NetStumbler.org Forums

Go Back   NetStumbler.org Forums > WiFi Forums > News
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 07-26-2002   #1 (permalink)
JimmyPopAli
Registered Member
 
JimmyPopAli's Avatar
 
Join Date: Apr 2002
Location: Washington the state
Posts: 242
Ethical hacker faces war driving charges.

http://www.theregister.co.uk/content/55/26397.html

From the Kismet list.
JimmyPopAli is offline   Reply With Quote
Old 07-26-2002   #2 (permalink)
g0tr00t
Welcome to my nightmare
 
g0tr00t's Avatar
 
Join Date: May 2002
Location: r00ting y0ur b0x.
Posts: 352
Can I be honest here?

This is such bullsh*t.

"an alleged intrusion that cost the county a reported $5,000 to clean up."

WTF? What cost $5000???? For the county to ream out the net admins for f*cking up!!! The cost of the wireless AP's that mr dumbsh*t net admin recommended? - Oh just leave it at default. It's the best security setting in the world.

"District Clerk Charles Bacarisse told the paper that no confidential information was disclosed but the alleged intrusion eventually resulted in the county closing its wireless LAN only a month after it was activated. "

So what cost $5000????????

Check this out!
"On March 18, Puffer demonstrated to a county official and a Chronicle reporter how easy it was to gain access to the court's system using only a laptop computer and a wireless LAN card. "

And now he is doing jail time for this???

Let me get this straight:
1. A reporter contacted him to "stumble"
2. A county official accompanied them to go stumble.
3. He accessed their network and showed them, lets say, the workstations.
4. He did NOTHING to their networks.
5. Now is facing jail time!!!

"Puffer, who was employed briefly by the county's technology department in 1999, could get five years in jail and faces a $250,000 fine on each count if convicted, the Houston Chronicle reports."

Sorry to stoop to the level of cursing. But this crap pisses me off! Here someone was helping them and now they turn around and lock him up.

Ok, ok so he should of had a signed contract with the court house and what not, but it still frosts my ass..



---Ok, so I missed the part about uploading porn. Ok, so he did hack, pretty deep too. Oh well, his loss. Dumbass.
__________________
g0tr00t

"Its all fun and games until someone gets killed."

Last edited by g0tr00t : 07-26-2002 at 10:58 AM.
g0tr00t is offline   Reply With Quote
Old 07-26-2002   #3 (permalink)
lincomatic
Squaaawk! WiFi! WiFi!
 
lincomatic's Avatar
 
Join Date: Apr 2002
Location: Tinsel Town
Posts: 1,682
---Ok, so I missed the part about uploading porn. Ok, so he did hack, pretty deep too. Oh well, his loss. Dumbass.


this part is a joke, right?

you should post this on the main netstumbler site too. very interesting.
__________________
~lincomatic
lincomatic is offline   Reply With Quote
Old 07-26-2002   #4 (permalink)
g0tr00t
Welcome to my nightmare
 
g0tr00t's Avatar
 
Join Date: May 2002
Location: r00ting y0ur b0x.
Posts: 352
Quote:
Originally posted by lincomatic

this part is a joke, right?
http://www.chron.com/cs/CDA/story.hts/tech/news/1507766

Quote:
County Attorney Mike Stafford said he will resume his investigation into whether the security breach was corrected as promptly as county officials learned of it and the origin of a pornographic picture found on the clerk's office server in March.
The guy is getting blamed for this too....
__________________
g0tr00t

"Its all fun and games until someone gets killed."
g0tr00t is offline   Reply With Quote
Old 07-26-2002   #5 (permalink)
lincomatic
Squaaawk! WiFi! WiFi!
 
lincomatic's Avatar
 
Join Date: Apr 2002
Location: Tinsel Town
Posts: 1,682
sounds a more than a bit far-fetched to try to pin the porno pic on him too. another case of overzealous DA's. it was probably an inside job from some dork surfing pr0n at his desk.
__________________
~lincomatic
lincomatic is offline   Reply With Quote
Old 07-26-2002   #6 (permalink)
g0tr00t
Welcome to my nightmare
 
g0tr00t's Avatar
 
Join Date: May 2002
Location: r00ting y0ur b0x.
Posts: 352
Well you know someone has to be the scapegoat. This poor guy is it. So now every intrusion from 1 month prior to them shutting down wirelesss will be blamed on this guy.

Instead of going after the net admin that installed the AP's. AGHHH!!!!!

This kills me...Just think about it now.

The county is going to hire a forensics team to analyze the network, they will all need new computers , the old ones may have trojans and cannot be cleaned , now they are going to spend much more $$$$ on having a "security consultant" to come in, flip on WEP and enable MAC filtering.

Kills me....
__________________
g0tr00t

"Its all fun and games until someone gets killed."
g0tr00t is offline   Reply With Quote
Old 07-26-2002   #7 (permalink)
Sh00t3r
Registered Member
 
Sh00t3r's Avatar
 
Join Date: Apr 2002
Location: Michigan
Posts: 199
G0tr00t, you hit the nail on the head. There's going to be thousands spent now only because someone actually exposed a vulnerability, or did he? What he actually did to "hack" the network is going to have to be determined. Nonetheless he did have previous working experience at the location and this could've made his attack a heck of alot easier.

Quote:
The article quoted Bacarisse as saying his staff was alerted when someone tried to access the system March 8. He also characterized Puffer's demonstration as a "low-level intrusion" that did no permanent damage.

As for Puffer's March 18 demonstration, Bacarisse said Wednesday, "Normally you secure a contract with an entity before you hack into a system, if that's what you're saying your expertise is."
Sorry to say but this Bacarisse guy is right. Anyone attempting to take a reporter along and show him how to "hack" into a WLAN better be prepared for repurcusions after the hacked company is all over the TV. Simply using NetStumbler or Kismet as means to "identify" WLANS is another story (as fungus did recently).

Maybe the article should've been titled "ethical hacker faces charges after exposing an exploit of a wireless LAN". As opposed to the war driving title?

Time will tell
Sh00t3r is offline   Reply With Quote
Old 07-26-2002   #8 (permalink)
carbolic
Move Zig
 
carbolic's Avatar
 
Join Date: Apr 2002
Location: Los Angeles
Posts: 107
Read on...

Back story from March 2002:
http://www.chron.com/cs/CDA/story.hts/topstory/1302663
__________________
www.SoCalWUG.org
carbolic is offline   Reply With Quote
Old 07-26-2002   #9 (permalink)
lincomatic
Squaaawk! WiFi! WiFi!
 
lincomatic's Avatar
 
Join Date: Apr 2002
Location: Tinsel Town
Posts: 1,682
Re: Read on...

Quote:
Originally posted by carbolic
Back story from March 2002:
http://www.chron.com/cs/CDA/story.hts/topstory/1302663
that is really sad. a couple of bureaucrats trying to save their sorry asses by blaming a scapegoat. it's their heads that should roll for putting up a wide open network in the first place. hell, anyone in a nearby building w/ XP would have gotten on automatically. just goes to show you the slimy "damage control" public officials resort to when they make a mistake.
__________________
~lincomatic

Last edited by lincomatic : 07-26-2002 at 06:20 PM.
lincomatic is offline   Reply With Quote
Old 07-27-2002   #10 (permalink)
drnazo
I'm special
 
Join Date: May 2002
Location: CO / Springs
Posts: 29
This is exactly why war drivers and wi-fi junkies should keep a low profile.
Another case similar happened here. Only he got in trouble for wardriving. He told people that the cops said that they could see the glow of the LCD on his face and twas the reason they pulled him over. Once he was pulled over they gave him a ticket for operating a computer while driving and also a ticket for scanning.

He was actually doing them a favor and was punished for it. This shows you how bad ignorant people can hurt a good cause.

I plan on continuing wardriving and everything but I also plan on modifying my wardriving habits.
drnazo is offline   Reply With Quote
Old 07-27-2002   #11 (permalink)
stumble_butt
Good Lookin Old Geezer
 
stumble_butt's Avatar
 
Join Date: May 2002
Location: Somewhere in the Ether
Posts: 103
Thumbs down Amateurs!

That's what this guy was - an amatuer! Someone said it right - you get a contract to evaluate a system FIRST then you hack it! This bozo deserves everything he gets! To many freaking wannabes calling themsleves "security specialists" without knowing the first thing about the ground rules.

Yes, the Clerk of the Court needs to share this guys fate for allowing an unsecured system to be installed. But we all know that's not going to happen.

One other thing - let's don't kid ourselves about wardriving being a good "cause". If all you do is collect APs then you've got a hobby. If it goes any further then it's hacking - something this court is probably going to make case law about.

That FOX news story the other night ended up with the talking head spouting something about "this is a gray area until the courts get involved". Well I think the "courts" are about to "get involved" and legistlators will soon follow it up with black letter law.

If you want to call informing and educating others about the insecurities of 802.xx a "cause" - I'll buy that - but wardriving? Wardriving has been fun, and educational but a "cause"? .... I don't think so.

"We have for a long time being breaking little laws, and the big laws are beginning to catch up with us." ~ A.F. Coventry 1888-1973 Canadian Naturalist
__________________
Marius -- You ' Da Man
stumble_butt is offline   Reply With Quote
Old 07-27-2002   #12 (permalink)
TheSovereign
Master of the universe
 
TheSovereign's Avatar
 
Join Date: Jun 2002
Location: chicago
Posts: 658
man they got ripped off 5,000 bux to delete porn
well no good deed goes unpunished i hope this is a lesson to u all
if your gonna scan use a mac address spoofer!
__________________
SO SAYS TheSovereign
TheSovereign is offline   Reply With Quote
Old 07-27-2002   #13 (permalink)
Sh00t3r
Registered Member
 
Sh00t3r's Avatar
 
Join Date: Apr 2002
Location: Michigan
Posts: 199
Quote:
Originally posted by carbolic
Back story from March 2002:
http://www.chron.com/cs/CDA/story.hts/topstory/1302663
Ok after reading this article, I have to say this Charles Bacarisse guy is quite a tool bag. But the case should still go to court to determine what hacking, compromising of the network, porn placement, etc. was actually done. This could be a landmark case for wardrivers if they focus on the wireless factor. So much for that "gray area". Think if in a year it was ILLEGAL to war drive. jeeesh!
Sh00t3r is offline   Reply With Quote
Old 07-27-2002   #14 (permalink)
g0tr00t
Welcome to my nightmare
 
g0tr00t's Avatar
 
Join Date: May 2002
Location: r00ting y0ur b0x.
Posts: 352
So what if....

What if you wanted to let someone know. What if you just mentioned to one of your co workers and said, hey someone needs to know this. Then the next day your co-workers squeals and you are led out in cuffs.

What no contract between you and a coworker. People talk, this guy got a raw deal in my book.

It's his fault for not having a contract in his back pocket? The news article doesn't tell the whole story and never will. I say to hell with this wireless a--holes. If they went up with no WEP or MAC filtering that is their fault.

Yeah he should have gotten a signed contract. But what if he wanted to get a contract. Then his boss, says well how do you know this? Hmm, umm well let me show you my NS logs. BAM - busted.

This story sounds incomplete to me. My support goes for Stefan Puffer. He just wanted to let someone, anyone know that they were wide open.

I am in his boat. Becasue I don't have my CISSP, nor do I have a track record of penetration testing, nor do I have certs in being a Net Admin, I know what am doing. But there is no one to tell of the open AP's at my work. If I do I may be another Stefan Puffer. So now thousands of peoples info is flying through the air, why, because there is no one that I can get to "sign a contract" so I can show them how wide open they are.

So on they will go exposing thousands US citizens information clearly through the air. Just becuase I can't hang a shingle over my head that says, "Security Analyst". Life ain't fair sometimes....
__________________
g0tr00t

"Its all fun and games until someone gets killed."
g0tr00t is offline   Reply With Quote
Old 07-28-2002   #15 (permalink)
fordem
Tropical Stumbler
 
Join Date: Apr 2002
Posts: 575
And that $5000 cleanup - is not for cleaning up. That's probably the security analyst's fee - you know - the guy they called in to secure what should have been secured in the first place.
fordem is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 07:33 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.