Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 43 guests and 1 member online
You are here:
EH-Net
May 18, 2013, 12:32:31 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Malware
(Moderator:
don
) >
Joe McCray's Exploit Development Workshop
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: Joe McCray's Exploit Development Workshop (Read 7331 times)
0 Members and 1 Guest are viewing this topic.
superkojiman
Jr. Member
Offline
Posts: 59
Re: Joe McCray's Exploit Development Workshop
«
Reply #15 on:
February 11, 2013, 09:16:41 PM »
Quote from: cd1zz on February 11, 2013, 06:48:43 PM
If you haven't heard, Mr. McCray is in a bit of hot water in regards to this course...Google
full
fu. (Damn dumbphone)
Just read the blog posts on it. Bit disappointing. Still, I hope he comes up with his own material and starts over.
Logged
OSCP, GSEC
cd1zz
Hero Member
Offline
Posts: 561
Re: Joe McCray's Exploit Development Workshop
«
Reply #16 on:
February 11, 2013, 09:23:46 PM »
He addressed it on his blog but still, why would he put his entire reputation at risk if all he did was use their VMs? Just seems like he must have done more, or, it was just an extremely stupid move. I just don't understand why you would jeopardize everything to save like a day or two of work.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: Joe McCray's Exploit Development Workshop
«
Reply #17 on:
February 11, 2013, 09:25:37 PM »
Based on this
http://blog.exploitlab.net/2013/02/defending-our-work-part-2-exploit-lab.html
he did a whole lot more than just use the VM's
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
cd1zz
Hero Member
Offline
Posts: 561
Re: Joe McCray's Exploit Development Workshop
«
Reply #18 on:
February 11, 2013, 09:28:54 PM »
I know, but on his blog he basically says he only used their VMs.
http://strategicsec.com/blog/
- that's what I'm saying, his rebuttal doesn't make any sense.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: Joe McCray's Exploit Development Workshop
«
Reply #19 on:
February 11, 2013, 09:35:47 PM »
None of it makes sense.........
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
MaXe
Hero Member
Online
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Joe McCray's Exploit Development Workshop
«
Reply #20 on:
February 11, 2013, 10:48:53 PM »
Quote from: Dark_Knight on February 11, 2013, 09:07:35 PM
This has got to be a MISTAKE!!!!! Given the likes of attrition.org and the infosec community at large, why would any sane individual in the community so BLATANTLY rip off some else's work? And then go on to charge for it? Seriously??
Why would someone go to such great lengths at advertising a course that they STOLE? How could someone be so brazen?
Makes no sense....
No it's not. Many people defy attrition.org and the infosec community at large still. The length at which strategisec ripped off others' work is not just limited to a single episode. It's spread out across multiple vendors.
However, most of the "students" who are also doing all the hard work, are simply taking other infosec courses and rewriting them into strategisec courses, easy way to minimize the amount of work you have to do.
Quote from: cd1zz on February 11, 2013, 09:28:54 PM
I know, but on his blog he basically says he only used their VMs.
http://strategicsec.com/blog/
- that's what I'm saying, his rebuttal doesn't make any sense.
It doesn't make sense any sane infosec professional would do this, but this is the case and it is not the only case. The only thing that makes sense, is simply that it shortens the time needed to come up with new courseware. It's the easy way to make money. Use others' courseware, modify it so it looks like your own, sell it cheap, profit. It's almost like the botnet business and I know this sounds harsh, but it's about cutting corners and taking shortcuts.
Quote from: Dark_Knight on February 11, 2013, 09:35:47 PM
None of it makes sense.........
It does make sense. I am not sure who authorized to copy other vendors' courseware, but if it was Joe McCray himself, he may not be the whitehat / ethical hacker other people believe he is. I myself, do not know. I only know that this has been going on for months.
Fun side-note:
Quote from: TheMatrix
Neo: Right now we're inside a computer program?
Morpheus:
Is it really so hard to believe?
Your clothes are different. The plugs in your arms and head are gone. Your hair is changed. Your appearance now is what we call residual self image. It is the mental projection of your digital self.
Neo: This...this isn't real?
What is real? How do you define real? If you're talking about what you can feel, what you can smell, what you can taste and see, then real is simply electrical signals interpreted by your brain.
«
Last Edit: February 11, 2013, 10:53:51 PM by MaXe
»
Logged
I'm an InterN0T'er
DragonGorge
Jr. Member
Offline
Posts: 83
Re: Joe McCray's Exploit Development Workshop
«
Reply #21 on:
February 11, 2013, 11:51:55 PM »
Uh, I think I'll take a pass on Mr. McCray's offerings...
Wow, reads like an article in the enquirer.
http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/
Quote
At this point I didn’t care anymore, I was so angry with him for being such a cowardly bitch that I couldn’t stand it. I swore that the next time I see him there was gonna be some furniture moving. Yes ChrisJohnRiley THIS IS THE NEW BLACK I was 2 seconds away from whooping Saumil’s ass. I was ready to put my foot so far up his ass that his breath would smell like shoe polish!
I told him explicitly (yes that means I dropped a lot of F-Bombs) how I felt, and that I’m not paying him the remaining money because he and Hiren are both some bitches. After that – all of these notes I rewrote, scripts I ported from perl to python, lab manuals that I wrote – for him as a gift to show my appreciation that he mentions in his blog post, and yes his precious virtual machines – I used them in classes, webinars, and workshops I taught. I did it to spite him. I was pissed at him – immature I realize – but at least it’s the truth. I might as well try to make my money back after all of this mess.
Saumil and anybody else for that matter – you can write whatever you want about me. You can put me on what ever page you want, talk about me on twitter, but at the end of the day Saumil can have a hot steamy cup of FUCK YOU! At this point I flat out don’t care how many people you tell, how many people talk about this on twitter. I hope that every single human being on this earth learns how much of a whining wimpy little bitch you are, and knows that I can’t stand you and I would rather eat hot shit before I’d even acknowledge that you are a fucking human being let alone speak to you.
No I’m not paying you, and I sincerely feel bad for every single incident of a people loosing respect for me with regard to this issue, I know that I will never do it again because there is no HUMAN being that would ever be the way that he was to me, but I refuse to continue to talk to people like you are a good person when I know you are not.
So Saumil, and Hiren – I just want you to know what I think of you personally, and professionally.
From the bottom of my heart…
FUCK YOU!
Joe
Logged
MaXe
Hero Member
Online
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Joe McCray's Exploit Development Workshop
«
Reply #22 on:
February 12, 2013, 12:05:47 AM »
He's beginning to sounds more and more like Gregory D. Evans.
(
http://attrition.org/errata/charlatan/gregory_evans/
) Except that Joe, actually knows something.
Logged
I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Joe McCray's Exploit Development Workshop
«
Reply #23 on:
February 12, 2013, 03:47:05 AM »
That's too bad about McCray. He seemed like a pretty cool dude the times I've heard him interviewed, attended webinars, etc. All those issues explain a bit of the flakiness he's had with courses and events. He could have made the same points using a bit more tact.
@MaXe: Yea, he's definitely not a charlatan. I guess everyone has a breaking point and just needs to vent... I probably wouldn't have used a corporate blog through
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
MaXe
Hero Member
Online
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Joe McCray's Exploit Development Workshop
«
Reply #24 on:
February 12, 2013, 04:40:35 AM »
Using a corporate blog in that way has just severely damaged their reputation more than it already is, and writing "fuck you" and threats of physical violence only attracts trolls and those who may want to prove Joe wrong that he's not the smartest nor the strongest guy in the world.
If he makes a response video (which I doubt as he's not Greg Evans), it will most likely become viral and be "songified" or perhaps even get unwanted attention from organisations/hives/groups such as Anonymous.
I do however, look forward to how the aftermath will unroll. Personally I'm hoping for drama, popcorn, perhaps even a movie. Mostly because of the other affected vendors.
Logged
I'm an InterN0T'er
DragonGorge
Jr. Member
Offline
Posts: 83
Re: Joe McCray's Exploit Development Workshop
«
Reply #25 on:
February 12, 2013, 09:07:50 AM »
Quote from: MaXe on February 12, 2013, 12:05:47 AM
He's beginning to sounds more and more like Gregory D. Evans.
(
http://attrition.org/errata/charlatan/gregory_evans/
) Except that Joe, actually knows something.
Hard to believe that Anonymous hasn't taken this guy down already. World's #1 Hacker indeed.
http://gregorydevans.com/
Quote
He could have made the same points using a bit more tact.
Never a good idea to drive, e-mail, or blog angry.
I'm thinking McCray has some other things going on in his life besides the financial troubles and (intense) dislike for the folks at exploitlabs.
Logged
superkojiman
Jr. Member
Offline
Posts: 59
Re: Joe McCray's Exploit Development Workshop
«
Reply #26 on:
February 12, 2013, 10:22:37 AM »
Quote from: DragonGorge on February 11, 2013, 11:51:55 PM
Uh, I think I'll take a pass on Mr. McCray's offerings...
Wow, reads like an article in the enquirer.
http://strategicsec.com/2013/02/12/the-final-statement-on-this-issue/
Quote
At this point I didn’t care anymore, I was so angry with him for being such a cowardly bitch that I couldn’t stand it. I swore that the next time I see him there was gonna be some furniture moving. Yes ChrisJohnRiley THIS IS THE NEW BLACK I was 2 seconds away from whooping Saumil’s ass. I was ready to put my foot so far up his ass that his breath would smell like shoe polish!
I told him explicitly (yes that means I dropped a lot of F-Bombs) how I felt, and that I’m not paying him the remaining money because he and Hiren are both some bitches. After that – all of these notes I rewrote, scripts I ported from perl to python, lab manuals that I wrote – for him as a gift to show my appreciation that he mentions in his blog post, and yes his precious virtual machines – I used them in classes, webinars, and workshops I taught. I did it to spite him. I was pissed at him – immature I realize – but at least it’s the truth. I might as well try to make my money back after all of this mess.
Saumil and anybody else for that matter – you can write whatever you want about me. You can put me on what ever page you want, talk about me on twitter, but at the end of the day Saumil can have a hot steamy cup of FUCK YOU! At this point I flat out don’t care how many people you tell, how many people talk about this on twitter. I hope that every single human being on this earth learns how much of a whining wimpy little bitch you are, and knows that I can’t stand you and I would rather eat hot shit before I’d even acknowledge that you are a fucking human being let alone speak to you.
No I’m not paying you, and I sincerely feel bad for every single incident of a people loosing respect for me with regard to this issue, I know that I will never do it again because there is no HUMAN being that would ever be the way that he was to me, but I refuse to continue to talk to people like you are a good person when I know you are not.
So Saumil, and Hiren – I just want you to know what I think of you personally, and professionally.
From the bottom of my heart…
FUCK YOU!
Joe
Daaayuuum...
Logged
OSCP, GSEC
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(4) by
impelse
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
Web Applications
: Nessus and Nikto
(3) by
Cyber.spirit
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.