GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   HERE IT IS! How The Hacker did it!! Exclusive (https://gfy.com/showthread.php?t=434412)

josian 02-20-2005 07:38 PM

HERE IT IS! How The Hacker did it!! Exclusive
 
Secret Service hacker, how did he do it?
Nick Jacobsen pleaded guilty today to hacking into T-Mobile, specifically for violating 18 U.S.C. § 1030(a)(2)(C), accessing a computer without authorization. It looks like Nick was part of the carding community that has been recently attracting a lot of attention from the US Secret Service (little known, but the Secret Service have jurisdiction over counterfeiting crimes). Carders have gotten bold in the last couple of years, opening online exchanges (muzzfuzz.com, shadowcrew.org) for trading stolen credit cards, selling data used for identity theft, etc. When I first heard of this incident a few months ago, I was very interested on how he actually did it. There was very little information on how the attack was performed, and I decided to a little bit of research to see what I could find.

A summarization of affidavit, is that Nick was already under investigation by the Secret Service, hacked into T-Mobile, where was able to access accounts including those of agents in the Secret Service that were investigating him for other activities. He found that they had been monitoring his conversations over ICQ, (Nick's ICQ # was 23292256). Nick also discovered a number of Secret Service documents that an Agent, Peter Cavicchia, had left in his inbox unencrypted. Nick posted on muzzfuzz that he was selling T-Mobile account information, offering:

reverse lookup of information for a tmobile cell phone, by phone number at the very least, you get name, ssn, and DOB at the upper end of the information returned, you get web username/password, voicemail password, secret question/answer, sim#, IMEI#, and more.

Also of interest, he went on to access Paris Hilton's account and capture some of the pictures she had been taking with her camera. Now, here is where it gets interesting. How did Nick get into T-Mobile? Did he use an IIS exploit? Did he hack the web interface for T-Mobile accounts?

The affidavit from Nick's case states that he was observed logging into a specific server, http://login.sidekick.dngr.com, with Agent Peter Cavicchi's account information. While this site itself is hosted by Danger, Inc., the makers of the Sidekick device used by Agent Cavicchi, it appears that the same username/passwords that are used on the primary T-Mobile login page, https://my.t-mobile.com/Login, can also be used to log into this page. We also get some very valuable information from the affidavit, that will help us narrow down how Nick hacked these accounts (the CI is a Confidential Information, who was working with the Secret Service to bring Nick in, ethics is the semi-ironic pseudonym Nick chose for himself):

On or about October 19, 2004, Ethics sent a private message to the CI which contained a link that provides unauthorized access to the T-Mobile database. This link allows a user to input a phone number ultimately allowing access to the user?s personal information.

This information leads me to believe it was likely a web application attack, not a "traditional" buffer overflow attack against a server storing account information. Although it is possible to peform a buffer overflow against a program by passing input through a web app, we can also read Nick's resume on SecurityFocus, and see that he doesn't seem to have enough experience in that area. Unless he picked up a copy of The Shellcoder's Handbook last year. ;)

To further corraborate that Nick used a web application hack, most likely SQL Injection (a little research shows that the T-Mobile site uses IIS/ASP/SQL Server, which happens to be the easiest and most well documented platform for SQL Injection attacks), we can check out the website and try to put some invalid input into the T-Mobile login page. I was very surprised with the results, we can still put all sorts of crazy input into the login page! It is still vulnerable, even after one of the largest, most well known, and high profile hacks in the last couple of years! Let's try some (notice the error text on the resulting T-Mobile webpage):

xlogger 02-20-2005 07:40 PM

That "nick" dude have some balls.

pornstar2pac 02-20-2005 07:40 PM

that's old news

toddler 02-20-2005 07:40 PM

NOT exclusive, known about for weeks.

BRISK 02-20-2005 07:40 PM

Exclusive?

brand0n 02-20-2005 07:41 PM

stc is the greatest

OzMan 02-20-2005 07:41 PM

Quote:

Originally Posted by toddler
NOT exclusive, known about for weeks.

very old news

xlogger 02-20-2005 07:42 PM

Quote:

Originally Posted by brand0n
STD is the greatest

:uhoh :uhoh :uhoh

pxxx 02-20-2005 07:51 PM

Guy got some skills though.

digifan 02-20-2005 07:55 PM

Quote:
Originally Posted by brand0n
STD is the greatest

Quote:

Originally Posted by xlogger
:uhoh :uhoh :uhoh

:1orglaugh :1orglaugh :1orglaugh

yaz 02-20-2005 07:55 PM

loves it

Chris 02-20-2005 07:56 PM

that is the OLD one from along time ago
not what just happend

XPays 02-20-2005 07:58 PM

tmobile et al need to get better security


Signup To Promote HotelHeiress.com Right Now Exclusively at http://XPays.com UNLIMITED EARNING POTENTIAL

rollinOn20s 02-20-2005 08:00 PM

Quote:

Originally Posted by xlogger
That "nick" dude have some balls.

Unlike a lot of peeps on this board!

xlogger 02-20-2005 08:00 PM

Quote:

Originally Posted by rollinOn20s
Unlike a lot of peeps on this board!

I have huge balls. Thank you. :thumbsup

reynold 02-20-2005 08:01 PM

That's one cool hacker. :1orglaugh

quantum-x 02-20-2005 08:02 PM

old news, it was on slashdot 4 days ago now ;)

ytcracker 02-20-2005 08:20 PM

shut the fuck up

tungsten 02-20-2005 08:23 PM

welcome to 2 weeks ago

sickkittens 02-20-2005 08:27 PM

He'll have a job w/ the CIA/FBI I'm sure.

maddox 02-20-2005 08:38 PM

pretty old

foxxx 02-20-2005 09:07 PM

rofl @ exclusive

yellowmenace 02-20-2005 09:10 PM

that's fucking awesome!!

MGPspots 02-20-2005 09:14 PM

Tmobile are gonna go to town on this guy after the Feds are done with him

spideriux 02-21-2005 08:34 AM

I hear ti about 2 weeks ago, old :/


All times are GMT -7. The time now is 01:12 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123