How did he do it?
Author
Discussion

andygo

Original Poster:

7,288 posts

278 months

Friday 31st July 2009
quotequote all
How did the guy hack into the pentagon computers/ Think its quite funny in a way. Reckon he's been watching too much 'Mission Impossible'.

bigandclever

14,215 posts

261 months

Friday 31st July 2009
quotequote all
andygo said:
How did the guy hack into the pentagon computers/ Think its quite funny in a way. Reckon he's been watching too much 'Mission Impossible'.
Spencer Kelly at Auntie: How did you go about trying to find the stuff you were looking for in Nasa, in the Department of Defense?

Gary McKinnon: Unlike the press would have you believe, it wasn't very clever. I searched for blank passwords, I wrote a tiny Perl script that tied together other people's programs that search for blank passwords, so you could scan 65,000 machines in just over eight minutes.

SK: So you're saying that you found computers which had a high-ranking status, administrator status, which hadn't had their passwords set - they were still set to default?

GM: Yes, precisely.

Piece of proverbial smile

Halb

53,012 posts

206 months

Friday 31st July 2009
quotequote all
All he did was look for pc's that had not had their default password changed.biggrin

andygo

Original Poster:

7,288 posts

278 months

Friday 31st July 2009
quotequote all
But how did he access the pc's through the web?
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!

I know if I leave my car unlocked or no immobiliser armed, and it gets stolen, the insurance company will not pay out for my loss.



Edited by andygo on Friday 31st July 15:38

bigandclever

14,215 posts

261 months

Friday 31st July 2009
quotequote all
As I understand it, he set the software to look for machines where the password hadn't been set and then used an application on his machine called RemotelyAnywhere to log in and have a nosey around the unprotected machines.

wakster

265 posts

201 months

Friday 31st July 2009
quotequote all
go to my PC isn't so safeeek?

cs02rm0

13,816 posts

214 months

Friday 31st July 2009
quotequote all
andygo said:
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!
Correct, but they called him a 'hacker' and so a bunch of ignorant cowards are extraditing him for it. Seems crazy to me.

Murray993

1,515 posts

256 months

Friday 31st July 2009
quotequote all
cs02rm0 said:
andygo said:
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!
Correct, but they called him a 'hacker' and so a bunch of ignorant cowards are extraditing him for it. Seems crazy to me.
not really I suspect he was also getting through their firewall system then using these "passwords he found lying around". I do feel sorry for him though, seems wrong that you can walk away scott free after busting the economy but you hack a few computers and do nothing and you get the full weight of the law.

branflakes

2,039 posts

261 months

Friday 31st July 2009
quotequote all
andygo said:
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!
I remember a time (pre-WWW) when anyone could send email directly from the whitehouse.gov servers with a simple telnet command without even needing a password.

Murray993

1,515 posts

256 months

Friday 31st July 2009
quotequote all
branflakes said:
andygo said:
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!
I remember a time (pre-WWW) when anyone could send email directly from the whitehouse.gov servers with a simple telnet command without even needing a password.
When no one had email.

Marf

22,907 posts

264 months

Friday 31st July 2009
quotequote all
bigandclever said:
As I understand it, he set the software to look for machines where the password hadn't been set and then used an application on his machine called RemotelyAnywhere to log in and have a nosey around the unprotected machines.
Correct.

To call him a hacker grossly overstates his abilities.

Podie

46,647 posts

298 months

Friday 31st July 2009
quotequote all
Pentagon computer said:
Login:
Password:
So, that'll be admin and password then... hehe

grumbledoak

32,374 posts

256 months

Friday 31st July 2009
quotequote all
andygo said:
If he could access the pc's because there was no security, then the Pentagon almost only have themselves to blame!
yes That is why he has been trumped up as a big, nasty hacker. The truth, that the Pentagon staff were utterly fking useless, is a little unpalateable.

And, as to 'how' - telnet will do just fine.

Marf

22,907 posts

264 months

Friday 31st July 2009
quotequote all
grumbledoak said:
yes That is why he has been trumped up as a big, nasty hacker. The truth, that the Pentagon staff were utterly fking useless, is a little unpalateable.
Thats about the size of it. Plus the security services in the US were looking for a reason to justify to Congress a massive hike in their cyber security. McKinnon was a welcome patsy IMO.

mattviatura

2,996 posts

223 months

Friday 31st July 2009
quotequote all
And our government is absolutely marvellous at protecting our sensitive data.

For God's sake, he broke into a foreign power's military computer. WHAT DID HE EXPECT?

Marf

22,907 posts

264 months

Friday 31st July 2009
quotequote all
mattviatura said:
For God's sake, he broke into a foreign power's military computer. WHAT DID HE EXPECT?
Hardly breaking in if the door is left open.

He also left notes in the systems telling them to secure their computers.

Hardly the actions of a malicious black hat hacker. wink

s3fella

10,524 posts

210 months

Sunday 2nd August 2009
quotequote all
Marf said:
mattviatura said:
For God's sake, he broke into a foreign power's military computer. WHAT DID HE EXPECT?
Hardly breaking in if the door is left open.

He also left notes in the systems telling them to secure their computers.

Hardly the actions of a malicious black hat hacker. wink
He sounds like he was being a smartarse and it ried them somewhat! !

DIW35

4,195 posts

223 months

Sunday 2nd August 2009
quotequote all
Basically he has made the CIA/Pentagon/whoever look liek a bunch of amateur muppets, and the only way they can save face is to extradite him to the USofA and lock him away for 60 years.

If I was the Pentagon, once I'd found out what he had done, I'd have been on the phone to offer him a job in the security department.

Mexico.

1,254 posts

210 months

Sunday 2nd August 2009
quotequote all
DIW35 said:
Basically he has made the CIA/Pentagon/whoever look liek a bunch of amateur muppets, and the only way they can save face is to extradite him to the USofA and lock him away for 60 years.

If I was the Pentagon, once I'd found out what he had done, I'd have been on the phone to offer him a job in the security department.
The USA Have cocked up simple as that and are so embarrassed they will prosecute a halfwit so called autism UFO looking chap for it smile

Olf

11,977 posts

241 months

Sunday 2nd August 2009
quotequote all
I've seen enough films to know they'll pretend he's a criminal but ACTUALLY give him a remote house next to a lake where he can hone his skills and someday save the USofA from a mortal threat.