The birth of the Electronic Frontier Foundation was announced July 10, 1990. EFF is a group dedi-cated to protecting our constitutional rights; it was created as a response to a series of rude and unin-formed blunderings by the Secret Service in the witch hunt known as Operation Sundevil. By May, 1989, this "hacker hunt" had led 150 Secret Service agents to serve 28 search warrants in 14 cities. They seized 23,000 disks and 42 computers, often for in-appropriate reasons. E-mail was left undelivered. Public postings never made it to the screens of the computer community. Many innocent bystanders (as well as criminals) were arrested.
John Perry Barlow (author, retired cattle rancher, and a lyricist for the Grateful Dead), and computer guru Mitch Kapor, best known for writ-ing Lotus 1-2-3, were outraged by these events (and by their own run-ins with the FBI over stolen source code that was being distributed by the NuPrometheus League). They teamed up with attorney Harvey Silverglate who was known for taking on offbeat causes. Some yellow journalism by the Washington Post provided the publicity needed to attract Steve Wozniak (co-founder of Apple) and John Gilmore (of Sun Microsystems) who offered monetary support for the enterprise. It was at this point that the Steve Jackson inci-dent made the headlines. An Austin, Texas, pub-lisher of role-playing games, Jackson's business was raided by the Secret Service because one of his games, called GURPS Cyberpunk, had to do
with a kind of futuristic computer hacking. The Secret Service called Jackson's game "a handbook for computer crime." This was ludicrous, akin to arrest-ing Milton Bradley because they sell Chess, which teaches kids how to wage war.
Jackson's office equipment was confiscated, he was forced to lay off half his staff, and he very nearly went into bankruptcy. "Eventually," Jackson later wrote, "we got most of our property back (though some of it was damaged or destroyed). The Secret Service admitted that we'd never been a tar-get of their investigation."
Jackson sued the U.S. government (the Secret Service, two of its agents, and a Bellcore official were named in the suit) on charges that the Secret Service had violated his right to free speech during the office raid. Justice prevailed and the SS was held guilty. Jackson has, since made a role-playing game about the incident.
The summer of 1990 was filled with all sorts of similar surprises. There are the famous stories, the infamous ones, and the ones that barely made the back page. In the middle of August, thirteen New York young adults and minors were charged with felonies involving computer tampering, computer trespassing, and theft of
services. They had broken into the Pentagon's computers, among others, and got a whole load of law enforcers on their tail. $50,000 worth of computing equipment was seized, said to have been used by the hackers to do the break-ins. Dozens of stories like this were reported then quickly faded. Other tales and other hackers held more interest, like Acid Phreak and Phiber Optik, who became "celebrity hackers," speaking on behalf of the hacker community for various media. Phiber Optik was eventually arrested and sentenced to thirty-five hours of community service in'February, 1991. And the Craig M. Neidorf story made head-lines. We have already mentioned Neidorf (Knight Lightning) as one of the co-founders of Phrack. Nei-dorf published an (edited) internal BellSouth paper in Phrack and was quickly charged with interstate transport of stolen property, with a possible sen-tence of 60 years in jail and $122,000 in fines. What was particularly absurd was that the document was easily and legally available (though BellSouth declared it to be full of company secrets), and it talked about the BellSouth bureaucracy as it per-tained to 911 lines. Sixty years in jail for copyright infringement?
The EFF helped Neidorf through these troubled times (as they'd helped Steve Jackson, and would come to aid many hackers and crackers who'd been treated unfairly or with ignorance by the law). The U.S. dropped its case against Neidorf at the end of July, 1990.
There are dozens or hundreds of stories about hackers every year, and there have been for quite some time. Some are quickly forgotten; others pro-voke controversy. Such was the case on November 6,1992, when a group of hackers, peacefully con-vening in the food court of the Pentagon City Mall outside Washington, D.C., were bullied and man-handled by mall security personnel, Secret Service and FBI agents.
Hacking has had a long past and will continue to enjoy a prosperous and successful future because of people like us who enjoy seeing what secrets are out in the world, waiting to be unearthed.
Sound Bytes from Reviews of Secrets of a Super Hacker "Secrets of a Super Hacker is a fascinating hacker cookbook that reveals the ease of penetrating even the most stalwart computer system"
Showing posts with label Chapter 2. Show all posts
Showing posts with label Chapter 2. Show all posts
Sunday, 27 November 2011
The History of Hacking: Shadow Hawk
Bill Landreth, who had been arrested in 1983, was let out on parole and there are reports of his mysterious disappearance following publication of his guide to computer security called Out of the Inner Circle. He left a note stating that he would cornmit suicide "sometime around my 22nd birthday..." There was much
discussion about all this. Was it a publicity stunt, or for real? Eventually Landreth reappeared in Seattle, Washington, in July, 1987, and he was hastily carted back to jail for breaking probation.
The month before - on the anniversary of D-Day - a cracker named Shadow Hawk (also identified by some press reports as Shadow Hawk 1) had been discovered by an AT&T security agent to be bragging on a Texas BBS called Phreak Class-2600 about how he had hacked AT&T's computer system. Shadow Hawk (really Herbert Zinn of Chicago) was an 18-year-old high school drop-out when he was arrested. He'd managed to get the FBI, the Secret Service, the Defense Criminal Investigative Service and the Chicago U.S. attorney on his tail for not only the above mentioned hack, but also for invading computers belonging to NATO and the US Air Force, and stealing a bit over $1 million worth of software. Shadow Hawk's case is important because in 1989 he became the first person to be prosecuted under the Computer Fraud and Abuse Act of 1986.
Shadow Hawk is just one example of how this hobby has gotten people in trouble with the law. Around this time there were a lot of hackers being brought down by all manner of cops: security officers for the telephone companies and other organizations, the FBI, local police and concerned citizens. This was the time when the investigators got smart. Not that they suddenly knew more about computers and hacking, but now they understood that to catch a lion, one must step into its den. These police agents started logging onto hacker BBSs and amassed huge dossiers on the people who normally used those boards. Many warnings were issued, and many arrests were made.
In August, 1986, Cliff Stoll first set out to find out why there was a 7,50 imbalance in the computer accounts at the Lawrence Berkeley Laboratory in California. Stoll's efforts led to the discovery of a group of German hackers who had broken into the computer system. In October, 1989, a book about Stoll's exploits called The Cuckoo's Egg was published and became an instant best seller.
Organized and independent hacker activity continued for the next few years with little public interest. There were threats in early 1988 by the West Berlin Chaos Computer Club that they would trigger Trojan horses they had implanted into NASA's Space Physics Analysis Network, thus causing the chaos of their name. The
threats never materialized but minor havoc was wrought anyway, as many computers were temporarily pulled from the net until the threat could be analyzed.
The end of 1988 - November 2, to be exact -marked the beginning of a new surge in anti-hacker sentiment. It was then that Robert Morris Jr.'s com-puter worm began its race through the Internet. Exploiting an undocumented bug in the sendmail program and utilizing its own internal arsenal of tricks, the worm would
infiltrate a system and quickly eat up most or all of the system's process-ing capabilities and memory space as it squiggled around from machine to machine, net to net.
discussion about all this. Was it a publicity stunt, or for real? Eventually Landreth reappeared in Seattle, Washington, in July, 1987, and he was hastily carted back to jail for breaking probation.
The month before - on the anniversary of D-Day - a cracker named Shadow Hawk (also identified by some press reports as Shadow Hawk 1) had been discovered by an AT&T security agent to be bragging on a Texas BBS called Phreak Class-2600 about how he had hacked AT&T's computer system. Shadow Hawk (really Herbert Zinn of Chicago) was an 18-year-old high school drop-out when he was arrested. He'd managed to get the FBI, the Secret Service, the Defense Criminal Investigative Service and the Chicago U.S. attorney on his tail for not only the above mentioned hack, but also for invading computers belonging to NATO and the US Air Force, and stealing a bit over $1 million worth of software. Shadow Hawk's case is important because in 1989 he became the first person to be prosecuted under the Computer Fraud and Abuse Act of 1986.
Shadow Hawk is just one example of how this hobby has gotten people in trouble with the law. Around this time there were a lot of hackers being brought down by all manner of cops: security officers for the telephone companies and other organizations, the FBI, local police and concerned citizens. This was the time when the investigators got smart. Not that they suddenly knew more about computers and hacking, but now they understood that to catch a lion, one must step into its den. These police agents started logging onto hacker BBSs and amassed huge dossiers on the people who normally used those boards. Many warnings were issued, and many arrests were made.
In August, 1986, Cliff Stoll first set out to find out why there was a 7,50 imbalance in the computer accounts at the Lawrence Berkeley Laboratory in California. Stoll's efforts led to the discovery of a group of German hackers who had broken into the computer system. In October, 1989, a book about Stoll's exploits called The Cuckoo's Egg was published and became an instant best seller.
Organized and independent hacker activity continued for the next few years with little public interest. There were threats in early 1988 by the West Berlin Chaos Computer Club that they would trigger Trojan horses they had implanted into NASA's Space Physics Analysis Network, thus causing the chaos of their name. The
threats never materialized but minor havoc was wrought anyway, as many computers were temporarily pulled from the net until the threat could be analyzed.
The end of 1988 - November 2, to be exact -marked the beginning of a new surge in anti-hacker sentiment. It was then that Robert Morris Jr.'s com-puter worm began its race through the Internet. Exploiting an undocumented bug in the sendmail program and utilizing its own internal arsenal of tricks, the worm would
infiltrate a system and quickly eat up most or all of the system's process-ing capabilities and memory space as it squiggled around from machine to machine, net to net.
Labels:
Chapter 2
The History of Hacking: WarGames and Phrack
A hacker named Bill Landreth was indicted for computer fraud in 1983, and convicted in 1984 of entering such computer systems as GTE Tele-mail's electronic mail network, and reading the NASA and Department of Defense correspondence within. Naughty boy! His name will come up again. 1983 also saw the release of
WarGames, and all hell broke loose. Certainly there had been plenty of hacker activity before the movie came out, but previous to WarGames those hackers were few in number and less visible. The exciting story of David Lightman (played by Matthew Broderick), a school-age whiz kid who nearly starts World War 111,
became the basis for many modems for Christmas presents that year. Suddenly there was a proliferation of people on the hacking scene who were not really hackers in expertise or spirit. Bulletin board systems flour-ished, and a large number of boards catering to hackers, phreaks, warez dOOds (software pirates), anarchists, and all manner of restless youth sprung up.
The online publication Phrack was founded on November 17, 1985, on the Metal Shop Private BBS in St. Louis, Missouri, operated by Taran King and Knight Lightning. The term "online" referred to the fact that this magazine was distributed, not at newsstands and through the mails, but on the finews racks" of electronic bulletin board systems, where collections of files are available for the taking.
Later, when the journal's founders went off to college and received Internet access, the publication was distributed through list servers which can automatically e-mail hundreds of copies of the pub-lication throughout the world. Phrack is still dis-tributed in this way. As the name implies, Phrack deals with PHReaking and hACKing, but it also is pleased to present articles on any sort of mischief-making.
Annual conventions, hosted by Phrack, called SummerCons, are now held in St.
Louis.
WarGames, and all hell broke loose. Certainly there had been plenty of hacker activity before the movie came out, but previous to WarGames those hackers were few in number and less visible. The exciting story of David Lightman (played by Matthew Broderick), a school-age whiz kid who nearly starts World War 111,
became the basis for many modems for Christmas presents that year. Suddenly there was a proliferation of people on the hacking scene who were not really hackers in expertise or spirit. Bulletin board systems flour-ished, and a large number of boards catering to hackers, phreaks, warez dOOds (software pirates), anarchists, and all manner of restless youth sprung up.
The online publication Phrack was founded on November 17, 1985, on the Metal Shop Private BBS in St. Louis, Missouri, operated by Taran King and Knight Lightning. The term "online" referred to the fact that this magazine was distributed, not at newsstands and through the mails, but on the finews racks" of electronic bulletin board systems, where collections of files are available for the taking.
Later, when the journal's founders went off to college and received Internet access, the publication was distributed through list servers which can automatically e-mail hundreds of copies of the pub-lication throughout the world. Phrack is still dis-tributed in this way. As the name implies, Phrack deals with PHReaking and hACKing, but it also is pleased to present articles on any sort of mischief-making.
Annual conventions, hosted by Phrack, called SummerCons, are now held in St.
Louis.
Labels:
Chapter 2
The History of Hacking: 2600
Tom Edison and Cheshire Catalyst, two phone phreaks who had been interested in the nether side of technology for ages, took over TAP in the late 70s. The journal came to an end before its time in 1983 when Torn Edison's New Jersey condominium burned to the ground, the victim of a professional burglary and an
amateurish arson. The burglars had gotten all of Tom's computer equipment, the stuff from which TAP was born. The arson, perhaps an attempt to cover the burglary, did not succeed. It was a sloppy fire, one which Tom and Cheshire hypothesized had been engineered by some irate phone company officer. A few months later, the original TAP printed its final issue. The following year, in 1984, hacker Eric Corley (aka Emmanuel Goldstein) filled the void with a new publication: 2600 Magazine. Ironically, Goldstein is more a rhetorician than a hacker, and the magazine is less technical and more political (like the original YIPL).
Networks were being formed all over, enabling hackers to not only hack more sites but to exchange information among themselves quicker and more easily. Mo needs published magazines? The City University of New York and Yale University joined together as the first BITNET (Because It's Time NETwork) link in May 1981. Now there are net-works of networks (such as Internet) connecting the globe, putting all hackers and common folk in di-rect communication with one another.
amateurish arson. The burglars had gotten all of Tom's computer equipment, the stuff from which TAP was born. The arson, perhaps an attempt to cover the burglary, did not succeed. It was a sloppy fire, one which Tom and Cheshire hypothesized had been engineered by some irate phone company officer. A few months later, the original TAP printed its final issue. The following year, in 1984, hacker Eric Corley (aka Emmanuel Goldstein) filled the void with a new publication: 2600 Magazine. Ironically, Goldstein is more a rhetorician than a hacker, and the magazine is less technical and more political (like the original YIPL).
Networks were being formed all over, enabling hackers to not only hack more sites but to exchange information among themselves quicker and more easily. Mo needs published magazines? The City University of New York and Yale University joined together as the first BITNET (Because It's Time NETwork) link in May 1981. Now there are net-works of networks (such as Internet) connecting the globe, putting all hackers and common folk in di-rect communication with one another.
Labels:
Chapter 2
The History of Hacking: Computer Crime
The first recorded computer abuse, according to Donn B. Parker, a frequent writer on computer crime, occurred in 1958. The first federally prose-cuted crime identified specifically as a computer crime involved an alteration of bank records by computer in Minneapolis in 1966. Computers were not so widespread then as they are now, and the stakes weren't quite so high. It's one thing to have money controlled and kept track of via computer; it's quite another to have power controlled in this way. In 1970, many criminology researchers were stating that the problem of computer crime was merely a result of a new technology and not a topic worth a great deal of thought. Even in the mid-1970s, as crimes by computer were becoming more frequent and more costly, the feeling was that the machines themselves were just a part of the environment, and so they naturally would become a component of crime in some instances. It doesn't matter if a burglar carries his loot in a pillow case or a plastic bag - why should the props of the crime determine the way in which criminologists think about the case?
This was an unfortunate mode of thought for those charged with preventing computer crimes, because while research stagnated, the criminals, crackers and hackers were actively racking their brains to come up with more ingenious methods of doing things with computers they were not sup-posed to be able to do. The
criminologists could not have realized then that the computer really was an integral part of the crime, and that the existence of these machines - and the systems built around them - led to whole new areas of crime and think-ing about crime that had never before been explored.
Lawmakers and enforcers, however, finally did sit up and take notice. In 1976 two important de-velopments occurred. The FBI established a 4-week training course for its agents in the investigation of computer crime (and followed it up with a second course for other agencies in 1978). Also in 1976, Senator Abraham Ribicoff and his U.S. Senate Gov-ernment Affairs Committee realized that something big was going on, and it was important for the gov-ernment to get in on it. The committee produced two research reports and Ribicoff introduced the first Federal Systems Protection Act Bill in June, 1977. These reports eventually became the
Com-puter Fraud and Abuse Act of 1986. Florida, Michi-gan, Colorado, Rhode Island, and Arizona were some of the first states to have computer crime legislation, based on the Ribicoff bills that had devel-oped into the 1986 Act.
A year before, a major breakthrough was an-nounced at the Securicom Conference in Cannes by a group of Swedish scientists who had invented a method of silently eavesdropping on a computer screen from a far-off distance. But let's save this story for later. Much later.
This was an unfortunate mode of thought for those charged with preventing computer crimes, because while research stagnated, the criminals, crackers and hackers were actively racking their brains to come up with more ingenious methods of doing things with computers they were not sup-posed to be able to do. The
criminologists could not have realized then that the computer really was an integral part of the crime, and that the existence of these machines - and the systems built around them - led to whole new areas of crime and think-ing about crime that had never before been explored.
Lawmakers and enforcers, however, finally did sit up and take notice. In 1976 two important de-velopments occurred. The FBI established a 4-week training course for its agents in the investigation of computer crime (and followed it up with a second course for other agencies in 1978). Also in 1976, Senator Abraham Ribicoff and his U.S. Senate Gov-ernment Affairs Committee realized that something big was going on, and it was important for the gov-ernment to get in on it. The committee produced two research reports and Ribicoff introduced the first Federal Systems Protection Act Bill in June, 1977. These reports eventually became the
Com-puter Fraud and Abuse Act of 1986. Florida, Michi-gan, Colorado, Rhode Island, and Arizona were some of the first states to have computer crime legislation, based on the Ribicoff bills that had devel-oped into the 1986 Act.
A year before, a major breakthrough was an-nounced at the Securicom Conference in Cannes by a group of Swedish scientists who had invented a method of silently eavesdropping on a computer screen from a far-off distance. But let's save this story for later. Much later.
Labels:
Chapter 2
The History of Hacking: YIPL and TAP
So there was the telephone, there was the computer, and there was an undaunted inquisitiveness in the collective human subconscious. It took another war to shake that curious imagination loose onto the world, and on May Day, 1971, the Youth International Party Line became the newsletter of the fun-seeking, disenfranchised riffraff of New York City's Greenwich Village. Abbie Hoffman and a phone phreak who went by the handle Al Bell used YIPL to disburse information about cracking the phone network. It was the first instance of subver-sive information of its kind finding a wide audi-ence. Subscriptions to the journal spread the word of this arm of the underground far away from Bleecker Street to people of all walks of life. Today this distribution would be done by computer, and indeed, a great deal of hacker/phreaker/anarchist material surfs around the world on the
invisible waves of cyberspace.
A few years after YIPL's inception, it became TAP - Technological Assistance Program - when the goals of the phreaks collided with the more po-litically-minded members of YIPL. TAP was more technical than partisan, and more suited for hackers and their kin.
invisible waves of cyberspace.
A few years after YIPL's inception, it became TAP - Technological Assistance Program - when the goals of the phreaks collided with the more po-litically-minded members of YIPL. TAP was more technical than partisan, and more suited for hackers and their kin.
Labels:
Chapter 2
The History of Hacking: First Came Hardware
Where does one begin a history of hacking?
Do we start with the creation of the computer, by J. Presper Eckert and John Mauchly? During World War 11 this pair of engineer and physicist approached the US Army with a proposal for an electronic device that would speedily calculate gunnery coordinates - a job that was then tedi-ously being done by hand. With the
government backing their way, the Electronic Numerical Inte-grator And Calculator (ENIAC) was born in 1946. It was a year after the war's end - the machine's designed function was now superfluous - but the dream behind its imagined future uses lived on.
Of course, the origin of the computer - the computer for god's sake - the most revolutionary invention since the telephone, can not be so easily summed up in a tidy paragraph of wartime patri-otic stupor. The real story goes back further, to Konrad Zuse, whose patent for a general-purpose electromechanical relay computer
in 1938 was turned down by the Patent Office as being not specific enough. It may have been ENIAC that spawned the next generation of computers, but ENIAC was a one-task machine. Zuse's contraption had the feel of modernity to it: a machine that would do... anything.
But is that where hacking began? Certainly not. The longing to do... anything has been in the human psyche for ages. Perhaps we should begin with the revolutionary creation of the telephone, culminat-mg with Alexander Graham Bell's historic "acci-dent" on March 10, 1876. The telephone was not an immediate best
seller. After all, you couldn't simply buy one and place it in your house and use it. Lines had to be installed. Networks had to be created to link home to home, business to business, and fi-nally, state to neighboring state. Almost thirty years of growth for the phone to spread throughout the country.
Do we start with the creation of the computer, by J. Presper Eckert and John Mauchly? During World War 11 this pair of engineer and physicist approached the US Army with a proposal for an electronic device that would speedily calculate gunnery coordinates - a job that was then tedi-ously being done by hand. With the
government backing their way, the Electronic Numerical Inte-grator And Calculator (ENIAC) was born in 1946. It was a year after the war's end - the machine's designed function was now superfluous - but the dream behind its imagined future uses lived on.
Of course, the origin of the computer - the computer for god's sake - the most revolutionary invention since the telephone, can not be so easily summed up in a tidy paragraph of wartime patri-otic stupor. The real story goes back further, to Konrad Zuse, whose patent for a general-purpose electromechanical relay computer
in 1938 was turned down by the Patent Office as being not specific enough. It may have been ENIAC that spawned the next generation of computers, but ENIAC was a one-task machine. Zuse's contraption had the feel of modernity to it: a machine that would do... anything.
But is that where hacking began? Certainly not. The longing to do... anything has been in the human psyche for ages. Perhaps we should begin with the revolutionary creation of the telephone, culminat-mg with Alexander Graham Bell's historic "acci-dent" on March 10, 1876. The telephone was not an immediate best
seller. After all, you couldn't simply buy one and place it in your house and use it. Lines had to be installed. Networks had to be created to link home to home, business to business, and fi-nally, state to neighboring state. Almost thirty years of growth for the phone to spread throughout the country.
Labels:
Chapter 2
Subscribe to:
Posts (Atom)