's computer, Fyodor posted his screen captures and a log of his breakin to www.insecure.org/tmp/trolls. The content was removed 24 hours later. He went on to boast in sid=20721 about his "troll hunting finale". While sid 20721 is regularly cleaned, a cache of Fyodor's boasting about his illegal break-in is available here. Very interesting reading.

So, while Fyodor's interview is no doubt very interesting, I think that, as an accomplished (and due to the lack of prosecution very successful) criminal, the nature of questions given to Fyodor in the interview don't do justice to the type of expertise this man has in illegally penetrating computers across state lines and getting away with it. I'm sure that many companies would like to have a man of this caliber at their disposal in order to infiltrate and destroy their competitor's IT infrastructure.

Of course, no sane person would use this man's software without compiling it from inspected source, given his history. Fortunately the folks at Redhat pore over his code with a fine toothed comb before including it in their distribution, so if you've ever wanted to peer into the mind of a madman, I encourage you to take a look at Redhat's copy of nmap.

Also if anyone has a cached copy of fyodor's insecure.org/tmp/trolls page, please let me know in the comments so we can get it hosted. This particular piece of sordid Slashdot history just became more relevant.

Additional reading:
Sdem's account of the incident
Trolltalk cache, circa break-in
Cache of Fyodor's "Troll Hunting 101" from www.insecure.org/tmp/trolls

Verification:
Above are caches of both Fyodor's bragging about the break-in on his web site, and his bragging in a Slashdot comment about having hacked Sdem. Numerous people witnessed this and have posted comments in my following journal entries certifying to the veracity of these mirrors. To date, no one at Slash Team and no one at insecure.org has denied it. Nor will they; they have almost certainly been advised by legal counsel not to speak about it in public.

That said, any journalist or researcher wishing to pursue this story may wish to take additional steps. The Slashdot editorial staff was well aware of this story when it happened. Jamie McCarthy used Fyodor's information to penetrate the irc server Fyodor discovered and attack the irc bot he found there. Jamie McCarthy and Michael Sims are both aware of the details surrounding this incident and can confirm their recollection and involvement in the incident by email. Their email addresses are easily available to a curious researcher so I won't bother repeating them for spam robots, but suffice it to say that asking Jamie the question "did you see Fyodor's page on his web site in which he took screen captures from a hacked trolls computer" will probably yield you positive confirmation. There is the possibility that they won't want to involve themselves for legal reasons, but I doubt it. Jamie is historically honest to a fault and forthcoming when approached with a legitimate question.
So, if you're a doubter, email the Slashdot editorial staff. Fyodor is a Black Hat, and the eds know it.

Slashdot Top Deals

Old programmers never die, they just hit account block limit.

Working...