Thursday, October 15, 2009

Hackers-(Master of Deception)

Masters of Deception (MOD)

  • was a New York-based hacker group.
  • MOD reportedly controlled all the major telephone RBOC's and X.25 networks as well as controlling large parts of the backbone of the rapidly emerging Internet.

Origin of Masters of Deception

  1. MOD's initial membership grew from meetings on Loop-Around Test Lines that led to legendary collaborations to hack RBOC phone switches and the various minicomputers and mainframes used to administer the telephone network.
  2. They successfully remained underground using alternative handles to hide even their true hacker identities.
  3. Acid Phreak founded the Masters of Deception with Scorpion and HAC.
  4. The name itself was, among other things, a mockery of LoD, as 'M' is one letter up in the alphabet from 'L', although the name originally was a flexible acronym that could be used to identify membership in situations where anonymity would be the best course of action.
  5. It could stand for "Millions of Dollars" just as easily as "Masters of Deception."
  6. Members of MOD








The original Masters of Deception included:

1. Mark Abene ("Phiber Optik"),













2. Paul Stira ("Scorpion"),


3. Eli Ladopoulos ("Acid Phreak"),


4. HAC, John Lee ("Corrupt," a.k.a. "Netw1z"),





Julio Fernandez ("Outlaw").

Additional members whose real names are unknown include:

  1. Supernigger (also of DPAK)
  2. Wing
  3. Nynex Phreak
  4. Billy_The_Kid
  5. Crazy Eddie
  6. The Plague
  7. ZOD
  8. Seeker
  9. Red Knight (who was also a member of Cult of the Dead Cow)
  10. Lord Micro
  11. n00gie
  12. peaboy (aka, MCI Sprinter)

Philosophy

  • Masters of Deception operated differently in many respects to previous hacking groups. Although they openly shared information with each other, they took a controversial view on sharing information outside the group.
  • It was believed that access to MOD's knowledge should be earned via degrees of initiation and a proven respect for the craft, rather than releasing powerful information into the wild where it could be used for nefarious purposes.
  • A demonstration of responsibility on the part of the initiate was required.
  • This informal compartmentalized protection of more sensitive knowledge was a structure originally employed by LOD in the 1980s, rather successfully.
  • Giving out useful things to irresponsible people would inevitably lead to whatever thing it was being abused and no longer useful. I was very possessive of my information and frequently withheld things from my articles." --Phrack #40 interview, 1/8/1992.

The Fall of MOD

  • As a result of a major nationwide investigation by a joint FBI/Secret Service task force, five of MOD's members were indicted in 1992 in federal court.
  • Within the next six months (in 1993), all five pleaded guilty and were sentenced to either probation or prison.

Masters of Deception have appeared in many magazine and newspaper articles, and the individual members have appeared on television numerous times.

  1. Village Voice July 24, 1990. Cover Article by Julian Dibbel.
  2. Masters of Deception — The Gang that Ruled Cyberspace (ISBN 0-06-092694-5)
  3. Gang War in Cyberspace Wired 2.12
  4. This American Life Oct. 3, 1997. How Bad Is Bad? Act Five profiles Eli
  5. Ladopoulos after his release from prison.

Thursday, October 8, 2009

HACKERS-(Kevin Mitnick, Raphael Gray)





















Kevin Mitnick

Born: August 6, 1963 (1963-08-06) (age 46)

Los Angeles, California

Occupation: Computer Consultant, Mitnick Security Consulting, Author



  • is a computer security consultant and author. He was a world-famous controversial computer hacker in the late 20th century, who was, at the time of his arrest, the most wanted computer criminal in United States history.
  • At the age of twelve, he used social engineering to by pass the punchcard system used in the Los Angeles bus system.
  • After a friendly bus driver told him where he could buy his own punch, he could ride any bus in the greater LA area using unused transfer slips he found in the trash.
  • Social engineering became his primary method of obtaining information, whether it be user names and passwords, modem phone numbers or any number of other pieces of data.
  • In high school, he was introduced by "Petronix" to phone phreaking, a method of manipulating telephones, which he often used to evade long distance charges.
  • He also became handy with amateur radios; using radio equipment, He reportedly managed to gain unauthorized access to the speaker systems of nearby fast food restaurants.


  • After a well-publicized pursuit, the FBI arrested him on February 15, 1995 at his apartment in Raleigh, North Carolina, on federal offenses related to a 2½-year computer hacking spree.
  • In 1999, he confessed to four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting a wire communication, as part of a plea agreement before the United States District Court for the Central District of California in Los Angeles.
  • He was sentenced to 46 months in prison in addition to 22 months for violating the terms of his 1989 supervised release sentence for computer fraud.
  • He admitted to violating the terms of supervised release by hacking into PacBell voicemail and other systems and to associating with known computer hackers, in this case co-defendant Louis De Payne.
  • He served five years in prison, four and a half years pre-trial and eight months in solitary confinement, because law enforcement officials convinced a judge that he had the ability to "start a nuclear war by whistling into a pay phone".
  • He was released on January 21, 2000. During his supervised release, which ended on January 21, 2003, he was initially restricted from using any communications technology other than a landline telephone. He fought this decision in court, eventually winning a ruling in his favor, allowing him to access the Internet.
  • As per the plea deal, He was also prohibited from profiting from films or books that are based on his criminal activity for a period of seven years.
  • As for now, he runs Mitnick Security Consulting LLC, a computer security consultancy.

Confirmed Criminal Acts

  1. Using the Los Angeles bus transfer system to get free rides
  2. Evading the FBI
  3. Hacking into DEC system(s) to view VMS source code (DEC reportedly spent $160,000 in cleanup costs)
  4. Gaining full admin privileges to an IBM minicomputer at the Computer Learning Center in LA in order to win a bet

Alleged Criminal Acts

  1. Stole computer manuals from a Pacific Bell telephone switching center in Los Angeles
  2. Read the e-mail of computer security officials at MCI Communications and Digital
  3. Wiretapped the California DMV
  4. Made free cell phone calls
  5. Wiretapped FBI agents according to John Markoff,although denied by Kevin Mitnick.

Controversy

  • Kevin Mitnick's criminal activities, arrest, and trial, along with the associated journalism were all controversial.
  • Though Mitnick has been convicted of copying software unlawfully and possession of several forged identification documents, his supporters argue that his punishment was excessive.
  • Mitnick states that he compromised computers solely by using passwords and codes that he gained by social engineering.
  • He claims he did not use software programs or hacking tools for cracking passwords or otherwise exploiting computer or phone security.
  • The case against Mitnick tested the newly enacted laws that had been enacted for dealing with computer crime, and it raised public awareness of security issues involving networked computers.
  • The controversy remains, however, and Mitnick is often used today as an example of the quintessential computer criminal.
  • Supporters of Mitnick have asserted that many of the charges against him were fraudulent and not based on actual losses.

The Story behind of Kevin Mitnick?

  • Kevin Mitnick arrested in Raleigh, N.C. last February was of a 31-year old computer programmer, who had been given a number of chances to get his life together but each time was seduced back to the dark side of the computer world.
  • Kevin David Mitnick reached adolescence in suburban Los Angeles in the late 1970s, the same time the personal computer industry was exploding beyond its hobbyist roots.
  • His parents were divorced, and in a lower-middle-class environment that lacked adventure and in which he was largely a loner and an underachiever, he was seduced by the power he could gain over the telephone network.
  • The underground culture of phone phreaks had already flourished for more than a decade, but it was now in the middle of a transition from the analog to the digital world. Using a personal computer and modem it became possible to commandeer a phone company's digital central office switch by dialing in remotely, and Kevin became adept at doing so.
  • Mastery of a local telephone company switch offered more than just free calls: It opened a window into the lives of other people to eavesdrop on the rich and powerful, or on his own enemies.
  • Mitnick soon fell in with an informal phone phreak gang that met irregularly in a pizza parlor in Hollywood.
  • Much of what they did fell into the category of pranks, like taking over directory assistance and answering operator calls by saying, "Yes, that number is eight-seven-five-zero and a half. Do you know how to dial the half, ma'am?" or changing the class of service on someone's home phone to payphone status, so that whenever they picked up the receiver a recorded voice asked them to deposit twenty cents. But the group seemed to have a mean streak as well.
  • One of its members destroyed files of a San Francisco-based computer time-sharing company, a crime that went unsolved for more than a year -- until a break-in at a Los Angeles telephone company switching center led police to the gang.
  • The case was actually solved when a jilted girlfriend of one of the gang went to the police...
    That break-in occurred over Memorial Day weekend in 1981, when Kevin and two friends decided to physically enter Pacific Bell's COSMOS phone center in downtown Los Angeles. COSMOS, or Computer System for Mainframe Operations, was a database used by many of the nation's phone companies for controlling the phone system's basic recordkeeping functions.
  • The group talked their way past a security guard and ultimately found the room where the COSMOS system was located. Once inside they took lists of computer passwords, including the combinations to the door locks at nine Pacific Bell central offices and a series of operating manuals for the COSMOS system.. To facilitate later social engineering they planted their pseudonyms and phone numbers in a rolodex sitting on one of the desks in the room. With a flourish one of the fake names they used was "John Draper," who was an actual computer programmer also known as the legendary phone phreak, Captain Crunch, the phone numbers were actually misrouted numbers that would ring at a coffee shop pay phone in Van Nuys.
  • The crime was far from perfect, however. A telephone company manager soon discovered the phony numbers and reported them to the local police, who started an investigation. The case was actually solved when a jilted girlfriend of one of the gang went to the police, and Kevin and his friends were soon arrested. The group was charged with destroying data over a computer network and with stealing operator's manuals from the telephone company. Kevin, 17 years old at the time, was relatively lucky, and was sentenced to spend only three months in the Los Angeles Juvenile Detention Center, followed by a year's probation.
  • A run-in with the police might have persuaded most bright kids to explore the many legal ways to have computer adventures, but Mitnick appeared to be obsessed by some twisted vision. Rather than developing his computer skills in creative and productive ways, he seemed interested only in learning enough short-cuts for computer break-ins and dirty tricks to continue to play out a fantasy that led to collision after collision with the police throughout the 1980s. He obviously loved the attention and the mystique his growing notoriety was bringing. Early on, after seeing the 1975 Robert Redford movie Three Days of the Condor, he had adopted Condor as his nom de guerre. In the film Redford plays the role of a hunted CIA researcher who uses his experience as an Army signal corpsman to manipulate the phone system and avoid capture. Mitnick seemed to view himself as the same kind of daring man on the run from the law.
  • After he was released, he obtained the license plate "X HACKER" for his Nissan...
  • His next arrest was in 1983 by campus police at the University of Southern California, where he had gotten into minor trouble a few years earlier, when he was caught using a university computer to gain illegal access to the ARPAnet.
  • This time he was discovered sitting at a computer in a campus terminal room, breaking into a Pentagon computer over the ARPAnet, and was sentenced to six months at the California Youth Authority's Karl Holton Training School, a juvenile prison in Stockton, California.
  • After he was released, he obtained the license plate "X HACKER" for his Nissan, but he was still very much in the computer break-in business.
  • Several years later he went underground for more than a year after being accused of tampering with a TRW credit reference computer; an arrest warrant was issued, but it later vanished from police records without explanation.
  • By 1987, Mitnick seemed to be making an effort to pull his life together, and he began living with a woman who was taking a computer class with him at a local vocational school.
  • After a while, however, his obsession drew him back, and this time his use of illegal telephone credit card numbers led police investigators to the apartment he was sharing with his girlfriend in Thousand Oaks, California.
  • He was convicted of stealing software from the Santa Cruz Operation, a California software company, and in December 1987, he was sentenced to 36 months probation. That brush with the police, and the resultant wrist slap, seemed only increase his sense of omnipotence.
  • In 1987 and 1988, Kevin and a friend, Lenny DiCicco, fought a pitched electronic battle against scientists at Digital Equipment's Palo Alto research laboratory.
  • Mitnick had become obsessed with obtaining a copy of Digital's VMS minicomputer operating system, and was trying to do so by gaining entry to the company's corporate computer network, known as Easynet.
  • The computers at Digital's Palo Alto laboratory looked easiest, so every night with remarkable persistence Mitnick and DiCicco would launch their modem attacks from a small Calabasas, California company where DiCicco had a computer support job.
  • Although Reid discovered the attacks almost immediately, he didn't know where they were coming from, nor did the local police or FBI, because Mitnick was manipulating the telephone network's switches to disguise the source of the modem calls.
    ...he agreed to one year in prison and six months in a counseling program for his computer "addiction."
  • The FBI can easily serve warrants and get trap-and-trace information from telephone companies, but few of its agents know how to interpret the data they provide. If the bad guy is actually holed up at the address that corresponds to the telephone number, they're set. But if the criminal has electronically broken into to the telephone company's local switch and scrambled the routing tables, they're clueless. Kevin had easily frustrated their best attempts at tracking him through the telephone network using wiretaps and traces. He would routinely use two computer terminals each night -- one for his forays into Digital's computers, the other as a lookout that scanned the telephone company computers to see if his trackers were getting close. At one point, a team of law enforcement and telephone security agents thought they had tracked him down, only to find that Mitnick had diverted the telephone lines so as to lead his pursuers not to his hideout in Calabasas, but to an apartment in Malibu. Mitnick, it seemed, was a tough accomplice, for even as they had been working together he had been harassing DiCicco by making fake calls to DiCicco's employer, claiming to be a Government agent and saying that DiCicco was in trouble with the Internal Revenue Service.
  • The frustrated DiCicco confessed to his boss, who notified DEC and the FBI, and Mitnick soon wound up in federal court in Los Angeles. Although DEC claimed that he had stolen software worth several million dollars, and had cost DEC almost $200,000 in time spent trying to keep him out of their computers, Kevin pleaded guilty to one count of computer fraud and one count of possessing illegal long-distance access codes.
  • It was the fifth time that Mitnick had been apprehended for a computer crime, and the case attracted nationwide attention because, in an unusual plea bargain, he agreed to one year in prison and six months in a counseling program for his computer "addiction."
  • It was a strange defense tactic, but a federal judge, after initially balking, bought the idea that there was some sort of psychological parallel between the obsession Mitnick had for breaking in to computer systems and an addict's craving for drugs.
  • After he finished his jail time and his halfway-house counseling sentence for the 1989 Digital Equipment conviction Mitnick moved to Las Vegas and took a low-level computer programming position for a mailing list company. His mother had moved there, as had a woman who called herself Susan Thunder who had been part of Mitnick's phone phreak gang in the early 1980s, and with whom he now became reacquainted.
  • It was during this period that he tried to "social engineer" me over the phone. In early 1992 Mitnick moved back to the San Fernando Valley area after his half-brother died of an apparent heroin overdose. He briefly worked for his father in construction, but then took a job he found through a friend of his father's at the Tel Tec Detective Agency .
  • Soon after he began, someone was discovered illegally using a commercial database system on the agency's behalf, and Kevin was once again the subject of an FBI investigation.
  • In September the Bureau searched his apartment, as well as the home and workplace of another member of the original phone phreak gang. Two months later a federal judge issued a warrant for Mitnick's arrest for having violated the terms of his 1989 probation. There were two charges: illegally accessing a phone company computer, and associating with one of the people with whom he'd originally been arrested in 1981.
  • His friends claimed Mitnick had been set up by the detective firm; whatever the truth, when the FBI came to arrest him, Kevin Mitnick had vanished.
  • His escape, subsequently reported in the Southern California newspapers, made the authorities look like bumblers who were no match for a brilliant and elusive cyberthief.
  • In late 1992 someone called the California Department of Motor Vehicles office in Sacramento, and using a valid law enforcement requester code, attempted to have driver's license photographs of a police informer faxed to a number in Studio City, near Los Angeles. Smelling fraud, D.M.V. security officers checked the number and discovered that it was assigned to a Kinko's copy shop, which they staked out before faxing the photographs. But somehow the spotters didn't see their quarry until he was going out the door of the copy shop. They started after him, but he outran them across the parking lot and disappeared around the corner, dropping the documents as he fled. The agents later determined that they were covered with Kevin Mitnick's fingerprints. His escape, subsequently reported in the Southern California newspapers, made the authorities look like bumblers who were no match for a brilliant and elusive cyberthief.

    Raphael Gray







Born: 1982 (age 26–27)

Clynderwen, Wales, UK


Alias(es); Curador


Conviction(s): Pleaded guilty to theft and hacking offences.


Penalty: 36 months of psychiatric treatment.

  • was just 19 when he hacked computer systems around the world over six weeks between January and February 1999 as part of a multi-million pound credit card mission.
  • He then proceeded to publish credit card details of over 6,500 cards as an example of weak security in the growing number of consumer websites.

  • Gray was able to break into the secure systems using just a £800 computer he bought in his home town Clynderwen, Pembrokeshire, Wales.
  • After publishing the credit card info on his webpages Gray posted on the page that law enforcers would never find him "because they never catch anyone.
  • The police can't hack their way out of a paper bag."
  • He was dubbed the Bill Gates hacker when he sent Viagra tablets to Gates' address and then published what he said was the billionaire's own number.
  • He was tracked down by ex-hacker Chris Davis who was insulted by Gray's "arrogance".
  • It took Davis under a day to find Gray which he then forwarded to the FBI, "The FBI was actually quite easy to deal with, although technically, they didn't really understand what it was I was explaining to them.
  • The local police were also very polite, but they didn't understand it," said Davis.
  • Gray was arrested when FBI agents and officers from the local Dyfed Powys Police turned up at the door of his home, which he shared with his mother and two sisters, in March 1999.The sentencing judge ruled that Gray serve 36 months of psychiatric treatment after hearing evidence that he was suffering from a mental condition which needed medical treatment rather than incarceration.
  • Gray also obtained the credit card particulars of Microsoft founder Bill Gates, and he consequently had a batch of Viagra sent to GatesÂ’ California home. In the end, Gray did not go to jail but was issued a three-year “rehabilitation sentence” for his cybercrime.

















Thursday, October 1, 2009

Hackers-Introduction

  • one who hacks, particularly
  • one who cuts with rough or heavy blows.
  • one who kicks wildly or roughly.
  • one who is consistent and focuses on accomplishing a task or several tasks.
  • one who uses a computer to gain unauthorized access to data.
  • (computing) one who is expert at programming and solving problems with a computer.
  • (computing) a computer security professional.
  • (informal) one who manages or copes (one hacks it).
  • (informal) one who annoys (another party).
  • (US) one who is inexperienced or unskilled at a particular activity (e.g. tennis).
  • (US) one who loafs (around).
  • (US) one who rides or drives at an ordinary pace or over the roads (especially distinguished from from racing or hunting).

There are a lot of meaning, terms, and definition of this word. It is also a broad meaning about this word.

  • And those definition, terms, and meaning are follows:

1. Hacker (computer security)

  • hacker is a person who breaks into computers, usually by gaining access to administrative controls.

  • The subculture that has evolved around hackers is often referred to as the computer underground.
  • Proponents claim to be motivated by artistic and political ends, and are often unconcerned about the use of illegal means to achieve them.
  • Other uses of the word hacker exist that are not related to computer security (computer programmer and home computer hobbyists), but these are rarely used by the mainstream media.
  • term referred to exploration of the phone network without authorization, and there has often been overlap between both technology and participants.
  • A person who enjoys exploring the details of programmable systems and how to stretch their capabilities, as opposed to most users, who prefer to learn only the minimum necessary. RFC1392, the Internet Users' Glossary, usefully amplifies this as:
  • A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular.
  • One who programs enthusiastically (even obsessively) or who enjoys programming rather than just theorizing about programming.
  • A person capable of appreciating hack value.
  • A person who is good at programming quickly.
  • An expert at a particular program, or one who frequently does work using it or on it; as in ‘a Unix hacker’. (Definitions 1 through 5 are correlated, and people who fit them congregate.)
  • An expert or enthusiast of any kind. One might be an astronomy hacker
  • One who enjoys the intellectual challenge of creatively overcoming or circumventing limitations.

A malicious meddler who tries to discover sensitive information by poking around. Hence password hacker, network hacker. The correct term for this sense is cracker.

***The term ‘hacker’ also tends to connote membership in the global community defined by the net.

Buttom line:
Hackers are those people who do illegal work deals with computer for both business and personal reasons. A person who uses a computer system without a specific, constructive purpose or without proper authorization. Though, hacking is a good business especially now a days that we are experiencing and facing economic crisis. According to some expert, hacking is part of a new generation of easy money-easy go. Now you see, now you don't.
Hackers do have also code of ethics or Hacker ethics (principles) as they called it. This Hacker ethics are there bases upon on their work or operations. And this ethics or principles are followed below:
1. The belief that information-sharing is a powerful positive good, and that it is an ethical duty of hackers to share their expertise by writing open-source code and facilitating access to information and to computing resources wherever possible.

2. The belief that system-cracking for fun and exploration is ethically OK as long as the cracker commits no theft, vandalism, or breach of confidentiality.

Both of these normative ethical principles are widely, but by no means universally, accepted among hackers. Most hackers subscribe to the hacker ethic in sense 1, and many act on it by writing and giving away open-source software. A few go further and assert that all information should be free and any proprietary control of it is bad; this is the philosophy behind the GNU project.

Sense 2 is more controversial: some people consider the act of cracking itself to be unethical, like breaking and entering. But the belief that ‘ethical’ cracking excludes destruction at least moderates the behavior of people who see themselves as ‘benign’ crackers
On this view, it may be one of the highest forms of hackerly courtesy to:
(a) break into a system, and then
(b) explain to the sysop, preferably by email from a superuser account, exactly how it was done and how the hole can be plugged — acting as an unpaid (and unsolicited) tiger team.
The most reliable manifestation of either version of the hacker ethic is that almost all hackers are actively willing to share technical tricks, software, and (where possible) computing resources with other hackers. Huge cooperative networks such as Usenet, FidoNet and the Internet itself can function without central control because of this trait; they both rely on and reinforce a sense of community that may be hackerdom's most valuable intangible asset.
2. Hacker (programmer subculture)
  • one of several meanings of the word in computing, a hacker is a member of the computer programmer subculture originated in the 1960s in the United States academia, in particular around the Massachusetts Institute of Technology (MIT)'s Tech Model Railroad Club (TMRC) and MIT Artificial Intelligence Laboratory.
  • Hackers follow a spirit of creative playfulness and anti-authoritarianism, and sometimes use this term to refer to people applying the same attitude to other fields.
  • The Jargon File, a compendium of hacker slang, defines hacker as "A person who enjoys exploring the details of programmable systems and stretching their capabilities, as opposed to most users, who prefer to learn only the minimum necessary."
  • The Request for Comments (RFC) 1392, the Internet Users' Glossary, amplifies this meaning as "A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular."
  • These hackers are disappointed by the mass media and mainstream public's usage of the word hacker to refer to security breakers, calling them "crackers" instead.The difference between hackers and crackers, according to them, is that where hackers use their skills and knowledge to learn more about how systems and networks work, crackers will use the same skills to author harmful software (like viruses, trojans, etc.) and illegally infiltrate secure systems with the intention of doing harm to the system. True hackers don't participate in these activities and generally frown upon them.

3.Hacker (hobbyist)

  • a hacker is a person who heavily modifies the software or hardware of their computer system. It includes building, rebuilding, modifying and creating software (software cracking, demo scene) and electronic hardware (hardware hacking, modding) either to make it better, faster, give added features or to make it do something it was never intended to do.
  • Hobby hacking originated around the MITS Altair.
  • one who creates novel hardware modifications.
  • Hardware hackers are those who modify hardware (not limited to computers) to expand capabilities; this group blurs into the culture of hobbyist inventors and professional electronics engineering. An example of such modification includes the addition of TCP/IP Internet capabilities to a number of vending machines and coffee makers during the late 1980s and early 1990s.
  • Hackers who have the ability to write circuit-level code, device drivers, firmware, low-level networking, (and even more impressively, using these techniques to make devices do things outside of their spec sheets), are typically in very high regard among hacker communities. This is primarily due to the difficulty and enormous complexity of this type of work, and the electrical engineering knowledge required to do so.
    Hardware hacking can consist of either making new hardware, or simply modifying old hardware (known as "modding").
  • Real hardware hackers perform novel and perhaps dangerous modifications to hardware, to make it suit their needs.
4. Hacker (computing)

[a] person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular."

Sometimes, Hackers lost their charm or their good luck charms. They were hacked in the cyber world by other hackers. And for some were indicted and end-up in jail. Through this, they were discovered, praise, and honored by other Hackers and computer addicts, as their "IDOLS" and they considered them as COMPUTER GENIUS or known as COMPUTER WIZARD. Which encourage them to explore their life, work, and their masterpiece beyond the publics knowledge. And this Indicted COMPUTER WIZARD are written as follows:

  1. Abene, MarkMark Abene
  • Phiber Optik
  • United States
  • Misdemeanor theft-of-service for a free-call scam to a 900 number.
  • One count of computer trespass and one count of computer conspiracy 1991 19911993 1993.
  • 35 hours of community service.
  • One-year jail sentence

2. Jeanson James Ancheta

  • United States
  • Plead guilty to four felony charges of violating United States Code Section 1030, Fraud and Related Activity in Connection with Computers, specifically subsections (a)(5)(A)(i), 1030 (a)(5)(B)(i) and 1030(b).
  • United States
  • Conspiracy to steal credit card numbers from the Lowe's chain of home improvement stores
  • 2004-12-16 December 16, 2004
  • Two years and two months imprisonment, followed by two years of supervised release
  • cam0
  • United States
    Plead guilty to hacking into the cell-phone account of celebrity Paris Hilton and participated in an attack on data-collection firm
    LexisNexis Group that exposed personal records of more than 300,000 consumers
  • 2005-09-13 September 13, 2005
  • 11 months in a Massachusetts juvenile detention facility
  • MafiaBoy
  • Canada
  • Plead guilty to 56 charges of "mischief to data"
  • 2001-09-12 September 12, 2001
  • Eight months "open custody," by the Montreal Youth Court, one-year of probation, restricted use of the Internet and a small fine
  • Mindphasr
  • United States
  • Intentionally hacking a protected computer and wilfully causing damage
  • 2000-03-01 March 1, 2000
  • Six months in prison, US$8,054 in restitution and three years probation
  • Phoenix
  • Australia
  • 15 charges including trespassing on the University of Texas computer network, altering data at NASA and the theft of the ZARDOZ file
  • 1993 1993
  • One-year suspended sentence: AU$1,000 good-behaviour bond and 500 hours community service

8. Raphael Gray

  • Curador
  • United Kingdom
  • Plead guilty to theft and hacking offences which fall under the Computer Misuse Act and six charges of intentionally accessing sites containing credit card details and using this information for financial gain
  • 2001-07-06 July 6, 2001
  • Three years of psychiatric treatment after evidence emerged that he was suffering from a mental condition which needed medical treatment rather than incarceration

9. Jonathan James

  • c0mrade
  • United States
  • Two counts of juvenile delinquency
  • 2000-09-21 September 21, 2000
  • Six-month prison sentence and probation until the age of eighteen

10. Richard Jones

  • Electron
  • Australia
  • Trespassing on the University of Texas computer network and theft of the ZARDOZ file
  • 1993 1993
  • One year and six months suspended sentence, 300 hours of community service and psychiatric assessment and treatment

11. Adrian Lamo

12. Kevin Mitnick

  • Condor
  • United States
  • Four counts of wire fraud, two counts of computer fraud and one count of illegally intercepting a wire communication
  • 1999-08-09 August 9, 1999
  • 46 months in federal prison

13. Dennis Moran

  • Coolio
  • United States
  • Misdemeanor charges of hacking
  • 2001-03-09 March 9, 2001
  • Nine months in jail and US$5,000 in restitution to each victim

14. Robert Tappan Morris-rtm

  • United States
  • Intentional access of federal interest computers without authorization thereby preventing authorized access and causing a loss in excess of US$1,000
  • 1990-05-16 May 16, 1990
  • Three years probation and 400 hours of community service in a manner determined by the Probation Office and approved by the Court

15. Jeffrey Lee Parson

  • T33kid
  • United States
  • Plead guilty on August 11, 2004 to one count of intentionally causing or attempting to cause damage to a protected computer via his version of the Blaster computer worm
  • 2005-01-01 January 1, 2005
  • 18 months in prison and 100 hours of community service

16.Kevin Poulsen

  • Dark Dante
  • United States
  • Plead guilty to seven counts of mail, wire and computer fraud, money laundering and obstruction of justice
  • 1994-06-01 June 1, 1994
  • 51 months in prison and ordered to pay US$56,000 in restitution

17. Leonard Rose

  • Terminus
  • United States
  • Illicit use of proprietary software (UNIX 3.2 code) owned by AT&T[1] and 2 counts of computer fraud and three counts of interstate transportation of stolen property.
  • 1991-06-12 June 12, 1991
  • One-year jail sentence

18. David L. Smith

  • Kwyjibo
  • United States
  • Plead guilty to knowingly spreading a computer virus, the Melissa virus, with the intent to cause damage
  • 2002-05-01 May 1, 2002
  • 20 months in federal prison, US$5,000 fine and 100 hours of community service upon release

19. Ehud Tenenbaum

  • Analyzer
  • Israel
  • Admitted to cracking US and Israeli computers, and plead guilty to conspiracy, wrongful infiltration of computerized material, disruption of computer use and destroying evidence
  • 2001-06-15 June 15, 2001
  • Six months of community service, one-year of probation, a two-year suspended prison sentence and fined about US$18,000

20. Simon Vallor

  • Gobo
  • United Kingdom
  • Writing and distributing three computer viruses
  • 2003-01-21 January 21, 2003
  • Two-year jail sentence

21. Gerald Wondra

  • The 414s
  • United States
  • Unauthorized access to computers at the Sloan-Kettering Cancer Center in New York and a Los Angeles bank and two counts of "making harassing telephone calls"
  • 1983-05-01 May 1, 1983
  • Two years probation

22. Jan de Wit

  • Netherlands
  • Spreading data into a computer network with the intention of causing damage as the creator of the Anna Kournikova virus
  • 2001-09-27 September 27, 2001
  • 150 hours community service

Hacking is a good challenge especially for those freshmen or First time on this job or kind of work....But on the second thought it is a good practice especially for those professional 'coz it affect your profession, personality, and your whole self.....You're breaking a law, breaking the code of ethics as a professional, destroying your future and breaking yourself as well.....

Monday, September 28, 2009

Computer Viruses-(Melissa, Code Red Virus, & Conficker Worm)

  1. Melissa Virus or Melissa Worm


  • also known as "Mailissa", "Simpsons", "Kwyjibo", or "Kwejeebo", is a mass-mailing macro virus. As it is not a standalone program, it is not in fact a worm.
  • First found on March 26, 1999, Melissa shut down Internet mail systems that got clogged with infected e-mails propagating from the virus.
  • was not originally designed for harm, but it overloaded servers and caused unplanned problems.
  • was first distributed in the Usenet discussion group alt.sex.
  • was inside a file called "List.DOC", which contained passwords that allow access into 80 pornographic websites.
  • original form was sent via e-mail to many people.

CREATED BY OR MADE BY:

Virus specifications

  • Melissa can spread on word processors Microsoft Word 97 and Word 2000 and also Microsoft Excel 97, 2000 and 2003.
  • It can mass-mail itself from e-mail client Microsoft Outlook 97 or Outlook 98.
    If a Word document containing the virus, either LIST.DOC or another infected file, is downloaded and opened, then the macro in the document runs and attempts to mass mail itself.
    When the macro mass-mails, it collects the first 50 entries from the alias list or address book and sends itself to the e-mail addresses in those entries.
  1. Melissa.U
    This variant also deletes critical files. Before deleting the files, it strips them of their archive, hidden, and read-only attributes.
    C:\Command.com
    C:\
    IO.SYS
    C:\
    Ntdetect.com
    C:\Suhdlog.dat
    D:\Command.com
    D:\Io.sys
    D:\Suhdlog.dat
  2. Melissa.V
  • This is another variant of the original Melissa macro virus, and is akin to Melissa.U.
  • It uses Microsoft Outlook, and tries to send itself to the first 40 addresses in Outlook's address book.
  • The subject line of the infected e-mail sent out is: "My Pictures ()", where is the name to whom the sender's copy of Microsoft Word is registered.
  • There is also a variant of the virus named Melissa.V/E which is known to seek and destroy Microsoft Excel documents, randomly deleting sets of data from files, or, at the worst, making them completely useless by applying a set of malicious Macro code. To simplify the code, the author has encrypted only a vectorial search pattern in it, so the virus can only delete linear sets of data, usually random rows or columns in a table. It also has a search parameter that makes it go only for unique sets of data, known to cause more damage.
    A later edit of this variant makes backup copies of the destroyed files, and asks for a ransom of $100 to be transferred into an offshore account in return for the files. The account has been traced back to the owner. Due to a malfunction in code, in less than 1% of cases the code still makes copies.
  • This virus was rendered obsolete when it was discovered that it leaves visible traces in the Windows Registry, providing enough data to ensure its destruction and the retrieval of stolen data.
  • A special version of this variant also modifies the backed-up data, fooling the user even more.
  • It searches for numeric data inside the files, and then, with the help of a random number generator, slightly modifies the data, not visibly, but making it useless.
    There is no body to the email, but there is an infected document attached. If this is opened, the payload is triggered immediately.
  • It tries to delete data from the following (local or network) destinations: F:, H:, I:, L:, M:, N:, O:, P:, Q:, S:, X:, and Z:.
    Once complete, it beeps three times and then shows a message box with the text: "Hint: Get Norton 2000 not McAfee 4.02".

3. Melissa.W

  • This is the same as Melissa.A.

4. Melissa.AO

  • This is what the e-mails from this version contain:

subject: Extremely URGENT:

To All E-Mail User - Attachment: Body:

This announcement is for all E-MAIL user. Please take notethat our E-Mail Server will down and we recommended you to readthe document which attached with this E-Mail.Melissa.AO's payload occurs at 10 a.m. on the 10th day of each month. The payload consists of the virus inserting the following string into the document: "Worm! Let's We Enjoy."

2. Code Red (computer worm)

  • was a computer worm observed on the Internet on July 13, 2001.
  • It attacked computers running Microsoft's IIS web server.
  • was first discovered and researched by eEye Digital Security employees Marc Maiffret and Ryan Permeh, and named it; CodeRed, because they were drinking Pepsi's Mountain Dew CodeRed over the weekend they analyzed it and because of the worms references to China.
  • pecifically the worm code contained the phrase "Hacked By Chinese!" with which the worm defaced websites.
  • had been released on July 13, the largest group of infected computers was seen on July 19, 2001. On this day, the number of infected hosts reached 359,000.
  • On August 4, 2001 Code Red II appeared.

Code Red II

  • is a variant of the original Code Red worm.
  • it uses the same injection vector it has a completely different payload.
  • It pseudo-randomly chose targets on the same or different subnets as the infected machines according to a fixed probability distribution, favoring targets on its own subnet more often than not.
  • it used the pattern of repeating 'X' characters instead of 'N' characters to overflow the buffer.
    eEye believed that the worm originated in Makati City, Philippines (the same origin as the VBS/Loveletter (aka "ILOVEYOU") worm).

How it worked?

  1. Exploited vulnerability
  • The worm exploited a vulnerability in the indexing software distributed with IIS, described in MS01-033, for which a patch had been available a month earlier.
  • The worm spread itself using a common type of vulnerability known as a buffer overflow.
  • It did this by using a long string of the repeated character 'N' to overflow a buffer, allowing the worm to execute arbitrary code and infect the machine.

2. Worm payload

The payload of the worm included:

  1. defacing the affected web site to display:
    HELLO! Welcome to http://www.worm.com! Hacked By Chinese!
    (The last sentence became a meme to indicate an online defeat)
    trying to spread itself by looking for more IIS servers on the Internet.
  2. waiting 20–27 days after it was installed to launch denial of service attacks on several fixed IP addresses. The IP address of the White House web server was among those. When scanning for vulnerable machines, the worm did not test to see if the server running on a remote machine was running a vulnerable version of IIS, or even to see if it were running IIS at all.
  3. Apache access logs from this time frequently had entries such as these:
  • GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNN
    %u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801
    %u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3 %u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0

3. Conficker worm

  • also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008.
  • uses a combination of advanced malware techniques which has made it difficult to counter, and has since spread rapidly into what is now believed to be the largest computer worm infection since the 2003 SQL Slammer.
  • the name Conficker is thought to be a portmanteau of the English term "configure" and the German word Ficker, which means "fucker."
  • Microsoft analyst Joshua Phillips described the name as a rearrangement of portions of the domain name trafficconverter.biz, which was used by early versions of Conficker to download updates.
  • The first variant of Conficker, discovered in early November 2008, propagated through the Internet by exploiting a vulnerability in a network service (MS08-067) on Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2 Beta.
  • While Windows 7 may have been affected by this vulnerability, the Windows 7 Beta was not publicly available until January 2009.
  • Although Microsoft released an emergency out-of-band patch on October 23, 2008 to close the vulnerability, a large number of Windows PCs (estimated at 30%) remained unpatched as late as January 2009.
  • A second variant of the worm, discovered in December 2008, added the ability to propagate over LANs through removable media and network shares.
  • these were decisive factors in allowing the worm to propagate quickly: by January 2009, the estimated number of infected computers ranged from almost 9 million to 15 million.
  • Antivirus software vendor Panda Security reported that of the 2 million computers analyzed through ActiveScan, around 115,000 (6%) were infected with Conficker. Recent estimates of the number of infected computers have been more notably difficult because of changes in the propagation and update strategy of recent variants of the worm.
  • s spreading through networks at alarming rates.
  • It's weapon: exploiting vulnerability called MS08-067 in Windows 2000, XP, and Server 2003.
  • spreads via Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability.

Operation

  • almost all of the advanced malware techniques used by Conficker have seen past use or are well-known to researchers, the worm's combined use of so many has made it unusually difficult to eradicate.
  • The worm's unknown authors are also believed to be tracking anti-malware efforts from network operators and law enforcement and have regularly released new variants to close the worm's own vulnerabilities.
  • Five variants of the Conficker worm are known and have been dubbed Conficker A, B, C, D and E. They were discovered 21 November 2008, 29 December 2008, 20 February 2009, 4 March 2009 and 7 April 2009, respectively.

Initial infection

  • Variants A, B, C and E exploit a vulnerability in the Server Service on Windows computers, in which an already-infected source computer uses a specially-crafted RPC request to force a buffer overflow and execute shellcode on the target computer.
  • On the source computer, the worm runs an HTTP server on a port between 1024 and 10000; the target shellcode connects back to this HTTP server to download a copy of the worm in DLL form, which it then attaches to svchost.exe.
  • Variants B and later may attach instead to a running services.exe or Windows Explorer process.
  • Variants B and C can remotely execute copies of themselves through the ADMIN$ share on computers visible over NetBIOS. If the share is password-protected, a dictionary attack is attempted, potentially generating large amounts of network traffic and tripping user account lockout policies.
  • Variants B and C place a copy of their DLL form on any attached removable media (such as USB flash drives), from which they can then infect new hosts through the Windows AutoRun mechanism.
  • To start itself at system boot, the worm saves a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service.

Payload propagation

  • The worm has several mechanisms for pushing or pulling executable payloads over the network. These payloads are used by the worm to update itself to newer variants, and to install additional malware.
  • Variant A generates a list of 250 domain names every day across five TLDs.
  • The domain names are generated from a pseudo-random number generator seeded with the current date to ensure that every copy of the worm generates the same names each day. The worm then attempts an HTTP connection to each domain name in turn, expecting from any of them a signed payload.
  • Variant B increases the number of TLDs to eight, and has a generator tweaked to produce domain names disjoint from those of A.
    To counter the worm's use of pseudorandom domain names, Internet Corporation for Assigned Names and Numbers (ICANN) and several TLD registries began in February 2009 a coordinated barring of transfers and registrations for these domains.
  • Variant D counters this by generating daily a pool of 50000 domains across 110 TLDs, from which it randomly chooses 500 to attempt for that day. The generated domain names were also shortened from 8-11 to 4-9 characters to make them more difficult to detect with heuristics.
  • This new pull mechanism (which was disabled until April 1) is unlikely to propagate payloads to more than 1% of infected hosts per day, but is expected to function as a seeding mechanism for the worm's peer-to-peer network.
  • The shorter generated names, however, are expected to collide with 150-200 existing domains per day, potentially causing a distributed denial of service attack (DDoS) on sites serving those domains.
  • Variant C creates a named pipe, over which it can push URLs for downloadable payloads to other infected hosts on a local area network.
  • Variants B, C and E perform in-memory patches to NetBIOS-related DLLs to close MS08-067 and watch for re-infection attempts through the same vulnerability.
  • Re-infection from more recent versions of Conficker are allowed through, effectively turning the vulnerability into a propagation backdoor.
  • Variants D and E create an ad-hoc peer-to-peer network to push and pull payloads over the wider Internet. This aspect of the worm is heavily obfuscated in code and not fully understood, but has been observed to use large-scale UDP scanning to build up a peer list of infected hosts and TCP for subsequent transfers of signed payloads.
  • To make analysis more difficult, port numbers for connections are hashed from the IP address of each peer.

Once this virus infects a computer it does a number of things including:

  • Extracts all of its files to the %System% directory with random DLL file names, which can wreak havoc on your computer.
  • Deletes the user's Restore Points.
  • Registers a services called Netsvcs
  • Creates scheduled tasks that execute all of the DLL files.
  • Creates it's own simple HTTP server on the infected computer and spreads the worm to other computers in the network through file shares.
  • Creates an Autorun.inf file in file shares to execute the warm files once the share is accessed by another computer.
  • Connects to external sites to download additional files.

Symptoms

  1. Account lockout policies being reset automatically.
  2. Domain controllers responding slowly to client requests.
  3. Congestion on local area networks (ARP flood as consequence of network scan).
  4. Web sites related to antivirus software or the Windows Update service becoming inaccessible.
  5. User accounts locked out

Response

Armoring

  • To prevent payloads from being hijacked, variant A payloads are first SHA1-hashed and RC4-encrypted with the 512-bit hash as a key.
  • The hash is then RSA-signed with a 1024-bit private key.
  • The payload is unpacked and executed only if its signature verifies with a public key embedded in the worm.
  • Variants B and later use MD6 as their hash function and increase the size of the RSA key to 4096 bits.

Self-defense

End action

  • Variant E of the worm was the first to use its base of infected computers for an ulterior purpose.
  • It downloads and installs, from a web server hosted in Ukraine, two additional payloads:
  1. Waledac, a spambot otherwise known to propagate through e-mail attachments.
  2. Waledac operates similarly to the 2008 Storm worm and is believed to be written by the same authors.
  3. SpyProtect 2009, a scareware anti-virus product.

Removal and detection

  • Microsoft has released a removal guide for the worm, and recommends using the current release of its Windows Malicious Software Removal Tool to remove the worm, then applying the patch to prevent re-infection.

Third-parties

Automated remote detection

  • On 27 March 2009, Felix Leder and Tillmann Werner from the Honeynet Project discovered that Conficker-infected hosts have a detectable signature when scanned remotely.
  • The peer-to-peer command protocol used by variants D and E of the worm has since been partially reverse-engineered, allowing researchers to imitate the worm network's command packets and positively identify infected computers en-masse.
    Signature updates for a number of network scanning applications are now available including NMap and Nessus.
  • Also it can be detected in passive mode by sniffing broadcast domain for repeating ARP requests.

The Action or response of US CERT

  • The United States Computer Emergency Readiness Team (US-CERT) recommends disabling AutoRun to prevent Variant B of the worm from spreading through removable media.
  • Prior to the release of Microsoft knowledgebase article KB967715, US-CERT described Microsoft's guidelines on disabling Autorun as being "not fully effective" and provided a workaround for disabling it more effectively.
  • US-CERT has also made a network-based tool for detecting Conficker-infected hosts available to federal and state agencies.

From that time on.....

  • The ICANN has sought preemptive barring of domain transfers and registrations from all TLD registries affected by the worm's domain generator.
  • Those which have taken action include:
  1. On 13 March 2009, NIC Chile, the .cl ccTLD registry, blocked all the domain names informed by the Conficker Working Group and reviewed a hundred already registered from the worm list.
  2. On 24 March 2009, CIRA, the Canadian Internet Registration Authority, locked all previously-unregistered .ca domain names expected to be generated by the worm over the next 12 months.
  3. On 27 March 2009, NIC-Panama, the .pa ccTLD registry, blocked all the domain names informed by the Conficker Working Group.
  4. On 30 March 2009, SWITCH, the Swiss ccTLD registry, announced it was "taking action to protect internet addresses with the endings .ch and .li from the Conficker computer worm."
  5. On 31 March 2009, NASK, the Polish ccTLD registry, locked over 7,000 .pl domains expected to be generated by the worm over the following five weeks. NASK has also warned that worm traffic may unintentionally inflict a DDoS attack to legitimate domains which happen to be in the generated set.
  6. On 2 April 2009, Island Networks, the ccTLD registry for Guernsey and Jersey, confirmed after investigations and liaison with the IANA that no .gg or .je names were in the set of names generated by the worm.
  • By mid-April all domain names generated by the Conficker.A variant had been successfully blocked, rendering its update mechanism ineffective.