Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
A Visit from the FBI
Scott Granneman, 2004-01-21

Comments Mode:
A Visit from the FBI 2004-01-22
Lee (7 replies)
Every technique you posted about is exact carbon copy, tool for tool, and scenario for scenario from the introduction course of the SANS hacking project.

I know as I taught this course to people yesterday. Are the FBI using SANS material?

Regards...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-23
Anonymous
yes. the government is sans largest customer.
You know send em to a sans class, wow them with some code, tell some stories and their an insto presto expert. then they go on to teach :)

...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-23
Eduardo
Great read, really makes one understand how things are working nowadays and get an idea of how things will keep on working in the future.

Regards,

Ed...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-23
Anonymous
"are the FBI using SAN's material?"

Isnt everyone?...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-25
Anonymous (2 replies)
You said "Every technique you posted about is exact carbon copy, tool for tool, and scenario for scenario from the introduction course of the SANS hacking project." Are you implying the FBI would stoop so low as to steal techniques from abroad? You sound like a terrorist, perhaps al Qaeda? Perceptio...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Anonymous
thats a terribly naive post....

[ more ]  [ reply ]
A Visit from the FBI 2004-02-01
Anonymous
I agree, about al queda, everyone seems to be giving these punk asses a bunch of credit for being hacker ex tro di n air. The fact of the matter is, they are going to move from airplanes to Ryder trucks, ala mckvey. In the future, I see an IDS tech looking at logs as a Ryder Truck pulls up to his ...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
Anonymous
hmmm how is it you can claim ownership of information like this.. you totally missed the point of the entire article.

stupid people using computers are the problem, so educate them. ...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
Dan
SANS teaches people how to in class. If he taught something that looked like SANS courseware, it's probably made the lecture circuit by way of HOPE or one of the countless other hacker conventions years before it was ever mentioned at SANS. SANS is Infosec for middle management.

...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-30
Anonymous

Every technique and idea taught by SANS is lifted from somewhere else. Watermarks in your slides prove it.
What is your point? This GS or SES level guy doesn't have time to play with powerpoint. He understands the material and chooses to augment his speech with a few canned demos.
Big whoop....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-22
Anonymous (2 replies)
Minsk in not in Russia......

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
Anonymous
Minsh IS in Eastern Europe....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-30
Anonymous
No it is not but given that your average American could not find Belarus on a map or even care that existed I say Russia as well. Why, because it saves on giving the ignorant a geography lesson...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-22
Kathy
Ok, I'm not clear on the visit part of things... was that referring to the class visit?

In any case, this article is great for laughs, but it's scary as hell too. And people think Can Spam will do any good? Uh Huh.

http://www.gurugazette.com...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-22
Anonymous (5 replies)
Your story made me feel all warm and cozy. I'm proud that the FBI has such skilled and accomplished agents that they can "playback" a scripted show about computer seekurity. I lost all respect for the guy when he wouldn't hook his laptop up the Internet because it was too dangerous and/or against ...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-27
Eta(s)
I guess you completely missed the point: He is a good teacher and a mentor, as abiding regulations is not being "sissy" about being predated, it's really childish to think that.

If you're a computer security expert, you know well enough that you protect against the CHANCE of getting attacked, jus...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-28
Anonymous (1 replies)
Unplugging the network cable is the ultimate in security. ;)

I would certainly hope that the FBI is telling its agents not to connect their laptops to the Internet except when it's strictly necessary. *Especially* if they're running Windows. Too many 0-day exploits.
...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-30
Anonymous (1 replies)
it was probably a wireless enabled system connected to some kids at the neighboring starbucks :-)...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-30
Anonymous
McDonalds, not Starbucks...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-29
Matt
I would suspect that the regulation is not taht connecting to the internet is forbidden or even discouraged - but rather something more along the lines of when visiting a facility with an in house network do not connect to their network unless you can first verify what type of security from virus an...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-29
Anonymous (2 replies)
Are you stupid? Most government comps with sensitive info are banned from hooking up to the net...for obvious reasosn. ...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-30
Anonymous
If it has sensitive info it shouldn't be on a college campus, it should be in a locked room. The reg is probably that you don't hook up a computer to the net unless you need to. Agent Dave didn't need to hook it up, so he didn't.

But why are the FBIs using Windows when they could run Linux on t...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-30
Anonymous
This is the exact same reason many hospitals now do not have their critical networks connected to the internet. Even connecting to AOL or dialup while on the networks is a big no-no...

[ more ]  [ reply ]
A Visit from the FBI, blah, blah, blah 2004-01-30
Anonymous
The only 100% surefire way to prevent babies is not to have sex. In the same way, the only 100% surefire way to prevent all kinds of hacking is not to hook up to any network anywhere ever.

Hope your condom doesn't break....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-23
nevada smith (1 replies)
yes i heard one of these guys speak at uva.
pretty standard stuff. all pretty common knowledge to computer geeks. It would be good if some of this were to reach the average joe though. 60 miniutes or 48hrs would be a good choice.
These fbi guys toot thier own horn quite a bit though, the ego comes...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
Anonymous
Hey Nevada,

Are you upset because they wouldn't hire you?

Keep in mind what their job really is - to investigate and report. They're not reseachers!

Lighten up big fella....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-24
Andrew Taylor
Interesting article - very informative I am from Canada so having a Mac wouldn't help - but I don't do anything illegal or unethical so it wouldn't hurt either...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-24
Anonymous
verry interesting!...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
Anonymous (1 replies)
You did verify that Dave's credentials were real, right?

Also, there is SO much more to cover (from employee background checks, to suspicious network activity, to recommending home users buy and install routers with firewall protection...).

You know what I recommend? A Parent-Teacher-FBI Weeke...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-29
Anonymous
> You know what I recommend? A Parent-Teacher-FBI Weekend...

What I would recommend: A Parent-Teacher-FBI/CIA weekend with smart and honest person. Hard to find this one.

BTW, better run background check on your financial advisor. You'll be amazed... Forget about that sysadmin - he's too busy ...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
Anonymous (1 replies)
Cybercrime is not "a grotesque parody of capitalist supply and demand;" there's no parody about it. This is free market capitalism at its purest -- i.e. unhampered by "regulation" that capitalists always complain puts a damper on business....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
Anonymous
True. All laws that I can think of regulate economic behaviour....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-26
sol289 (2 replies)
"russian mafia"... ho-ho-ho... very funny, but it's old story already. does anyone still believing in "evil russian haxors"?

and yes, minsk is not in russia... that FBI guy (is he exist? or you have nothing to write about?) is surely not an FBI. i think that FBI folks knows geography. ...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-31
Anonymous
If you are likening the Russian Mafia to Santa Claus- maybe you had better stop for lunch one day in any Russian cafe in Denver. :o) They are alive and well my friend...

[ more ]  [ reply ]
A Visit from the FBI 2004-02-01
Anonymous
¨ i think that FBI folks knows geography. ¨

No, that would be the CIA folks.
...

[ more ]  [ reply ]
Wonder how clever the KGB is 2004-01-27
Anonymous (1 replies)
If E. European crooks are so clever, wonder how clever the KGB is!...

[ more ]  [ reply ]
Wonder how clever the KGB is, they are!!! 2004-01-28
Anonymous (1 replies)
Eastern European crooks are clever, you know why, many of them are former engineers and military workers who lost their jobs during the fall of communism. Now they are looking to exploit and find new ways of making money....

[ more ]  [ reply ]
Wonder how clever the KGB is, they are!!! 2004-01-30
Anonymous
Or could it be that E. Europeans invest a bit more geld in their education system raising the bar, where more than 1/2 of the unemployed have a college/uni degree under their belt?

My guess: some really clever ppl, with lot's of time 2 kill!...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
Angelbracket
Every security pro is able to draw such an outline right out of his head without attending any course.

mvg,
...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
rawlogic (1 replies)
Remarkably, the only Dave Thomas that I'm aware of died. Are you sure that he was really an FBI agent, and not an imposter just trying to blow smoke and gain access to your facilities?...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-29
Anonymous
High probability......

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
Anonymous (2 replies)
The only thing I want to ask about is. Why can't they extract Mac data? Especially on OS X, since it is a *nix based OS!...

[ more ]  [ reply ]
Macs 2004-01-28
Anonymous (4 replies)
My guess is they just haven't put money into the tools and training for it, since Macintosh is such a minority architecture in the U.S. The article mentioned that they get the RCMP to do Mac forensics for them. If only, say, 5% of your cases involve a Macintosh, it probably makes sense to outsourc...

[ more ]  [ reply ]
Macs 2004-01-29
HET2
OSX is *nix indeed
but it also uses HFS
ever tried using HFS outside a mac?
if you haven't, try it :)
it's an enlightening experience...

[ more ]  [ reply ]
Macs are secure. Today. Not 2006. 2004-01-30
Anonymous
Not 2006, or whenever Microsoft decides Longhorn is ready. Even then, it probably won't be....

[ more ]  [ reply ]
Macs 2004-01-30
Anonymous
Any1 know why the canuck's can crunch mac's so well? Is everybody in CAD using mac's?...

[ more ]  [ reply ]
Macs 2004-01-30
klpnyc
File Vaul, available on Panther (X.3) tautomatically encrypts and decrypts the contents of your home directory on the fly with powerful AES-128 encryption...

[ more ]  [ reply ]
why they can't extract form a mac 2004-01-29
Anonymous (6 replies)
well..for one thing macs don't keep a backup of every e-mail you've ever recieved in the registry.

macs are actually secure...so they have to get through passwords and permissions.

third..with the latest revision of OS X you can encrypt your entire home directory with 128 bit encryption. this ...

[ more ]  [ reply ]
why they can't extract form a mac 2004-01-30
Anonymous
Fundimental Fact:

Macs are built on *nix, an operating system designed to be used on a network.

Windows wasn't....

[ more ]  [ reply ]
why they can't extract form a mac 2004-01-30
Anonymous (1 replies)
only plug a firewire cable to another mac and you'll see your target powerbook......

[ more ]  [ reply ]
why they can't extract form a mac 2004-01-30
Anonymous
All that has to be done is to set one password and the drive cannot be accessed. This can be done in open firmware...

[ more ]  [ reply ]
Right-Mouse-Click 2004-01-30
Anonymous (2 replies)
Hey, this machine doesn't right-mouse-click! How do I get to the "Properties" window? Oh, well... send it to the Mounties....

[ more ]  [ reply ]
Right-Mouse-Click 2004-01-30
MACLVR (1 replies)
Hold down CNTRL and click the mouse button. That is the same as a right mouse click. You can also buy a two button mouse. They have Mac-compatible two-button mice....

[ more ]  [ reply ]
Right-Mouse-Click 2004-01-31
Anonymous
I think he was kidding MAC. Don't be so sensitive....

[ more ]  [ reply ]
Right-Mouse-Click 2004-01-31
Anonymous
My Macs have 2-button scroll wheel mice, even trackballs. You don;t need the properties windows anyway to get at the files. The use of Outlook combined with open ports and scripting is an awful combination. The Mac is more secure for a variety of reasons, but the most basic reasons could be duplicat...

[ more ]  [ reply ]
why they can't extract form a mac 2004-01-31
Anonymous
>all..for one thing macs don't keep a backup of every e-mail you've ever recieved in the registry.

And don't forget to wear your aluminium hats so that Microsoft can't spy on your thoughts.

>macs are actually secure...so they have to get through passwords and permissions.

Windows NT/2000/...

[ more ]  [ reply ]
why they can't extract form a mac 2004-02-02
Anonymous
>well..for one thing macs don't keep a backup of every e-mail you've ever recieved in the registry.

Neither does Windoze


>macs are actually secure...so they have to get through passwords and permissions.

So is XP, if you know what you're doing.

>third..with the latest revision of OS ...

[ more ]  [ reply ]
why they can't extract form a mac 2004-02-02
Anonymous
And the number one reason:

No floppy drive!!!!!

LOL...

[ more ]  [ reply ]
Access the FBI through InfraGard 2004-01-27
Jeff
Probably the best way to connect with the FBI on these issues is through the InfraGard organization (http://www.infragard.net):

"InfraGard is a Partnership between Private Industry and the U.S. government (represented by the FBI). The InfraGard initiative was developed to encourage the exchange o...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-27
Anonymous (1 replies)
Truth or Fiction? The hackers do exist and so does the FBI. People are stupid and don't usually care about computer security. It is just something that is 'suposed' to happen by 'magic.' Knowledge is power, but true knowledge also includes wisdom. The real trouble is simply this - most folks ar...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Anonymous
ok thanks for help...

[ more ]  [ reply ]
no way 2004-01-27
Anonymous
"One way to trace just how bad the situation has gotten: track the price for a million credit card numbers. Just a few years ago, Dave saw prices of $100 or more for a million stolen credit card numbers. Now? Pennies. "

So it turns out you can get a million credit card numbers for less than you c...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Ms Mo (4 replies)
Ok, I am sure I will just be asking for trouble by asking for comments and or help from here...

Please tell me where I can find reliable information on how to protect my system. I am a home user, Real Estate agent and full time law student. I was recently "hacked" into and it was a night mare. I ...

[ more ]  [ reply ]
A Visit from the FBI - personal protection 2004-01-28
Jim Lang
Assuming you won't stay off the internet completely:

Simply, I recommend the following:

* Norton Internet Security (You're on the right track). Set it to "paranoid", and block outside traffic. Blockups, too.
* Mozilla - get rid of Internet Explorer. While it may or may not be "better", it...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-29
Zozzlhandler (1 replies)
You should use a hardware gateway product with
stateful packet inspection (firewall) capabilities. These are available for under $100, and protect you much better than software firewalls. Brand names that come to mind are Linksys, Dlink, and Netgear, but there are others. A software firewall that r...

[ more ]  [ reply ]
A Visit from the FBI 2004-02-02
Anonymous
Buy a Cisco PIX 501....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-31
Nick
Here's a helpful site on the net, that is dedicated to security.
http://grc.com/
If you are willing to spend some time reading on this site, there's a lot to learn. One of the useful services on their site is a page where you can test your firewall. You find it here: https://grc.com/x/ne.dll?bh0bk...

[ more ]  [ reply ]
security steps for your home PC 2004-02-01
www.i-t-w.com
Look for a local computer users group at www.apcug.com. There are often pros who participate in these groups (I'm secretary of mine) who would be happy to point you in the right direction. That said: Windows update (auto update helps), Firewall (Norton 2004 is fine), Antivirus software (again, you ...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Jay Edgar Hoover (1 replies)
This paragraph scared the hell out of me...

[...]

many of the computer security folks back at FBI HQ use Macs running OS X, since those machines can do just about anything: run software for Mac, Unix, or Windows, using either a GUI or the command line. And they're secure out of the box.

[....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-29
Anonymous
Are you saying that they're insecure out of the box? They come with pretty much nothing running. So they're pretty secure, in addition to 'being able to run everything'....

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Scotty
The real issue for me, is that "average joe" isn't going to get access to this article unless it's reprinted in the non-tech press.
Even associates of mine in the police forces have no mechanism to distribute useful and insightful articles such as this to their users.

As a sysadmin, I know exact...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
Hans Gruber
All I can say is this (taken from the movie 'Die Hard')...

indiv-1: Sir, I........
indiv-2: Yea
indiv-1: Sir. The FBI is here.
indiv-2: The FBI is here? NOW???!!!???
indiv-1: Yes sir, right over there.
indiv-2: Here. Hold this.
indiv-1: Want a breath mint?

Sorry -- all too funny. To whi...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-28
HB
this is very interesting. I have a teacher that isletting me make a unit for my class and i would like to do security awareness.. if ther is any way anyone reading would like to help feel free to e-mail me at rageing_night@hotmail.com...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-30
Anonymous
Well one way thats easy. Start with MacOSX, don't turn on any filesharing servises or anything with the net exept just surfing use the firewall. Use Safari instead for Internet Explorer. Then your pretty secure. Use your brain when e-mailing...

[ more ]  [ reply ]
Firewire Target mode 2004-01-30
Anonymous (1 replies)
A firewire cable will get you access to everything except FileVault-encrypted home directories, where all the good stuff is kept. Then you're out of luck....

[ more ]  [ reply ]
Firewire Target mode 2004-01-30
Anonymous
But, as always, if you have physical access to the machine you've pretty much won the game.

Besides. Ever hear of "rubber hose cryptography"? The technique consists of "Tell us the passphrase or something bad will happen to you."

128-bit encryption keeps out the thief, the common hacker, the c...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-30
Mr. Glass
That article made me start thinking: if scripts are all over the net, why only east-europeans use them? I would spect blaming on iraquies, or north-koreans, the enemies of the month. Or is it just my twisted mind ho suspects on each statement about only a segment of our big planet is bad, like 'only...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-30
Anonymous
oh yes, there are too many prejudices in that article ... and the distribution of good and evil around the globe is 'normal' ;)

and did you choke on the conclusion ? so american ......

[ more ]  [ reply ]
Mac are ok, but... 2004-01-31
Blackdog (1 replies)
I recently tackled a mac/windows integration project. It is very optimistic to think that Mac's are "secure right out of the box". After installation, you need to download security updates for a long list of vulnerabilities.

Want root on Jaguar? all you need is an install CD and physical access....

[ more ]  [ reply ]
Mac are ok, but... 2004-02-03
Anonymous
"Want root on Jaguar? all you need is an install CD and physical access."

Don't be stupid. All you need is physical access. CMD-S during boot gets you into single-user mode with root privileges.

MacOS X is far from the only UNIX to provide an easy-to-enter single user mode. This because the...

[ more ]  [ reply ]
A Visit from the FBI 2004-01-31
fireweasel
Read most of the replies-some funny and some truly arrogant. Cut the agent some slack- he was dealing with computer illiterates,generally, and that represents the vast majority of users in U.S. I see the same problem with drivers jabbering on their phones while driving--they deny the laws of physics...

[ more ]  [ reply ]
Macs more expesive than IBM? 2004-02-02
Anonymous
Which planet does this FBI man live on? Mac laptops are cheaper than COMPARABLE WinTel Boxes and definately no more expensive than IBM. Maybe Apple should run an apple store for feds alongside the education one :-)...

[ more ]  [ reply ]
"Danger Will Robinson! Danger!" 2004-02-02
Anonymous
FBI speaker sounds like a the robot from lost in space. Only differance is the robot was smarter. If he was a real security expert he would connect to the internet because he would have made sure his system was locked down for most attacks. There was really no usefull info that has not been passed...

[ more ]  [ reply ]
A Visit from the Federal Bureau of Insecurity 2004-02-03
Krag
ANYONE using a PC today has to have all kinds of anti-virus, anti-spyware, anti-adware, utilities running to prevent their machine being taken over.. and still it may happen... don't ever put your SSN or credit card info on your PC...

A new ThinkPad and PowerBook are comparably priced.

* Windo...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus