HAKIN9▊
Organization dossier Security Media Status: still publishing
A magazine that taught readers how to find web vulnerabilities — and, per the researchers who documented it, ran a cross-site-scripting bug on its own login page, paid its authors nothing, and mailed the security community so many unsolicited article requests it earned a conference talk titled "Spam Kings."
I would like to ask for opportunity to cooperate with you. What's the condition? Please visit our magazine website … to find out more. I don't want to send so many details in this mail …
Hakin9 "partnership" solicitation, sent by editor Ewa Dudzic (software.com.pl) to attrition.org, 11 May 2006 — reproduced verbatim by Attrition.org
Yes — we are working on it. Thank you for your engagement with helping us develope [sic] our service.
Hakin9's Pawel Plocki, replying to a researcher who reported an XSS bug on hakin9.org, 5 Oct 2012 — reproduced by Attrition.org
- ENTITY
- Hakin9 Magazine — an online information-security publication, published in Poland by Hakin9 Media Sp. z o.o. Sp. K., a subsidiary of Software.com.pl; sister titles include PenTest Magazine and eForensics FACT
- THE RAP SHEET
- Per Attrition.org's errata file: unsolicited-mail "spam" solicitations at scale; non-payment of authors; plagiarism and improper citation; XSS on its own site; a website that once served malware; and legal threats ATTRIBUTED
- THE DRAMA
- A BruCON 2012 lightning talk — Robin Wood's "Hakin9 — Spam Kings" — and years of researchers publicly asking, and asking again, to be taken off the list
- RECORD
- No court or regulator has adjudicated any of this. The record is documentation and complaint by named researchers — loud and corroborated in the sources below, but not a legal finding. FACT
- STATUS
- STILL PUBLISHING — hakin9.org is live; a "do not contact" reform followed in 2013
This one is a company, not a person — a real, long-running publication with a paper past and a live website. Keep that distinct; this file does. What follows is the whole file in order: the recruiting model, the community's response, the glass house, and the reform that actually came.
Almost none of this was documented by an institution. It was documented by one errata site and one researcher with a lightning-talk slot. That is why the archive exists. Every beat below carries its receipt. Both sides get the microphone. You decide who wins.
the drama timeline
ACT I — THE MODEL (2006–2011)
Every publication needs copy. This one had a recruiting model the field would come to know by heart: ask everyone, pay no one, and never quite take no for an answer.
-
FROM 2006
The solicitations begin
Per Attrition.org, Hakin9 sent unsolicited article-recruitment mail "to thousands of people, often repeatedly," and extended the practice to social media and vendor forums. Attrition traces the same solicitations on the Security Basics, Full Disclosure, and EduCause mailing lists "as far back as 2006," and reproduces two Hakin9 "partnership" emails sent to attrition.org itself — the sort of note, it observes, that directs the reader to a website rather than saying what it wants.
The rarest audience to mail your spam to: the people who run a security-company spam-documentation project.
-
c. 2009
"They didn't pay for articles"
Researcher Robin Wood (DigiNinja) recounts being invited to write for Hakin9; when he asked what it paid, "the message came back that they didn't pay for articles but you got a free copy of the edition you were in." Since the magazine charged readers, he declined — "I didn't like the idea that they would be profiting from my work." Attrition.org keeps a separate page on the non-payment complaints.
ACT II — THE PUSHBACK (2011–2012)
Ask a whole industry the same question often enough and it starts comparing notes. What one researcher took for flattery, the timeline shows a hundred took for a form letter.
-
OCT 2011
Everyone was getting the same email
When Wood mentioned the requests on Twitter, others answered that they were getting them too. Attrition.org preserves the exchange: Sandro Gauci — "are you also getting 'spammed' by pentest/hakin9 zine looking for writers? its getting annoying"; and, in August 2012, Dave Lewis — "Based on the volume of queries I'm receiving it seems Hakin9 is spamming the universe in search of writers." Attrition's summary: it was "common knowledge… that Hakin9 is a spam friendly company."
-
OCT 4, 2012
"Spam Kings" at BruCON
Robin Wood gives a lightning talk at BruCON 2012 titled "Hakin9 — Spam Kings," and publishes the companion blog post. He documents Hakin9 reaching out after his critical tweets, a Google+ conversation with a staffer, and a promised "Do not contact" list — after which, he writes, the requests kept coming, sometimes the very next day, from Hakin9 or a sister title. In the end he assembled a list of 146 staff addresses and mailed them all to ask, collectively, to be left alone.
A field that will not police its own charlatans will, reliably, give one an eight-minute slot and a projector.
-
2007 (LAW)
The possible legal angle
Attrition.org raises, as a possibility rather than a finding, that the practice "might be violating Polish law regarding unfair commercial practice" — pointing to Poland's Unfair Commercial Practices Act of 23 August 2007, whose Article 9 lists "making persistent solicitations by… e-mail or other remote media" among practices "regarded as unfair." Hakin9 is a Polish publication. No enforcement action is documented; the citation is Attrition's, and the question was never adjudicated.
ACT III — THE GLASS HOUSE (2011–2012)
The sharpest entry in the file is not the recruiting. It is the address bar. A magazine that sold web-security tutorials, the sources say, could not keep the flaws it taught about out of its own front door.
-
2011
The website served malware
Attrition.org documents, citing Kahu Security's 2011 write-up "Hacking Magazine Hacked," that Hakin9's website at one point served up malware to visitors. The finding is Kahu Security's and Attrition's; a hacking magazine's own site being turned against its readers is the incident, stated as those researchers reported it.
-
OCT 5, 2012
XSS on its own login page
Attrition.org publishes several reported cross-site-scripting issues on hakin9.org — including in the WordPress login page (wp-login.php) — submitted, it notes, "by several people who have a history of finding XSS vulnerabilities" (Attrition did not test them itself). Its dry aside: "any company that sells security… should try to maintain a secure online presence." Hakin9's on-record reply to one reporter, preserved on the same page: "Yes — we are working on it."
The flaw the magazine's own first issue would have covered, live on the magazine's own door.
-
2012
Plagiarism and citation problems
Attrition.org maintains separate pages alleging "Frequent Plagiarism & Improper Citation" and "No Technical Editors," and both Attrition and Wood point to a published Hakin9 nmap tutorial as an exhibit in the quality case. These are Attrition's documented findings about the magazine's editorial practice, presented as such.
ACT IV — THE REFORM (2013)
And then — unusually for this genre — something changed. The reform belongs in the file at full strength, because it happened, and because the researcher who documented the problem is the one who confirmed it.
-
MAR 15, 2013
The "do not contact" pages go up
In a March 2013 update, Wood reports that after six months of silence — and after a fresh round following up — Hakin9 senior editor Ewa Duranc apologised, sent a screenshot showing the offending sites blocked on the office network, and agreed to publish public opt-out pages for Hakin9 and PenTest Magazine, "created within minutes." Wood's own verdict: "I do feel that they are trying to reform… thank you Ewa for putting the policies in place and lets hope they work."
-
EPILOGUE
Still publishing
hakin9.org is live. The errata file remains up, uncorrected and unretracted by either side. The magazine kept publishing; the archive kept the receipts. Both are still here.
both sides, on the record
The documentation (its sources', not ours): Attrition.org's errata file catalogs, on dedicated pages, unsolicited "spam" solicitations "to thousands of people, often repeatedly," non-payment of authors, plagiarism and improper citation, XSS on the magazine's own site, and a period in which its website served malware [1] [2] [4] [5].
The community record: named researchers — Gauci, Lewis, and others — publicly reported receiving the same solicitations, and Robin Wood's BruCON 2012 talk "Spam Kings" documented opt-out requests that, he says, went unhonored for a year [2] [3].
The irony that carries the file: a publication whose subject was finding and exploiting web vulnerabilities was itself reported vulnerable to an XSS on its own login page — a flaw covered in the first chapter of the material it sold [4].
Hakin9's position, and the fair reading: it is a real, long-running information-security publication with a print heritage and a live site — not a shell. A free-contribution model, in which authors are paid in exposure and a copy rather than cash, is a normal (if disliked) arrangement across many trade and hobbyist outlets; declining to pay is not fraud. Aggressive recruiting mail is a marketing practice, not a crime, and the "spam" label is the recipients' characterization [1] [2].
Its strongest card is the reform — from the critic's own keyboard: Robin Wood, who wrote the "Spam Kings" talk, later reported that Hakin9 apologised, blocked the relevant sites on its office network, and stood up public opt-out pages within minutes, and wrote that he "do[es] feel that they are trying to reform." When your loudest documented critic files an update saying you fixed it, that update is evidence [3].
Scope of the record: the XSS reports were, in Attrition's own words, "not tested by attrition.org"; the plagiarism and quality findings are that site's characterizations; the Polish-law point was raised as a possibility, never adjudicated. No court, no regulator, and no finding of fraud appears in this record. The magazine operates today [4] [9].
YOU DECIDE
Scoped to the claims, never the company. The claim "Hakin9 spammed the security community" is corroborated on the public record by multiple named researchers and a conference talk — and then partly answered by a documented 2013 reform the original critic confirmed. The claim "a security magazine could not secure itself" rests on reported XSS its own documenter did not independently test and a malware incident attributed to a third-party writeup — serious if accurate, and stated as its sources stated it. Nothing here is adjudicated. Nothing here is a fraud finding.
Weigh the costly signals: the community's rebuttal cost a lightning-talk slot and a 146-address mailing list; the reform, when it came, cost Hakin9 an apology and a few opt-out pages "created within minutes." The magazine paid its authors nothing and its critics answered for free — which tells you who, in this story, was working on principle.
The archive does not judge. The archive merely keeps the tape running.
evidence locker
PRIMARY DOCUMENTATION
Attrition.org — "Errata: Hakin9 Magazine" (the master errata file; imprint, spam, plagiarism, non-payment, legal threats, malware, XSS) ATTRIBUTED — the index of documented findings; characterizations are Attrition's.
attrition.org/errata/charlatan/hakin9/
Attrition.org — "Hakin9 Magazine & Their Spam Problem" ATTRIBUTED — the "thousands of people, often repeatedly" scale, the mail-list traces to 2006, the reproduced Hakin9 emails, and the Polish-law citation.
attrition.org/errata/charlatan/hakin9/spam.html
DigiNinja (Robin Wood) — "Hakin9 Spam Kings" (blog + BruCON 2012 lightning talk, with the March 2013 reform update) ATTRIBUTED — the non-payment account, the ignored opt-outs, and the reform, all first-person.
digi.ninja/blog/hakin9_spam_kings.php
Attrition.org — "Errata: Hakin9 Vulnerabilities" (XSS) ATTRIBUTED — the reported XSS on hakin9.org incl.
wp-login.php; expressly "not tested by attrition.org"; Hakin9's on-record reply.
attrition.org/errata/charlatan/hakin9/xss.html
CORROBORATION & DETAIL
SUBJECT'S OWN CHANNELS — THE MAGAZINE, UNEDITED
hakin9.org SELF-PUBLISHED — the publication, still live and still publishing.
hakin9.org
The standard. Everything above is sourced to a named documentation project (Attrition.org's errata file and its sub-pages), a named researcher's conference talk and blog (Robin Wood / DigiNinja), a third-party incident write-up (Kahu Security), and the magazine's own reproduced words. Facts of publication and live-site status are stated as facts; every characterization — "spam," plagiarism, the XSS, the malware, the possible legal violation — is stated as its source's finding and wears that source's name. The XSS reports carry Attrition's own caveat that it did not test them. The company is a real publication, not a shell, and the 2013 reform — confirmed by the very critic who raised the alarm — is presented at full strength. No motive is asserted, no fraud is alleged, no individual is charged. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.