Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Recommendations
Salvia
Wow I have been away from the forums for a while and just got done reading the Complaint article. Well I could say some things about people calling the board kiddies then threatening DDoS, yeah that makes alot of sense smile.gif

Okay but now what this topic is meant for is Recommendations. What do you people think could be done around the board to improve what is going on here at GSO?

I would like to see all the member's input on this one.

I personally after reading the complaint section see that there is a huge hostility towards memberships being locked down. so here are my recommendations:

1) Unlock Membership,
2) Move Trial Member's to Full Member's
3) Remove Trial Membership Group
4) Remove downloads section
5) Make it very clear that autohax0rs are not allowed
6) do not allow people to upload attachments
6) Make some more advanced discussion areas that downloads/ attachments are allowed in.
7) Make those advanced areas paid subscription (This will deture some fxp problems)
8) Still in the paid areas don't allow autohax0rs
9) Don't Delete 0 posters

What will this accomplish?
It will get rid of the Negative attention from people not being able to become full members.
Because autohaxors are not allowed fxp kiddies will go elsewhere to get their utilities.
Because downloads / attachments are not allowed you won't have to spend so much time moderating and making sure skiddies are not backdooring utils. (Plus save alot of bandwidth)
Having paid areas will more than likely only interest the people who are serious about network security.

Why not delete 0 posters? well for instance I am a member on many forums where I never make a post at all because those forums are informational sites to me only I really have no reason to offer my input. For example I have been a member of IPB forums for nearly 5 years yes it sais only 3 years there but that was because my account was deleted for inactivity of more than 6 months. But I am there for searching articles to find answers on stuff, I am havng problems with. I have very few posts there. Some sites no posts at all.

As long as people are logging into those accounts we should leave them alone.
But if an account shows that someone has not logged in within 6 months it is safe to say they are not coming back.
AdmiralB
I believe we shouldn't abolish the systems.
The seperation is to prove that the member isn't here just for nonsense.
If we remove this preventive systems,flamers would just come back with
more power this time and this move would probably encourage more of them to arrive.
I recommand to hold the system for the time being and wait
Salvia
QUOTE(AdmiralB @ May 21 2005, 08:09 PM)
I believe we shouldn't abolish the systems.
The seperation is to prove that the member isn't here just for nonsense.
If we remove this preventive systems,flamers would just come back with
more power this time and this move would probably encourage more of them to arrive.
I recommand to hold the system for the time being and wait
*



Yes very agreeable, But the paid sections is what I am refuring to as a way to separate the garbage from the people who are serious about security, this will help get rid of the anomosity towards the board and show people GSO is moving towards a more professional image.
Serhat
here's what I think..
I am witnessing that the staff warns many of those 'problem' members.. and I am not sure after how many warns, but if it reaches 100% they'll get banned etc.. (BN says: usually 30% gets you the boot)
and those kinda accounts are beeing removed constantly..
imo there is nothing really wrong with the system we have..
it will take some more time to get these kinda people out of here..
so time is what's needed.. imo..
of course.. could be that it could be that GSO changes some lil stuff after this topic.. but then again imo we shouldn't need drastic changes

Serhat
Head_Hunter
QUOTE(Salvia @ May 21 2005, 07:52 PM)
Why not delete 0 posters? well for instance I am a member on many forums where I never make a post at all because those forums are informational sites to me only I really have no reason to offer my input. For example I have been a member of IPB forums for nearly 5 years yes it sais only 3 years there but that was because my account was deleted for inactivity of more than 6 months. But I am there for searching articles to find answers on stuff, I am havng problems with. I have very few posts there. Some sites no posts at all.

As long as people are logging into those accounts we should leave them alone.
But if an account shows that someone has not logged in within 6 months it is safe to say they are not coming back.
*


This is very true. IF you expect people not to give someone a "good job" post, then why delete their account cause they dont post. Sometimes people dont post tutorials if they dont feel anyone appreciates it. How are you supposed to know if you are on track with a tutorial or not. But on the flip side, it takes up "valuable" spaceand some say its useless... Kinda of a catch 22.
tibbar
i personally dont fancy gso becoming another paid site like astalavista.

the current system is working well imo, just because two people complain, doesn't mean the other 30,000 are unhappy.
plinius
QUOTE
the current system is working well imo

I agree about that, however, I allso agree with:
QUOTE
IF you expect people not to give someone a "good job" post, then why delete their account cause they dont post


So, I think that the system works OK, I still don't see why you can post "thank you" ( It's maybe 0.5 % of the people who post thank you that post "thank you" for increasing their post-count....)...

just my opinion
SyS49152
well if I can say my word ..
I don't like people that get knowledge without giving out their tricks ..
and
I don't like people that have no knowledge and waste the job done by
others (kiddies).
So for me the trial member system and
0 posters deletion is ok ..
Partizaan
I think the admins alway make it very clear what is allowed and what not.
They warn enough and take actions.

Altough expanding the sections is a good idea.

But information is free. I guess if members want to support do it on a free basis. Like paypal or so. But please ... no payed memberships. Info must be free.

Terminal
I am not sure if trial memberships should be removed or not but gso should be kept free to people smile.gif
And yeh membership should be kept open as we see that mods are doing a good job and we can help them by reporting posts of "thank you" posters smile.gif
sabrodiesel2000
QUOTE
I personally after reading the complaint section see that there is a huge hostility towards memberships being locked down. so here are my recommendations:

1) Unlock Membership,
2) Move Trial Member's to Full Member's
3) Remove Trial Membership Group
4) Remove downloads section
5) Make it very clear that autohax0rs are not allowed
6) do not allow people to upload attachments
6) Make some more advanced discussion areas that downloads/ attachments are allowed in.
7) Make those advanced areas paid subscription (This will deture some fxp problems)
8) Still in the paid areas don't allow autohax0rs
9) Don't Delete 0 posters



i think that memberships should be locked it reduces down the incoming trashy traffic too.... trial membership group is a very good thing to check on the level of the user if its capable to join the gso member group, this way the admins & mods can keep an eye on the new comers.... uploading attachments involved risk........and i believe like several others here that gso should be kept free......... autohaxors should be DISALLOWED here atleast.......... 0 posters should indeed be removed as this board is i believe for contribution and not just being selfish and using it lol.......

well these are just my views and i do not control the views of others so feel free to share comments...

but serhat believe me the incoming trashy traffic will still be there even after 2 years time cuz its neverending thing... u guys just have to keep eyes open for them...

<system working fine>
Spookie
QUOTE
1) Unlock Membership,
2) Move Trial Member's to Full Member's
3) Remove Trial Membership Group
4) Remove downloads section
5) Make it very clear that autohax0rs are not allowed
6) do not allow people to upload attachments
6) Make some more advanced discussion areas that downloads/ attachments are allowed in.
7) Make those advanced areas paid subscription (This will deture some fxp problems)
8) Still in the paid areas don't allow autohax0rs
9) Don't Delete 0 posters


My comments to this may irritate some but I will voice them none the less.

To the comments of 1 -2 -and 3

Membership should remain locked untill the Admin/Mods feel it is appropriate to open it up again for a limited time. New members are always a good thing as it adds fresh input and ideas. In turn it also allows the scum sucking mutts who have nothing better to do but to act like an idiot to filter in.

Which comes to comment #2- Keeping the trial member status active is a good thing. As it will allow the admin/mods a chance to view and monitor the feedback and "civility" of the new member. No one likes coming to a board or forum where you have a bunch of idiots running around posting flames, and acting like spoiled brat kids who can't have there lollipop in a store. (talk of DoS'ing comes to mind") Last I looked this wasn't Burger King, so don't expect eveything to go your way.

Comment #3 - like I just mentioned, bad idea and whole heartedly support keeping it. It's not how much you post , put what you post that should allow for full membership.

Comment #4- Removing the downloads would be in a sense taking away the ability to share information. This is just my opinion. Information is a key element of why people become forum visitors. JMO

Comment #5- Someone wants to post an AH, ok no big thing. Information is like what is contained in books like Grey Hat Hacking. It's not the information that is technically dangerous but the person behind it. If I lay my 45 on the table with the safety on and the hammer down, its not going to jump up and kill anyone. But then again if you give it to some whacked out person, then your asking for trouble. Once again by keeping trial membership in place it will help weed out the schmucks. JMO also

Comment #6- Not allowing members to upload information is somewhat disturbing to me. If I create a white paper and want to post it up to fellow memebrs for their review and feedback I should be allowed to do that as a full member. Trial members can be dealt with on a case by case basis. You are responsible for what you upload, do up malware and face the music.

Comment #7 - Making an advanced section allowable to "paid" members does not ensure that the quality will be there or the cash.

Comment #9 (actually #10) - I strongly support removing 0 posters. To many people use their "0 account" to come back if their a pain in the "arse and get the boot. It also makes room for opening the forum up to new members that may be more active in their participation then someone who is just a lurking.

These are my opinions

Spookie
nuorder
I like how this board is, but perhaps its time to open the floodgates for a while to let some new members in. (and the old ones rolleyes.gif )
belgther
-Closing registration makes sense. Because there are stupid people who like making admins crazy by disobeying forum rules, getting their account deleted, then registering by another address. And every database has a limit. If the admins feel that this limit would be reached when keeping membership open, then they close registration.
-Trial membership has another sense. ComSec said that the forum was once overrun by script kiddies, making lame requests and trying to make this forum a warez link sharing place. And they were flooded, too, and they don't want that happen again.
-GSO is a non-profit site, which makes it great. You have to post content, or useful information, help the community. Everything has a price. But that must be something else than money, which you will like to give. That's why 0 posters are deleted, too. They don't post, but leech the forum, and don't even help the community...
-Autohaxors are mostly not made for script kiddies. They are in the downloads section, so that admins can test them on their server. And removing them will not make so much difference, these exploits can be found somewhere else, there are lots of exploit sites which I won't mention here.
beardednose
QUOTE
Spookie said: My comments to this may irritate some but I will voice them none the less.


I wish more of you would stick your neck out more often (after reading the rules, of course). Thanks, Spookie. Irritate away, just as long as it's done nicely (as you have done). You should post a lot more frequently, friend. I don't think I disagreed with anything you said.

We've hashed through all of this in other threads, so I'll say only a few things. I was a mod before trial members and the other controls, and I ain't going back to Kansas anymore, Dorothy. The system works for the most part.

It's hard to say this nice...but...I don't think we are overly concerned how irritated folks get about the controls, rules, etc. If you want to scratch in our sandbox, you have to enter the narrow gate and walk carefully.

There are plenty of other sandboxes out there, and that's one of the reasons this one was created...the admins wanted to do it differently, and I think, better.

Don't forget that when you limit the supply (locking the site), you increase demand. That was not our intention at all (the mods just occasionaly get up to their beardedears with whacking noobies once in a while), but I see it as a benefit. It makes us more desirable, and as a result, more is expected of the site, and we want to deliver just that.

Lockout is harsh, yes, but it's also reality. This ain't your father's democracy.

It's hard to shut my yap, so I'll fad out here.... cool.gif
ComSec
fair comment belgther

from what i can see... a lot of members want to do away with the trial status... ok ..BUT FOR the pure safty of our current members we would DISABLE uploads....

so the download section woruld become an archive.... we will from then onwards NOT be up to date with the latest tools...

THIS WOULD ALSO apply if we opened our doors again... we do NOT want a repeat of the Virii and trojan uploaders

the reason for the trial members was to PROTECT CURRENT FULL MEMBERS from Virii , trojan and various other malicious links and code being uploaded here

so in away i for one dont mind opening the doors here...providing all UPLOADS will be stopped... because at the end of the day... its what has caused 80% of the problems here

as for types of programs... we have stated in the past ..the best way to understand security issues ... is to have an insight of the tools used in an attack.... just like anyone ...i to would like to know them inside out.... but some people go over the top with some programs... like Serv-u etc ...

then we get the deleted accounts... well most forums delete accounts if they are not classed as active.... sheeesh... 1 lousy post can keep an account open

i guess the guys who complained...are the one's with multi-accounts... yet again against the rules... thing is why should we clog up the db with dead accounts ?

then we have the forum Trolls... who wants to complain about this and that... they Slag GSO down , its admin team and members.... thing is WHY do these crying members RETURN HERE ... even after they have been deleted...THEY STILL RETURN...why ? .... another thing ... hey Smartie , clubfed , Jetprice .... if were that CRAP... where are YOUR ATTEMPTS AT RUNNING A FORUM.... lol .... thing is they DONT RUN ONE....why BECAUSE they dont know how to ...thats why wink.gif

i Challenge them to start there OWN and make it a QUARTER the success GSO has been..... they dont have a clue... what to do ...do you boys !!

and Jetprice... you say you use to be a member here who posted QUALITY material.... then how about you reveal who you was... coz i think that to is a load of CRAP

well i hope you who slagged off.. stay away from GSO..... but i have a feeling you will be lurking in the background.... why... because your lost without us.... THATS why you all return once your banned

do us all a favour.... and simply leave GSO.... and get a life ....we dont hold you captive here...so do one wink.gif

ps... if you wish for your account to be deleted...then PLEASE PM me or any admin team member.... it will be a pleasure.... also anyone who wants to join them... just a simple PM saying "Please delete my account"...simple as that smile.gif

regards
sabrodiesel2000
ok comsec i admit onething, all that you said in the end of your thread i was to say but i didnt while i replied to the complaint lol , thinking that im a new subscriber and might get kicked so i was just watching my step hehe.. but hey nice to let it all out yea? than rather to keep it inside and get it rotten in there... i personally appreciate all the adminz/modz who play an active role at gso administration.
GhostShell
I really think this is a good board. Are there kiddies? yes but I know people who were FXP kiddies on this board and after a while they got tired of being a fxp kiddie hacker and they quit because they realized it was stupid and they went on to learn more about security and hacking because they had that drive to learn more. I believe that two things will happen with the kiddies they will give up and quit OR they will want to stop being a kiddie and learn more and eventually become a guru. the kiddies come and go just ignore them or guide them in the right direction to learn more instead of flaming them and making them go more towards the kiddie way because no1 will show them the path. for you dang flamers that keep nagging GSO "get a life" dont try to criticize a board that does a pretty dam* good job of keeping the posts modded and handling thousands of users. I think we should do away with the posting flood control... was there an event that happened to cause the mods to turn this on? I could post 50 posts faster without flood protection and my posts would be nice and long i wont just post to post like the "thank you" posters. I am very proud to be a part of this forum kiddies and all because we all get what we need from here and i think this board eventually shows the kiddies not to be kiddies because the kiddies see things they dont understand and if they really want to know what it means they will search and read and thats where the kiddie starts the transformation. It took me a while to become a trial memeber on this board and i am now and i am very happy with the results wink.gif . excuse me if im rambling because these dam* flamers got my fingers pis*ed. I think the forum does a pretty good job modding the "teach me how to hack posts". anyway i would like to thank GSO for letting me be a part of the board and I would like to say you are doing a good job on the forum. One suggestion is that instead of using your anger from the kiddies to flame use it to direct them in the right path as i said before. well that was enough for now.
have phun,
(Gh0stSheLL)
vnet576
My only comment to this thread is the part that talks about paid membership. This forum and ideally the internet at large is about the free spread and discussion of information. Putting money into the equation is one of the grosest violations imaginable to the dissemination of information. There are places in this world where payment for information/access is appropriate and there are places where it is not.
bonarez
the suggestions to lock the downloads could keep away some skids, but it won't change the board that much imo.

a better suggestion could be a little test for people who want to become a member. Read the rules and answer some questions about them, then become a trial member. Now members are supposed to have read the rules, but I doubt many newcomers have done so. even I had not read the rules in the first few weeks. blush.gif

another idea could be some early warning system > mods do not have the time to read every topic and start warning people for 'thanks posts'. But other long-time members could 'warn' the mods by clicking a button near the members post, thus adding to a counter whitch could easily be parsed into a simple report, mailed or viewed by mods.

just a few ideas
sabrodiesel2000
yea the members can REPORT for invalid posts just by clicking a button... this is one of the least efforts...

another thing on my mind was to create a questionare for the incoming trial members to even qualify for the trial membership...thus to have an idea on the level of the person... you know something like a GSO TEST... the sound of it excites me really and believe me even being a member i would go for the test.


<just a suggesstion>
belgther
QUOTE(sabrodiesel2000 @ May 24 2005, 06:25 AM)
yea the members can REPORT for invalid posts just by clicking a button... this is one of the least efforts...

another thing on my mind was to create a questionare for the incoming trial members to even qualify for the trial membership...thus to have an idea on the level of the person... you know something like a GSO TEST...  the sound of it excites me really and believe me even being a member i would go for the test.


<just a suggesstion>
*




I thought of it once, too. But the problem is that you have to make a database of test questions, which will repeat themselves after a while, and you have to make an automatic answer controller, which has to know the possible answers, but an answer can be given in many ways, so a manual controlling of the answers is required.
And the admins have no time to evaluate every single member, just make a simple calculation, if you need approximately 10 minutes for each test, then that would make 4 hours a day if 24 members register themselves each day. No admin has time for such an effort.
bonarez
QUOTE
but an answer can be given in many ways


not with multiple choice
ComSec
naaahhh..... tests and paper...the answers would be on every group within a few hours of release

if Cisco , M$ , etc... cannot keep there papers safe from being exploited...then what chance do we have

it would take to much man hours to case every individual that joins here....
........

1 idea is that NEW members have to use there IP of registration matched e-mail address

so if your ISP is BT.Com ...then we expect and e-mail validation like blah@bt.com

if no match...then its rejected

this would then be a lot more easy to keep track and report abusive members etc

just a thought
sabrodiesel2000
ok good point there comsec... then how about a 10 min live interview at irc?

i mean we have to give the incoming traffic an image that gso is not just another forum...

<suggesstion sent>
ComSec
QUOTE(sabrodiesel2000 @ May 24 2005, 06:37 AM)
ok good point there comsec...      then how about a 10 min live interview at irc?

i mean we have to give the incoming traffic an image that gso is not just another forum...

<suggesstion sent>
*



a good idea .... i see were your coming from with just random on the spot questions would stop the test paper issue... but could also be an open opportunity for banned ex members gain your confidence .... easy done with a bit of SE

would also be a problem and very time consuming .... a few months back we were averaging 200-300-400 a DAY new members .... even if 24 a day wanted an interview on irc thats 4 hours solid each day doing interviews.... we just dont have that time to spare bud

but perhaps a selected few who are known to be good in the forum circles... could apply this way...as long as they have a good track record we could follow up we dont see it a problem

cheers wink.gif
GhostShell
could you out up bots on irc to ask the questions and grant acsess.... this would be exploitable but what if you change the questions on the bot every week or so? and the irc bot that gives out a different test for membership everyweek would be nice and pretty stable to keep a handle on those trying to remember all the questions.
just an idea
(Gh0stSheLL)
sabrodiesel2000
ok comsec i get ur point, it indeed is very time consuming lol... but hey im always up with ideas innit? i mean ok lets just say u created a group on ur board with a few of the senior members, or maybe just make a seperate gso hiring team or something lol ok i admit im always up with silly ideas but im sure i mean nothing but creativity:)

i mean ok i myself was added here by a senior mod (wont mention names) and he asked me like y wud v b giving u memberships? i was like ok .... then blablabla i went on saying stuff and introducing myself.. didnt take more than 5 min there... and if that was extended to 10 min TOPS i dont see it as a very big deal. yes it wont be a single bloke sitting there and just talkin to people ur right lol...

but anyway it was just an idea...........rest is finE smile.gif
GSecur
One small note, we will not be charging to get into the forum so stay calm about that. Most of these suggestions bout test and what not are interesting but a bit time consuming. One thing I was thinking about was perhaps having scheduled new member days that only last for about 2 days maximum. We would announce them in advance. This would allow the inflood of people and then the subsequent weeding out of the fools to be limited.

As for the Trial member status, I believe that we should still leave it in, but we should be able to give more rights to the usergroup as far as access but then restrict there upload permissions which I think is now possible in this version of IPB, This feature was not avaialable in the earlier versions. This would hopefully protect our current members from the virii posters.

I would also like to promote all current trial members to the full members group. I think this is a pretty good reward for the guys that have been with us for so long. I would also reduce the flood control.

These are some of the short term changes I would like to make, I will see what the response will be from the other mods and keep you posted on what will happen.
ComSec
yes... i also agree... make all current Trial members ... full members smile.gif

QUOTE
I would also reduce the flood control.


no need to .... because it only effected Trial members... and if they are all promoted to full.... then there is no flood control for full members
satknis
i think the gso rules are all ok.
i like how you handel the things here.
FLX
I see alot of positive recommendations here, and it pleases me very much, after the b*tchfight with jetprice.
anywayz, i think GhostShell last idea is very well thought.
What if we combine powers and make a bot, on eggdrop source or something, and make a database with RANDOM questions, that ppl can answer. then we restrict them for doing a test once per month. They can try from different ips, but that doesnt matter, because they must say for what username they want to be upgraded, and then the server decides if it hasent been questioned this month. all serverside.
i know i write a bit silly, but i hope you ppl understand what i mean smile.gif

Regards,

FLX
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.