Photograph, circa 2001
Three Old School Hackers
One of them pwned the SS7-era phone plant well enough to decide who won a radio contest. One ran the only documented blind TCP spoofing attack of its era, or at least got the credit for it. One did most of his work in a browser. Then someone put all three in one photo.
Dark Dante. In 1983, at 17, he and an older hacker allegedly broke into ARPAnet. He was not charged, because of his age. SRI hired him anyway.
His real domain was the telco. Working days at SRI and hacking at night, he and associates physically entered Pacific Bell facilities using forged ID, picked locks, and walked out with technical manuals, switch documentation and test equipment. The prize was COSMOS, the Computer System for Mainframe Operations, Pac Bell's line and facility provisioning database. Access to COSMOS meant the ability to create lines, reassign them, and identify which subscriber lines were under lawful intercept.
The same physical intrusions surfaced SAS, Switched Access Services, an internal Pac Bell test and maintenance system reachable through Remote Access Test Points. SAS let a technician dial in, run diagnostics on a subscriber line, and bridge onto it. Mitnick, in the middle of the photo, learned SAS existed from Justin Petersen, who went by Agent Steal and had found references to it while breaking into Pac Bell offices with Poulsen.
On 1 June 1990, KIIS-FM ran a caller-102 contest for a Porsche 944 S2. Poulsen seized all 25 trunks into the station so that no call but his own completed. He collected the car under the name Michael B. Peters. He did not do it alone, and it was not a one-off. Across roughly two years he, Ronald Austin and Petersen ran variations at several stations, taking two Porsches, more than $22,000 in cash and trips to Hawaii.
He also got into FCC systems, altered enforcement records, and tracked federal wiretap activity. Prosecutors charged him under an espionage statute, the first time it had been used against an American hacker, after a 1988 search of his storage locker turned up secret orders from a military exercise and evidence he had eavesdropped on a confidential federal investigation into Ferdinand Marcos. His lawyer called the charge absurd.
NBC's Unsolved Mysteries aired his case and the show's 1-800 tip lines went down. Every retelling implies he did it. Nobody has ever demonstrated it.
Arrested April 1991 after a supermarket manager recognised him. Pleaded guilty June 1994. Sentenced to 51 months, reported by the Los Angeles Times as the longest hacking sentence to that date, plus a three-year post-release ban on computers and the internet, lifted in 2004.
Then the turn. SecurityFocus, then Wired, then The Daily Beast. Two Knight-Batten grand prizes, two Webby Awards for Threat Level. With Aaron Swartz and James Dolan he designed and built the platform released as DeadDrop and now known as SecureDrop, first deployed at The New Yorker in May 2013 and later handed to the Freedom of the Press Foundation, where he sat on the technical advisory board. The man who used COSMOS to find out who was being wiretapped spent the second half of his career building the thing that makes sources harder to trace.
The lazy version of Mitnick is that he was a talker who never touched a keyboard. He spent twenty years pushing back on it, and Ghost in the Wires is full of Unix exploitation. He was convicted in part for copying proprietary source. The Justice Department's account has him accessing dozens of networks while a fugitive, hiding behind cloned cellular handsets, lifting proprietary software from major cellular and computer companies, intercepting credentials and reading private mail. Where he was genuinely without peer was pretexting: knowing the internal jargon, the org chart, the escalation path, and calling until someone read him what he wanted.
Shimomura wrote up the Christmas Day 1994 attack on his own systems and posted it to comp.security.misc on 25 January 1995. The material came from a talk he had given two weeks earlier at CMAD III, the third annual workshop on Computer Misuse and Anomaly Detection, an invitation-only event at Sonoma sponsored by the NSA, the Air Force Information Warfare Center and UC Davis. Two mechanisms were used. First, IP source address spoofing plus TCP initial sequence number prediction to gain access to a diskless workstation running mostly as an X terminal. The trusted host was silenced with a flood of half-open SYNs from a non-routable source so it could not respond to the SYN/ACK, letting the attacker complete a blind handshake against a target whose ISN generation was predictable. Second, once root was obtained, an existing connection to another system was hijacked using a loadable STREAMS kernel module called tap-2.01.
Steve Bellovin had described the sequence-guessing technique in "Security Problems in the TCP/IP Protocol Suite" in 1989. The Christmas Day incident is generally treated as the first known use in the wild. It is also why your stack now randomises ISNs.
In Ghost in the Wires, Mitnick says an Israeli hacker known as JSZ wrote and executed the spoofing code, and that he himself connected through the backdoor JSZ had already established. Mitnick was never charged over the Shimomura intrusion. That is his account rather than a court finding, but the "Mitnick attack" label carries more than the evidence supports.
What actually burned them was housekeeping. They cleaned up, but missed tcpdump capturing traffic and a cron job mailing the logs offsite to Shimomura's assistant. Later, cellular signal tracing put him in an apartment complex in Raleigh, and the FBI arrested him there on 15 February 1995 with cloned handsets, more than 100 cloned phone codes and multiple false identities.
He served five years, four and a half of them pre-trial, including eight months in solitary. By his account, law enforcement convinced the judge he could start a nuclear war by whistling into a payphone. Released 21 January 2000. Died of pancreatic cancer, July 2023.
The homeless hacker, working from Kinko's terminals, coffee shops and libraries. He did not write code. He wrote almost nothing. His toolchain was Proxy Hunter and a browser.
The technique was the same every time. Scan a target's public address space for open or misconfigured HTTP proxies, find the one the admins forgot, point a browser at it, and you are now originating traffic as an internal node. Everything behind it that trusts network position rather than identity opens up.
- Excite@Home / 2001A single rogue proxy at the Redwood City headquarters exposed internal web applications, and with them a customer list of 2.95 million cable modem subscribers. Lamo's own assessment, to SecurityFocus, was that it was not rocket science.
- Yahoo / September 2001An exposed web-based production tool let him edit a Reuters wire story on Yahoo News. He deliberately picked an old story to limit the impact. Secondary accounts say he inserted a fabricated quote attributed to John Ashcroft.
- WorldCom / December 2001Five open proxies on the corporate address space, one of them sitting at wireless.wcom.com. From inside, he reached an HR system that could return names and matching Social Security numbers for all 86,000 employees, and WARM, a legacy tool inherited from the ANS acquisition that granted access to routers on privately provisioned WANs belonging to customers including Bank of America and JP Morgan. WorldCom publicly thanked him.
- The New York Times / February 2002A two-minute scan turned up seven misconfigured proxies bridging the public internet and the Times intranet. Weak internal password policy handled lateral movement. He ended up browsing employee names and Social Security numbers, home delivery stop and start logs, dial-up instructions for stringers filing copy, Metro and Business desk contact lists, and the WireWatch keyword sets individual reporters used to monitor the wires.
At the Times he also added himself to the op-ed contributor database, 3,000 records deep, listing his number as 415-505-HACK and his expertise as "computer hacking, national security, communications intelligence". Then he created five accounts under the paper's LexisNexis contract and ran more than 3,000 searches. In February 2002 those five accounts accounted for roughly 18 percent of all searches on the Times LexisNexis account. Prosecutors put the bill at $300,000. Lamo disputed the figure and so did several people in the industry.
Until the Times, his pattern of disclosing to the victim first had kept him out of court. Much of the contemporaneous reporting on those disclosures carried Poulsen's byline at SecurityFocus. The Times filed a complaint, and after a 15-month federal investigation he surrendered in September 2003 and pleaded guilty in January 2004. Six months of home detention, two years probation, roughly $65,000 restitution, and a felony conviction that closed off the security career the industry was about to start hiring for.
When this photo was taken, the Times break-in was still months away.
In May 2010 an Army intelligence analyst named Chelsea Manning told Lamo over chat that she had passed hundreds of thousands of classified documents to WikiLeaks. Lamo reported her to Army investigators. The chat logs were published by Wired, where Poulsen was an editor, and Poulsen broke the story of Manning's arrest. Two of the three men in this picture ended up at opposite ends of the same disclosure, one of them running the platform designed to protect exactly that kind of source.
Lamo was found dead in Wichita in March 2018, aged 37. The Sedgwick County coroner returned cause and manner of death as undetermined.
Three trust models, three failures
Mitnick attacked the trust humans place in a voice that knows the right jargon, then used real technical skill once the credential was in hand. Lamo attacked the trust networks place in source address and network position. Poulsen attacked the trust everyone placed in the phone plant itself, with a false badge, a set of lock picks and the provisioning database.
None of those three failure modes has gone away.
Sources
- Tsutomu Shimomura, technical details of the 25 December 1994 intrusion, posted 25 January 1995. Archived copy
- S. M. Bellovin, "Security Problems in the TCP/IP Protocol Suite", Computer Communication Review, 1989
- CMAD III workshop record, UC Davis Computer Security Lab, Sonoma, January 1995. Workshop page
- Jeannette DeSantis, "Man Gets Longest Term for Hacker", Los Angeles Times, 11 April 1995. LA Times archive
- US Department of Justice, complaint and plea press releases in United States v. Lamo, 2003 and 2004. DOJ release
- Kevin Poulsen, "Lamo's Adventures in WorldCom", SecurityFocus, December 2001. Republished
- "At Home's mis-configured proxy Excites hacker", SecurityFocus, June 2001. Republished
- Kevin Mitnick with William L. Simon, Ghost in the Wires, Little, Brown, 2011
- Sedgwick County Regional Forensic Science Center autopsy report on Adrian Lamo, released June 2018