SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Salesforce “Red Team” Members Present Tool at Defcon, Get Fired
Date    Friday August 11, @09:50PM
Author    martyb
Topic   
from the METASPLOIT-SPAMTOILET-MOISTPLATE-MEATPISTOL dept.
https://soylentnews.org/article.pl?sid=17/08/11/139207

Fnord666 writes:

At Defcon in Las Vegas last month, word rapidly spread that two speakers—members of Salesforce's internal "red team"—had been fired by a senior executive from Salesforce "as they left the stage." Those two speakers, who presented under their Twitter handles, were Josh "FuzzyNop" Schwartz, Salesforce's director of offensive security, and John Cramb, a senior offensive security engineer.

Schwartz and Cramb were presenting the details of their tool, called Meatpistol. It's a "modular malware implant framework" similar in intent to the Metasploit toolkit used by many penetration testers, except that Meatpistol is not a library of common exploits, and it is not intended for penetration testing. The tool was anticipated to be released as open source at the time of the presentation, but Salesforce has held back the code.

[...] Schwartz had reportedly gotten prior approval to speak at Defcon from Salesforce management, and he was working toward getting approval to open-source Meatpistol (which is currently in a very rough "alpha" state but was at use internally at Salesforce). But at the last moment, Salesforce's management team had a change of heart, and it was trying to get the talk pulled. As ZDNet's Zach Whittaker reports, a Salesforce executive sent a text message to Schwartz and Cramb an hour before their scheduled talk, telling the pair not to announce the public release of the code.

[...] A Salesforce spokesperson contacted by Ars would not comment, stating, "We don't comment on matters involving individual employees."

Source: Ars Technica

Also at ZDNet and The Register


Original Submission

Links

  1. "Fnord666" - https://soylentnews.org/~Fnord666/
  2. "were presenting the details of their tool, called Meatpistol" - https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-FuzzyNop-and-Ceyx-MEATPISTOL-A-Modular-Malware-Implant-Framework-UPDATED.pdf
  3. "ZDNet's Zach Whittaker reports" - http://www.zdnet.com/article/salesforce-fires-red-team-staffers-who-gave-defcon-talk/
  4. "Ars Technica" - https://arstechnica.com/gadgets/2017/08/salesforce-fires-two-security-team-members-for-presenting-at-defcon/
  5. "ZDNet" - http://www.zdnet.com/article/salesforce-fires-red-team-staffers-who-gave-defcon-talk/
  6. "The Register" - https://www.theregister.co.uk/2017/08/10/salesforce_fires_its_senior_security_engineers_after_defcon_talk/
  7. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=21701

© Copyright 2017 - SoylentNews, All Rights Reserved

printed from SoylentNews, Salesforce “Red Team” Members Present Tool at Defcon, Get Fired on 2017-10-19 03:56:15