Underground: Hacking, madness and obsession on the electronic frontierDreyfus, Suelette
Science
Underground: Hacking, madness and obsession on the electronic frontier
Dreyfus, Suelette
Computer crimes -- Australia; Computer hackers -- Australia -- Biography; Computer security -- Australia
Perhaps to prove the point, Mendax decided to crack passwords to the
NorTel system. He collected 1003 password files from the NorTel sites,
pulled up his password cracking program, THC, and started hunting
around the network for some spare computers to do the job for him. He
located a collection of 40 Sun computers, probably housed in Canada,
and set up his program on them.
THC ran very fast on those Sun4s. The program used a 60000 word
dictionary borrowed from someone in the US army who had done a thesis
on cryptography and password cracking. It also relied on `a
particularly nice fast-crypt algorithm' being developed by a
Queensland academic, Eric Young. The THC program worked about 30 times
faster than it would have done using the standard algorithm.
Using all 40 computers, Mendax was throwing as many as 40000 guesses
per second against the password lists. A couple of the Suns went down
under the strain, but most held their place in the onslaught. The
secret passwords began dropping like flies. In just a few hours,
Mendax had cracked 5000 passwords, some 100 of which were to root
accounts. He now had access to thousands of NorTel computers across
the globe.
There were some very nice prizes to be had from these systems. Gain
control over a large company's computer systems and you virtually
controlled the company itself. It was as though you could walk through
every security barrier unchecked, beginning with the front door. Want
each employee's security codes for the office's front door? There it
was--on-line.
How about access to the company's payroll records? You could see how
much money each person earns. Better still, you might like to make
yourself an employee and pay yourself a tidy once-off bonus through
electronic funds transfer. Of course there were other, less obvious,
ways of making money, such as espionage.
Mendax could have easily found highly sensitive information about
planned NorTel products and sold them. For a company like NorTel,
which spent more than $1 billion each year on research and
development, information leaks about its new technologies could be
devastating. The espionage wouldn't even have to be about new
products; it could simply be about the company's business strategies.
With access to all sorts of internal memos between senior executives,
a hacker could procure precious inside information on markets and
prices. A competitor might pay handsomely for this sort of
information.
And this was just the start of what a malicious or profit-motivated
hacker could do. In many companies, the automated aspects of
manufacturing plants are controlled by computers. The smallest changes
to the programs controlling the machine tools could destroy an entire
batch of widgets--and the multi-million dollar robotics machinery
which manufactures them.
Public-domain text, read in full here on John Shaqi.
Reviews
Reviews
No reviews yet
Be the first to share your thoughts on this work.
Elsewhere in the archive
Join the Discussion
Join the discussion
Sign in to leave a comment or review.
Sign InorCreate an account