 |
|  |
 |
|
Asher
|
 |
Calgary, Alberta
Nov 1999 time: 22:25
|
|
http://software.silicon.com/securit...39127703,00.htm
quote: University offers spam and spyware writing course
February 08 2005
by Will Sturgeon
The virus writing class of 2006 now get to create their payload...
The controversial computer science department at the University of Calgary has once again kicked off heated debate in the security industry by offering students a course in writing spyware and the tools for sending and propagating spam.
The move follows the introduction of a widely-criticised virus writing course offered by the university in 2003.
However, the reaction to the latest addition to the syllabus has been more measured, with many in the security sector saying the right skills, taught in a controlled environment will prove a useful addition to their industry.
Steve Purdham, CEO of SurfControl, said he'd certainly look favourably upon any applicant who was a graduate of the course.
"If we're looking for an engineer to help us combat problems like spam then we'd rather have somebody who has already been taught about these things and who knows how they work."
Purdham says it does the students and the university a great disservice to assume they will abuse the knowledge rather than put it to good use.
"It's like teaching safe sex," he said. "Rather than hiding ourselves away from this stuff and mystifying it – which can actually make it more appealing – we need to understand the mechanics in order to protect ourselves.
Mark Murtagh, European technical director at Websense, said: "Any good security analyst will have used spyware and hacking tools like Trojans and keyloggers to keep them up to speed on the dangers out there. Knowledge is power, and the security space is like a game of chess - you need to be completely up to date on what's available to ensure you understand your opponents potential next move."
Murtagh said there are no guarantees that students won't be 'tempted by the dark side' but said if an individual really is intent on writing spyware or spam tools they don't have to go to the lengths of enrolling in University courses.
"This information is all freely available on the internet," said Murtagh.
But not everybody in the industry is in favour of the idea.
Pete Simpson, ThreatLab manager at Clearswift, expressed shock that the university has re-opened old wounds and criticised what he sees as the unnecessary risk of training students to use techniques which can jeopardise the safety of internet users.
"When the University of Calgary first caused controversy with the virus writing course, their dubious defence was that only by writing viral code could a student fully understand and be able to protect against real viruses, but I'm sorry, that argument really falls flat for spamming tools."
Clearswift's Simpson believes the saleability of spam tools may create too much of a financial temptation for hard-up students.
And unlike with viruses the covert nature of spyware and spam tools means it may be even more difficult to trace any abuse back to students at the university if they do stray.
The university threatens students with a fail and prosecution if they are involved in any irresponsible or criminal use of malicious code. |
I took the original course last term.
I never could understand the backlash it generated.
Is this a bad thing, or a good thing?
|
|
|  |
 |
|  |
 |
|  |
 |
|
Fve Crathva
|
|
I think the important question is whether or not it should be an undergrad course.
SP
|
|
|  |
 |
|  |
 |
|  |
 |
|
Asher
|
 |
Calgary, Alberta
Nov 1999 time: 22:25
|
|
quote: Originally posted by Urban Ranger
Before the advent of Windows, particularly ActiveX, viruses were hard to write, even on MS-DOS. |
This is complete nonsense.
One of the first things you learn in the course is the majority of viruses don't rely on exploits, they rely on social engineering and getting people to run code they didn't want.
The reason there weren't as many before ActiveX and such is because there was no internet on most computers at the time.
You need to get a sense of perspective -- it's not a fundamental Windows issue, it's an issue with it being the dominant platform and a huge anti-social cracker target.
quote: I maintain a general knowledge of how viruses spread is sufficient at this point. |
You're clearly not in a position to make such judgement, since you have no clue at all how these spread. You're a perfect candidate to take a course such as this, to get a reality check and dismiss your simple claims that Viruses wouldn't be a problem were it not for Windows...
It's not a simple case of them telling you buzzwords like "stack smashing" and blaming that on how viruses spread, clearly that is not adequate for you at the very least. It's a hands-on exercise, one that teaches you what to look for in vulnerabilities in programs. This is an invaluable skill to learn, and teaches you far more about security.
My school has always had a course like this, minus the name including "virus" (whcih caught PR). Coincidentally, the most secure operating system on Earth -- OpenBSD -- is based in Calgary and its main architects consist of mostly University of Calgary grads.
|
|
|  |
All times are GMT. The time now is 05:25. Apolyton Time is 00:25. |
top of page
|
|
|
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is ON
vB code is ON
Smilies are ON
[IMG] code is ON
|
|
|
|
|
|