Interview with Frank Van Vliet aka {}
By Sugarking (C)2001 SugarKing/HWA

Please quote source if using any part of this interview
http://hwa-security.net/
http://hwa-security.net/interviews.html
http://hwa-security.net/frank.html
Session Start: Mon Jan 08 17:29:20 2001
[17:36] [SugarKing] alright....ummm.....logging now:)
[17:36] <{}_> erhm let me fix you a new window (:
[17:36] <{}_> there (:
[17:36] [SugarKing] so how did you get into computers? how old were you and how old are you now?
[17:37] <{}_> erhm not that long ago, i was like 10/11 while playing with the old XT of my dad
[17:38] <{}_> he teached my a bit of gwbasic so i could make really irritating music programs with keyboard as keyboard and stuff like that (:
[17:38] <{}_> now i'm 18
[17:38] <{}_> from XT it wend to some old 386
[17:38] <{}_> where i learned vb
[17:38] <{}_> i programmed vb for quite a while
[17:38] [SugarKing] yuck, vb:P
[17:39] <{}_> its less then 2 years i'm into linux
[17:39] <{}_> where i kind'a started with reading the kernel
[17:39] <{}_> kernel tought me C
[17:39] [SugarKing] 2 years? that's a short amount of time
[17:39] <{}_> i had some guide papers besides reading kernel focourse
[17:39] <{}_> well just skipped the 'scriptkiddo' part
[17:39] <{}_> makes you go really fast (:
[17:40] <{}_> most ppl tend to 'hang' in the scriptkiddo part
[17:40] [SugarKing] yeah I would imagine
[17:40] <{}_> get there ego growing while doing more easy thingies
[17:40] [SugarKing] how many hours a day do you spend on your computer?
[17:40] <{}_> like hacking microsoft.com with exploits of others (:
[17:41] <{}_> erhm now i'm a student, i study computertechnologie or whatever it is called in english
[17:41] <{}_> i live at the campus with a 100mbps internet link
[17:41] [SugarKing] heh
[17:41] [SugarKing] what college do you attend?
[17:41] <{}_> in a small room with a computer a bed and a cough and a drawer
[17:41] [SugarKing] hah
[17:42] <{}_> so i'm like erhm 10+ behind pc
[17:42] <{}_> i think i reach 15 when i'm not doing school stuff
[17:42] <{}_> except for weekends
[17:42] <{}_> weekends are 100% with girlfriend so not really computers
[17:43] [SugarKing] heheh
[17:43] <{}_> (she started running linux before i did)
[17:43] <{}_> on school i only really follow math classes
[17:43] [SugarKing] oh? hahah...
[17:43] [SugarKing] nod, math is pretty important
[17:43] [SugarKing] not to mention the most difficult
[17:43] [SugarKing] and the biggest pain in the ass
[17:43] <{}_> nah dunno
[17:43] <{}_> at least the most difficult
[17:44] <{}_> never needed math really
[17:44] <{}_> not in what i'm interested in
[17:44] [SugarKing] what about in C?
[17:44] [SugarKing] what are you interested in?
[17:44] <{}_> right now i'm coding some zero knowledge authentication library
[17:44] <{}_> don't need any math for that really
[17:44] [SugarKing] cool
[17:44] <{}_> just read the papers and implement their idea
[17:45] [SugarKing] so what programming languages do you know, and when did you learn them?
[17:45] <{}_> erhm i code
[17:45] <{}_> erhm i code C for a year now
[17:46] <{}_> today i read some final thingies out of 'the c programming language' (expensive book, almost a dollar per 3 pages)
[17:46] <{}_> nah 4 pages (:
[17:46] [SugarKing] is that the only thing you mainly code in?
[17:46] [SugarKing]heh
[17:46] <{}_> so now i think i know most C
[17:46] <{}_> kernel is full of gcc magic so trying to get the hang of that to
[17:46] <{}_> yeah i mostly code in C
[17:46] [SugarKing] yeah
[17:46] <{}_> i like to see the asm in my head when i code
[17:46] <{}_> great for optimilisations
[17:47] <{}_> besides C i do perl/php/tcl/scriptthingies like bash
[17:47] [SugarKing] ahhh, I was going to say...
[17:47] <{}_> i do asm, but mostly for optimising in C
[17:47] [SugarKing] you did of bit of php on your apache hack...
[17:47] [SugarKing] which was very clever btw
[17:47] <{}_> that was peters php
[17:47] [SugarKing] peter == hardbeat I presume?
[17:47] <{}_> his passtrou($bla); or something
[17:48] <{}_> still dont know how to spell that word
[17:48] [SugarKing] heh
[17:48] <{}_> yeah peter is hardbeat
[17:48] [SugarKing] does peter also live in the netherlands?
[17:48] <{}_> apache was fun
[17:48] <{}_> took 2 weeks
[17:48] [SugarKing] 2 weeks? that's quite a project
[17:48] <{}_> yeah he does, i meet him regularely for he is the brother of my girlfriend (((:
[17:48] [SugarKing] ahhh
[17:49] [SugarKing] I took a vacation to the Netherlands once, it's a nice country:)
[17:49] <{}_> yeah most real hacks take time
[17:49] <{}_> slashdot also took 2 weeks
[17:49] <{}_> freebsd took 'just' one week
[17:49] [SugarKing] what are your purposes for hacking big sites like apache and slashdot?
[17:49] <{}_> but we cheated on that one (:
[17:49] <{}_> we didnt used configuration bugs to get root
[17:49] [SugarKing] slashdot was also configuration bugs?
[17:50] <{}_> let me start with purpose, thats important (:
[17:50] [SugarKing] ok:)
[17:50] <{}_> hacking big sides got several purposes ofcourse
[17:50] <{}_> first of all, its a mindgame, try to be smarter then them
[17:50] <{}_> great entertainment (:
[17:50] [SugarKing] hah ya
[17:50] <{}_> besides that apache was also hosting its cvs and ftp repositery on that box
[17:50] [SugarKing] yes
[17:51] <{}_> meaning everybody that comes in can do really nasty things
[17:51] <{}_> and distrobutions like redhat dont check EVERY upgrade
[17:51] <{}_> not for 100%
[17:51] <{}_> nah redhat prolly wouldnt check
[17:51] <{}_> but debian wouldnt check for 100%
[17:51] <{}_> for just an update
[17:51] <{}_> and we wrote that paper so admins who read it would start thinking
[17:51] <{}_> those bugs all are just a 'way of thinking'
[17:52] [SugarKing] yeah I think the apache hack was very underminded
[17:52] [SugarKing] it didn't recieve the attention it should have
[17:52] [SugarKing] considering the possibilities
[17:52] <{}_> if those admins see the light and start thinking that way they aren't likely to be surprised by a 'echo could you please come to undernet channel #yourcompany, there are some securitybugs to discuss | wall"
[17:53] <{}_> a friend of mine saw it on CNN's financial news
[17:53] <{}_> or at least it was mentions
[17:53] <{}_> or at least it was mentioned
[17:53] [SugarKing] oh yeah?
[17:53] [SugarKing]never heard about that
[17:53] <{}_> i and hardbeat secured apache.org before going public with that 'hack'
[17:54] <{}_> on apache.org we tried to be subtile, on slashdot even more subtile
[17:54] <{}_> on freebsd i(we) finally succeeded
[17:54] <{}_> we bypassed attrition (:
[17:55] [SugarKing] yeah
[17:55] <{}_> you can try to look it up, it isnt on attrition.net
[17:55] [SugarKing] heh
[17:55] [SugarKing] what do you plan on doing after college? security consultant?
[17:55] [SugarKing] didn't apache offer you and hardbeat jobs?
[17:56] <{}_> apache offered us jobs
[17:56] <{}_> but me and peter are both working at the same company now (:
[17:56] <{}_> both happy enough to not leave
[17:56] [SugarKing] what are you doing at this company?
[17:56] <{}_> ppl will find me in some secret service of goverment later (:
[17:56] [SugarKing]heh
[17:57] <{}_> erhm i read code of others and poison it with comments like /* DANGER: bladiebladiebla this is insecure because of bladiebladiebla */
[17:57] [SugarKing] hahahah
[17:57] <{}_> later some govermental work would be kewl i think
[17:57] [SugarKing] yeah
[17:58] [SugarKing] you have the skills?
[17:58] [SugarKing] erm, no ? on that one
[17:58] <{}_> lol i sure hope they have much beter ppl then me there
[17:58] [SugarKing] what do you think about all those script kiddos out there, that are on attrition?
[17:58] <{}_> like i said, they are all hanging in the scriptkiddophase
[17:59] <{}_> and i do think they enjoy themselves too much to go on
[17:59] <{}_> and really learn stuff
[17:59] <{}_> i hope goverments will soon be able to deal with them (:
[17:59] [SugarKing] yeah
[18:00] <{}_> because of one kiddo i hade detectives at my door once
[18:00] [SugarKing] eh? why?
[18:00] <{}_> and i was a 'whitness' so i wasn't allowed to lie and that stuff
[18:01] <{}_> some kiddo hacked some company
[18:01] <{}_> and they were interrogating some erhm dude that thinks he is a hacker (:
[18:01] [SugarKing] heh
[18:02] <{}_> so the detectives drove 2 hours to my place
[18:03] <{}_> i put them in my room where i had turned on heat to kinda max
[18:03] <{}_> i was just in a tshirt, they were in sweaters etc
[18:03] <{}_> they asked me questions for one hour in that heat
[18:03] <{}_> while koffie was in sight but i didnt offered them
[18:03] <{}_> kinda forgot (:
[18:03] [SugarKing] hahah
[18:03] <{}_> there didnt knew anything more when they left
[18:04] <{}_> but they did spend 5 hours of them time
[18:04] <{}_> because of that uberhaubt mansur (:
[18:04] [SugarKing] heh
[18:06] <{}_> at least i wouldn't know why, everything i do does gets published (:
[18:06] <{}_> also the freebsd story and so
[18:06] [SugarKing] do you plan on doing any more big sites?
[18:06] <{}_> i always do
[18:06] <{}_> but you don't just hack any big site
[18:07] <{}_> something like microsoft.com i would never touch
[18:07] <{}_> first of all they are commercial, and they really need money
[18:07] <{}_> hacks are bad for there business
[18:07] <{}_> they will sue you
[18:07] [SugarKing] yeah
[18:08] <{}_> and if you hack them, nobody will think like 'hey those were nice guys, good for microsoft they helped them'
[18:08] <{}_> they will think 'bad microsoft, bad windows, dont use windows'
[18:08] [SugarKing] nod
[18:08] <{}_> afaik nobody switched from apache to some other httpserver after that hack
[18:09] <{}_> apache ofcourse didnt sued, they were very friendly and understood what we did
[18:09] <{}_> freebsd got from there sponsors a guy to check all there cgi scripts (:
[18:09] [SugarKing] haha
[18:09] <{}_> i keep using we, but sometimes thats me and ahrdbeat, sometimes it me and nohican
[18:09] <{}_> slashdot/freebsd was me and nohican
[18:10] <{}_> i work best in pair
[18:10] [SugarKing] why pair?
[18:10] <{}_> works just best, perhaps it is because dcc chat doesnt do treesomes (:
[18:10] [SugarKing] haha
[18:11] <{}_> but i think with threesomes you'll eventually have 1 that backs off
[18:11] <{}_> pairs just work great
[18:11] <{}_> at least thats my experience
[18:11] [SugarKing] yeah
[18:11] [SugarKing] well, I think I'm out of questions, and probably out of your time;)
[18:12] <{}_> lol let take this oppertunitie to pretent i'm a very busy guy ((:
[18:12] [SugarKing] haha;)
Session Close: Mon Jan 08 19:00:42 2001 [END]