<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kuji Media Corporation</title>
	<atom:link href="http://www.kujimedia.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kujimedia.com</link>
	<description>The history of a computer hacker</description>
	<lastBuildDate>Sat, 26 Jul 2008 23:53:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Accused Pentagon hacker prosecution could backfire</title>
		<link>http://www.kujimedia.com/accused-pentagon-hacker-prosecution-could-backfire/</link>
		<comments>http://www.kujimedia.com/accused-pentagon-hacker-prosecution-could-backfire/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 17:40:40 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[Other hackers]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=94</guid>
		<description><![CDATA[Analysis Accused Pentagon hacker Gary McKinnon is continuing to fight against extradition to the US after losing an appeal last week. Only the Law Lords now stand between the Scot and a US trial for allegedly breaking into and damaging 97 US government computers between 2001 and 2002 and causing $700,000 worth of damage, in [...]]]></description>
			<content:encoded><![CDATA[<p>Analysis Accused Pentagon hacker Gary McKinnon is continuing to fight against extradition to the US after losing an appeal last week.</p>
<p>Only the Law Lords now stand between the Scot and a US trial for allegedly breaking into and damaging 97 US government computers between 2001 and 2002 and causing $700,000 worth of damage, in what US authorities have described as the &#8220;biggest military&#8221; computer hack ever. He allegedly infiltrated networks run by the US Army, US Navy, US Air Force, Department of Defense and NASA. US authorities described McKinnon as an uber-hacker who posed a threat to national security in the aftermath of the 9/11 attack.</p>
<p>McKinnon (AKA Solo) admits he infiltrated computer systems without permission. The 41-year-old former sysadmin said he gained access to military networks &#8211; using a Perl script to search for default passwords &#8211; but describes himself as a bumbling amateur motivated by curiosity about evidence of UFOs. He said numerous other hackers had access to the resources he was using and questions why the US authorities have singled him out for extradition.</p>
<p>Any damage he did was purely accidental, McKinnon claims. If convicted, following extradition and a US trial, McKinnon faces a jail term of up to 45 years&#8217; imprisonment.<br />
Scapegoat</p>
<p>According to a reformed computer hacker accused of similar crimes 10 years ago, McKinnon is been made a scapegoat for the shortcomings of US military security.</p>
<p>Mathew Bevan, whose hacker handle is Kuji, was accused of breaking into US military computer systems but his 1997 case at Woolwich Crown Court was dropped after a legal battle lasting around 18 months. No attempt was made to extradite Bevan. After the case, Bevan became an ethical hacker and security consultant, first with Tiger Computer Security, and later on a freelance basis with his firm the Kuji Media Corporation.</p>
<p>&#8220;Both Gary and I were accused of similar offences. The difference is his alleged crimes were committed in a different political climate, post 9-11. The decision to push extradition in Gary&#8217;s case is political,&#8221; Bevan told El Reg.</p>
<p>Bevan, like McKinnon, has an interest in free energy and evidence of UFOs. The similarities in the case go further. The crimes Bevan is alleged to have committed were cited as evidence of cyberterrorism in US senate hearings in 1996. &#8220;They haven&#8217;t found a cyberterrorist or &#8216;bad boy&#8217; for a while and it looks like they are trying to make an example in Gary&#8217;s case,&#8221; he said.</p>
<p>McKinnon should have been allowed to plead guilty in his own country and not be faced with the prospect of a long prison term in a US prison with &#8220;inhumane&#8221; conditions, Bevan argues.</p>
<p>He says the military systems McKinnon is accused of hacking remain vulnerable to attack. &#8220;I&#8217;m sure there are a lot of people on these machines, some of who the US authorities allow to get in.&#8221;</p>
<p>&#8220;The prosecution against Gary is about saving face for security lapses by the US military that remain as bad as they were 10 years ago,&#8221; Bevan said. &#8220;If this had happened with a corporation someone would have been sacked.&#8221;</p>
<p>He added that US authorities are keen to talk up the cyberterrorism threat in order to protect information security budgets.</p>
<p>McKinnon, unlike a US citizen who faced similar charges, is in a particularly bad situation. &#8220;The authorities are trying to rip him away from his family and ruin his life. Gary committed his alleged offences in the UK, and according to the Computer Misuse Act, jurisdiction lies here.</p>
<p>&#8220;Gary has suffered trial by media over the last five years, with everything weighed against him,&#8221; Bevan added.</p>
<p>Despite everything that&#8217;s happened to McKinnon, he reckons the case will fail to act as much of a deterrent to other would-be hackers. &#8220;Has it scared anyone? I shouldn&#8217;t think so,&#8221; Bevan said.<br />
Final appeal</p>
<p>Lawyers for McKinnon are petitioning for leave to appeal to the House of Lords on grounds including the use of &#8220;deliberately coercive plea bargaining&#8221; tactics by US authorities during the course of the long running case. His lawyers argued that he had been subjected to &#8220;improper threats&#8221; that he would receive a much harsher sentence and be denied the opportunity to serve out the back-end of his jail term in the UK unless he played ball.</p>
<p>Appeal court judges Lord Justice Maurice Kay and Mr Justice Goldring criticised US prosecution tactics but said these didn&#8217;t offer enough grounds for appeal against the Home Secretary&#8217;s decision to confirm a 2006 ruling that McKinnon ought to be extradited to the US.</p>
<p>The unemployed sysadmin has had these charges over his head since March 2002 when he was arrested by officers from the UK&#8217;s National High Tech Crime Unit. The case against him lay dormant until July 2005 when extradition proceedings commenced. McKinnon has suffered ill health over recent months as a result of the stress caused by the case, according to his lawyers.</p>
<p>McKinnon&#8217;s supporters argue the case has wider political implications. &#8220;It is not just about Gary McKinnon, there are lots of other people, from computer hackers to legitimate businessmen, who will continue to fall foul of this sort of surrender of British sovereignty and obeisance before the extra- territorial demands of the US legal bureaucracy,&#8221; Mark, a member of London 2600 who runs the Free Gary blog, told us. &#8220;However the same lack of a requirement to show prima facie evidence also applies to European Union countries under the European Arrest Warrant,&#8221; he adds.</p>
<p>McKinnon&#8217;s lawyers chose not argue about whether he might be put on trial before a military tribunal but that this may well be argued in the House of Lords if leave to appeal (which is by no means guaranteed) is granted.</p>
<p>&#8220;Basically the judges have said &#8216;we have to trust the USA Government to act in good faith&#8217;, until they show that they have broken their promises &#8211; which will by then, of course, be too late for Gary McKinnon. Unlike Babar Ahmad or even any of the British citizens who were held without trial at Guantanamo Bay, Gary is actually accused of directly &#8216;attacking the US military&#8217; systems,&#8221; Mark notes.</p>
<p>&#8220;Even if Gary faces a civilian court in the USA, his chances of being found not guilty or of getting a lenient sentence appear to be slim, given the prosecutions recommendations as to length of sentence.&#8221;</p>
<p>But the whole effort to try McKinnon in the US might backfire on the US military by putting its security shortcomings under the spotlight.</p>
<p>&#8220;If there is an actual trial in the USA, rather than a coerced or otherwise &#8216;plea bargain&#8217;, there are a large number of senior US military officers and civilian IT managers and auditors who are going to have to explain the incompetence or possible corruption or perhaps treason, which went on for years and months under their command, both before and after September 11,&#8221; Mark claims.</p>
<p>&#8220;Even if this is suppressed in court, it might lead to Congressional Committee hearings,&#8221; he adds. ®</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/accused-pentagon-hacker-prosecution-could-backfire/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>History repeats for former hacker</title>
		<link>http://www.kujimedia.com/history-repeats-for-former-hacker/</link>
		<comments>http://www.kujimedia.com/history-repeats-for-former-hacker/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 17:32:26 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[Other hackers]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=93</guid>
		<description><![CDATA[For most people it must be hard to understand what confessed hacker Gary McKinnon is going through as the US attempts to extradite him to face trial. But Mathew Bevan can definitely sympathise with Mr McKinnon because, ten years ago, he was in a very similar position. As a teenager Mr Bevan became adept at [...]]]></description>
			<content:encoded><![CDATA[<p>For most people it must be hard to understand what confessed hacker Gary McKinnon is going through as the US attempts to extradite him to face trial.</p>
<p>But Mathew Bevan can definitely sympathise with Mr McKinnon because, ten years ago, he was in a very similar position.</p>
<p>As a teenager Mr Bevan became adept at breaking in to computer networks. At first any system was fair game but he soon started concentrating on those run by US military institutions.</p>
<p>Like Mr McKinnon he was caught, charged and threatened with extradition for what he had done.</p>
<p>Net losses</p>
<p>The knowledge he had built up hacking business, university and government computers helped find connections to military systems that he exploited to gain access.</p>
<p>Reading about how Mr McKinnon got started, Mr Bevan said he was amazed that security had improved so little between the time he had been exploring US military networks and when Gary McKinnon was hacking.</p>
<p>The same failings let both Mr Bevan and Mr McKinnon gain access to supposedly secure systems.</p>
<p>&#8220;It just shows that in 10 years nothing has changed,&#8221; he said.</p>
<p>The only difference is that in the time between the two cases the US government has been spending heavily to beef up computer security.</p>
<p>&#8220;Where have the budgetary increases actually been spent?&#8221; he asked.</p>
<p>Like Gary McKinnon, Mr Bevan was interested in information about UFOs and spent months combing networks in search of hidden data.</p>
<p>Mr Bevan can easily understand why Mr McKinnon kept hacking the same systems for so long when common-sense would have told him that his luck would run out sooner or later.</p>
<p>&#8220;You just feel like you are invincible really,&#8221; he said, describing the feeling he got when he successfully broke in to a network.</p>
<p>Once a hacker has won access to sensitive networks, the urge to keep on going to find more hidden information was hard to fight, he said.</p>
<p>&#8220;I liken it to perhaps the feeling that a parent might get if they find their child&#8217;s diary,&#8221; he said. &#8220;They know they should not read it, they know its wrong [but] they just cannot help themselves.&#8221;</p>
<p>Case closed</p>
<p>Eventually, US computer security investigators caught up with Mr Bevan, or Kuji as he was known, and he was arrested on 21 June 1996.</p>
<p>The US portrayed him as a dangerous potential spy rather than the teenager from Cardiff that he actually was.</p>
<p>He was held in a police station for 36 hours, charged under the Computer Misuse Act, and then freed to wait 18 months until the case came to trial.</p>
<p>It is a pity, said Mr Bevan, that the evidence against Mr McKinnon has not been exposed to scrutiny in court.</p>
<p>&#8220;I was almost gunning for my case to go to trial because of the amount of witnesses we had that were contradicting each other,&#8221; said Mr Bevan.</p>
<p>He added that there were &#8220;numerous&#8221; inconsistencies in the 40,000 pages of evidence submitted by the US that would have been good to mention in court.</p>
<p>&#8220;I can imagine that it would be the same in Gary&#8217;s case,&#8221; he said.</p>
<p>Although there were efforts made to extradite Mr Bevan, his case came to trial in the UK in 1998 but he was acquitted as it was judged not in the public interest to pursue the case. He now runs his own computer consultancy businesss.</p>
<p>Should Mr McKinnon face trial in the US and be sentenced to decades in jail, Mr Bevan feels such a sentence would be too harsh for what he has confessed to doing.</p>
<p>&#8220;Where is the leniency for admission of guilt?&#8221; he asked. &#8220;Let this guy talk to kids about how this trial has affected his life. Let this guy talk and discuss and explain, don&#8217;t send him to a punishment likely to be worse than he would receive in this country for murder.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/history-repeats-for-former-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers target latest Windows fix!</title>
		<link>http://www.kujimedia.com/hackers-target-latest-windows-fix/</link>
		<comments>http://www.kujimedia.com/hackers-target-latest-windows-fix/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:38:56 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Other hackers]]></category>
		<category><![CDATA[hacker]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=69</guid>
		<description><![CDATA[Hi-tech hackers have started to produce malicious programs that target the latest bugs in Microsoft&#8217;s Windows. A worm has been spotted online that tries to use the vulnerabilities to hijack home computers. Any computer compromised by the worm will become part of a large network set up to send out junk mail. At the same [...]]]></description>
			<content:encoded><![CDATA[<p>Hi-tech hackers have started to produce malicious programs that target the latest bugs in Microsoft&#8217;s Windows.<br />
A worm has been spotted online that tries to use the vulnerabilities to hijack home computers.</p>
<p>Any computer compromised by the worm will become part of a large network set up to send out junk mail.</p>
<p>At the same time Microsoft is re-issuing a recent security patch which has made the Internet Explorer browser crash on some computers.</p>
<p>Spam sender</p>
<p>On 8 August Microsoft released a bumper collection of security patches for 23 separate flaws in Windows and programs in the Office software suite.</p>
<p>One of the problems identified in the August update was deemed so serious that the US Department of Homeland Security (DHS) issued a warning urging users to download the patch and apply it as soon as possible. The DHS has a role in securing America&#8217;s critical infrastructure which includes the internet.</p>
<p>Now security companies have caught copies of a worm travelling the net that tries to infect Windows machines via this loophole.</p>
<p>The Mocbot worm attacks machines running Windows 2000 or XP that only have Service Pack 1 installed.</p>
<p>&#8220;As Microsoft only issued a patch against this vulnerability last week, many Windows computers probably remain unpatched and vulnerable to these threats,&#8221; said Carole Theriault, senior security consultant at Sophos in a statement.</p>
<p>Computer security firms have seen two variants of this worm circulating online. Analysis by Joe Stewart at security firm Lurhq show that, once installed, it tries to download a trojan known to act as a spam proxy.</p>
<p>These are networks of compromised machines that junk mailers have been forced to use because so few net service firms will host companies that send out millions of unwanted messages.</p>
<p>Microsoft said it would be re-issuing one of the security patches because, in certain circumstances, it can cause the Internet Explorer browser to crash.</p>
<p>The problem occurs with the MS06-42 update which tried to fix eight separate vulnerabilities in the IE browser.</p>
<p>Relatively few users are thought to be suffering from the clash between IE and the security patches. Microsoft said it affected IE with Service Pack 1 installed but only if visiting websites that use data compression and the widely used version 1.1 of the HTTP web protocols.</p>
<p>Microsoft said it expected to have the new version of the MS06-42 update ready by 22 August. However, a &#8220;hotfix&#8221; has been made available but Microsoft said this should only be installed on those computers crashing because of the update.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/hackers-target-latest-windows-fix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Nasa hackers&#8217; detained in Chile!</title>
		<link>http://www.kujimedia.com/nasa-hackers-detained-in-chile/</link>
		<comments>http://www.kujimedia.com/nasa-hackers-detained-in-chile/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:38:29 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Other hackers]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[hacker]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=68</guid>
		<description><![CDATA[The authorities in Chile have arrested four people who the police say are members of one of the world&#8217;s most successful groups of computer hackers. The men are accused of breaching more than 8,000 websites, including that of US space agency Nasa. One of the men, who has used the alias &#8220;Net Toxic&#8221;, is alleged [...]]]></description>
			<content:encoded><![CDATA[<p>The authorities in Chile have arrested four people who the police say are members of one of the world&#8217;s most successful groups of computer hackers.<br />
The men are accused of breaching more than 8,000 websites, including that of US space agency Nasa.</p>
<p>One of the men, who has used the alias &#8220;Net Toxic&#8221;, is alleged to be one of the most prolific hackers in the world.</p>
<p>The men were detained in simultaneous raids in three cities in Chile, including the capital Santiago.</p>
<p>The Chilean police carried out the operation in co-ordination with Interpol and intelligence services from the US, Israel and several Latin American nations. The arrests came after an investigation lasting eight months, Chilean officials said.</p>
<p>The four men also allegedly managed to infiltrate the websites of the Chilean finance ministry and University of California at Berkeley in the US.</p>
<p>And they are accused of gaining access to government websites from a range of other countries, including Venezuela, Turkey and Israel.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/nasa-hackers-detained-in-chile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Those Russians and their laws!</title>
		<link>http://www.kujimedia.com/those-russians-and-their-laws/</link>
		<comments>http://www.kujimedia.com/those-russians-and-their-laws/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:37:35 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Other hackers]]></category>
		<category><![CDATA[hacker]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=67</guid>
		<description><![CDATA[Police in Moscow have arrested a group of hackers led by a 63-year old retired computer programmer, who they said was bitter about his small pension. Police said the hackers worked from internet cafes in Moscow to steal numbers from credit cards belonging to clients in foreign countries. Police said they then used the cards [...]]]></description>
			<content:encoded><![CDATA[<p>Police in Moscow have arrested a group of hackers led by a 63-year old retired computer programmer, who they said was bitter about his small pension.</p>
<p>Police said the hackers worked from internet cafes in Moscow to steal numbers from credit cards belonging to clients in foreign countries.</p>
<p>Police said they then used the cards to make false purchases, using an online company they had created.</p>
<p>The hackers could face up to 10 years in prison, if convicted under Russian law.</p>
<p>According to police, computer fraud in the Russian capital costs businesses at least $12m a month.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/those-russians-and-their-laws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My statement regarding today&#8217;s events re Mckinnon extradition trial</title>
		<link>http://www.kujimedia.com/my-statement-regarding-todays-events-re-mckinnon-extradition-trial/</link>
		<comments>http://www.kujimedia.com/my-statement-regarding-todays-events-re-mckinnon-extradition-trial/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:37:14 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Mathew Bevan]]></category>
		<category><![CDATA[mckinnon]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=66</guid>
		<description><![CDATA[The verdict in the Gary Mckinnon extradition trial was really no shock to me considering the political climate. Lets face it, this is not about hacking or security this is about politics and money. Cynical? You bet I am, having been through an almost identical situation, very similar computer intrusions and similar motives &#8211; the [...]]]></description>
			<content:encoded><![CDATA[<p>The verdict in the Gary Mckinnon extradition trial was really no shock to me considering the political climate. Lets face it, this is not about hacking or security this is about politics and money. Cynical? You bet I am, having been through an almost identical situation, very similar computer intrusions and similar motives &#8211; the only difference was I was pre-terrorism mania where everything and everyone is a suspect.</p>
<p>Think about this, almost a decade ago machines belonging to the military, navy, army etc were broken into and this was the proof Congress needed to show that cyber terrorism existed. An unknown spy running rings of computer hackers to steal secrets for foreign governments. The fact that I was not a spy, and certainly not &#8220;possibly the single biggest threat to world peace since Adolf Hitler&#8221; didn&#8217;t really make much of a difference to the fear machine that was put in place selling the idea that cyber terrorism was a real threat.</p>
<p>Millions of dollars in budget increases, that is where the difference occurred. If you take the threat to be real (which it certainly wasn&#8217;t back then and highly unlikely to exist today) then this raises questions, namely;</p>
<p>1. Where have the mega budgetary increases actually been spent?</p>
<p>Education cannot be one of them, as if machines are left in a state of &#8216;unpatched since install&#8217;, with unpassworded points of entry &#8211; I cannot see that the money has gone to the improvement of sysadmin skills or awareness of the problems of being online.</p>
<p>If you compare the awareness by consumers of security threats, people have seriously woken up to the fact that unprotected they are just sitting ducks to the onslaught of manual and automated attacks.</p>
<p>Phishing, hacking, spam, bots, virii, worms &#8211; the majority of home users now have firewalls, anti virus software, spyware checkers etc &#8211; all of which have a much lower budget than the military. I suspect that as governments, unlike corporate entities do not have shareholders to answer to. They do not have to explain why their machines were offline and money was lost, that in fact they can just blame budget instead of actually being proactive and moving with the times.</p>
<p>2. If in this case as in mine, there were clearly many other hackers</p>
<p>with access to the same systems at the same time, why have they not been prosecuted or even mentioned?</p>
<p>This seems to me to be more proof of my theory that so-called super hackers are hauled in front of the courts when it is convenient for their cases to be used for ore proof of computer insecurity and the need for greater budgetary increases..</p>
<p>3. Where are the administrators and their bosses in this case?</p>
<p>In this political climate, one of the dark looming threat from the bad men all around us (as we are constantly reminded), to not secure machines properly they have committed federal offences. It is surely not good practice to have machines, sitting on the Internet, unfirewalled, unpassworded containing alleged sensitive information &#8211; and most likely a direct violation of their contract and training.</p>
<p>This is a sysadmins first job, to change any default passwords or to set ones where they are not needed &#8211; and certainly ensure that those machines are sitting behind a firewall. I am not trying to say that Gary was attempting to test their security, but if this was a corporate environment the sysadmin would have some major explaining to do.</p>
<p>4. Is the fact that the USA are fighting so hard for extradition a dig at our legal system?</p>
<p>Gary has admitted his guilt and wants his trial to be in the UK, so why can&#8217;t he be tried here? Could this be to do with the fact that most computer crime here (financial gain notwithstanding) is dealt with by means of fines. Do the USA see us as a soft touch? This brings the idea of two scenarios;</p>
<p>- Gary being tried by a jury of his peers. They hear the evidence and consider the fact that the machines were badly administrated and this is taken into consideration when sentencing.</p>
<p>- Gary being tried in a foreign country by a jury that hears he has &#8216;attacked their country&#8217; this is bound to have a bearing on the sentencing.</p>
<p>A possible 70 years in prison, for what exactly? showing that in a decade the USA military have not learned, or at worst, blatantly ignored the security threats around them when it is they who tell us every day that we should be afraid.</p>
<p>In my case I was never debriefed by any of the authorities that I hacked, never asking how I did what I did &#8211; never asking me to comment on my peers or related community. Gary says he is guilty, why are we going to punish this man further by sending him to a foreign jail which are known for brutality against inmates: [http://www.hrw.org/reports/2001/prison/report.html]</p>
<p>- where is the leniency for admission of guilt? Let this guy talk to kids about how this trial has affected his life. Let this guy talk to governments.. Let this guy talk and discuss and explain.. don&#8217;t send him to a punishment likely to be worse than he would receive in this country for murder.</p>
<p>The extradition bill is being tested right in front of your eyes, it is a blatant decline in our civil liberties and a worrying step forward for our so-called democratic society.</p>
<p>Mathew Bevan<br />
www.kujimedia.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/my-statement-regarding-todays-events-re-mckinnon-extradition-trial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentagon&#8217;s pursuit of &#8216;scapegoat&#8217; hacker hides real threat from the web</title>
		<link>http://www.kujimedia.com/pentagons-pursuit-of-scapegoat-hacker-hides-real-threat-from-the-web/</link>
		<comments>http://www.kujimedia.com/pentagons-pursuit-of-scapegoat-hacker-hides-real-threat-from-the-web/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:36:48 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[air force]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Mathew Bevan]]></category>
		<category><![CDATA[mckinnon]]></category>
		<category><![CDATA[pentagon]]></category>
		<category><![CDATA[ufo]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=65</guid>
		<description><![CDATA[Criminal gangs taking over from amateur hobbyists Owen Bowcott, Saturday June 11, 2005, The Guardian Gary McKinnon is deemed to be so deviously manipulative at the keyboard that he has been banned from using the internet. He is not even allowed a passport. The peculiar bail conditions imposed this week on the 39-year-old computer systems [...]]]></description>
			<content:encoded><![CDATA[<p>Criminal gangs taking over from amateur hobbyists</p>
<p>Owen Bowcott, Saturday June 11, 2005, The Guardian</p>
<p>Gary McKinnon is deemed to be so deviously manipulative at the keyboard that he has been banned from using the internet. He is not even allowed a passport. The peculiar bail conditions imposed this week on the 39-year-old computer systems administrator from Wood Green, north London, suggest that the law enforcement community stands in awe of his technological prowess.</p>
<p>Until his next court appearance, due on July 27, the tousle-haired programmer, who is fighting extradition to the United States, has been ordered to stay away from any computer connected to the web.</p>
<p>Mr McKinnon has gained international notoriety for his alleged ability to break into scores of sensitive US defence computers, steal secret passwords, sabotage email systems and delete military files. In the hi-tech world of online hacking, however, he is perceived as one of a dying breed of amateur hobbyists &#8211; those the Americans deride as &#8220;script-kiddies&#8221;.</p>
<p>Despite US prosecution claims that he perpetrated &#8220;the biggest military computer hack of all time&#8221;, Mr McKinnon&#8217;s supposed achievements are by no means unique. The attempt to extradite him to answer charges in Virginia and New Jersey is far more unusual. Systems run by Nasa, the Pentagon and the Department of Defence have long been hackers&#8217; trophy targets. His misfortune, apparently, was to get caught, and to have carried out his explorations shortly after September 11.</p>
<p>According to security experts, US military sites are not the most heavily protected on the internet. They rely on the deterrent threat of legal action rather than deploying highly sophisticated software or enforcing best practice among military personnel.</p>
<p>Mathew Bevan, another British hacker arrested for breaches of security at Nasa and US Air Force sites, found himself similarly demonised by US lawyers as &#8220;the single biggest threat to world security since Adolf Hitler&#8221; back in 1994. The case against him eventually collapsed. Like Mr McKinnon, he was also hunting for evidence about UFOs hidden on military installations.</p>
<p>Mr Bevan, now 30, is an IT consultant and living in Wiltshire. &#8220;The security on US military machines is probably not much better than it was back then,&#8221; he said. &#8220;There were plenty of military machines with sensitive information that had account names with no passwords. Others had been left with the standard default passwords used by the manufacturers.</p>
<p>&#8220;University systems and corporations are much harder to break into than military machines: universities because there are always students testing their skills, and companies because they have shareholders demanding better security.&#8221;</p>
<p>In Britain, the hacking subculture that nurtured Mr McKinnon&#8217;s talents has been driven underground by diligent enforcement of the Computer Misuse Act, which since 1990 has criminalised those who gain unauthorised access to computer systems.</p>
<p>Mr Bevan typifies the career trajectory once pursued by teenage hackers. After years hunched alone over a computer screen, and an infamous brush with the law, he has graduated to running his own company, the Kuji Media Corporation, which offers security and technology advice.</p>
<p>&#8220;Hackers are a dying breed,&#8221; said Mr Bevan. &#8220;Organised criminals have cottoned on to the potential rewards. There&#8217;s viruses and trojan programs flooding out of places like Russia and Bulgaria these days.</p>
<p>&#8220;I get people asking, &#8216;Why is my machine running slowly?&#8217; And when you look, there are 300 viruses, bits of adware [advertising programs] and trojans mucking up the system. Internet service providers should really be doing deals with security firms to provide virus-free connections.&#8221;</p>
<p>Mr Bevan said he spoke to Mr McKinnon in 2002, &#8220;after he was first busted&#8221;.</p>
<p>&#8220;He&#8217;s only been selected by US prosecutors because he&#8217;s an excellent scapegoat. Maybe the amount of recreational hacking is the same, but the volume of people on the net means far more are involved in genuinely nefarious activities.&#8221;</p>
<p>&#8220;Pharming&#8221;, for example, is the latest threat to the integrity of internet banking services. It has emerged from Estonia in the past few months. This cunning electronic fraud may force banks to issue customers with a new generation of identity devices.</p>
<p>Unlike &#8220;phishing&#8221; scams &#8211; which rely on the gullibility of those who receive emails urging them to log on to sites purporting to be their online bank and confirm passwords and account details &#8211; pharming is more insidious.</p>
<p>Customers&#8217; computers are infected by a trojan program &#8211; either delivered through an innocent-looking email or inadvertently downloaded from a fake advert on the internet. When the user tries to log on to the online account, the hidden program diverts the web browser to a seemingly identical site operated by criminal gangs in eastern Europe. Their electronic identities are captured, then used to empty the accounts.</p>
<p>&#8220;There&#8217;s discussions about whether banks will eventually have to give out security devices for customers to plug into their computers,&#8221; said Sandra Quinn of APACS, the banking industry&#8217;s payments organisation. &#8220;Barclays have already carried out trials.&#8221;</p>
<p>Last year, online fraud cost British banks ?12m, an increase on previous losses. That figure was dwarfed, however, by the ?150m taken via what is known as &#8220;card not present&#8221; frauds, where goods are purchased over the telephone using stolen credit cards or simply their numbers.</p>
<p>The array of online threats grows all the time. Denial of service (DoS) attacks, where firms&#8217; email systems are bombarded into overload, are frequently accompanied by blackmail demands for cash to switch off the onslaught. Last year, the bookmaker William Hill was targeted and then received a demand for $50,000 (?28,000).</p>
<p>&#8220;Bot&#8221; programs enable computers across the net to be hijacked by remote users who in effect turn them into &#8220;zombie&#8221; machines which can be used in DoS attacks. Keylogging programs can infiltrate computers and record the keystrokes customers make in typing in credit card numbers or passwords. The criminals behind these attacks are based mainly in eastern Europe, it is believed, because law enforcement there is relatively slack and there is a plentiful supply of skilled but poorly paid programmers.</p>
<p>&#8220;It&#8217;s a classic low-risk crime,&#8221; said Ms Quinn. &#8220;We have seen some police action, however, and now we are getting phishing attacks coming from China.&#8221;</p>
<p>Threats have also been made to call-centre staff working in the financial services sector in Britain, in an attempt to force them to record and hand over customer account details. Many companies now prevent staff from using pens or paper when they sit at their screens.</p>
<p>The difficulty in penetrating banks has encouraged gangs to combine online techniques with strongarm tactics. The reported theft of computer backup tapes from US financial institutions while in transit to storage facilities has generated concerns about the security of millions of customers&#8217; accounts.</p>
<p>An attempt earlier this year to steal ?220m by electronic transfers from the London headquarters of the Japanese bank Sumitomo was foiled, but it sparked alarm about criminals infiltrating banks to carry out insider robberies.</p>
<p>&#8220;Gary McKinnon appears to be an example of the type of hacking that people have moved away from,&#8221; said Felicity Bull of the National Hi-Tech Crime Unit, which investigates major computer crime in Britain. &#8220;We know that organised crime is now hiring IT-literate workers.&#8221;</p>
<p>Some law enforcement agencies now question whether the Computer Misuse Act needs to be overhauled, enabling it to be used to prosecute those involved in DoS attacks.</p>
<p>In Washington, the secret service is the force responsible for combating online fraud and hacking. &#8220;There are still plenty of script-kiddies out there bragging about what they&#8217;re doing,&#8221; one agent, Jim Dobson, told the Guardian. Some were still at high school, he said, adding: &#8220;There&#8217;s a huge amount of information out there.&#8221;</p>
<p>Other threats, such as gangs in Russia targeting financial institutions, or those in Asia carrying out intellectual property thefts, have eclipsed the old-style hacker community, he acknowledged.</p>
<p>The rise of mobile phone technology has provided fresh opportunities for a new generation of hackers.</p>
<p>Meanwhile, wireless computer networks have been found to be particularly vulnerable, said Paul Carratu, whose Surrey firm carries out penetration testing to assess security systems. &#8220;People are not using the encryption devices they should.&#8221;</p>
<p>Last month, two British hackers, Jordan Bradley, from Darlington, and Andrew Harvey, from Durham, who belonged to an Anglo-US group called the &#8220;Thr34t Krew&#8221;, pleaded guilty in Newcastle to computer crime offences. The TK worm they released exploited a weakness in web servers and caused up to ?5.5m damage to companies using the net. They now face possible prison sentences.</p>
<p>It may be too soon to write off the perverse ingenuity of British hackers.</p>
<p>The lingo and what to look out for</p>
<p>Trojan (horse) An innocent-looking program concealing destructive intentions.</p>
<p>Pharming Hijacking online bank customers by infecting web browsers. They are redirected to fake internet sites and asked to disclose account details.</p>
<p>Phishing Sending out emails telling online account customers they must reconfirm IDs and passwords. When they hit reply they are sent to a cloned web page.</p>
<p>Key logging Programs which record keystrokes and can be used to retrieve credit card and PIN numbers.</p>
<p>Malware Umbrella term for assorted malicious software programs which sabotage your computer.</p>
<p>Zombies Online computers that have been infected by trojans and can then be remotely controlled to churn out spam emails at targeted sites.</p>
<p>Bots Programs used to infect and control computers which are then turned into zombies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/pentagons-pursuit-of-scapegoat-hacker-hides-real-threat-from-the-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The &#8216;spider&#8217;s web&#8217; of hacking</title>
		<link>http://www.kujimedia.com/the-spiders-web-of-hacking/</link>
		<comments>http://www.kujimedia.com/the-spiders-web-of-hacking/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:36:11 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[air force]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Matthew]]></category>
		<category><![CDATA[ufo]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=64</guid>
		<description><![CDATA[By Margaret Ryan &#8211; BBC News As a Briton faces possible extradition to the US for alleged computer crime, a former hacker, whose prosecution collapsed, talks about the lure of breaking into systems. Matthew Bevan had stood accused of mounting a determined &#8220;information warfare&#8221; campaign against the US air force and leading defence contractors in [...]]]></description>
			<content:encoded><![CDATA[<p>By Margaret Ryan &#8211; BBC News</p>
<p>As a Briton faces possible extradition to the US for alleged computer crime, a former hacker, whose prosecution collapsed, talks about the lure of breaking into systems.</p>
<p>Matthew Bevan had stood accused of mounting a determined &#8220;information warfare&#8221; campaign against the US air force and leading defence contractors in 1994.</p>
<p>The case against Mr Bevan collapsed<br />
US Senate hearings were initially told the security breaches were the work of highly skilled foreign agents.</p>
<p>Mr Bevan, whose hacker alias was Kuji, was charged with conspiracy and faced accusations of being an Eastern European spy.</p>
<p>But the truth was somewhat more prosaic, said the 30-year-old computer consultant.</p>
<p>&#8220;I was just a kid in my bedroom hunting for UFO information.&#8221;</p>
<p>Then a computer programmer for an insurance firm, he says he had previously been bullied and had felt ostracised by his peers.</p>
<p>&#8220;But the computer system was a place where I was king and showed power.</p>
<p>&#8220;In the real world I had none and I was quite defenceless. I didn&#8217;t deliberately cause any damage.&#8221;</p>
<p>Thrill of the chase</p>
<p>But the amateur hacker&#8217;s pastime landed him in court in the UK after his activities came to the attention of the US authorities and the British police tracked him down.</p>
<p>Mr Bevan can only talk about his own experiences &#8211; but his case, he believes, was overblown from the start as he was portrayed in the States as a spy running rings of spies.</p>
<p>It&#8217;s like a parent finding their child&#8217;s diary. You know you shouldn&#8217;t look at it but you just can&#8217;t help yourself</p>
<p>&#8220;At the time I was &#8216;the single biggest threat to world security since Adolf Hitler&#8217;,&#8221; he said.</p>
<p>By the time his case came to court the allegations made against him had died down.</p>
<p>The case against him finally collapsed in 1997 after the judge was told he posed no threat to security.</p>
<p>Another, a 16-year-old defendant, was fined £1,200 after admitting breaking into a number of US military systems.</p>
<p>Mr Bevan, who now lives in Wiltshire, freely admits that, for hackers, successfully breaking into systems provides an ego boost.</p>
<p>Reports claiming that UFO were being held secretly at American military installations had set the young hacker down the path of trying to find out more.</p>
<p>&#8220;It&#8217;s an adrenalin rush. It&#8217;s like a parent finding their child&#8217;s diary.</p>
<p>&#8220;You know you shouldn&#8217;t look at it but you just can&#8217;t help yourself.</p>
<p>&#8220;You know it&#8217;s wrong but you still do it. It becomes addictive,&#8221; he explained.</p>
<p>Competitive element</p>
<p>More than a decade on Mr Bevan understands the havoc hackers can cause in compelling companies to install more security, but resents the suggestion his actions were done out of malice.</p>
<p>&#8220;It&#8217;s like a spider&#8217;s web &#8211; once you break into one machine you can compromise a few accounts.</p>
<p>The search for UFOs prompted Mr Bevan&#8217;s hacking</p>
<p>&#8220;You may go into a machine not with the intent to find anything but just as a staging ground for another computer system.&#8221;</p>
<p>&#8220;It&#8217;s a case of &#8216;how many computers can I hack into in two hours?&#8217; We used to have competitions.&#8221;</p>
<p>But he claimed hackers had been &#8220;tainted&#8221; by the rise in identity theft and viruses.</p>
<p>For the hacker, he argued there is an ethical code that information should be free and there are strict rules about using that information.</p>
<p>He believes companies have to accept some responsibility for hacking, arguing insurance firms would not generally pay out on insurance claims if it could be shown that not enough care had been taken in guarding against it.</p>
<p>To this day he believes his arrest was politically motivated, suggesting hacking cases make headlines when companies want funding to fight cyber crime.</p>
<p>&#8220;In my cynical view the powers that be decided &#8216;we&#8217;ll have you two and make a good example of you&#8217;&#8221;, he said.</p>
<p>Childhood pursuit</p>
<p>He says he had already left hacking behind him before the day he was arrested at work.</p>
<p>Since his case was dropped the world of hacking has changed but he believes the potential for disruption remains stronger than ever as young people become ever more computer literate.</p>
<p>&#8220;When I was doing it people didn&#8217;t have net access in the UK. I was dialling up to the States,&#8221; he said.</p>
<p>For many hacking is a young person&#8217;s pursuit that they eventually grow out of, he suggested, but before they do the potential for disruption is incalculable.</p>
<p>&#8220;They [children] are smart and can develop skills that adults can&#8217;t keep up with,&#8221; he said.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/the-spiders-web-of-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Hacker&#8217; faces extradition battle</title>
		<link>http://www.kujimedia.com/hacker-faces-extradition-battle/</link>
		<comments>http://www.kujimedia.com/hacker-faces-extradition-battle/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:35:24 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[air force]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[mckinnon]]></category>
		<category><![CDATA[pentagon]]></category>
		<category><![CDATA[scotland yard]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=63</guid>
		<description><![CDATA[A British man who allegedly hacked into US military and Nasa computer networks has been arrested, say Scotland Yard. Gary McKinnon, 39, of Wood Green, north London, faces extradition proceedings over claims he hacked into 53 military and Nasa computers in 2001 and 2002. The US government believe tracking and correcting the alleged problems has [...]]]></description>
			<content:encoded><![CDATA[<p>A British man who allegedly hacked into US military and Nasa computer networks has been arrested, say Scotland Yard.</p>
<p>Gary McKinnon, 39, of Wood Green, north London, faces extradition proceedings over claims he hacked into 53 military and Nasa computers in 2001 and 2002.</p>
<p>The US government believe tracking and correcting the alleged problems has cost around $1m (?570,000).</p>
<p>Mr McKinnon is being held at a central London police station and will appear at Bow Street Magistrates Court.</p>
<p>Mr McKinnon was arrested by officers from the Metropolitan Police Service Extradition Unit on Tuesday night around 1830BST.</p>
<p>Mr McKinnon is charged with the biggest military computer hack of all time</p>
<p>The unemployed computer systems administrator, who is known on the internet as `Solo&#8217;, is due to appear in court on Wednesday.</p>
<p>He is accused of hacking into computer networks operated by Nasa, the US Army, US Navy, Department of Defence and the US Air Force.</p>
<p>One of the networks belonged to the Pentagon.</p>
<p>If he is extradited and found guilty, Mr McKinnon faces a maximum penalty of five years in prison and a ?157,000 fine.</p>
<p>The Briton was indicted in 2002 by a Federal Grand Jury on eight counts of computer-related crimes in 14 different states.</p>
<p>It claimed that he hacked into an army computer at Fort Myer, Virginia, obtained administrator privileges and transmitted codes, information and commands.</p>
<p>Unauthorised access</p>
<p>He is accused of then deleting around 1,300 user accounts.</p>
<p>The indictment alleged Mr McKinnon also &#8220;deleted critical system files&#8221; on the computer, copied a file containing usernames and encrypted passwords for the computer, in addition to installing tools to gain unauthorised access to other computers.</p>
<p>A loss of over $5,000 (£2,725) to the Army stemmed from the alleged damage, according to the indictment.</p>
<p>At the time of the indictment, Paul McNulty, the US Attorney for the Eastern District of Virginia, said: &#8220;Mr McKinnon is charged with the biggest military computer hack of all time.&#8221;</p>
<p>http://news.bbc.co.uk/1/hi/uk/4071708.stm</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/hacker-faces-extradition-battle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Heists all done.</title>
		<link>http://www.kujimedia.com/heists-all-done/</link>
		<comments>http://www.kujimedia.com/heists-all-done/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:34:54 +0000</pubDate>
		<dc:creator>Kuji</dc:creator>
				<category><![CDATA[Kuji]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[The Heist]]></category>

		<guid isPermaLink="false">http://www.kujimedia.com/?p=62</guid>
		<description><![CDATA[Channel 4 &#8211; The Heist.. got 1.7 million viewers for each episode.. Wasn&#8217;t quite what I had hoped for, but hey.. you do the show you put your life in the hands of the directors and editors&#8230; wasnt too bad.. but apparently most of what I said and did had to be cut out for [...]]]></description>
			<content:encoded><![CDATA[<p>Channel 4 &#8211; The Heist.. got 1.7 million viewers for each episode..</p>
<p>Wasn&#8217;t quite what I had hoped for, but hey.. you do the show you put your life in the hands of the directors and editors&#8230; wasnt too bad.. but apparently most of what I said and did had to be cut out for &#8220;legal reasons&#8221;&#8230; bah&#8230;. Look out for some snippets on this site someday of the bits &#8220;too hot for tv&#8221;&#8230; 80)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kujimedia.com/heists-all-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

