02:10 AM
Connect Directly

HD Moore Unplugged

Security researcher HD Moore talks about how he got into the biz, Microsoft, and what it's like to be a security rock star

HD Moore got his first real job in security research eight years ago, at the tender age of 17. He worked for the U.S. Department of Defense.

Moore, who today is one of the best known names in security research, had just returned to high school after dropping out for two years. He was getting some hands-on experience in security by auditing, consulting, and setting up collocation servers. Moore didn't have the proper classified security clearance at DOD, but his job description was written so that his then-rare skills could still be applied to some classified DOD work. He developed some exploits and wrote "something that captures traffic based on a set of rules" (essentially a sniffer) for DOD.

Figure 1:
Security researcher HD Moore.

"An example of how my development role worked -- really vague requirements that allowed me to provide useful code for projects that were classified," says Moore, director of security research with BreakingPoint Systems and developer of the wildly popular open source Metasploit tool. (See Metasploit Issues New Beta and Free Fuzzing Tool Launched.)

Today, most everything Moore, 25, does is watched closely by the commercial world, especially by software companies like Microsoft. His Metasploit penetration testing software has been hailed as a crucial tool for security white hats (the black hats love it, too), and his memorable Month of Browser Bugs (MOBB) project and other vulnerability discoveries and disclosures at times have put him at odds with Microsoft. (See Getting Buggy with the MOBB.) All of this activity has made him one of the most respected -- and sometimes criticized -- security researchers.

Moore's awkward relationship with Microsoft hasn't really changed much, he says, despite having several friends working there and his close ties with the Microsoft Security Response Team. Microsoft has at times credited him with finding bugs, and he gets invited to its Blue Hat summits. But his knack for finding and disclosing bugs in Microsoft's products hasn't always ingratiated him with the software giant. "There are definitely people there who see anyone who doesn't play by their rules as detrimental," he says. "And there are really sharp people at Microsoft who really care about the code and what they are working on."

But the relationship has definitely improved from when one former Microsoftie resorted to publicly calling Moore "spawn of the devil" and a few other choice things, he says.

Moore's philosophy on sharing and disclosing research information is "share early, share often." He admits, though, that his vulnerability data and tools can be abused by bad guys, too. When he gets complaints of the Metasploit tool being used to break into an organization, he says he doesn't feel guilty. "Yes, we provide the tools you can use for bad things, but we are not responsible for people misusing them," he says. "Nor are we saying you had it coming to you because you weren't patching."

Moore says what scares him most about security today is how careless people are about it. Once while driving around San Antonio with some friends and "watching" network traffic, he saw someone uploading "warez" files onto an FTP server housing medical transcription logs. It was some kids storing their pirated software on the outpatient services organization's server, he says. "The fact is, they were totally exposed," he says of the outpatient organization. And many people are afraid to blow the whistle when their organizations aren't properly handling sensitive data. "They’re scared to talk or don’t want to be involved in criminal charges," he says. "What scares me is this gross negligence [out there], and [there's] no way to report it responsibly."

Of course, being the industry's most famous white hat hacker also makes you a popular target. Moore says he's regularly "hammered" by attempted hacks, but he was only really hit once, when he worked for Digital Defense. While vacationing in Tokyo, he found a previously unknown vulnerability being exploited on the latest version of software on one of the servers he was maintaining. "I had to reverse-engineer it, bring the server down, and patch it."

That apparently provoked the hackers further. "They got pissed off and DDOSed us for two weeks," he says.

Lately, Moore has been busy with his day job, putting the final touches on exploits he's writing for a new product rollout for BreakingPoint. He spends his evenings working on Metasploit 3.0 and mapping out another pet project of his, building a more user-friendly Metasploit that any admin can use.

"If you don't know what an exploit is, it's difficult to use the current version," he says. "Our goal is to make exploit and vulnerability information more accessible" so admins wouldn’t need to be exploit experts to determine whether they should patch for a particular vulnerability.

Meanwhile, Moore's rock star status is about to go Hollywood (yes, really). The upcoming Die Hard sequel with Bruce Willis will feature an evil hacker named "evil hax0r" who takes down the U.S. infrastructure using the Metasploit tool. Moore can't help rooting for the bad guy: "Who needs marketing with movies like this?"

Personality Bytes

  • Worst part about writing exploits: "Finding a copy of the affected software and installing it. Many vendors only distribute the latest copy of their software, making it a challenge to locate a vulnerable copy for exploit development. I maintain a ~200Gb archive of evaluation software, solely for exploit development and Metasploit QA."

  • Microsoft Job Offers: "As long as I'm releasing exploit code, I couldn't work for them, and I'm fine with that. My work is contrary to companies who sell security solutions... I don't want to be gagged by corporate culture."

  • Favorite hangout: "A dark room full of electronics."

  • PC or Mac?: "Whatever runs Linux the fastest."

  • In his iPod: "Outkast, Kidney Thieves, Gnarls Barkley, Kool Keith, NWA, Praga Khan, Nine Inch Nails, Mos Def. Mostly hip-hop, industrial, or electronica."

  • Off the clock: "I head to the Alamo Drafthouse (drafthouse.com) to view the latest flicks through beer goggles, read books -- mostly science fiction -- Stross, Cheryhh, Sterling, Friedman, etc., and play basketball."

  • Favorite comfort food: "Sushi."

    — Kelly Jackson Higgins, Senior Editor, Dark Reading

    Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Higher Education: 15 Books to Help Cybersecurity Pros Be Better
    Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
    'PowerSnitch' Hacks Androids via Power Banks
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
    Worst Password Blunders of 2018 Hit Organizations East and West
    Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
    Register for Dark Reading Newsletters
    White Papers
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: camera, camera everywhere, not a single news to rely on
    Current Issue
    10 Best Practices That Could Reshape Your IT Security Department
    This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
    Flash Poll
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    PUBLISHED: 2018-12-14
    A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulne...
    PUBLISHED: 2018-12-14
    Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.
    PUBLISHED: 2018-12-14
    Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
    PUBLISHED: 2018-12-14
    Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
    PUBLISHED: 2018-12-14
    Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an escalation of privilege via local access.