Pentagon’s pursuit of ‘scapegoat’ hacker hides real threat from the web

Posted by Kuji on June 26th, 2008

Criminal gangs taking over from amateur hobbyists

Owen Bowcott, Saturday June 11, 2005, The Guardian

Gary McKinnon is deemed to be so deviously manipulative at the keyboard that he has been banned from using the internet. He is not even allowed a passport. The peculiar bail conditions imposed this week on the 39-year-old computer systems administrator from Wood Green, north London, suggest that the law enforcement community stands in awe of his technological prowess.

Until his next court appearance, due on July 27, the tousle-haired programmer, who is fighting extradition to the United States, has been ordered to stay away from any computer connected to the web.

Mr McKinnon has gained international notoriety for his alleged ability to break into scores of sensitive US defence computers, steal secret passwords, sabotage email systems and delete military files. In the hi-tech world of online hacking, however, he is perceived as one of a dying breed of amateur hobbyists – those the Americans deride as “script-kiddies”.

Despite US prosecution claims that he perpetrated “the biggest military computer hack of all time”, Mr McKinnon’s supposed achievements are by no means unique. The attempt to extradite him to answer charges in Virginia and New Jersey is far more unusual. Systems run by Nasa, the Pentagon and the Department of Defence have long been hackers’ trophy targets. His misfortune, apparently, was to get caught, and to have carried out his explorations shortly after September 11.

According to security experts, US military sites are not the most heavily protected on the internet. They rely on the deterrent threat of legal action rather than deploying highly sophisticated software or enforcing best practice among military personnel.

Mathew Bevan, another British hacker arrested for breaches of security at Nasa and US Air Force sites, found himself similarly demonised by US lawyers as “the single biggest threat to world security since Adolf Hitler” back in 1994. The case against him eventually collapsed. Like Mr McKinnon, he was also hunting for evidence about UFOs hidden on military installations.

Mr Bevan, now 30, is an IT consultant and living in Wiltshire. “The security on US military machines is probably not much better than it was back then,” he said. “There were plenty of military machines with sensitive information that had account names with no passwords. Others had been left with the standard default passwords used by the manufacturers.

“University systems and corporations are much harder to break into than military machines: universities because there are always students testing their skills, and companies because they have shareholders demanding better security.”

In Britain, the hacking subculture that nurtured Mr McKinnon’s talents has been driven underground by diligent enforcement of the Computer Misuse Act, which since 1990 has criminalised those who gain unauthorised access to computer systems.

Mr Bevan typifies the career trajectory once pursued by teenage hackers. After years hunched alone over a computer screen, and an infamous brush with the law, he has graduated to running his own company, the Kuji Media Corporation, which offers security and technology advice.

“Hackers are a dying breed,” said Mr Bevan. “Organised criminals have cottoned on to the potential rewards. There’s viruses and trojan programs flooding out of places like Russia and Bulgaria these days.

“I get people asking, ‘Why is my machine running slowly?’ And when you look, there are 300 viruses, bits of adware [advertising programs] and trojans mucking up the system. Internet service providers should really be doing deals with security firms to provide virus-free connections.”

Mr Bevan said he spoke to Mr McKinnon in 2002, “after he was first busted”.

“He’s only been selected by US prosecutors because he’s an excellent scapegoat. Maybe the amount of recreational hacking is the same, but the volume of people on the net means far more are involved in genuinely nefarious activities.”

“Pharming”, for example, is the latest threat to the integrity of internet banking services. It has emerged from Estonia in the past few months. This cunning electronic fraud may force banks to issue customers with a new generation of identity devices.

Unlike “phishing” scams – which rely on the gullibility of those who receive emails urging them to log on to sites purporting to be their online bank and confirm passwords and account details – pharming is more insidious.

Customers’ computers are infected by a trojan program – either delivered through an innocent-looking email or inadvertently downloaded from a fake advert on the internet. When the user tries to log on to the online account, the hidden program diverts the web browser to a seemingly identical site operated by criminal gangs in eastern Europe. Their electronic identities are captured, then used to empty the accounts.

“There’s discussions about whether banks will eventually have to give out security devices for customers to plug into their computers,” said Sandra Quinn of APACS, the banking industry’s payments organisation. “Barclays have already carried out trials.”

Last year, online fraud cost British banks ?12m, an increase on previous losses. That figure was dwarfed, however, by the ?150m taken via what is known as “card not present” frauds, where goods are purchased over the telephone using stolen credit cards or simply their numbers.

The array of online threats grows all the time. Denial of service (DoS) attacks, where firms’ email systems are bombarded into overload, are frequently accompanied by blackmail demands for cash to switch off the onslaught. Last year, the bookmaker William Hill was targeted and then received a demand for $50,000 (?28,000).

“Bot” programs enable computers across the net to be hijacked by remote users who in effect turn them into “zombie” machines which can be used in DoS attacks. Keylogging programs can infiltrate computers and record the keystrokes customers make in typing in credit card numbers or passwords. The criminals behind these attacks are based mainly in eastern Europe, it is believed, because law enforcement there is relatively slack and there is a plentiful supply of skilled but poorly paid programmers.

“It’s a classic low-risk crime,” said Ms Quinn. “We have seen some police action, however, and now we are getting phishing attacks coming from China.”

Threats have also been made to call-centre staff working in the financial services sector in Britain, in an attempt to force them to record and hand over customer account details. Many companies now prevent staff from using pens or paper when they sit at their screens.

The difficulty in penetrating banks has encouraged gangs to combine online techniques with strongarm tactics. The reported theft of computer backup tapes from US financial institutions while in transit to storage facilities has generated concerns about the security of millions of customers’ accounts.

An attempt earlier this year to steal ?220m by electronic transfers from the London headquarters of the Japanese bank Sumitomo was foiled, but it sparked alarm about criminals infiltrating banks to carry out insider robberies.

“Gary McKinnon appears to be an example of the type of hacking that people have moved away from,” said Felicity Bull of the National Hi-Tech Crime Unit, which investigates major computer crime in Britain. “We know that organised crime is now hiring IT-literate workers.”

Some law enforcement agencies now question whether the Computer Misuse Act needs to be overhauled, enabling it to be used to prosecute those involved in DoS attacks.

In Washington, the secret service is the force responsible for combating online fraud and hacking. “There are still plenty of script-kiddies out there bragging about what they’re doing,” one agent, Jim Dobson, told the Guardian. Some were still at high school, he said, adding: “There’s a huge amount of information out there.”

Other threats, such as gangs in Russia targeting financial institutions, or those in Asia carrying out intellectual property thefts, have eclipsed the old-style hacker community, he acknowledged.

The rise of mobile phone technology has provided fresh opportunities for a new generation of hackers.

Meanwhile, wireless computer networks have been found to be particularly vulnerable, said Paul Carratu, whose Surrey firm carries out penetration testing to assess security systems. “People are not using the encryption devices they should.”

Last month, two British hackers, Jordan Bradley, from Darlington, and Andrew Harvey, from Durham, who belonged to an Anglo-US group called the “Thr34t Krew”, pleaded guilty in Newcastle to computer crime offences. The TK worm they released exploited a weakness in web servers and caused up to ?5.5m damage to companies using the net. They now face possible prison sentences.

It may be too soon to write off the perverse ingenuity of British hackers.

The lingo and what to look out for

Trojan (horse) An innocent-looking program concealing destructive intentions.

Pharming Hijacking online bank customers by infecting web browsers. They are redirected to fake internet sites and asked to disclose account details.

Phishing Sending out emails telling online account customers they must reconfirm IDs and passwords. When they hit reply they are sent to a cloned web page.

Key logging Programs which record keystrokes and can be used to retrieve credit card and PIN numbers.

Malware Umbrella term for assorted malicious software programs which sabotage your computer.

Zombies Online computers that have been infected by trojans and can then be remotely controlled to churn out spam emails at targeted sites.

Bots Programs used to infect and control computers which are then turned into zombies.

The ‘spider’s web’ of hacking

Posted by Kuji on June 26th, 2008

By Margaret Ryan – BBC News

As a Briton faces possible extradition to the US for alleged computer crime, a former hacker, whose prosecution collapsed, talks about the lure of breaking into systems.

Matthew Bevan had stood accused of mounting a determined “information warfare” campaign against the US air force and leading defence contractors in 1994.

The case against Mr Bevan collapsed
US Senate hearings were initially told the security breaches were the work of highly skilled foreign agents.

Mr Bevan, whose hacker alias was Kuji, was charged with conspiracy and faced accusations of being an Eastern European spy.

But the truth was somewhat more prosaic, said the 30-year-old computer consultant.

“I was just a kid in my bedroom hunting for UFO information.”

Then a computer programmer for an insurance firm, he says he had previously been bullied and had felt ostracised by his peers.

“But the computer system was a place where I was king and showed power.

“In the real world I had none and I was quite defenceless. I didn’t deliberately cause any damage.”

Thrill of the chase

But the amateur hacker’s pastime landed him in court in the UK after his activities came to the attention of the US authorities and the British police tracked him down.

Mr Bevan can only talk about his own experiences – but his case, he believes, was overblown from the start as he was portrayed in the States as a spy running rings of spies.

It’s like a parent finding their child’s diary. You know you shouldn’t look at it but you just can’t help yourself

“At the time I was ‘the single biggest threat to world security since Adolf Hitler’,” he said.

By the time his case came to court the allegations made against him had died down.

The case against him finally collapsed in 1997 after the judge was told he posed no threat to security.

Another, a 16-year-old defendant, was fined £1,200 after admitting breaking into a number of US military systems.

Mr Bevan, who now lives in Wiltshire, freely admits that, for hackers, successfully breaking into systems provides an ego boost.

Reports claiming that UFO were being held secretly at American military installations had set the young hacker down the path of trying to find out more.

“It’s an adrenalin rush. It’s like a parent finding their child’s diary.

“You know you shouldn’t look at it but you just can’t help yourself.

“You know it’s wrong but you still do it. It becomes addictive,” he explained.

Competitive element

More than a decade on Mr Bevan understands the havoc hackers can cause in compelling companies to install more security, but resents the suggestion his actions were done out of malice.

“It’s like a spider’s web – once you break into one machine you can compromise a few accounts.

The search for UFOs prompted Mr Bevan’s hacking

“You may go into a machine not with the intent to find anything but just as a staging ground for another computer system.”

“It’s a case of ‘how many computers can I hack into in two hours?’ We used to have competitions.”

But he claimed hackers had been “tainted” by the rise in identity theft and viruses.

For the hacker, he argued there is an ethical code that information should be free and there are strict rules about using that information.

He believes companies have to accept some responsibility for hacking, arguing insurance firms would not generally pay out on insurance claims if it could be shown that not enough care had been taken in guarding against it.

To this day he believes his arrest was politically motivated, suggesting hacking cases make headlines when companies want funding to fight cyber crime.

“In my cynical view the powers that be decided ‘we’ll have you two and make a good example of you'”, he said.

Childhood pursuit

He says he had already left hacking behind him before the day he was arrested at work.

Since his case was dropped the world of hacking has changed but he believes the potential for disruption remains stronger than ever as young people become ever more computer literate.

“When I was doing it people didn’t have net access in the UK. I was dialling up to the States,” he said.

For many hacking is a young person’s pursuit that they eventually grow out of, he suggested, but before they do the potential for disruption is incalculable.

“They [children] are smart and can develop skills that adults can’t keep up with,” he said.

RIAA Website Defaced, Taken Offline

Posted by Kuji on June 26th, 2008

(By Jay Lyman, www.NewsFactor.com) – After drawing the ire of the online file-swapping community and Internet users at large, the Recording Industry Association of America (RIAA) Web site was defaced and taken offline Wednesday. The defacement, described as “the funniest hack ever” on a forum site, resembled the normal RIAA site but featured such links as “Piracy can be beneficial to the music industry” and “Where can I find information on giant monkeys?”

After drawing the ire of the online file-swapping community and Internet users at large, the Recording Industry Association of America (RIAA) Web site was defaced and taken offline Wednesday.

The defacement, described as “the funniest hack ever” on a forum site, resembled the normal RIAA site but featured such links as “Piracy can be beneficial to the music industry” and “Where can I find information on giant monkeys?”

Fix in the Works

While the RIAA would not acknowledge that its site had been hacked or defaced, the group, which has tried to prevent Napster ( news – web sites)-like online file sharing, admitted that its site was offline.

“There’s a problem with our site that we’re fixing,” an RIAA spokesperson told NewsFactor. “It should be back up shortly.”

The spokesperson would not comment on whether the association is a favorite target of hackers or is disliked by an array of Internet users.

Defacement Cheered

However, distaste for the RIAA and its legal offensive on Internet music file-sharing services was apparent in posts to forum site Fark.com, which generally cheered the defacement and jeered at the recording industry.

Among posts at the online forum were: “Yeah! Stick it to the man!” and “That hack is like six levels deep. Someone put their time into this. Sweet.”

“There is a growing sentiment of ill will toward the RIAA, the Motion Picture Association of America and content owners in general,” Yankee Group senior analyst Mike Goodman told NewsFactor.

Goodman said that despite the RIAA’s legal contentions that free online music trading violates copyright law and constitutes piracy, the majority of consumers resent content owners’ efforts to clamp down on file sharing.

“It’s a bit more of a radical reaction,” Goodman said of the defacement. “But it underlies a much more mainstream feeling that we’re going to share our music online and you guys are infringing on that.” Goodman pointed out that the general feeling among consumers is that file sharing is an inalienable right.

Industry Cries Foul

While studies, including a recent Yankee Group report, have indicated that free online music trading will flourish until legitimate, licensed sites offer the content, ownership and portability that consumers want, the RIAA continues to blame free online music trading for declining CD sales.

Music CD sales declined 7 percent in the first half of this year, costing the industry more than US$280 million, the RIAA said this week.

In addition, an RIAA-commissioned study indicated that increased music downloading from the Internet corresponds to reduced CD purchases. The RIAA, which has leveraged copyright law against peer-to-peer site Napster, among others, has warned that it might pursue individual users of free online file trading services.

Technology Revolution

Goodman said the RIAA must take the defacement seriously but can do little about it other than increase the site’s security. He alluded to the explosion of free online music trading by saying, “Technology is causing a revolution in the way consumers consume content.”

He pointed out that content owners are trying to impede this revolution, but “it’s not a particularly consumer-friendly approach.”

Hackers Rule OK

Posted by Kuji on June 26th, 2008

06:05 Monday 27th December 1999
Will Knight

People may associate it with the US, but
hacking – both legal and illegal – is an international phenomenon. And Britain has its own distinct history of computer exploits

Hackers are often thought of as sinister computer criminals or a grubby and degenerate social underclass. In reality the history of hacking includes some of the greatest technological and intellectual innovations in modern times alongside the better-publicised computer crimes. Many prefer to draw a line between experimentation and programming, on the one hand, and illegal or destructive computer activity (often referred to as “cracking”) on the other.

Hacking is intricately linked with the emergence of the open- source movement, the development of the Internet and the creation of computers, as well as the emergence of a new techno-savvy subculture. The contribution that Brits have made to this saga has been woefully under-represented in the histories of hacking that have proliferated on the Web.

Here, then, are some of the milestones of British hackerdom.

“Hacking might be characterised as ‘an appropriate application of ingenuity’. Whether the result is a quick-and- dirty patchwork job or a carefully crafted work of art, you have to admire the cleverness that went into it.” — Eric Raymond, The Hacker’s Dictionary

1940

Alan Turing and other cryptanalyts apply the scientist’s theory of The Universal Turing Machine at the Government Code and Cipher School (GC&CS) at Bletchley Park to crack the German military’s legendary Enigma code. These tweed and corduroy cyber-cowboys received virtually no public acknowledgement for their exploits because of national secrecy as well as the lack of mean handles such as “laser boy” or pHr3Ak!n tUr1N9.

1952

Government Communications Headquarters (GCHQ) located in Cheltenham takes over from GCCS as Britain’s answer to the US’ NSA (National Security Agency). In charge of developing and implementing computer surveillance technology, GCHQ still plays a vital role fending off the malevolent forces of freelance British hacking.

1960

BT introduces Switched Packet System (SWP) paving the way for increased phone hacking.

1981

IBM introduces the first Personal Computer (PC)

1982

Thieves hack into the telephone line at Lloyds bank in Holborn in order to disable its alarm system.

1983

Head of the metropolitan computer crime unit Ken McPherson predicts that in 15 years all fraud would be computer related.

1984

Ribert Schifreen and Steve Gold break into BT’s prehistoric Prestel messaging system and gain unlawful access to the personal account of beloved royal patriarch Prince Philip. Estimated to have cost Prestel customers a grand total of ?11, Schifreen and Gold are fined ?750 and ?600 respectively.

1988

Peter Sommer creates the influential classic “The Hacker’s Handbook” under the pen-name of Hugo Cornwall. Although now largely outdated, the book is a testament to the heritage of phone phreaking in Britain and contains memorable guides to subverting all manners of computer and telecommunications networks.

The “Mad Hacker”, also known by the slightly less intimidating handle Nick Whitely, is arrested and accused of running amok on the computer systems of the Ministry of Defence and MI5. Whitely claimed to have gathered evidence of Conservative government surveillance of the Labour party and CND. Despite this extraordinary behaviour, Whitely served only two months in prison in 1990.

1990

Briton Tim Berners-Lee co-invents the World Wide Web, paving the way for thousands of script kiddie Web site defacements and denial of service attacks.

The Computer Misuse Act is amended to make it illegal to gain unauthorised access a personal computer or to alter the data on a personal computer without permission. Only a handful of individuals have, however, even been charged under this act. It remains far more practical to prosecute for software piracy and bizarrely even for stealing electricity.

1992

A group of three hackers calling themselves the Little Green Men are arrested, although one famously escapes prosecution after pleading computer addiction.

1994

This is the year when a couple of Limey computer tricksters give the might of the US government a bit of a shock. Matt Bevan and Richard Pryce, AKA Kuji and Datastream Cowboy, made headlines in the national press when they broke into the computer network of a modest little American government compound called the Pentagon.

Group of Russian hackers are arrested in London after breaking into the computer systems at Citibank and stealing more than $10m, one of the few instances of computer fraud that have reached the papers. The International Chamber of Commerce recently admitted it was aware of a number of cases of organised computer extortion and theft. Hardly surprisingly, however, no other British financial institution has ever come clean and admitted to having been targeted by computer hackers.

1996

Conservative Party Web site is cracked in Britain’s first ever politically inspired piece of Web defacement.

1997

Coldfire (Leon Fitch) is arrested after alleged hacking activities. While on bail, he is charged with cloning cellular phones.

A group called Milw0rm, containing a number of British hackers, targets Indian nuclear bases at the time of India’s controversial nuclear testing.

Paul Spiby is arrested and accused of nefarious telephone activities.

Pipex Dial 0800 loophole allows free unauthorised Internet access until details of the flaw were inadvertently published in underground magazine Port Sniffer.

1999

Endorsing the view that one politician is as good as the next, another bunch of crackers deface the Labour Party’s site, much to the annoyance of the supposedly techno-savvy new government.

An individual is apprehended for alledgedly gaining illegal access to a 0800 number created by a BT employee and enjoying the luxury of totally free Internet access (the case is ongoing).

Computer hacking appears to have entered public consciousness (albeit with particularly negative connotations) to such an extent that even the technophobic Tory party blames hackers for the exposure of its shady financial dealings.

British cyber activists attempt to co-ordinate even the most technologically inept into a mass denial of service attack on the World Trade Organisation. Misfires somewhat, but still illustrates the growing importance of computer “misuse” to the average Brit.

Herbless the hacker goes legitimate

Posted by Kuji on June 26th, 2008

06:06 Tuesday 21st November 2000
Will Knight

The UK’s most infamous “black hat” hacker,
trying to go straight?

A UK hacker who made a name for himself cracking commercial Web servers and posting political messages on corporate sites, says that he/she is now keen to move into legitimate security work.

“Herbless” says that he (or she) is hoping to land some paid work but has already helped many companies secure their networks — free of charge. The benevolent ex-hacker claims not to be a malicious individual and says his “black hat”, or illegal, activities have never stretched to stealing personal or financial information.

Herbless says that he has only ever revealed a vulnerability when he’s felt that security has been completely ignored and argues that his past misdemeanours should not be seen as a black mark against his character. “I would argue that they are assuming that ‘wrong’ and ‘illegal’ are the same thing, which is not always the case,” says Herbless in an email.

“All that time I was also helping companies secure their networks. If I was in the network of a company and discovered credit card details or such things, I would immediately inform the systems administrators making sure that the general public didn’t find out until the problems were fixed.”

The activities of Herbless nevertheless caught the imagination of the public and the press because of the political nature of the defacements and the high profile targets. In September, Herbless broke into a number of Web sites belonging to HSBC bank and posted pages criticising the government over fuel taxation. Herbless also struck UK government Web sites to protest about the government’s stance on smoking.

The uncomfortable nature of this past behaviour leads some experts to question whether Herbless would make a trustworthy employee for any computer security company.

Matt Bevan, who was arrested in 1997 for breaking into computers belonging to the Pentagon, has since founded his own security company, Kuji Media Corporation. He suggests that even if Herbless doesn’t choose to reveal his past misdeeds he could face a tough time. “His illegal activity may come back and bite him,” he says.

Another consultant, Neil Barrett of security firm IRM, has seen one recent security evaluation by Herbless. He says that although he has technical ability, this doesn’t detract from his dubious past “He’d have to work in a team and they’d have to be able to trust him not to do something stupid,” he says.

The presence of hackers with a dark past within legitimate companies has become a controversial topic in recent months, with some companies stating that they would never employ someone who has been involved in criminal activities. Some experts, however, believe that previously “black hat” hackers inevitably find their way into companies.

UK Hacker Says He Found Anti-Gravity Engine File

Posted by Kuji on June 26th, 2008

UK Hacker Says He Found Anti-Gravity Engine File
At W/P AFB

By Matthew Williams

2-7-99

Mathew Bevan is a 23 old computer hacker with an interest in UFOs. Recently he made front page world headlines when he was charged with hacking offences which included access to the most secret military computers of the United States Military. Mathew was able to access computers, which had the ability to launch nuclear missiles or other missiles. Described by one pentagon spokesman as being “The biggest threat to world peace since Adolf Hitler”, Mathew Bevan talks to Matthew Williams about how he did it and the fact that whilst in Wright Patterson Air Force Base computers he saw plans to a secret Anti Gravity propulsion engine….

Matthew Williams: How many years have you been into the Internet.

Mathew Bevan: Since about 16. It was a case that over here there were very few Internet providers. The only one was Demon Internet and the closest phone number to dial was in Bristol, so it was just easier to do a free (hacked) phonecall to the States and use a free provider and not worry about paying any bills.

MW: How does one “hack” the phones – what is the procedure involved.

MB: You use a little program on the old computer… The Amiga was the first computer to be used for “Blueboxing” (hacking phones) and the reason was that it has four channels of sound whereas the PC could only go “BEEP”. To get the blueboxing to work you had to play dual tones into your phone. There was a set of frequencies of tone not dissimilar to DTMF which is on most modern phones (DTMF – the tones played when you press a number on your phone keypad). When the special tones were played it would cause the network to do a number of special things.

What you then needed to do is to call a 0800 number for a foreign countries operator service – such as Columbia or Hawaii. You would play a few tones down the line and it would cut the operator off and BT would think that you had hung up the call but in fact you were still in the trunking system and you play a few more tones and you could re-route your call anywhere.

MW: Is it complicated to do these things because playing sets of musical tones down the phone line sounds quite complicated and what if you make a mistake.

MB: Well it is complicated but is a case of playing around to see what you could do. If you make a mistake you just hang up and try again. There were some other interesting things you could do like dialling a number and when you get the engaged signal then play a couple of tones and break into the call and listen without the two parties knowing you were there.

MW: You are saying that there are ways to listen to calls without being detected and this can be done from any home phone with such codes! Are you saying that you could listen to another call anywhere in the world?

MB: Yes but most of the time I was calling into the States anyway so that’s where I did it the most. I think that secretly listening in is what it was designed for.

MW: So when did you go from hacking innocent university computers into hacking the military computers?

MB: It was a case of getting onto a system and getting the password file and then running the encrypted passwords through a code cracking program so that you get the passwords. Once you have the passwords then you can get a higher level of access and get into peoples files and folders and you can monitor the system to see what it is happening. You can see that there are people that are themselves who are going from computer to computer with legitimate reasons. Now it would just happen that some of these people would be working on projects with the military. You could find that a professor would be contacting a military site (computer).

One would get fed up with doing small computer systems and would want to try to hack something bigger. The thing with people is that they tend to like the same password for multiple systems and so if you have hacked their account on a relatively unprotected system then the password will probably work on another more well protected system. The professor probably has some silly password like “professor” on the university computer and more often than not would use the same on a military system.

It is not a case of sitting there typing in millions of passwords and hoping that you get the right one. There are much more intelligent programs to do that for you and get you in to a system.

We now use things called SNIFFERS, which are covert and do not harm the system in any way. These sit in the background and watch for people’s passwords and they send them back to you. This is something that I was charged with and the offence read “modification to a system with intent to impair the operation of the computer”. Well the whole point of a sniffer is that it sits there and nobody knows it is there – if it did any harm we wouldn’t use them.

Well once inside you would use various hacker techniques to bump up your access level to that of systems administrator, so that you would have the entire system under your control. You could connect to other systems on the network with the same authority. You could monitor people’s emails and you could get into their project folders and look at their research and development work or papers that they have written. Occasionally you would get into somewhere that was quite interesting but it wasn’t always that way. Most of it was quite boring. Back in the old days before Internet Browsers that give you nice pictures and buttons to click on, it was all text based and you had to use the keyboard to type commands. There were pictures, but you had to manually download them and view them “offline”.

MW: So what were the most exciting computer systems you hacked?

MW: Firstly there was the FLEX system. This stands for Force Level Execution, and this is the thing which the News of the World newspaper picked up on. The reason this system was of interest because it had control of nuclear missiles. To explain what this program does; the official line is to plan an air war and to find out what things are incoming and what air strikes are pending. The system would then advise you of where to strike next with the best killing ratio and where to launch you missiles etc. From looking on the computer and through the “source code” I got the impression that the system had direct access to real missiles. What type of missiles I do not know and the News of the World printed that these were in fact Peacekeeper Missiles, but that didn’t come from me – I don’t know where they got those details from…?

The easiest comparison I could make is that it was a very similar system to the Skynet System in the Terminator movies. This means that the computer has access to all available information and can make intelligent decisions about how to operate a war and even control the weapons.

Of course the FLEX system is secret and something that they do not want the public to know about and the fact that weapons are controlled solely by computer. You would think that there would be other failsafe system but, as far as I could tell, that was not the case.

There were other systems such as Wright Patterson Air Force base and White Sands Missile Testing Ground, some now I forget – I went to a lot. I had been to so many I had to tell the police that I could not remember all the systems I had been in.

The lawyers couldn’t get their stories straight even for a trial of this type, which you would have expected. They would not present evidence to show how I was able to hack into their systems. So with the details of the computer systems real purpose having been removed from the case then I am now pretty sure that I did have a good idea about the real function of the programs – they didn’t want this information out in any form. This was probably the reason that they were so pissed off about it because I came forward and told everyone. You see after I was arrested then I started to get some very strange phone calls from people claiming to be in the military, Koreans and other people. I had weird semi-threatening things said to me and this is why I moved away to get away from these treats and this is another reason that I spilled the beans, in order to keep myself and my wife safe, after all what is the point of silencing me after I had talked.

MW: Where were you living and did the police give you any assistance in your moving because of these threats.

MB: Firstly I was living in Grangetown and then I was moved by the benefits agency to another location. They were aware of the court case and the sensitivity and people from Scotland Yard were helping in this respect also. I was given a new name under the benefits agency computers and was living under name of Mr Smith for a while.

MW: Why do you think they were prepared to go to this trouble to help you?

MB: What you have to understand is the fact that there was a big Senate hearing on the fact that two hackers had got into secret computer systems. One of these was a 16-year-old who they had arrested and the other person was supposedly thought to be a foreign spy who was paying the 16-year-old for information. I was made out to be the foreign spy and I was prepared to believe from the threats I was getting that these people were serious. So I had to move home.

To give you an idea of the level of the ominous phone calls I was getting, at the time I was just about to change my phone over to British Telecom. Just days before I was arrested I was due to sign the BT phone forms and send them off, but had not done do at that point. Then I had another threatening phone call and I told them to **** off and said that I was now having my number changed. The voice on the other end of the line said “yeah we know that your new number is going to be 01222 233blah blah blah” and so they knew my new number already! My wife asked often who was speaking and one name we got was Chung Lee Makasuki and he gave some phone number in China, I think.

MW: When you were arrested what happened?

MB: I was working at Admiral Insurance at the time in their computer department for around a year and a half. One of the managers came in and asked me to come and have a look at one of their computer systems and I got up and went with him. I went with him to the MDs office and there were seven people in the office, your typical men in black so to speak but as this was the MDs office I didn’t at first see this as abnormal. When I got inside one of then said to me “Mathew Bevan” and I replied “yes” and then he put up his hand and said “I am placing you under arrest for hacking of NASA and various Air Force bases.” I was standing there stunned and I was going “Oh, gosh… ummm.” They then told me that they were going to search my desk, which they did, then they took me back to my house and searched there too.

When they got to the house they took all my X Files videos and X Files posters and the reason was because the “KUJI” hacker that they were after had a computer user description which read “The Truth Is Out There”. So they wanted to use the X Files material to prove that they had the correct “KUJI”. They just wanted to pin me on anything they could. They took all of my computer kit as well as my passport.

During the interview I agreed that I used the handle ‘Kuji’ and afterwards the police gave me my property back such as the X Files videos, posters,monitor and the keyboard back but they kept everything else.

I was taken to the Central Police station in Cardiff. The officers were from the computer crime unit of the Met Police. I believe that the C.C.U. also uses the code S.O.6 which leads me to believe that they are intelligence (MI6) related but I don’t think they would admit that.

MW: What was the atmosphere like in the interviews?

MB: It was a good cop bad cop scenario. The one person was very nice and the other guy was quite nasty and was giving snide remarks and shouting at me. There were bits in the interviews that were really stupid too where I was asked by the nice cop if I had any political leanings and I said no – then the other cop stepped in and said “Yeah, but your a vegetarian” and he then said “So you do have a leaning then.”. To this I then replied “Well if being vegetarian is a political leaning then I plead guilty!”. The other copper then steps in and make a lighthearted comment and then the other one steps in again and says “ah so you indicate a leaning then” and so on.

I was under arrest for the best part of 36 hours but there was about 28 hours spent in the cells. I wasn’t allowed to speak to my wife or anyone else. They threatened that they would arrest my wife and I pointed out that she knew nothing about computers and they said tough because they would arrest her anyway. This was part of their oppression tactics. I said what do I have to do to stop you arresting her and they said that if I co-operated then they would not arrest her. So the only telephone calls I was allowed were to my solicitor because they didn’t want me to tell anyone I had been arrested.

One thing I didn’t realise but found out was the fact that in Cardiff police station they bug the cells with listening devices and recently a few people have had tape recorded evidence used against them when they have admitted to things whilst in custody. This is immoral but they seem to be able to do it.

MW: What sort of specific questions were you asked by the police in the interview.

MB: They asked me about the Rome Labs computer and if I had placed a sniffer program on the computers. I would not admit to this. They also asked me about Goddard Space Flight Centre and Wright Patterson, I admitted to these but was never charged with them! They don’t charge me with the right things. They then charge me with conspiracy with the other hacker, but by the time they realise that they don’t have any evidence to prove this it transpires that they could not charge me with the original intended charges anyway because they are out of time by 6 months; They would have had to charge me with a summary offence within six months of my arrest. They also found out that they were out of time for a 3-year clause

The Americans position in court was that they claimed that they had to spend 1/2 a million dollars to repair their computer systems. A fundamental question that my defence asked was could we see a backup of the system to show before and after these so called repairs to prove what was being claimed. The Americans said that we could not see the records because they were so sensitive and also said that it was not in the jurisdiction of the British courts to order them to show the files. If it were any other trial then you would ask how could we accept this evidence but because we are asked to take the Americans word, this is supposed to be good enough.

The next thing that happened was that my barrister had meetings with the prosecution and he then turns around to me and says that he feels that they will find me guilty on some charges so I should give in and change my plea to guilty. So I ‘relieved’ him of his professional duties and got a new barrister who was then completely on my side and who felt that I did indeed have a worthwhile and quite solid defence.

MW: What was the final stage of the case and how did you get acquitted?

MB: The judge surprised everyone by saying to the prosecution that because my charges were lesser than those of the other hacker and that the other hacker had received a small fine of ?1200 then my sentence at best would be non-custodial so to proceed with such a case would not produce a large penalty whilst the costs for running such a case would run into millions. It was estimated that if I would be found guilty I would get a ?450 fine and considering that the court’s daily costs would be ?10,000 it would not be worth it.

However the prosecution was determined still and said that they would still proceed and then at the last stage they pulled out and said that they wished to offer no evidence and that it wasn’t in the public interest to run the case. Verdicts of not guilty were entered, this being the equivalent of a full acquittal and so ensuring that the police would waive the right to re-arrest me in conjunction with these charges.

This being the case I was then free to admit to the press and everyone else that I had in fact done some of those things and that I did hack those systems. This pissed Scotland Yard off immensely and they are now being very awkward about returning the seized goods that are in evidence storage even though the case has been dropped.

MW: How were you tracked down?

MB: I cannot be sure because this was never disclosed – I have my suspicions that I was grassed on by a hacker. They said they found my number on somebody’s computer system and traced me back like that but I think somebody told them who I was. The point was if it took them 2 years to find my number on the other hackers hard- drive as they claim then that is incompetence, as a search of a 250meg drive takes less than five minutes.

MW: Where does the story take a turn to where you started hacking military sites for UFO information?

MB: In a hacker magazine called PHRACK, it gave a list of sites that people who said they were interested in UFOs would like to see hacked and that hackers should check these out. Allegedly there were forty people who were trying to penetrate these sites and they got into some of them but they all went missing?

MW: A group of forty people went missing?

MB: Apparently so. They said in the magazine that if you were going to do it then do it carefully and printed a list of the sites. I used that list and used it and I also used some of the folklore of UFOs like “Roswell wreckage taken to Wright field”, “Lockheed space missile company have connection to Area 51” etc. It is then just a case then of picking up the addresses and names of these computers. They are quite easy to find as the military provide you with as much information on their computers as you could ever want.

It was a case of “go for it”, “lets have a look”. As far as I was concerned I was not traceable and not causing any harm to anybody. If I couldn’t get in then no big deal, if I could then I was not going to screw the system up.

MW: You did gain access to some interesting UFO type files – what were these?

MB: The information was obtained through the Wright Patterson Air Base computer system. I was looking for information on the Roswell crash. On one of the computers at Wright Patterson the systems administrator was very un-secured. Captain Beth Long was the system administrator she is supposedly working in a pumping station in Alaska now instead of working at Wright Patterson – the reason being, because she had no password so this meant that anyone logging in as her meant they had the highest level of access on the system with no password needed!

Wright Pattersons’ computers were strange because unlike all other computers I had hacked which had clear warnings to hackers and people using the system regarding the classified information, their system had a banner which read in flashing red letters that no classified information is to be stored on the computer system. This throws you a bit. I was unsure if it was a real banner or if it was to put off people who had got that far.

In getting into that there was one machine on the network where I read current files and future project proposals. I read documents which gave me the impression that they had an anti-gravity engine which was capable of at least Mach 12 to Mach 15. I don’t know how exactly how fast that is but I think that is faster than most aircraft we know of today. Supposedly the aircraft which employs this engine uses a reactor to which there were a lot of detailed numbers and figures for, but I have no idea what all this meant. I can remember that the documents referred to a super heavy element, whatever that means. The element is the main fuel for the reactor. The engine worked by making a disturbance of molecules at the front of the craft so that it was able to stop the inertia or G-force inside the craft. I got the impression that this information was the type of material I was looking for because it was far in advance of our current technology and could be something to do with the Roswell UFO. Finding this threw me ecause I didn’t know if this information was a disinformation exercise and that people were meant to get in and find this stuff or if it was real. I can’t be sure and this is the one annoying thing.

In the interviews that were carried out with the police Wright Patterson was mentioned. Officer D S Janes asked me, had I been in there and I said that I had. He then asked me if I had got any information from this computer and I said that I had found details of an anti-gravity propulsion system. He asked if I downloaded any files from this project and I said no and I had only read the files online. As I said earlier I admitted to this but no charges were brought against me on this matter which is a bit odd. Then the interviewing officer asked me if I knew what Hanger 18 meant. I said “well if you are thinking of a building where they store extraterrestrial aircraft then this is what you might mean but perhaps you mean it is a computer or a bulletin board -is this what you mean?”. He replied that this could be the place that he was thinking of. This was the only time that Hanger 18 was mentioned in the interview.

In one of the hearings at magistrates’ court there was a special agent who came over called Jim Hanson. When asked what did he feel I was trying to achieve by my hacking he said that he believed I was not trying to do any harm but was just looking for information on Hanger 18. The prosecution then asked Jim Hanson in a light-hearted manner if he could confirm if Hanger 18 exists and Hanson responded “I can’t tell you that because I am not party to that information”.

What surprised me is the fact that I was asked about the little known Hanger 18 story instead of somewhere well known such as Area 51. Some members of the press alluded that I had hacked into Area 51, but I never said this and I refused to comment on the UFO issue to them. There were things I was not prepared to talk about to the press because I was not sure if I would be able to sell my story or not, so I did not want to give the information away.

The point was that I knew where Wright Patterson airbase was but I didn’t know, until I read a UFO magazine recently, that Hanger 18 was located at Wright Patterson. This was the first I ever learned about this.

When you put it all together it seems weird – the fact that I hacked into Wright Patterson and found details of a secret gravity engine and then the coppers asking me about Hanger 18, even to have a secret service agent in an open court saying about Hanger 18 and then me later on finding out that the two places are the same.

MW: Wasn’t there a ban on press reporting of your case?

MB: The press were there and they heard many interesting things which the failed to print but yes there was a ban on reporting the case, they said because they did not want the press opinion to influence the case in any way. This is the principal of subjudicy.

The prosecution had originally intended to have the case heard in secret (In Camera) but we did not allow this to happen.

MW: Have you ever seen any UFOs yourself?

MB: There was a time when I was going back to Newport from Cardiff and there were two very feint lights which were like passenger plane lights at first. They looked like they were going towards Rhoose airport but in-between them there was a start which was shooting back and forth between these two points. I had to force my friends to look at the lights because they would not look and said was crazy but when eventually they did look they agreed that they had seen something strange.

My Wife and I went on holiday to Fuertaventura in the Canaries and there were unusual lights in the sky above us which we watched for many hours. They changed colour and went on and off. They seemed so far away that they couldn’t be sure if they were satellites or not. I am not saying that this could not have been explainable phenomena.

MW: What interest did you have in UFOs before the trial.

MB: Just before I got into the hacking scene I was making the free phone calls and I found a Bulletin Board in Australia which had loads of UFO files. There were about 500 or 600 text files on offer so I downloaded them all and waded through them slowly. I found it really interesting and I wanted to know more. I go into the MUFON files and Keelynet Bulletin Boards and they had interesting things on them also.

It seems to me that far more people have seen UFOs and have evidence of this than there is evidence of GOD but people go around believing in GOD and are not ridiculed for this in any way!

My opinion is that there is a lot of information UFO information out there and it is hard to separate the liars from the truthful people. The thing is that some of the wilder claims may also be the truth but sometimes you cannot be certain of any claims either way.

The types of thing I mean are cases where people say that they have been onboard spacecraft and seen the classic alien with big black eyes and that they had experiences which are consistent with other witnesses. You then hear from the same person that the aliens took her for a ride and they were walking around on the moon without a spacesuit and the story starts to take a strange turn. It seems that people seem to go overboard but who knows that person may in fact be telling the truth.

MW: Do you know much about Bob Lazar? Tell me what you about his story.

MB: Well yes, Bob Lazar was able to show documents from his previous work to show that he worked with certain companies, but they deny he ever worked for them.

As I remember he is a really nerdy looking guy that claims to have worked at Area 51’s S3 complex I think? He claimed to have been working on crashed UFO technology. He said that he had seen saucers in hangers and had seen one flying one day. Only recently I saw the original interview he gave on video where he talked about his work and was drawing on a blackboard. I think he got prosecuted for running a brothel, I don’t know much more than that.

MW: Do you know anything about the propulsion systems he was talking about in his work on the saucers?

MB: No not really – I can remember the shape of the craft and I can remember that the propulsion system was in the bottom of the craft and that it is like a segmented thing. I remember a little area in the middle where the “guys” would sit. I don’t really remember the details or specifics of that.

MW: I am interested because you used the term “heavy element reactor” earlier on and I wondered if you have heard about something called “element 115”?

MB: No I did chemistry at school but was very bad at it and got kicked out. I don’t know anything about elements full stop really.

MW: Bob Lazars story was that he worked on propulsion systems, which utilised a reactor, fuelled by a super heavy element. Everyday scientists do not know of the element 115 of which he speaks. Does this mean anything to you?

MB: Maybe that is a parallel. The only things I know about him really is that he worked on UFOs and his involvement in the brothel and the fact that he looks a bit “geeky”.

MW: Can you remember any names of people on the project. Were there dates on any of the letters you saw regarding the propulsion system?

MB: Nope, as for dates all the information was current at 1994. Whether this was a totally new engine or if it was a new version I can’t be sure. I do know that it was a working prototype.

MW: Did they say what type of aircraft the propulsion system would be used in?

MB: Not that I remember, although I believe the engine was in use.

MW: Do you fear going to the United States?

MB: I am, not so much worried about being tried in the US for these things because they still have the same flawed evidence – but I fear that over there they would just stick me in prison without a trial and leave me to rot. This is something I have to look at carefully and to study the international law on these matters because there is a question of where was the crime committed on my computer in my house in the UK or in the US on their systems. This is a legal dilemma and is open to question.

A point is that there is a hacker out there now called Kevin Minick who did some minor hacking and has been in prison for 2 years and hasn’t been charged with anything yet! This can happen.

MW: Why did you do all this? Are you an anarchist or is this political or just for pure curiosity?

MB: I just get a thrill out of exploring new computer systems. If you could see my CV I now have knowledge of all these computers systems I have used. If employers wanted to know how I got that experience it may get a bit awkward to have to tell them that these were military systems I was playing with – but it still makes for a good CV! I can now admit to my hacking and not have any fear because it may be a plus point in that I know a lot about systems security.

I did it for the pure adrenaline buzz of hacking a secret system. This can keep you awake on no food for hours and this is one of the other reasons – because of the thrill.

MW: Thank you very much.

MB: Thanks.

In final clarification on some of the interview I asked Mathew if he saw any images on the computer systems at Wright Patterson Airbase. He says he saw one but remembers that the antigravity engine was a working prototype and is fitted in some form of aircraft and is in use although the type of aircraft was not disclosed. The information was dated around 1994, when the system was originally breached. It is now up to researchers and hackers alike to try and find out more.

Welcome to the era of drive-by hacking

Posted by Kuji on June 26th, 2008

Welcome to the era of drive-by hacking

The slower the traffic the easier to spot wireless
networks

By BBC News Online technology
correspondent Mark Ward

BBC News Online has been shown just how lax security is on wireless networks used in London’s financial centre.

On one short trip, two-thirds of the networks we discovered using a laptop and free software tools were found to be wide open.

Any maliciously minded hacker could easily join these networks and piggy back on their fast net links, steal documents or subvert other machines on the systems to do their bidding.

None of the wireless networks we found used anything but their flawed, in-built security systems to protect against hack attacks.

On the warpath

Many people think of hacking as a sedentary pursuit, carried out in bedrooms and back rooms all over the world.

Often it is, but the growing popularity of wireless networks is making some curious folk leave their bedrooms and venture out into the fresh air.

Armed with a laptop, a wireless network adapter card, as well as some widely available software tools, you can travel the streets logging the location of these networks and picking up information that could let you attack them.

The pursuit has come to be called “war driving” if it is done in a car, “war pedalling” if done on a bike and “war walking” if on foot.

The phrase derives from the practice of “war dialling” in which phone phreaks and hackers map telephone systems by dialling a range of numbers to see which respond with tones used by data networks.

Tuning in

But, in contrast to the hacking practices carried out over telephone lines and the net, spotting and using wireless, or wifi, networks is very straightforward.

It is as easy as listening to the radio. What makes it easier is that everyone is broadcasting on the same frequency.

BBC News Online was shown just how easy it was by two ethical hackers who prefer to be known as Codex and Kuji. We drove with the pair around London’s financial district.

As we drove, we watched the screen of a notebook computer sitting on Codex’s lap. The machine was fitted with a wireless network card and a program that noted important information about any wifi nets we stumbled across.

Also attached to the laptop was a GPS handset that gave a more precise fix on where each network was detected from.

Wide open

Our journey began at the eastern end of The Strand and continued along towards Cannon Street. Within the space of one kilometre we logged the existence of 12 networks.

Only four of these had turned on the encryption system built into the wifi protocol. The other eight were wide open.

Codex said that using back and side streets to criss-cross an area would reveal even more networks.

“From an attackers point of view you want back roads because there is less road traffic,” said Codex, “and you might be able to park when you find a network.”

The pair’s past expeditions carried out on foot have spotted a lot more networks; Soho in particular.

Already websites exist which list the wireless networks in major cities. Many of those listed are doing nothing to stop people using them.

The names identifying the base stations controlling these wireless networks showed that little had been done to change the configuration of the system from the moment it was first switched on.

Good targets

Every time a new wifi network popped up on screen we eagerly looked out of the car windows to see if we could spot the building from which the signal was emanating.

Usually we couldn’t, but during our trip we passed investment banks, financial advisors and regional offices of large corporations – any one of which would be a prize target for a malicious hacker.

Codex said that many of the networks we found were likely to use a software package that automatically handed out internet identifiers to any devices joining those networks.

By using this identifier it would be possible to join the network and get access to all the services it provides just as if we were sat at a desk in the building.

Kuji said getting access via a wireless network puts you behind a firewall that usually stymies attempts to abuse a network.

Usually, wire-based hacking requires a formidable amount of knowledge, so you know which tools to use, what to look for and, more importantly, how to cover your tracks.

With wifi networks all this changes. The scary part is how easy they are to find, and how poorly protected they are.

Codex said that if companies took security seriously they would corral wireless networks behind a firewall and only allow trusted, encrypted and authenticated traffic to pass from that to the wider network.

“This mitigates against the risk of an attack against the corporate network,” said Codex, “it also limits the chance of an attacker using it to attack others, or distribute illegal material which may compromise the legal status of the company.”

Sadly, on the evidence gathered during one short trip across London, most have not done it properly, and have unwittingly created a hackers’ playground.

Hacker turns to vendors as IT PI

Posted by Kuji on June 26th, 2008

Hacker turns to vendors as IT PI

Steve Masters [05-12-1997]

One of the two hackers accused of almost starting World War III from his bedroom in the UK walked free from court on 21 November because the law is not set up to deal with cases like his, writes Sean Fleming.

In an interview with Computing, Matthew Bevan announced he is now considering a career in IT security.

Bevan was arrested on 21 June 1996 and charged with intent to secure access to computer systems belonging to the US Air Force and defence manufacturer Lockheed. His accusers maintained he knew that such access would be unauthorised.

More than three years and 14 court appearances later, the case has been dropped. The prosecution declared it would not be in the public interest to pursue the matter.

Bevan, who used the name Kuji, and Richard Pryce – known as Datastream Cowboy – stood accused of hacking into a research centre at Griffiss Air Force base in New York state. It took two years for the US authorities to admit the break-in had taken place.

In a statement to the court, US Air Force investigator Jim Christy said the incident cost the US Air Force $211,722 (#124,000) – exclusive of the cost of their investigations.

Christy outlined the events that almost brought East and West to the brink of war. He described how Datastream Cowboy (aged 16 at the time) hacked his way into a research facility in Korea. The US authorities became aware of this when they realised that the contents of the Korean Atomic Research Institute’s database had been deposited on USAF’s New York system.

‘Initially it was unclear whether the system belonged to North Korea or South Korea,’ Christy said. ‘The concern was that if it was North Korea, they would think the transfer of data was an intrusion by the US Air Force.’

It turned out to be South Korean data, but it is not hard to imagine the potential outcome had the 16-year-old found his way into North Korea’s system. The US press referred to Bevan and Pryce as ‘digital delinquents’.

Pryce walked out of court this summer with a #1,200 fine – not much of a slap on the wrists for actions that might have sparked a war. The lenience of his sentence was the key to Bevan escaping punishment altogether.

Simon Evenden, Bevan’s solicitor, told Computing why the prosecution chose not pursue his client. He stressed that in court, judge Jeffrey Rivlin QC made it clear that he felt the prosecution had in no way done anything wrong when preparing its case.

‘The case collapsed simply because it was not economically viable to take it forward. It would have cost hundreds of thousands of pounds to bring witnesses over from the US and because of what happened to Pryce, Matthew would probably only have been fined or given community service. So it was agreed that it was not in the public interests to continue.’

Had the case continued, getting the prosecution evidence to stand up in court could have proved problematic. It is unlikely the court would have accepted any evidence stored on a computer, unless it could satisfy itself it had not been tampered with. The US authorities were happy to supply copies of emails plus records showing times and dates at which computers were hacked into, but they would not allow the court access to original information.

In the light of the Bevan case, the defence and prosecution teams are to come together in an attempt to plug some of the gaps in the law. They will be arguing for changes to a system that is clearly finding it hard to keep pace with technological change.

From the horse’s mouth Interview with Matthew Bevan

Offered the choice between pleading guilty in the hope of the court being lenient or fighting it out, Matthew Bevan plumped for the latter. He explained why to Computing. ‘As far as I was concerned, I was charged with conspiracy, which was not true, and charged with working with Richard Pryce, which was not true. As well as having to prove that I did it, the prosecution would have had to prove there had been intent. I was accused of putting a sniffer on one of the computers. The point of a sniffer is to sit undetected on a computer monitoring who’s using it and copying their passwords. It’s not there to impair the performance of the computer. So, even if they could have proved I put it there, they couldn’t prove intent to cause damage.’ Bevan is now considering a career in IT security. ‘If I can find a job where I can get paid for doing the same sort of thing as hacking, I won’t complain,’ he said.

Hacker finds his skills in demand – VnuNet

Posted by Kuji on June 26th, 2008

Hacker finds his skills in demand

By Steve Masters [25-02-1998]

Reformed saboteur warns easy PC access will lead to rising tide of cyber terrorism

It was a case of poacher turned gamekeeper last week when Mathew Bevan, the hacker formerly known as Kuji, found a respectable job as a hacker, writes Sean Fleming.

Bevan was accused of breaking into US military computer systems but walked free from Woolwich Crown Court last November after the case was dropped.

He will work as a member of a team of six reformed saboteurs launching surprise attacks on customers of London-based Tiger Computer Security.

Once weve signed a client up, we tell them to expect an attack within the next six months, but we dont tell them exactly when.

It would defeat the purpose if they were watching out for us, he explained.

Bevan whose job title will be Chief Tiger said the incidence of cyber terrorism will increase over the next five years.

I was 11 when I got my first computer and 14 by the time I had a modem.

You’ve now got kids of eight or nine with PCs at home that have good processing power and Internet access. They will become mature in the use of computers long before they are mature in the wider sense the whole situation could go bananas, he warned.

Hacked off: Court frees Air Force one – VnuNet

Posted by Kuji on June 26th, 2008

Hacked off: Court frees Air Force one

By Steve Masters [26-11-1997]

A hacker charged with breaking into the US Air Force’s command and control centres walked free from court last week

A hacker charged with breaking into the US Air Force’s command and control centres walked free from court last week, writes Sean Fleming.

The Crown Prosecution Service (CPU) said a costly court case would not be in the interests of the public.

Matthew Bevan, known as Kuji, was one of two hackers alleged to have accessed US military intelligence centres in 1994. Richard Pryce was fined #1,200 earlier this year.

Bevan has said that he was searching the US Air Force’s command and control centre for evidence of encounters with UFOs.

US Air Force investigator Jim Christy revealed that the hackers had also accessed the South Korean Atomic Research Institute, copied all the data and placed it on the US Air Force system.

Christy pointed out that the US was concerned this would be misinterpreted by the Koreans as an act of US aggression.



Copyleft © 2007 - 2012+ Kuji Media Corporation Ltd.. All rights reserved.