Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Lamo denies $300,000 database hack
Kevin Poulsen, SecurityFocus 2003-09-10

Days before going public with his penetration of the New York Times internal network last year, hacker Adrian Lamo created five new user accounts with the LexisNexis database service under the Times corporate account, which he used to rack up $300,000 in charges over the following three months, a federal complaint in New York charges.

Comments Mode:
Lamo 2003-09-11
Anonymous (1 replies)
Easy target 2003-09-11
Anonymous
Lamo the polishing rag. 2003-09-11
Got Worm?
Lamo denies $300,000 ego-surfing spree 2003-09-11
Anonymous (1 replies)
Lamo denies $300,000 database spree 2003-09-11
Anonymous (1 replies)
Is Maurice Clarett 2003-09-11
Anonymous
Of course he should be tried 2003-09-11
drg (3 replies)
Of course he should be tried 2003-09-11
The 420 Zodiac (1 replies)
Of course he should be tried 2003-09-12
Wckd (1 replies)
Of course he should be tried 2003-09-12
Anonymous (2 replies)
Of course he should be tried 2003-09-14
Anonymous
Of course he should be tried 2003-09-18
Anonymous
Of course he should be tried 2003-09-15
Anonymous (1 replies)
Of course he should be tried 2003-09-21
Anonymous
Lamo denies $300,000 database hack 2003-09-11
Anonymous (1 replies)
Lamo denies $300,000 database hack 2003-09-11
Mike (2 replies)
The difference between my network and yours..... 2003-09-11
Anonymous Hacker Supporter (3 replies)
My network does not get hacked becuase I am conscious about security. I take steps to ensure my network is as secure as I can make it.

Your network get's hacked because you do not do these things. Your Network gets hacked because you run insecure services/applications exposed to the net.

Don't run these insecure apps/services and you'll reduce your threat of a hack.

Secure your network and you'll reduce your threat of a hack.

Hackers provide a way to DISTINGUISH and MAKE AN EXAMPLE of LAZY IT Admins and PROGRAMMERS.

It is a common fact that HACKERS exist. With this knowledge, these lazy IT people / Programmers, need to expect that what they have put into place is constantly being challenged. With that, they too should challenge their own networks/programs and search and scour for possible exploits.

Lamo was simply do his "job". That being to actively scour and search for exploits. Had someone over at NYTimes been doing their job, they would have found the problem first and repaired it.

Maybe he shouldn't have damaged the system or used resources which didn't belong to him, however these things shouldn't have been available to him in the first place.

If you want to compare the whole "Weak Lock on House Door" Theory that's simple to do. We don't keep weak locks because we KNOW that there are people out there who may want to break in and steal our possessions. We read about it everyday. ANd with the same diligence we use to make sure our families and homes are safe, we need to make sure our Networks and Apps are safe as well. Because as you know and read about EVERYDAY, there are people out there who want in. They are actively trying as we speak....just check your Firewall Logs, Web App Logs.. etc...

Lock it down and you wont have any problems.

Good Luck to LAMO! Hope he comes through with a BOOK deal, a Security SPecialist Job and a Television Interview.

IT Admins, Program Developers - Stop blaming others and get to work, Lock It Down!

- OUT -

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/6934/22217#22217
breaking into someone's house analogy doesn't work !!! 2003-09-11
Anonymous (2 replies)
breaking into someone's house analogy doesn't work !!! 2003-09-12
An idiot like the one that posted before me.
Moral question. 2003-09-12
Anonymous (2 replies)
Moral question. 2003-09-12
Anonymous (4 replies)
Moral question. 2003-09-12
Anonymous
Moral question. 2003-09-12
Anonymous
Moral question. 2003-09-12
Anonymous
Moral question. 2003-09-15
MartinX
Moral question. 2003-09-14
Anonymous (1 replies)
Moral question. 2003-09-17
Gregory T. Buckhead
Of course he should be tried 2003-09-12
BigTymer-
Adrian & me 2003-09-12
kepi blanc (1 replies)
Adrian & me 2003-09-17
lowtec
hacks and hacks 2003-09-14
Anonymous (1 replies)
hacks and hacks 2003-09-17
A nony mouse
He does not deserve a punishment 2003-09-15
HaCkGhosT
Lamo = Your Fiendly Neighborhood SPIDERMAN 2003-09-17
A nony mouse (1 replies)
Pssh. 2003-09-18
Phreak







 

Privacy Statement
Copyright 2009, SecurityFocus