GhostExodus, the ETA, and a Control-Systems Incident at Carrell Clinic (Part 2)
If you haven’t read Part 1 of this story, then you really ought to take a look at it first. It serves as a good overview, and the criminal complaint filed by the FBI is a good read.
Yesterday afternoon was GhostExodus’ detention hearing. I’m not very familiar with the process one goes through after being arrested for something like this, so I had to look up what this meant. I found the following site which, I believe, explains detention hearings well:
(Looks like a cool site beyond this, even. Kind of a legal equivalent to the blog I run here.)
I was informed yesterday afternoon that the Judge in this case found that there was probable cause to detain Jesse McGraw while the case is pending.
Here are some links to the coverage this is getting. I’m linking articles that I think my readers would enjoy, especially those where the reporters were thorough enough to contact me personally to get the stories:
- http://www.theregister.co.uk/2009/07/01/hospital_hacker_arrested/
- http://www.pcworld.com/businesscenter/article/167756/security_guard_charged_with_hacking_hospital_systems.html
- http://blogs.dallasobserver.com/unfairpark/2009/07/hacking_the_hacker_ghostexodus.php
The members of the press I’ve talked to on the phone and over IM have been very nice. There are many more stories than this, you can poke around on Google News if you like, but your best source of technical information for fellow security and control-systems folks is going to be right here, of course :)
Now, time to break out the popcorn. Here are two of the most interesting videos that were posted to GhostExodus’ youtube accounts. It’s my understanding that these videos were played in court yesterday. After each video, I’ve summarized some points of interest in each video:
- “Post July 4th” is a strange choice of title here, as it’s before July 4th, and in preparation for the attacks scheduled for the 4th
- He’s recording this by holding his laptop in front of him (reflections in elevator)
- Claims to have infiltrated corporate offices, but it’s obviously a medical facility
- Watch for medical charts and such on the walls when he sits down
- Appears to be the collar of a security guard uniform peeking out of the top of the hoodie
- The FBI identified this computer at the clinic by the toy flamingo on top of the monitor
- This was recorded at a desk at the hospital where McGraw was a security guard.
- I thought about buying one of those camera pens until I saw this. Not inconspicuous.
- Showing off your fake FBI credentials on youtube isn’t very smart.
I will continue this series with more posts, discussing the HVAC compromise, how I came to be aware of it, and the techniques I used to gather information on the suspect. Still pooped from talking to so many people about this, but I’m enjoying spreading the gospel of control-systems security ;)
This guy is great, I can’t wait to hear the lecture you do next semester about this guy.
What a tool. “Infiltrated”
Stay Classy, Jesse.
Wesley McGrew
I want to infiltrate your anus
stop sugar coating this your no big deal for busting some kid who played around with a ac unit like a kid with a light switch
He spends the whole “Response…” video hiding his face, then shows his fake FBI ID complete with his picture. What a dumbass.
Hi heysugarcoater,
Thanks for the comment, and sorry you’re not enjoying this series of posts. There will be more posts on the topic, so if you don’t like the ones so far, I wouldn’t hold out much hope for the rest of them.
Hope you have a good day!
Wesley
Anyone else find it dumb/ironic that he videoed himself putting on latex gloves to avoid leaving finger prints on the machine he was compromising in the first video, and then as Scott says, he shows his face on the false FBI credentials while hiding his face the rest of the video.
JonBoi:
Yeah. Also note that he puts on the latex gloves *AFTER* logging onto the computer.
[...] ‹ GhostExodus, the ETA, and a Control-Systems Incident at Carrell Clinic (Part 2) [...]
Thanks for posting this. Good stuff to help raise awareness.
[...] Part 2 – GhostExodus Videos [...]
[...] Part 2 [...]
“Yeah. Also note that he puts on the latex gloves *AFTER* logging onto the computer”
Soz u dont get teh skeet all in ya keys playa
HOLY CRAP OPHCRACK AND BACKTRACK
you got yourself one elite hacker dude there man if only i could fry fish that big
pretty cool you busted someone but it’s not like you busted some elite hacker this is some retard who read some 2600 articles and full disclosure and thought he was a hard ass.
Oh shit its Sampson, that crack dealing nieghborhood pimp nigger, look out!