Step 1: Don't post to Hackernews that you hack into places
.. Tongue in cheek commentary aside, the title comes off more like the content would be on par with the grugq's presentation on Opsec for hackers (http://www.slideshare.net/grugq/opsec-for-hackers).
The argument to never modify anything only holds true for pentesting, for a slightly more nefarious attacker it's not unheard of to actually do some system maintenance & configuration fixing to close holes behind them to prevent other attackers from gaining access through the same entry point. Increasing the system stability has a tendency to make people look the other way, it's far less likely that someone would say "Hey, that server has been performing better, let's see if it's been compromised."
This seems to written for penetration testers who are actually paid to "hack into places" and have the consent of the system owner therefor are not breaking the law.
Comments
Step 1: Don't post to Hackernews that you hack into places
.. Tongue in cheek commentary aside, the title comes off more like the content would be on par with the grugq's presentation on Opsec for hackers (http://www.slideshare.net/grugq/opsec-for-hackers).
The argument to never modify anything only holds true for pentesting, for a slightly more nefarious attacker it's not unheard of to actually do some system maintenance & configuration fixing to close holes behind them to prevent other attackers from gaining access through the same entry point. Increasing the system stability has a tendency to make people look the other way, it's far less likely that someone would say "Hey, that server has been performing better, let's see if it's been compromised."
This seems to written for penetration testers who are actually paid to "hack into places" and have the consent of the system owner therefor are not breaking the law.
I'm sure he didn't even read the article.
I'm sure I did, but couldn't resist being a smartass