<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>McGrew Security Blog &#187; skiddies</title>
	<atom:link href="http://www.mcgrewsecurity.com/category/skiddies/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcgrewsecurity.com</link>
	<description></description>
	<lastBuildDate>Tue, 27 Jul 2010 20:58:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>GhostExodus Pleads Guilty</title>
		<link>http://www.mcgrewsecurity.com/2010/05/14/ghostexodus-pleads-guilty/</link>
		<comments>http://www.mcgrewsecurity.com/2010/05/14/ghostexodus-pleads-guilty/#comments</comments>
		<pubDate>Sat, 15 May 2010 01:36:48 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=753</guid>
		<description><![CDATA[Today, the US Attorney&#8217;s Office announced that Jesse &#8220;GhostExodus&#8221; McGraw, has entered a guilty plea on two charges of transmitting a malicious code.  Jesse had compromised more than 14 computers at the Carrell Clinic in Dallas, Texas, where he worked as a night-shift security guard.  This included the system running the HMI (Human Machine Interface) [...]]]></description>
			<content:encoded><![CDATA[<p>Today, the US Attorney&#8217;s Office announced that Jesse &#8220;GhostExodus&#8221; McGraw, has entered a guilty plea on two charges of transmitting a malicious code.  Jesse had compromised more than 14 computers at the Carrell Clinic in Dallas, Texas, where he worked as a night-shift security guard.  This included the system running the HMI (Human Machine Interface) for the hospital&#8217;s HVAC system.  To the best of my knowledge this is the only arrest and conviction of a hacker involved in a control systems/SCADA incident in the United States.</p>
<p>This story began last year, when I became aware of the HVAC compromise, and gathered information about it to turn over to FBI.  Throughout the process, I have been very impressed with the technical skill and responsiveness of the FBI agents.  I am also very happy with this outcome.  This may serve to educate organizations with control systems about the threats and vulnerabilities that are possible, and put other &#8220;script-kiddie&#8221; type hackers on notice that they can be tracked down and prosecuted for their actions.</p>
<p>The press release for the guilty plea is not yet available on the DOJ website, but the following articles are available:</p>
<ul>
<li><a title="http://www.computerworld.com/s/article/9176811/Security_guard_pleads_guilty_to_hacking_his_employer" href="http://www.computerworld.com/s/article/9176811/Security_guard_pleads_guilty_to_hacking_his_employer" target="_blank">Security guard pleads guilty to hacking his employer </a>- Bob McMillian, IDG News Service</li>
<li><a title="http://blogs.dallasobserver.com/unfairpark/2010/05/hacker_known_as_ghostexodus_wh.php" href="http://blogs.dallasobserver.com/unfairpark/2010/05/hacker_known_as_ghostexodus_wh.php" target="_blank">Hacker Known as &#8220;GhostExodus,&#8221; Who Broke Into Carrell Clinic Computers, Pleads Guilty</a> &#8211; Robert Wilonsky, Dallas Observer (This article has the complete text of the DOJ press release)</li>
<li><a title="http://www.star-telegram.com/2010/05/14/2190429/arlington-man-pleads-guilty-to.html" href="http://www.star-telegram.com/2010/05/14/2190429/arlington-man-pleads-guilty-to.html" target="_blank">Arlington man pleads guilty to hacking medical clinic&#8217;s computers</a> &#8211; Nathaniel Jones, Star Telegram</li>
</ul>
<p>I have a large collection of PDFs of court filings for this case, which I may post with commentary at some point soon, now that he has entered a guilty plea.  The PDFs make for interesting reading and a wild ride, and I don&#8217;t know of any other resources that have good documentation of a hacker case.  I&#8217;m looking forward to going through them again.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2010/05/14/ghostexodus-pleads-guilty/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Skiddies hacking sites in my name</title>
		<link>http://www.mcgrewsecurity.com/2009/11/03/skiddies-hacking-sites-in-my-name/</link>
		<comments>http://www.mcgrewsecurity.com/2009/11/03/skiddies-hacking-sites-in-my-name/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 20:33:47 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=670</guid>
		<description><![CDATA[I noticed a realty website in my referrals today, so I checked it out to see why they&#8217;d be linking here.  Here&#8217;s what I found:


For those of you who are new here: This is obviously not how I roll.  Not only is it not something I would do (protip: don&#8217;t do pentesting for free), but [...]]]></description>
			<content:encoded><![CDATA[<p>I noticed a realty website in my referrals today, so I checked it out to see why they&#8217;d be linking here.  Here&#8217;s what I found:</p>
<p style="text-align: center;">
<p style="text-align: center;"><a href="http://mcgrewsecurity.com/img/nicetry.png"><img class="aligncenter" title="Nice try" src="http://mcgrewsecurity.com/img/nicetry.png" alt="http://mcgrewsecurity.com/img/nicetry.png" width="435" height="132" /></a></p>
<p>For those of you who are new here: This is <em>obviously</em> not how I roll.  Not only is it not something I would do (protip: don&#8217;t do pentesting for free), but the capitalization is awful.</p>
<p>Our good friend MR^E of the ETA dropped by this earlier in the day also, to leave troll comments and launch a pointless spider/scan against the site (again), so I figured I&#8217;d take a look and see what&#8217;s going on over at their new site, hackserver.org:</p>
<p><a href="http://mcgrewsecurity.com/img/mre1.png"><img class="aligncenter" title="http://mcgrewsecurity.com/img/mre1.png" src="http://mcgrewsecurity.com/img/mre1.png" alt="" width="443" height="370" /></a></p>
<p>Wow!  MR^E figured it out before I did!  When asked about it by another member, he responded:</p>
<p><a href="http://mcgrewsecurity.com/img/mre2.png"><img class="aligncenter" title="http://mcgrewsecurity.com/img/mre2.png" src="http://mcgrewsecurity.com/img/mre2.png" alt="" width="439" height="237" /></a></p>
<p>Stumbling across it before it even has a chance to get indexed by Google?</p>
<p>I&#8217;ll leave the conclusions as an exercise for the reader.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/11/03/skiddies-hacking-sites-in-my-name/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Slides for CSE4243 GhostExodus lecture</title>
		<link>http://www.mcgrewsecurity.com/2009/08/30/slides-for-cse4243-ghostexodus-lecture/</link>
		<comments>http://www.mcgrewsecurity.com/2009/08/30/slides-for-cse4243-ghostexodus-lecture/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 22:07:04 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=579</guid>
		<description><![CDATA[Tommorow morning, I will be giving a lecture to the CS4243/6243 Information and Computer Security class at Mississippi State University.  It will cover the events that led up to, and followed from, the arrest of Jesse &#8220;GhostExodus&#8221; McGraw on charges of installing malicious code onto hospital computer systems, including a system that was the HMI [...]]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Tommorow morning, I will be giving a lecture to the CS4243/6243 Information and Computer Security class at Mississippi State University.  It will cover the events that led up to, and followed from, the arrest of Jesse &#8220;GhostExodus&#8221; McGraw on charges of installing malicious code onto hospital computer systems, including a system that was the HMI (Human-Machine Interface) of the SCADA system controlling ventilation, air-conditioning, and various aspects of the surgery wing.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">The purpose of the talk is to cover some of the more interesting points of evidence that was gathered, documents surrounding the arrest and indictment, and some of the aftermath.  To give the students some practical skills to take away, I&#8217;ll be discussing some of the methodology used that would be applicable when responding other incidents.  It&#8217;s difficult to fit everything into a 50-minute lecture, but I believe I&#8217;m hitting the most interesting and entertaining points, and will be happy to go into more detail with smaller groups of interested students afterwards.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">I am making the slides available here, however you will notice that they mostly consist of images and screengrabs for me to use as talking points.  While they may or may not be interesting standing alone, I&#8217;ve uploaded them primarily to serve as a reference for the students that have attended the lecture.</div>
<div id="__ss_1928859" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="GhostExodus / Carrell Clinic Incident" href="http://www.slideshare.net/McGrewSecurity/ghostexodus-carrell-clinic-incident">GhostExodus / Carrell Clinic Incident</a><object style="margin:0px" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=ghostexoduswoembeddedvideo-090830175658-phpapp01&amp;stripped_title=ghostexodus-carrell-clinic-incident" /><param name="allowfullscreen" value="true" /><embed style="margin:0px" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=ghostexoduswoembeddedvideo-090830175658-phpapp01&amp;stripped_title=ghostexodus-carrell-clinic-incident" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/McGrewSecurity">McGrewSecurity</a>.</div>
</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">If I&#8217;m happy with how the lecture goes, I may use it as a reference to record some narration on top of the above slides and make it available on this site.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">If you are in the area and wish to drop in on this lecture, you are welcome to do so.  It will be at 9:00 AM, Monday August 31, in Butler 103.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">If you are a student in the class, coming here for the slides, and are new to the site, these are the posts related to this lecture:</div>
<p>Tommorow morning, I will be giving a lecture to the CS4243/6243 Information and Computer Security class at Mississippi State University.  It will cover the events that led up to, and followed from, the arrest of Jesse &#8220;GhostExodus&#8221; McGraw on charges of installing malicious code onto hospital computer systems, including a system that was the HMI (Human-Machine Interface) of the SCADA system controlling ventilation, air-conditioning, and various aspects of the surgery wing.</p>
<p>The purpose of the talk is to cover some of the more interesting points of evidence that was gathered, documents surrounding the arrest and indictment, and some of the aftermath.  To give the students some practical skills to take away, I&#8217;ll be discussing some of the methodology used that would be applicable when responding other incidents.  It&#8217;s difficult to fit everything into a 50-minute lecture, but I believe I&#8217;m hitting the most interesting and entertaining points, and will be happy to go into more detail with smaller groups of interested students afterwards.</p>
<p>I am making the slides available here, however you will notice that they mostly consist of images and screengrabs for me to use as talking points.  While they may or may not be interesting standing alone, I&#8217;ve uploaded them primarily to serve as a reference for the students that have attended the lecture:</p>
<p>If I&#8217;m happy with how the lecture goes, I may use it as a reference to record some narration on top of the above slides and make it available on this site.</p>
<p>If you are in the area and wish to drop in on this lecture, you are welcome to do so.  It will be at 9:00 AM, Monday August 31, in Butler 103.</p>
<p>If you are a student in the class, coming here for the slides, and are new to the site, these are the posts related to this lecture:</p>
<ul>
<li><a title="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" target="_blank">http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/</a></li>
<li><a title="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/" href="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/" target="_blank">http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/</a></li>
<li><a title="http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/" href="http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/" target="_blank">http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/</a></li>
<li><a title="http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/" href="http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/" target="_blank">http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/</a></li>
<li><a title="http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/" href="http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/" target="_blank">http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/</a></li>
<li><a title="http://www.mcgrewsecurity.com/2009/08/21/cisco-weighs-in-on-the-ghostexodus-control-systems-incident/" href="http://www.mcgrewsecurity.com/2009/08/21/cisco-weighs-in-on-the-ghostexodus-control-systems-incident/" target="_blank">http://www.mcgrewsecurity.com/2009/08/21/cisco-weighs-in-on-the-ghostexodus-control-systems-incident/</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/08/30/slides-for-cse4243-ghostexodus-lecture/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>GhostExodus indicted for control system incident</title>
		<link>http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/</link>
		<comments>http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 17:15:20 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=537</guid>
		<description><![CDATA[Just found out via the Dallas Observer&#8217;s blog that Jesse &#8220;GhostExodus&#8221; McGraw has been indicted by a federal grand jury, and has been charged with two counts of &#8220;transmitting a malicious code&#8221;, in reference to the malicious code he allegedly installed on computer systems at a hospital in the Dallas area:

Hacked! Dallas Federal Grand Jury [...]]]></description>
			<content:encoded><![CDATA[<p>Just found out via the Dallas Observer&#8217;s blog that Jesse &#8220;GhostExodus&#8221; McGraw has been indicted by a federal grand jury, and has been charged with two counts of &#8220;transmitting a malicious code&#8221;, in reference to the malicious code he allegedly installed on computer systems at a hospital in the Dallas area:</p>
<ul>
<li><a title="http://blogs.dallasobserver.com/unfairpark/2009/07/hacked_dallas_federal_grand_ju.php" href="http://blogs.dallasobserver.com/unfairpark/2009/07/hacked_dallas_federal_grand_ju.php" target="_blank">Hacked! Dallas Federal Grand Jury Indicts Electronik Tribulation Army&#8217;s GhostExodus</a></li>
</ul>
<p>If convicted, he faces up to 10 years in prison, and $250,000 in fines and restitution.</p>
<p>Meanwhile, the remaining members of ETA are a lot more quiet than they used to be.  XXxxImmortalxxXX, now also known as &#8220;system666&#8243;, is still a member of ETA, according to his signature on this forum, despite being the one that inadvertently tipped me off to GhostExodus&#8217; activities:</p>
<ul>
<li><a href="https://security-shell.ws/showthread.php?p=77078">Very Basic tut &#8211; SecurityTeam / Hackers Gr0up</a></li>
</ul>
<p style="text-align: center;"><img class="aligncenter" title="http://mcgrewsecurity.com/img/2i2hzn.png" src="http://mcgrewsecurity.com/img/2i2hzn.png" alt="" width="504" height="176" /></p>
<p>The Fixer, a member, or at least former member, is confused about the difference between the script kiddie hacker group ETA and the Basque seperatist group ETA (&#8220;Euskadi Ta Askatasuna&#8221;):</p>
<ul>
<li><a href="http://www.hackforums.net/archive/index.php/thread-104962.html">Hack Forums &#8211; Another ETA Member Arrested</a></li>
</ul>
<p>If you&#8217;d like to catch up, here are the previous posts in this series:</p>
<ul>
<li><a href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/">Part 1</a></li>
<li><a href="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/">Part 2</a></li>
<li><a href="http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/">Part 3</a></li>
<li><a href="http://www.mcgrewsecurity.com/2009/07/07/ghostexodus-part4/">Part 4</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/07/23/ghostexodus-indicted-for-control-system-incident/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>US Cyber Challenge: Positive Impact</title>
		<link>http://www.mcgrewsecurity.com/2009/07/12/us-cyber-challenge-positive-impact/</link>
		<comments>http://www.mcgrewsecurity.com/2009/07/12/us-cyber-challenge-positive-impact/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 20:41:26 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[fun]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=517</guid>
		<description><![CDATA[Poking around on various &#8220;hacker&#8221; forums, this sort of thing is a common sight:

If I had the stamina and will to maintain a &#8220;skiddie clown quote of the day&#8221; for any length of time, this would be a prime candidate.  Especially this part:
im sick of being hacked ive done nothing wrong expect steal about 200 [...]]]></description>
			<content:encoded><![CDATA[<p>Poking around on various &#8220;hacker&#8221; forums, this sort of thing is a common sight:</p>
<p><a href="http://mcgrewsecurity.com/img/oh_dear.png"><img class="aligncenter" src="http://mcgrewsecurity.com/img/oh_dear_th.png" alt="" width="400" height="202" /></a></p>
<p>If I had the stamina and will to maintain a &#8220;skiddie clown quote of the day&#8221; for any length of time, this would be a prime candidate.  Especially this part:</p>
<blockquote><p>im sick of being hacked ive done nothing wrong expect steal about 200 passes</p></blockquote>
<p>Looking at posts like this got me to thinking about this scene&#8217;s combination of wanting to learn about &#8220;hacking&#8221;, inexperience, and the desire to do something immediately &#8220;fun&#8221; (important point: they want to jump straight to 0wnage, with a minimum of time studying how).  It reminded me of a phenomenon I was seeing on forums like this a while back, where members were becoming aware of the CSIS and SANS US Cyber Challenge competitions:</p>
<ul>
<li><a title="http://www.sans.org/uscc/" href="http://www.sans.org/uscc/" target="_blank">SANS Institute &#8211; US Cyber Challenge</a></li>
</ul>
<p>These challenges are geared towards high school students and undergraduates, and it gives them a interesting and competitive outlet for exercising skills that might otherwise be used for more script-kiddie-like endeavors.  In addition, it helps give them motivation to learn new skills that&#8217;s missing when you have an entire Internet&#8217;s worth of computers out there that have vulnerabilities you already know how to exploit.  In a <a title="http://www.forbes.com/2009/05/21/cybersecurity-students-hackers-technology-security-cybersecurity.html" href="http://www.forbes.com/2009/05/21/cybersecurity-students-hackers-technology-security-cybersecurity.html" target="_blank">recent interview with Forbes</a>, the director of SANS, Alan Paller, stated the logic behind this kind of competition well:</p>
<blockquote><p>&#8220;Offense must inform defense,&#8221; he says. &#8220;We&#8217;d like it to be just training defenders, but if they don&#8217;t know how attacks are performed, they&#8217;ll be incompetent.&#8221;</p></blockquote>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 622px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">It might work, too.  If the structure of this training (which is still in its infancy) is good, and it&#8217;s interesting and challenging enough, then it could be possible to leverage script-kiddie-level skills into something useful.</div>
<p>It might work, too.  If the structure of this training (which is still in its infancy) is good, and it&#8217;s interesting and challenging enough, then it could be possible to leverage script-kiddie-level skills into something useful.</p>
<p>This might be what some of the people on these forums are looking for.  I&#8217;ve already witnessed an entire &#8220;hacking group&#8221; that normally occupies themselves with web defacement split into teams and sign up for the DC3 forensics challenge.  On another site, I noticed that <a title="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" target="_blank">GhostExodus</a>, before he was arrested, had signed up for the DC3 challenge as well, as had XXxxImmortalxxXX (the guy who bragged to me about GhostExodus&#8217; hacks).</p>
<p>Maybe in the near future, activities like the US Cyber Challenge will get people like this on a productive path before they wind up getting into trouble.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/07/12/us-cyber-challenge-positive-impact/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GhostExodus, the ETA, and a Control Systems Incident at Carrell Clinic (part 3)</title>
		<link>http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/</link>
		<comments>http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 15:01:52 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=496</guid>
		<description><![CDATA[Previous parts (Pre-requisite information.  There will be a pop quiz at the end.):

Part 1 &#8211; Definitely read the criminal complaint.
Part 2 &#8211; Watch some videos

In this post I will be displaying and discussing some screenshots that Jesse &#8220;GhostExodus&#8221; McGraw posted online.  These screenshots were taken on the PC controlling Carrell Clinic&#8217;s HVAC system, uploaded to [...]]]></description>
			<content:encoded><![CDATA[<p>Previous parts (Pre-requisite information.  There will be a pop quiz at the end.):</p>
<ul>
<li><a title="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" target="_blank">Part 1</a> &#8211; Definitely read the criminal complaint.</li>
<li><a title="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/" href="http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/" target="_blank">Part 2</a> &#8211; Watch some videos</li>
</ul>
<p>In this post I will be displaying and discussing some screenshots that Jesse &#8220;GhostExodus&#8221; McGraw posted online.  These screenshots were taken on the PC controlling Carrell Clinic&#8217;s HVAC system, uploaded to a photobucket account owned by GhostExodus, and linked to in posts on anarchistcookbook.com and warezscene.org (still available there).  When XXxxImmortalxxXX initially bragged to me about hacking this HVAC system himself, he linked the same photobucket images directly, which led me to discover the forum posts that linked the same images.</p>
<p>What you&#8217;re looking at in these screenshots, if you&#8217;re not familiar with control systems, is Human-Machine Interface (HMI) software.  HMI software represents what would have once been a physical control panel with switches, dials, gauges, and other similar elements.  The software displays the status of various elements of the system, and allows the operator to make changes, either directly (by flipping a switch, for example), or by modifying a parameter that the system automatically tries to maintain or use as a boundary.</p>
<p>Since the HMI for a control system is very specific to that system, HMI software is typically distributed as a combination of IDE (for developing the custom interface) and a runtime (for running the developed system).  HMI systems also implement access control and auditing, features that often serve as a last line of defense for a control system.  While I cannot speak for BACtalk&#8217;s security (I have no experience with it yet), a combination of misconfiguration and vulnerabilities in HMI products&#8217; security features can lead to this layer of defense being weak.  Until HMI software security improves, it&#8217;s very important to layer defenses around them, with strict control over who can access the systems physically or over a network.</p>
<p>Let&#8217;s take a look at the shots (click them to see them at full resolution):</p>
<p><a href="http://s860.photobucket.com/albums/ab166/mcgrewsec/?action=view&amp;current=1-1-1.png" target="_blank"><img src="http://i860.photobucket.com/albums/ab166/mcgrewsec/th_1-1-1.png" border="0" alt="Photobucket" /></a></p>
<p>In this shot, you can see what appears to be a &#8220;main menu&#8221; for the control system, with buttons that take you to other screens that control different sections of the hospital.  The most interesting thing here is the dialog box, &#8220;BACtalk Alarm&#8221;.  The &#8220;Acknowledge&#8221; buttons allow an operator to record that he or she has seen the alarm, which should go in an audit log that can be reviewed if there are problems in the future.  An attacker with access to these systems and the associated logs could &#8220;acknowledge&#8221; alarms that were meant to be seen by operators, and potentially even modify the audit logs.  The criminal complaint against GhostExodus made reference to problems with alarms this specific HVAC system was having after being compromised.</p>
<p><a href="http://s860.photobucket.com/albums/ab166/mcgrewsec/?action=view&amp;current=2-3.png" target="_blank"><img src="http://i860.photobucket.com/albums/ab166/mcgrewsec/th_2-3.png" border="0" alt="Photobucket" /></a></p>
<p>Here, we see a floorplan for an area of the hospital containing some operating rooms (OR 2 through OR 5).  Among other things, you can see the open/closed status of the vents in various rooms.  The buttons to the right of these status could be controls to toggle the status.  <span style="text-decoration: line-through;">I&#8217;m not really sure what the weird gray graphic between/overlapping the status of &#8220;AHU 7 OA Alarm&#8221; and &#8220;AHU 4 OR Alarm&#8221; is.  If you have a guess, leave a comment. </span> (Nevermind, glitch in GIMP.)</p>
<p>Note that since HMI interfaces are custom-designed in an IDE for the purposes of each control system, that the user interfaces are not always self-explanatory.  Operators have to be trained to understand the elements of each system.  This one&#8217;s not really that bad compared to a lot of them, though.</p>
<p><a href="http://s860.photobucket.com/albums/ab166/mcgrewsec/?action=view&amp;current=3-2.png" target="_blank"><img src="http://i860.photobucket.com/albums/ab166/mcgrewsec/th_3-2.png" border="0" alt="Photobucket" /></a></p>
<p>This is the scary one.  It&#8217;s a list of parameters for systems in a &#8220;Surgery Center&#8221; or operating room.  Here, an operator (or attacker) can modify the temperatures and levels at which pumps kick in, or shut things on and off.  I&#8217;m not familiar with hospital control systems, and especially not with those involved in surgery, but I imagine that changes made to these systems could wreak some havoc.</p>
<p>These screenshots were posted by GhostExodus on the warezscene and anarchistcookbook forums with the following text:</p>
<blockquote><p>Spreading botnets is boring. But sometimes you get a hefty prize for all your hard work and labor. Like this you see below. An HVAC server. An HVAC is: HVAC (pronounced either &#8220;H-V-A-C&#8221; or &#8220;H-vak&#8221;) is an initialism or acronym that stands for &#8220;heating, ventilating, and air conditioning&#8221;. HVAC is sometimes referred to as climate control and is particularly important in the design of medium to large industrial and office buildings such as skyscrapers and in marine environments yay for wiki</p></blockquote>
<p>In reality, GhostExodus compromised the system with physical access as a night security guard.  It is not known if this HMI was &#8220;legitimately&#8221; accessible remotely with RDP or similar protocols.  It was revealed in the criminal complaint that malicious software allowing for remote access was confirmed to be installed on the system.</p>
<p>GhostExodus followed up in the same thread on warezscene with this post:</p>
<blockquote><p>nice. You almost can&#8217;t help it ya know. It must be done!</p></blockquote>
<p>Hopefully this isn&#8217;t something many people feel compelled to do.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/07/06/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-3/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>GhostExodus, the ETA, and a Control-Systems Incident at Carrell Clinic (Part 2)</title>
		<link>http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/</link>
		<comments>http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 20:29:39 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[SCADA]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[fun]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=490</guid>
		<description><![CDATA[If you haven&#8217;t read Part 1 of this story, then you really ought to take a look at it first.  It serves as a good overview, and the criminal complaint filed by the FBI is a good read.
Yesterday afternoon was GhostExodus&#8217; detention hearing.  I&#8217;m not very familiar with the process one goes through after being [...]]]></description>
			<content:encoded><![CDATA[<p>If you haven&#8217;t read <a title="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" href="http://www.mcgrewsecurity.com/2009/06/30/ghostexodus-the-eta-and-a-control-systems-incident-at-carrell-clinic-part-1/" target="_blank">Part 1</a> of this story, then you really ought to take a look at it first.  It serves as a good overview, and the criminal complaint filed by the FBI is a good read.</p>
<p>Yesterday afternoon was GhostExodus&#8217; detention hearing.  I&#8217;m not very familiar with the process one goes through after being arrested for something like this, so I had to look up what this meant.  I found the following site which, I believe, explains detention hearings well:</p>
<ul>
<li><a title="http://bennettandbennett.com/blog/2007/08/detention-hearing-in-federal-court.html" href="http://bennettandbennett.com/blog/2007/08/detention-hearing-in-federal-court.html" target="_blank">http://bennettandbennett.com/blog/2007/08/detention-hearing-in-federal-court.html</a></li>
</ul>
<p>(Looks like a cool site beyond this, even.  Kind of a legal equivalent to the blog I run here.)</p>
<p>I was informed yesterday afternoon that the Judge in this case found that there was probable cause to detain Jesse McGraw while the case is pending.</p>
<p>Here are some links to the coverage this is getting.  I&#8217;m linking articles that I think my readers would enjoy, especially those where the reporters were thorough enough to contact me personally to get the stories:</p>
<ul>
<li><a title="http://www.theregister.co.uk/2009/07/01/hospital_hacker_arrested/" href="http://www.theregister.co.uk/2009/07/01/hospital_hacker_arrested/" target="_blank">http://www.theregister.co.uk/2009/07/01/hospital_hacker_arrested/</a></li>
<li><a title="http://www.pcworld.com/businesscenter/article/167756/security_guard_charged_with_hacking_hospital_systems.html" href="http://www.pcworld.com/businesscenter/article/167756/security_guard_charged_with_hacking_hospital_systems.html" target="_blank">http://www.pcworld.com/businesscenter/article/167756/security_guard_charged_with_hacking_hospital_systems.html</a></li>
<li><a title="http://blogs.dallasobserver.com/unfairpark/2009/07/hacking_the_hacker_ghostexodus.php" href="http://blogs.dallasobserver.com/unfairpark/2009/07/hacking_the_hacker_ghostexodus.php" target="_blank">http://blogs.dallasobserver.com/unfairpark/2009/07/hacking_the_hacker_ghostexodus.php</a></li>
</ul>
<p>The members of the press I&#8217;ve talked to on the phone and over IM have been very nice.  There are many more stories than this, you can poke around on Google News if you like, but your best source of technical information for fellow security and control-systems folks is going to be right here, of course :)</p>
<p>Now, time to break out the popcorn.  Here are two of the most interesting videos that were posted to GhostExodus&#8217; youtube accounts.  It&#8217;s my understanding that these videos were played in court yesterday.  After each video, I&#8217;ve summarized some points of interest in each video:</p>
<p><object width="425" height="344" data="http://www.youtube.com/v/WN3xUrFUoNw&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/WN3xUrFUoNw&amp;hl=en&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /></object></p>
<ul>
<li>&#8220;Post July 4th&#8221; is a strange choice of title here, as it&#8217;s before July 4th, and in preparation for the attacks scheduled for the 4th</li>
<li>He&#8217;s recording this by holding his laptop in front of him (reflections in elevator)</li>
<li>Claims to have infiltrated corporate offices, but it&#8217;s obviously a medical facility</li>
<li>Watch for medical charts and such on the walls when he sits down</li>
<li>Appears to be the collar of a security guard uniform peeking out of the top of the hoodie</li>
<li>The FBI identified this computer at the clinic by the toy flamingo on top of the monitor</li>
</ul>
<p><object width="425" height="344" data="http://www.youtube.com/v/qWevm9tDKVc&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/qWevm9tDKVc&amp;hl=en&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /></object></p>
<ul>
<li>This was recorded at a desk at the hospital where McGraw was a security guard.</li>
<li>I thought about buying one of those camera pens until I saw this.  Not inconspicuous.</li>
<li>Showing off your fake FBI credentials on youtube isn&#8217;t very smart.</li>
</ul>
<p>I will continue this series with more posts, discussing the HVAC compromise, how I came to be aware of it, and the techniques I used to gather information on the suspect.  Still pooped from talking to so many people about this, but I&#8217;m enjoying spreading the gospel of control-systems security ;)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/07/02/ghostexodus-part2/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Perl hacking is dead (lol)</title>
		<link>http://www.mcgrewsecurity.com/2009/05/26/perl-hacking-is-dead-lol/</link>
		<comments>http://www.mcgrewsecurity.com/2009/05/26/perl-hacking-is-dead-lol/#comments</comments>
		<pubDate>Tue, 26 May 2009 18:22:49 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[fun]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=422</guid>
		<description><![CDATA[Script kiddie forum pic of the day:

Naughty avatar censored, but I kept the language in case you want to try and make any sense of this chunk of thread.  PsyKon-X&#8217;s contribution is particularly hard to read through:
Perl does indeed work my friend but the coders in which the perl hack was designed for are being [...]]]></description>
			<content:encoded><![CDATA[<p>Script kiddie forum pic of the day:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-425" title="perlhackingisdead1" src="http://www.mcgrewsecurity.com/wp-content/uploads/2009/05/perlhackingisdead1.png" alt="perlhackingisdead1" width="435" height="350" /></p>
<p>Naughty avatar censored, but I kept the language in case you want to try and make any sense of this chunk of thread.  PsyKon-X&#8217;s contribution is particularly hard to read through:</p>
<blockquote><p>Perl does indeed work my friend but the coders in which the perl hack was designed for are being patched faster than the hacker is making the perl scripts, and also depends on if the person using the script for example is using phpbb and hasnt patched it with the new version this is vulnrable</p></blockquote>
<p>Diagram <em>that</em> sentence.</p>
<p>All of you whitehats posting scripts to milw0rm are killing the perl hacking scene ;-).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/05/26/perl-hacking-is-dead-lol/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Yousif Yalda&#8217;s friend, Mark gives me a call</title>
		<link>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/#comments</comments>
		<pubDate>Sun, 07 Sep 2008 18:49:55 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=203</guid>
		<description><![CDATA[Yousif called me several times after the first post about him, however, after a while he gave up and delegated the late-night calls to his friend Mark.  In response to a recent post, Mark gave me a call at about 2AM last night.  My wife and I were up watching DVDs of Battlestar Galactica, so [...]]]></description>
			<content:encoded><![CDATA[<p>Yousif called me several times after the <a title="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" href="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" target="_blank">first post about him</a>, however, after a while he gave up and delegated the late-night calls to his friend Mark.  In response to a <a title="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" href="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" target="_blank">recent post</a>, Mark gave me a call at about 2AM last night.  My wife and I were up watching DVDs of Battlestar Galactica, so it&#8217;s not as inconvenient as you would think.</p>
<p>I was getting bored of the call, and decided to fire up Audacity, in order to record some of his profane rants and play them back to him.  Once he wrapped his head around the fact that I was able to record the call, he decided that he wanted me to record a message to post here, on my website.</p>
<p>The following, is that message.  While I took this as an opportunity to play around with iMovie, I haven&#8217;t censored any of the language or idiocy that&#8217;s present in his audio.  If you are easily offended, then you might not want to watch.  If you&#8217;re at work, well, you might want to save this till you get home, or get some headphones :)</p>
<p><strong>Edit: </strong>Yousif apparently didn&#8217;t like the fact that this video was in the &#8220;Related Videos&#8221; box for the <a title="http://www.youtube.com/watch?v=Krmx8M-AL6g" href="http://www.youtube.com/watch?v=Krmx8M-AL6g">commercial</a> he <span style="text-decoration: line-through;">made</span> <a title="http://www.youtube.com/watch?v=oDIgL4NQbNA" href="http://www.youtube.com/watch?v=oDIgL4NQbNA">ripped off from Lanier Leather</a> for his affiliate marketing site.  He managed to report the YouTube version of this video into oblivion, so here it is on metacafe:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="345" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.metacafe.com/fplayer/1751334/yousif_yaldas_friend_mark_calls_me.swf" /><param name="wmode" value="transparent" /><embed type="application/x-shockwave-flash" width="400" height="345" src="http://www.metacafe.com/fplayer/1751334/yousif_yaldas_friend_mark_calls_me.swf" wmode="transparent"></embed></object></p>
<p><strong>Edit: </strong>Awesome comments down below.  Glad you could join us, Mark.  I guess this is where you can contact him for the time being.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Yousif Yalda Part 2: Script Kiddies in the Mist</title>
		<link>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/#comments</comments>
		<pubDate>Mon, 01 Sep 2008 19:46:14 +0000</pubDate>
		<dc:creator>Wesley McGrew</dc:creator>
				<category><![CDATA[fun]]></category>
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=184</guid>
		<description><![CDATA[&#8230;in which, our intrepid security geek finds out that there is a $400 bounty on his head.
Posts like this don&#8217;t have much technical content, but they&#8217;re fun, and the last one has been a wildly popular part of the site.  While you&#8217;re laughing your butt off, I hope you take away the real message here: [...]]]></description>
			<content:encoded><![CDATA[<p><em>&#8230;in which, our intrepid security geek finds out that there is a $400 bounty on his head.</em></p>
<p>Posts like this don&#8217;t have much technical content, but they&#8217;re fun, and the last one has been a wildly popular part of the site.  While you&#8217;re laughing your butt off, I hope you take away the real message here: do some background research on who you&#8217;re dealing with in the computer security scene.  If you got here by googling up information on this particular skiddie, then you&#8217;re already one step ahead of the game.  Just because someone has a <a title="http://vapt-sec.com/" href="http://vapt-sec.com/" target="_blank">legit-looking website</a> and <a title="http://yousifyalda.blogspot.com" href="http://yousifyalda.blogspot.com" target="_blank">blog</a> doesn&#8217;t mean they&#8217;re on the up-and-up :)</p>
<p>Since my <a title="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" href="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" target="_blank">first post about Yousif&#8217;s activities</a>, I&#8217;ve had the pleasure of many late-night phone calls from him, being DOS&#8217;d for about a half hour, and having his friend threaten to hack my coffee maker.  I was promised a beat-down at Black Hat, although I unfortunately could not make it.  I am, however, sort of disappointed that I don&#8217;t warrant being stabbed, like <a title="http://writequit.org/blog/?p=158" href="http://writequit.org/blog/?p=158" target="_blank">Yousif has threatened to do to Lee Hinman</a> over at the excellent <a title="http://writequit.org/blog/" href="http://writequit.org/blog/" target="_blank">writequit.org</a> blog.  He is, however, willing to pay someone else to do the dirty work.</p>
<p>In the meantime, he hasn&#8217;t let up in his activities.  He has been hanging out on an <a title="http://forums.digitalpoint.com/" href="http://forums.digitalpoint.com/" target="_blank">Internet marketing forum</a>, although his taste for script-kiddie hacking has not subsided.  He still has a penchant for <a title="http://mcgrewsecurity.com/img/yy2_1.png" href="http://mcgrewsecurity.com/img/yy2_1.png" target="_blank">attacking sites outside of well-defined pen-tests</a>, still loves to <a title="http://mcgrewsecurity.com/img/yy2_2.png" href="http://mcgrewsecurity.com/img/yy2_2.png" target="_blank">threaten people who correct him</a>, and <a title="http://mcgrewsecurity.com/img/yy2_3.png" href="http://mcgrewsecurity.com/img/yy2_3.png" target="_blank">runs his own small botnet</a>.</p>
<p>Apparently looking to supplement his <a title="http://vapt-sec.com" href="http://vapt-sec.com" target="_blank">vapt-sec.com</a> income with some <a title="http://en.wikipedia.org/wiki/Cost_per_action" href="http://en.wikipedia.org/wiki/Cost_per_action" target="_blank">cost-per-action</a> fraud, he&#8217;s been hunting around for cohorts to <a title="http://mcgrewsecurity.com/img/yy2_5.png" href="http://mcgrewsecurity.com/img/yy2_5.png" target="_blank">develop software to fill out forms and offers on CPA advertisers</a>, and to <a title="http://mcgrewsecurity.com/img/yy2_4.png" href="http://mcgrewsecurity.com/img/yy2_4.png" target="_blank">come in through his referral links from multiple IP addresses to fill out forms</a>.  I took this as an opportunity to form my own &#8220;black hat&#8221; alter-ego, and have a good heart-to-heart chat with Yousif.  After a couple of boring evening chat sessions building up my &#8220;black hat&#8221; cred with him, he began to open up.</p>
<p><em>The following are some choice excerpts and quotes.  I&#8217;ve censored both his language and mine.  I do swear in-person, occasionally on IRC, and rarely on the blog, however I did ratchet it up about 12 notches with &#8220;elite yousif&#8221;, to build rapport. </em></p>
<p>Since he gets others to write his software for him, he occasionally gets his languages confused:</p>
<blockquote><p>11:03:05 PM elite yousif: So<br />
11:03:12 PM elite yousif: You know anyone who has botnets<br />
11:03:39 PM bhb: i have a couple friends who might.  have a need?<br />
11:03:50 PM elite yousif: Yeah<br />
11:04:37 PM elite yousif: It&#8217;s quite helpful in CPA<br />
11:05:16 PM bhb: yeah i was thinking of writing some code to work through a botnet, filling stuff and using the random ID generator<br />
11:05:27 PM elite yousif: No need, lol.<br />
11:05:35 PM elite yousif: I&#8217;m making something like that as we speak.<br />
11:05:39 PM bhb: nice<br />
11:05:50 PM bhb: what language do you code in<br />
11:06:01 PM elite yousif: What language did I code this in?<br />
11:06:11 PM bhb: yah<br />
11:06:41 PM elite yousif: Net<br />
11:06:54 PM bhb: c#<br />
11:06:55 PM bhb: ?<br />
11:07:21 PM elite yousif: nope<br />
11:07:22 PM elite yousif: .NET &lt;<br />
11:07:29 PM elite yousif: Microsoft, ya know?<br />
11:08:01 PM bhb: .net&#8217;s a platform, theres lots of languages you can code targeting .net<br />
11:08:06 PM bhb: vb.net maybe?<br />
11:08:13 PM elite yousif: Yeah, that&#8217;s right.<br />
11:08:21 PM elite yousif: Vb.NET &lt;</p></blockquote>
<p>Don&#8217;t mess with this guy.  Especially in school:</p>
<blockquote><p>11:56:56 PM elite yousif: No one ***** w/ me..<br />
11:56:59 PM elite yousif: No one @ all.<br />
11:57:02 PM elite yousif: Not even in school<br />
11:57:03 PM elite yousif: They know<br />
11:57:05 PM elite yousif: I can change their grade<br />
11:57:09 PM elite yousif: expell them<br />
11:57:10 PM elite yousif: frame them<br />
11:57:11 PM elite yousif: etc<br />
11:57:17 PM elite yousif: I can drop your docs too<br />
11:57:21 PM elite yousif: know what shoe size you wear<br />
11:57:23 PM bhb: heh nice<br />
11:57:25 PM elite yousif: know your fam history<br />
11:57:27 PM elite yousif: CC<br />
11:57:29 PM elite yousif: S#<br />
11:57:30 PM elite yousif: where u live<br />
11:57:30 PM elite yousif: etc<br />
11:57:59 PM bhb: knock some kiddies on their ***** online lol<br />
11:58:18 PM elite yousif: lol<br />
11:58:59 PM bhb: ***** haters lol<br />
11:59:09 PM elite yousif: I know AOL internals too<br />
11:59:11 PM elite yousif: ppl who work there<br />
11:59:13 PM elite yousif: with high privs.<br />
11:59:14 PM elite yousif: can easily<br />
11:59:16 PM elite yousif: hi jack<br />
11:59:19 PM elite yousif: any AOL/AIM account<br />
11:59:22 PM elite yousif: and get info behind it<br />
11:59:23 PM elite yousif: =D<br />
11:59:31 PM elite yousif: i social engineer as well<br />
12:00:08 AM bhb: hah that&#8217;s useful</p></blockquote>
<p>A social engineering mastermind, to be sure.</p>
<p>Here, he&#8217;s a little sore that his affiliate program dropped him after figuring out his referrals weren&#8217;t legitimate:</p>
<blockquote><p>12:03:12 AM elite yousif: you haven&#8217;t made any money in CPA yet?<br />
12:03:43 AM bhb: haven&#8217;t even started.  just been reading up on it on the side, besides coding and work<br />
12:04:30 AM elite yousif: ah<br />
12:04:40 AM bhb: you made much?<br />
12:04:42 AM elite yousif: I got my account terminated<br />
12:04:45 AM elite yousif: 2 days ago<br />
12:04:48 AM elite yousif: from a network<br />
12:04:52 AM elite yousif: ***** bro, i swear<br />
12:04:52 AM bhb: haters<br />
12:04:53 AM elite yousif: I lost<br />
12:04:56 AM elite yousif: 2000+ dollars<br />
12:04:59 AM elite yousif: I better get my ***** back<br />
12:05:00 AM elite yousif: OR<br />
12:05:08 AM elite yousif: I&#8217;m gonna make my affiliate managers life a living HELL<br />
12:05:14 AM elite yousif: I have access to her AIM account<br />
12:05:15 AM elite yousif: verizon<br />
12:05:17 AM elite yousif: photobucket<br />
12:05:19 AM elite yousif: paypal<br />
12:05:20 AM elite yousif: blogger<br />
12:05:23 AM elite yousif: and some other *****<br />
12:05:25 AM elite yousif: and facebook<br />
12:05:29 AM elite yousif: she doesn&#8217;t know it yet<br />
12:05:31 AM elite yousif: but I phished that *****</p></blockquote>
<p>Bragging about taking down RSnake&#8217;s site (note: there&#8217;s an excellent chance this never really happened):</p>
<blockquote><p>3:00:44 AM elite yousif: you know rsnake?<br />
3:00:46 AM elite yousif: robert hansen<br />
3:00:48 AM elite yousif: famous as *****..<br />
3:00:49 AM bhb: yeah<br />
3:00:51 AM elite yousif: k<br />
3:00:51 AM elite yousif: well<br />
3:00:53 AM elite yousif: his site<br />
3:00:54 AM elite yousif: let me find it<br />
3:01:03 AM bhb: ha.ckers.org or something<br />
3:01:22 AM elite yousif: nah<br />
3:01:23 AM elite yousif: his company<br />
3:01:29 AM bhb: oh i dunno<br />
3:02:26 AM bhb: sectheory?<br />
3:02:58 AM elite yousif: yeah<br />
3:02:59 AM elite yousif: rofol<br />
3:03:02 AM elite yousif: i ddosed that<br />
3:03:03 AM elite yousif: with my friend<br />
3:03:04 AM elite yousif: in like<br />
3:03:05 AM elite yousif: what<br />
3:03:06 AM elite yousif: maybe<br />
3:03:09 AM elite yousif: 3 mins<br />
3:03:10 AM elite yousif: it was down<br />
3:03:14 AM elite yousif: some security expert eh?</p></blockquote>
<p>If there were any doubts about how he&#8217;s taking part in CPA fraud:</p>
<blockquote><p>4:44:10 PM bhb: how are you supposed to make any money at it if you arent botting it anyways lol<br />
4:44:25 PM elite yousif: what do you mean?<br />
4:44:48 PM bhb: like automating it through a bunch of proxies/bots<br />
4:45:02 PM bhb: how can you find that many people wanting to do it legit to keep making money<br />
4:45:14 PM elite yousif: lol<br />
4:45:17 PM elite yousif: u infect more victims<br />
4:45:22 PM elite yousif: you market your trojan or w.e.<br />
4:45:27 PM elite yousif: and more ppl open it<br />
4:45:37 PM bhb: heh yeah so a loose definition of &#8220;legit&#8221; lol :D<br />
4:45:48 PM elite yousif: yep<br />
4:45:48 PM elite yousif: lol<br />
4:45:59 PM elite yousif: you know what company is cool though?<br />
4:46:03 PM bhb: you have nice custom trojans for it?<br />
4:46:03 PM elite yousif: ******<br />
4:46:10 PM elite yousif: i talked to the owner<br />
4:46:10 PM bhb: cool you work with them too?<br />
4:46:12 PM elite yousif: really cool guy<br />
4:46:14 PM elite yousif: says<br />
4:46:18 PM elite yousif: i can do black hat if i want<br />
4:46:21 PM elite yousif: and he wont term. my account</p></blockquote>
<p>Then, I managed to get him on the subject of yours truly :):</p>
<blockquote><p>5:02:12 PM elite yousif: LOL<br />
5:02:19 PM elite yousif: http://archives.neohapsis.com/archives/fulldisclosure/2008-08/0545.html<br />
5:02:21 PM elite yousif: that link u sent me<br />
5:02:25 PM elite yousif: i know the guy who wrote that<br />
5:02:27 PM elite yousif: wesley mcgrew<br />
5:02:30 PM elite yousif: that dude is such a *****<br />
5:02:36 PM bhb: he talks like one<br />
5:03:01 PM elite yousif: he started talking ***** about my business and me because he claims that i hack around sites without permission and that i gave him access to my computer, WTF..<br />
5:03:25 PM elite yousif: so i told him to go to black hat in vegas, and he said hes not going this year &#8212; i told him if i saw him id tackle him</p></blockquote>
<p>I&#8217;m not really sure if the following about the director of Black Hat contacting him is true (I never contacted the Black Hat folks about it, since it&#8217;s not really a credible threat).  He probably just made it up after he found out how much Black Hat costs:</p>
<blockquote><p>5:05:11 PM elite yousif: u know what he did<br />
5:05:11 PM elite yousif: he spoke with teh director of black hat<br />
5:05:11 PM elite yousif: and he told him that i would beat his ***** if i saw him<br />
5:05:11 PM elite yousif: so he got scared<br />
5:05:11 PM elite yousif: so the director listened to him<br />
5:05:20 PM elite yousif: and said i cant attend black hat this yea<br />
5:05:20 PM elite yousif: year*<br />
5:05:38 PM bhb: lol that&#8217;s hilarious did the director email you or something<br />
5:05:44 PM elite yousif: no he IM&#8217;d me<br />
5:05:51 PM bhb: ahah<br />
5:05:52 PM elite yousif: then i followed his profile and he actually WAS the director of black hat<br />
5:05:54 PM elite yousif: oh well<br />
5:05:59 PM elite yousif: he knew i wasn&#8217;t kidding</p></blockquote>
<p>This did happen, although he and his friends would usually get bored and give up after a few calls:</p>
<blockquote><p>5:06:00 PM elite yousif: i called him<br />
5:06:03 PM elite yousif: 1000 times<br />
5:06:07 PM elite yousif: i cussed him out badly<br />
5:06:12 PM elite yousif: and i demanded to talk to his wife<br />
5:06:14 PM elite yousif: so i can cuss her outtoo<br />
5:06:17 PM elite yousif: her out too*<br />
5:06:18 PM elite yousif: but he wouldn&#8217;t elt<br />
5:06:20 PM elite yousif: let*</p></blockquote>
<p>Remember kids, don&#8217;t DDOS on a school night:</p>
<blockquote><p>5:14:51 PM elite yousif: ask him if i DDoSed his *****<br />
5:15:03 PM elite yousif: he&#8217;ll either lie and say &#8216;it&#8217;s server issues @ night&#8221; or he&#8217;ll admit like a ***** i owned him<br />
5:15:25 PM bhb: hah what an idiot.  how long did you ddos him for<br />
5:15:36 PM elite yousif: for about 2-3 hrs<br />
5:15:42 PM elite yousif: i was bored and it was late<br />
5:15:45 PM elite yousif: i had school next morninig<br />
5:15:47 PM elite yousif: so i let him go<br />
5:15:48 PM elite yousif: lol</p></blockquote>
<p>There&#8217;s a $400 bounty on my head.  My wife, a friend, and I considered faking some photos and video to claim it, but I guess we&#8217;re just too nice:</p>
<blockquote><p>5:33:36 PM elite yousif: can you go to missipi?<br />
5:33:39 PM elite yousif: ill pay you like<br />
5:33:42 PM elite yousif: 400<br />
5:33:44 PM elite yousif: to beat his ***** for me<br />
5:33:46 PM elite yousif: no joke<br />
5:34:03 PM bhb: lol maybe if im hard up for some money one day<br />
5:34:14 PM bhb: you should definitely go though, that ***** would be classic<br />
5:34:28 PM elite yousif: do u know anyone would do it?<br />
5:34:34 PM bhb: show all the whitehats that you dont ***** with the blackhats cause they take it into RL<br />
5:34:36 PM elite yousif: i seriously will pay $400 for it<br />
5:35:06 PM bhb: i dont know anyone up for that but it shouldnt be too hard to find<br />
5:35:20 PM bhb: lol craigslist, i bet theres tons of local rednecks there that would do it<br />
5:35:27 PM elite yousif: lol<br />
5:35:35 PM elite yousif: id rather talk to someone i already know<br />
5:36:03 PM bhb: hah just tell them the money transfers when you see a jpg of his bloody nose lol<br />
5:36:33 PM elite yousif: rofl<br />
5:36:35 PM elite yousif: good idea<br />
5:37:28 PM bhb: http://northmiss.craigslist.org/<br />
5:38:10 PM bhb: i dunno what category lol<br />
5:38:15 PM elite yousif: lol<br />
5:38:17 PM elite yousif: murder<br />
5:38:20 PM bhb: loool<br />
5:39:57 PM bhb: services &#8211; labor &amp; moving, that probably has the most steroid pumped rednecks<br />
5:40:15 PM elite yousif: lol<br />
5:40:21 PM elite yousif: bro i would never do it off tehre<br />
5:40:27 PM elite yousif: ***** u know feds just hang out there<br />
5:40:30 PM elite yousif: waiting for somone to ***** up</p></blockquote>
<p>I&#8217;ll leave you with the last words he had to say to my dummy AIM account:</p>
<blockquote><p>7:28:14 PM elite yousif: yo<br />
7:28:30 PM elite yousif: is there a way to make your cd burner recognize dvd-r&#8217;s?</p></blockquote>
<p>Brilliant.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/feed/</wfw:commentRss>
		<slash:comments>33</slash:comments>
		</item>
	</channel>
</rss>
