Underground: Hacking, madness and obsession on the electronic frontierDreyfus, Suelette
Science
Underground: Hacking, madness and obsession on the electronic frontier
Dreyfus, Suelette
Computer crimes -- Australia; Computer hackers -- Australia -- Biography; Computer security -- Australia
Whenever one computer connects to another across the Net, both
machines go through a special meet-and-greet process. The receiving
computer looks over the first machine and asks itself
a few questions. What's the name of the incoming machine?
Is that name allowed to connect to me? In what ways am I
programmed to `trust' that machine--to wave my normal security for
connections from that system?
The receiving computer answers these questions based in large part on
information provided by NIC. All of which means that, by controlling
NIC, you could make any computer on the Net `pose' as a machine
trusted by a computer you might want to hack. Security often depended
on a computer's name, and NIC effectively controlled that name.
When Prime Suspect managed to get inside NIC's sister system, he told
Mendax and gave him access to the computer. Each hacker then began his
own attack on NIC. When Mendax finally got root on NIC, the power was
intoxicating. Prime Suspect got root at the same time but using a
different method. They were both in.
Inside NIC, Mendax began by inserting a backdoor--a method of getting
back into the computer at a later date in case an admin repaired the
security flaws the hackers had used to get into the machine. From now
on, if he telnetted into the system's Data Defense Network (DDN)
information server and typed `login 0' he would have instant,
invisible root access to NIC.
That step completed, he looked around for interesting things to read.
One file held what appeared to be a list of satellite and microwave
dish coordinates--longitude, latitudes, transponder frequencies. Such
coordinates might in theory allow someone to build a complete map of
communications devices which were used to move the DOD's computer data
around the world.
Mendax also penetrated MILNET's Security Coordination Center, which
collected reports on every possible security incident on a MILNET
computer. Those computers--largely TOPS-20s made by DEC--contained
good automatic security programs. Any number of out-of-the-ordinary
events would trigger an automatic security report. Someone logging
into a machine for too long. A large number of failed login attempts,
suggesting password guessing. Two people logging into the same account
at the same time. Alarm bells would go off and the local computer
would immediately send a security violation report to the MILNET
security centre, where it would be added to the `hot list'.
Public-domain text, read in full here on John Shaqi.
Reviews
Reviews
No reviews yet
Be the first to share your thoughts on this work.
Elsewhere in the archive
Join the Discussion
Join the discussion
Sign in to leave a comment or review.
Sign InorCreate an account