这几年,就像我退出之前说的那样,已经不太碰这些东西了,可是心里还是总挂念着,所以还会时不时去收集和恶补一些信息和知识。这一年多,我的时间全被大大小小的事瓜分完了,能够自己坐下来做点感兴趣的事已经不容易了。毕业后,由于创业和求学的矛盾,最终搁置了种种计划。现在除了准备考试,时间总算都属于我了,这也算是我在纷乱中找到的一点平静吧,能够读点书,冥想,做点爱做的事。
保钓的时候有朋友来问我是不是该有所表示,我否决,感觉有些幼稚,我已没有了当年的那份冲动了吧。不过热情还是有的。今天我又尝试打开milw0rm的主页,访问无能了。一搜,说是站点关闭了。不禁有点心疼,多好的站子啊……
后来又是wiki又是forum地找,看到了一份比较官方的文字,当然不了解的同学也可以从这段文字中了解一些背景知识,如下:
One of the major sources of proof of concept (PoC) exploits on the Internet, milw0rm.com, will be closing down. The website´s maintainer, str0ke, announces that he can´t commit anymore to reviewing exploits submitted by third-parties, in a timely manner.
While this is sad news for people familiar with the exploit release scene, as well as a fair amount of script kiddies by some accounts, it might not mean much for the uninitiated without some background history.
Milw0rm was originally the name of a group of hackers with members from various parts around the globe that communicated with each other over IRC (Internet Relay Chat). The outfit went on to achieve international fame after it took credit for compromising the computer network of India´s Bhabha Atomic Research Centre (BARC) in Bombay and gaining administrative access (root) on multiple systems during the night of June 3, 1998.
The hackers walked off with confidential emails and classified documents about nuclear tests, amounting to around five megabytes. The first news outlet to break out the story (http://www.wired.com/science/discoveries/news/1998/06/12717) at the time was Wired, which the collective contacted with proof of their feat.
The reasons behind the attack were mostly political in nature. The group´s members, who were still teenagers at the time, wanted to show their disapproval over the development and testing of atomic weapons, making this pretty clear by defacing the BARC home page and posting (http://goo.gl/YAdF) pacifist messages.
˝I like the world in its current state (i guess), well its better than the world would be if the b0mb went b00m. think about it k1dz, its not clever, its not big, so don´t think destruction is cool, coz its not […] So India, LISTEN TO WISE OLD MILWORM … You do not need nuclear weapons in the 1990s!#@!˝ a part of the message, which was signed by JF, VeNoMouS, Hamst0r, Keystroke, savec0re and ExtreemUK, read.
Milw0rm announcement and exploit listing screenshot Enlarge picture The group disbanded soon after this high-profile hack, or at least its members stopped being hacktivists. Several years later, in 2004, Keystroke, who is, today, better known as str0ke, went on to set up milw0rm.com as a place to publish PoC exploits, with the consent of some of his former comrades.
In order to ensure a high quality for the published content, str0ke personally verified and tested all exploits submitted by other hackers, something that, unfortunately, he can no longer do. ˝Well, this is my goodbye header for milw0rm. I wish I had the time I did in the past to post exploits, I just don´t,˝ a message from str0ke displayed on the home page reads.
He goes on to explain that, ˝For the past 3 months I have actually done a pretty crappy job of getting peoples work out fast enough to be proud of, 0 to 72 hours (taking off weekends) isn´t fair to the authors on this site.˝ Finally, the hacker extends his thanks to everyone who contributed to the website. ˝I appreciate and thank everyone for their support in the past. Be safe, /str0ke,˝ he signs off.
The footer on milw0rm now informs visitors that, ˝Submissions are closed.˝
–By Lucian Constantin on Softpedia!
当然这些说得很官方。站长的身体状况确实不佳,曾在2009年11月3日爆出因心脏病死亡的消息。可5日的时候自己又发推说:
I’m not dead yet, just being trolled.
之后就没有推过。所以说句题外话,做技术的朋友们,要保重身体啊。
当然也有人说站点的关闭跟另一间事情有关,milw0rm 上公布了Lxadmin(现在的kloxo) 的exploit,当时那个exploit使很多站被黑,数据被清空,最后导致Lxadmin的作者Ligesh自杀。又是一个悲剧……再说一句题外话,做技术的朋友们,要有豁达的心态和过硬的心理素质啊,漏洞是客观存在的,不用为了这点事就自杀;工作压力是有的,但是也不值得自杀或熬夜慢性自杀。
就这样,我后知后觉地知道了这件事,虽然不是什么好消息,可有点释然,终于可以自由支配自己了。
最后再分享昨天我看一段视频听到的一句哲言:自由不是想做什么就做什么,自由是可以选择不做。是的,我现在自由了,短暂的。也许在生活面前,这自由就是奢侈品。
Be safe
