Deep Web
*** Scam Site? ***
i darkwebofficial.com legit, or a scam trying to troll clearnet ppl? Thnx.
submitted by /u/Gestan
[link] [comments]
*** Scam Site? ***
i darkwebofficial.com legit, or a scam trying to troll clearnet ppl? Thnx.
submitted by /u/Gestan
[link] [comments]
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What is this?
I found it in my google drive, it says I downloaded it lastnight but I didn't....
https://drive.google.com/file/d/1wadspFWwhnarbPCv5LTEir5FaCowj4__/view?usp=sharing
submitted by /u/leadonornot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is this?
I found it in my google drive, it says I downloaded it lastnight but I didn't....
https://drive.google.com/file/d/1wadspFWwhnarbPCv5LTEir5FaCowj4__/view?usp=sharing
submitted by /u/leadonornot
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is this?
I found it in my google drive, it says I downloaded it lastnight but I...
hacking: security in practice
Mac System Report
Hi, this is more general advice as I possibly might have become victim to a security hack on my MacBook. I have the before hack system report and a fresh install of a clean system report. Are there any specific programs or files I should be looking at in the “possibly affected” Mac system report? What would be some of the weird file names etc. (as a point I remember opening the Mac terminal and seeing a weird username). I have done a quick scan through it to compare the old and new and can’t really see anything obvious. Thanks.
submitted by /u/megaboobz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Mac System Report
Hi, this is more general advice as I possibly might have become victim to a security hack on my MacBook. I have the before hack system report and a fresh install of a clean system report. Are there any specific programs or files I should be looking at in the “possibly affected” Mac system report? What would be some of the weird file names etc. (as a point I remember opening the Mac terminal and seeing a weird username). I have done a quick scan through it to compare the old and new and can’t really see anything obvious. Thanks.
submitted by /u/megaboobz
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Mac System Report
Hi, this is more general advice as I possibly might have become victim to a security hack on my MacBook. I have the before hack system report and...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
INTERNET EXTORTION: Why is ‘ransomware’ on the rise?
https://cdn-images-1.medium.com/max/1920/1*NCc53EKYMd-gai19BgxSIQ.png
I’m sure you’ve heard of ransomware…
Continue reading on Medium »
INTERNET EXTORTION: Why is ‘ransomware’ on the rise?
https://cdn-images-1.medium.com/max/1920/1*NCc53EKYMd-gai19BgxSIQ.png
I’m sure you’ve heard of ransomware…
Continue reading on Medium »
hacking: security in practice
Log into router settings without redirecting to Mediacom control panel.
Anyone know how to do this on a hitron router/modem combo?
I don’t have physical access to the modem. It’s my stepdads and my family is on vacation.
submitted by /u/1NightWolf
[link] [comments]
Log into router settings without redirecting to Mediacom control panel.
Anyone know how to do this on a hitron router/modem combo?
I don’t have physical access to the modem. It’s my stepdads and my family is on vacation.
submitted by /u/1NightWolf
[link] [comments]
reddit
r/hacking - Log into router settings without redirecting to Mediacom control panel.
0 votes and 0 comments so far on Reddit
hacking: security in practice
Podcast/Webseries
Hello everyone, I have never been on the deepweb, and I don't plan on it... I am starting a podcast, or web-story thing, with my friend All about the deep web, hacking, true scary stories, etc Preferably with pictures or videos. If anyone would like to share with me, please DM me, don't comment on the thread, as I would like to have a private conversation with people.
Thanks :)
submitted by /u/GOD_OF_THUNDER1726
[link] [comments]
Podcast/Webseries
Hello everyone, I have never been on the deepweb, and I don't plan on it... I am starting a podcast, or web-story thing, with my friend All about the deep web, hacking, true scary stories, etc Preferably with pictures or videos. If anyone would like to share with me, please DM me, don't comment on the thread, as I would like to have a private conversation with people.
Thanks :)
submitted by /u/GOD_OF_THUNDER1726
[link] [comments]
reddit
Podcast/Webseries
Hello everyone, I have never been on the deepweb, and I don't plan on it... I am starting a podcast, or web-story thing, with my friend All about...
hacking: security in practice
Suspicious log in attempt from place I bought airplane tickets to..
This is so weird
I recently bought airplane tickets to Kyiv, Ukraine on my current email address. Then someone logged into my old instagram account on my old email account that is not anyway associated with my current email. The IP associated with that log in is Kyiv, Ukraine...
How would that be possible? I don't get how the IP log in was in Kyiv , the same place I am heading to.
submitted by /u/Tom1l1
[link] [comments]
Suspicious log in attempt from place I bought airplane tickets to..
This is so weird
I recently bought airplane tickets to Kyiv, Ukraine on my current email address. Then someone logged into my old instagram account on my old email account that is not anyway associated with my current email. The IP associated with that log in is Kyiv, Ukraine...
How would that be possible? I don't get how the IP log in was in Kyiv , the same place I am heading to.
submitted by /u/Tom1l1
[link] [comments]
reddit
Suspicious log in attempt from place I bought airplane tickets to..
This is so weird I recently bought airplane tickets to Kyiv, Ukraine on my current email address. Then someone logged into my old instagram...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PPLdump : Dump The Memory Of A PPL With A Userland Exploit
PPLdump implements a userland exploit that was initially discussed by James Forshaw (a.k.a. @tiraniddo) – in this blog post – for dumping the memory of any PPL as an administrator. I wrote two blog posts about this tool. The first part is about Protected Processes concepts while the second one dicusses the bypass technique itself. Blog post part #1: Do You Really Know […]
The post PPLdump : Dump The Memory Of A PPL With A Userland Exploit appeared first on Kali Linux Tutorials.
PPLdump : Dump The Memory Of A PPL With A Userland Exploit
PPLdump implements a userland exploit that was initially discussed by James Forshaw (a.k.a. @tiraniddo) – in this blog post – for dumping the memory of any PPL as an administrator. I wrote two blog posts about this tool. The first part is about Protected Processes concepts while the second one dicusses the bypass technique itself. Blog post part #1: Do You Really Know […]
The post PPLdump : Dump The Memory Of A PPL With A Userland Exploit appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
RPC Enumeration | Active Directory | Only for educational purposes!
NOTE: Only for educational purposes!
Hello Everyone!
Hope you all are doing great, In this video, I will show you how you can enumerate RPC to gain useful and important information about the target domain controller such as users, groups and so on! Hope you enjoy the video! Stay safe! Take care!
https://www.youtube.com/watch?v=FULONmrl3jo
submitted by /u/Vedant-Bhalgama
[link] [comments]
RPC Enumeration | Active Directory | Only for educational purposes!
NOTE: Only for educational purposes!
Hello Everyone!
Hope you all are doing great, In this video, I will show you how you can enumerate RPC to gain useful and important information about the target domain controller such as users, groups and so on! Hope you enjoy the video! Stay safe! Take care!
https://www.youtube.com/watch?v=FULONmrl3jo
submitted by /u/Vedant-Bhalgama
[link] [comments]
hacking: security in practice
How to change your public ip address without contacting isp?
I noticed that all of my devices connected to the same wifi network have the same ip when I look for “whats my ip” on google. I went into my router setting and I noticed that I can change my LAN ip (192.168.x.x)
But when I go to WAN settings I see the same ip address that I see on google on all my devices. I tried to change it from my router setting but it seems to be set in stone. All of this was done from my web browser on windows but I can use tools on kali as well I just dont know which ones.
submitted by /u/Matrix10011
[link] [comments]
How to change your public ip address without contacting isp?
I noticed that all of my devices connected to the same wifi network have the same ip when I look for “whats my ip” on google. I went into my router setting and I noticed that I can change my LAN ip (192.168.x.x)
But when I go to WAN settings I see the same ip address that I see on google on all my devices. I tried to change it from my router setting but it seems to be set in stone. All of this was done from my web browser on windows but I can use tools on kali as well I just dont know which ones.
submitted by /u/Matrix10011
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
About socat, a tool for listening to and connecting to shells on a remote machine after exploitation
https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/
<!-- SC_OFF -->I am currently studying syntax of socat tool. Here's a command :- socat TCP-L:(port) - (This is what we type on attacking machine for establishing a listener on it while using a reverse shell) I am confused with -L option here after tcp, i looked it up in man pages of socat and it say its a flag for lockfile.. And i am confused as to what file locking really is..and how is it related to socat in its syntax? <!-- SC_ON --> submitted by /u/Global_Negotiation_3 (https://www.reddit.com/user/Global_Negotiation_3)
[link] (https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/)
https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/
<!-- SC_OFF -->I am currently studying syntax of socat tool. Here's a command :- socat TCP-L:(port) - (This is what we type on attacking machine for establishing a listener on it while using a reverse shell) I am confused with -L option here after tcp, i looked it up in man pages of socat and it say its a flag for lockfile.. And i am confused as to what file locking really is..and how is it related to socat in its syntax? <!-- SC_ON --> submitted by /u/Global_Negotiation_3 (https://www.reddit.com/user/Global_Negotiation_3)
[link] (https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/o9gk3j/about_socat_a_tool_for_listening_to_and/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco ASA Bug Now Actively Exploited as PoC Drops
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco ASA Bug Now Actively Exploited as PoC DropsPost Views: 113
Reading Time: 1 Minute
Researchers have dropped a proof-of-concept (PoC) exploit on Twitter for a known cross-site scripting (XSS) vulnerability in the Cisco Adaptive Security Appliance (ASA).
Researchers at Positive Technologies published the PoC for the bug (CVE-2020-3580) on Thursday. One of the researchers there, Mikhail Klyuchnikov, noted that there were a heap of researchers now chasing after an exploit for the bug, which he termed “low-hanging” fruit.
https://s.w.org/images/core/emoji/13.0.1/72x72/1f381.png PoC for XSS in Cisco ASA (CVE-2020-3580)
POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1
Host: ciscoASA.local
Content-Type: application/x-www-form-urlencoded
Content-Length: 44
SAMLResponse="><svg pic.twitter.com/c53MKSK9bg
— PT SWARM (@ptswarm) June 24, 2021
Meanwhile, Tenable researchers published an alert about the PoC, noting that it has started to see cyberattacks using the vulnerability on targets in the wild.
“Tenable has also received a report that attackers are exploiting CVE-2020-3580 in the wild,” according to its Thursday alert. “With this new information, Tenable recommends that organizations prioritize patching CVE-2020-3580.”
And indeed, the PT PoC tweet was met with plenty of “Ooh thanks” and “thank you so much” responses, presumably from would-be hackers.
See Also: New iPhone Bug Breaks Your WiFi: Here’s The Fix
Meanwhile, researchers at WebSec noted that the bug could be exploited for more than XSS:
You could have gotten 2 CVE numbers for this, as this is not just XSS but also CSRF.
— WebSec (@websecnl) June 25, 2021
“Researchers often develop PoCs before reporting a vulnerability to a developer and publishing them allows other researchers to both check their work and potentially dig further and discover other issues,” Claire Tills, senior research engineer at Tenable, told Threatpost. “PoCs can also be used by defenders to develop detections for vulnerabilities. Unfortunately, giving that valuable information to defenders means it can also end up in the hands of attackers.”
Given that a patch has been available for this vulnerability for several months, organizations are able to protect themselves which isn’t the case with 0-day disclosures, she pointed out. “However, unpatched vulnerabilities continue to haunt many organizations,” Tillis added. “The public availability of a PoC is another stark reminder that effective patching is a vital step for organizations to protect themselves.” Real-World Attacks for Cisco ASAThe Cisco ASA is a cybersecurity perimeter-defense appliance that combines firewall, antivirus, intrusion prevention and virtual private network (VPN) capabilities, all meant to stop threats from making it onto corporate networks. A compromise of the device is akin to unlocking the front door of the castle for storming cyberattackers.
See Also: Offensive Security Tool: Pixload
XSS attacks occur when malicious scripts are injected into otherwise benign and trusted websites; any visitors to the compromised websites are thus subject to drive-by attacks.
Successful exploitation in this case means that unauthenticated, remote attackers could “execute arbitrary code within the [ASA] interface and access sensitive, browser-based information,” Tenable added.
Once in, they could modify the device’s configuration, according to Leo Pate, an application security consultant at nVisium.
However, the target would need to be logged into the ASA for the attackers to see any joy. “While th[...]
Cisco ASA Bug Now Actively Exploited as PoC Drops
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Cisco ASA Bug Now Actively Exploited as PoC DropsPost Views: 113
Reading Time: 1 Minute
Researchers have dropped a proof-of-concept (PoC) exploit on Twitter for a known cross-site scripting (XSS) vulnerability in the Cisco Adaptive Security Appliance (ASA).
Researchers at Positive Technologies published the PoC for the bug (CVE-2020-3580) on Thursday. One of the researchers there, Mikhail Klyuchnikov, noted that there were a heap of researchers now chasing after an exploit for the bug, which he termed “low-hanging” fruit.
https://s.w.org/images/core/emoji/13.0.1/72x72/1f381.png PoC for XSS in Cisco ASA (CVE-2020-3580)
POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1
Host: ciscoASA.local
Content-Type: application/x-www-form-urlencoded
Content-Length: 44
SAMLResponse="><svg pic.twitter.com/c53MKSK9bg
— PT SWARM (@ptswarm) June 24, 2021
Meanwhile, Tenable researchers published an alert about the PoC, noting that it has started to see cyberattacks using the vulnerability on targets in the wild.
“Tenable has also received a report that attackers are exploiting CVE-2020-3580 in the wild,” according to its Thursday alert. “With this new information, Tenable recommends that organizations prioritize patching CVE-2020-3580.”
And indeed, the PT PoC tweet was met with plenty of “Ooh thanks” and “thank you so much” responses, presumably from would-be hackers.
See Also: New iPhone Bug Breaks Your WiFi: Here’s The Fix
Meanwhile, researchers at WebSec noted that the bug could be exploited for more than XSS:
You could have gotten 2 CVE numbers for this, as this is not just XSS but also CSRF.
— WebSec (@websecnl) June 25, 2021
“Researchers often develop PoCs before reporting a vulnerability to a developer and publishing them allows other researchers to both check their work and potentially dig further and discover other issues,” Claire Tills, senior research engineer at Tenable, told Threatpost. “PoCs can also be used by defenders to develop detections for vulnerabilities. Unfortunately, giving that valuable information to defenders means it can also end up in the hands of attackers.”
Given that a patch has been available for this vulnerability for several months, organizations are able to protect themselves which isn’t the case with 0-day disclosures, she pointed out. “However, unpatched vulnerabilities continue to haunt many organizations,” Tillis added. “The public availability of a PoC is another stark reminder that effective patching is a vital step for organizations to protect themselves.” Real-World Attacks for Cisco ASAThe Cisco ASA is a cybersecurity perimeter-defense appliance that combines firewall, antivirus, intrusion prevention and virtual private network (VPN) capabilities, all meant to stop threats from making it onto corporate networks. A compromise of the device is akin to unlocking the front door of the castle for storming cyberattackers.
See Also: Offensive Security Tool: Pixload
XSS attacks occur when malicious scripts are injected into otherwise benign and trusted websites; any visitors to the compromised websites are thus subject to drive-by attacks.
Successful exploitation in this case means that unauthenticated, remote attackers could “execute arbitrary code within the [ASA] interface and access sensitive, browser-based information,” Tenable added.
Once in, they could modify the device’s configuration, according to Leo Pate, an application security consultant at nVisium.
However, the target would need to be logged into the ASA for the attackers to see any joy. “While th[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: Andrian Lamo – The ‘homeless’ Hackerhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="3193330934"
data-ad-format="auto"
data-full-width-responsive="true">
Post Views: 105
Reading Time: 6 Minutes
Adrian Lamo was a hacker that found new ways to challenge companies to re-think how secure they were. From hacking his way into the most prestigious companies while living out of a backpack to being called a “snitch” from the hacker community, Adrian was a highly controversial figure in the hacking world.
Early Days – Back Story
Adrián Alfonso Lamo Atwood was born in Malden, Massachusetts, U.S, on February 20th, 1981. He attended high school in San Francisco, but he dropped out after many arguments with his teachers. He did not graduate but he received a GED and then studied journalism at the American River College in Carmichael, California.
His computer skills were mainly self-taught. Adrian got his first computer, a Commodore 64 at a young age. He then became interested and familiar with software hacking by experimenting with coding that was used to create the video games that he loved to play.
His hacking journey started by hacking into computer games, creating viruses on floppy disks, and eventually practicing with phone phreaking. He was able to make free long-distance calls by tapping into stranger’s phone lines and finding ways to spoof his calls from the phone companies to go undetected.
First Steps in Hacking
In the mid-90s he started using a simple web browser and explorer the web to find holes in the security of companies.
He was unknowingly driven by the so-called Hacker culture, where individuals enjoy the intellectual challenge of overcoming the limitations of software systems using their creativity to achieve their individual goals. It’s not about how big the companies were or how sensitive the information was, but more about the odds of finding something that was never being found before.
Describing the security of the companies back then, he would say that was not all that challenging to find security holes in their systems. He would try to take the available information resources and arrange them in improbable ways, not spending time to download databases or leak any customer information.
He began exploring the Web by spending countless hours at the Public Library of San Francisco, using their Internet terminals to telnet out to other systems, including the ones that let him use their modems to dial out.
Security holes everywhere, living out of a backpack.
In 1997, AOL introduced one of the first instant messaging services, after ICQ in 1996 and the dot.com bubble was starting to form. Adrian was watching the explosion of activity on the Internet with a mixture of excitement and worry about the dangers that no one could see.
Living out of a backpack, he would then spend a couple of years traveling the country on a bus, sleeping in abandoned buildings and on friends’ couches while getting online from university libraries and Kinko’s laptop stations.
During this time, he’d been sleeping in an abandoned building underneath Philadelphia’s Ben Franklin Bridge when he discovered security vulnerabilities at Excite@Home, he would inform the executives but no action was taken at first. He would even start helping customers and trying to fix their problems that were reported as helpdesk tickets when the co[...]
Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: Andrian Lamo – The ‘homeless’ Hackerhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="3193330934"
data-ad-format="auto"
data-full-width-responsive="true">
Post Views: 105
Reading Time: 6 Minutes
Adrian Lamo was a hacker that found new ways to challenge companies to re-think how secure they were. From hacking his way into the most prestigious companies while living out of a backpack to being called a “snitch” from the hacker community, Adrian was a highly controversial figure in the hacking world.
Early Days – Back Story
Adrián Alfonso Lamo Atwood was born in Malden, Massachusetts, U.S, on February 20th, 1981. He attended high school in San Francisco, but he dropped out after many arguments with his teachers. He did not graduate but he received a GED and then studied journalism at the American River College in Carmichael, California.
His computer skills were mainly self-taught. Adrian got his first computer, a Commodore 64 at a young age. He then became interested and familiar with software hacking by experimenting with coding that was used to create the video games that he loved to play.
His hacking journey started by hacking into computer games, creating viruses on floppy disks, and eventually practicing with phone phreaking. He was able to make free long-distance calls by tapping into stranger’s phone lines and finding ways to spoof his calls from the phone companies to go undetected.
First Steps in Hacking
In the mid-90s he started using a simple web browser and explorer the web to find holes in the security of companies.
He was unknowingly driven by the so-called Hacker culture, where individuals enjoy the intellectual challenge of overcoming the limitations of software systems using their creativity to achieve their individual goals. It’s not about how big the companies were or how sensitive the information was, but more about the odds of finding something that was never being found before.
Describing the security of the companies back then, he would say that was not all that challenging to find security holes in their systems. He would try to take the available information resources and arrange them in improbable ways, not spending time to download databases or leak any customer information.
He began exploring the Web by spending countless hours at the Public Library of San Francisco, using their Internet terminals to telnet out to other systems, including the ones that let him use their modems to dial out.
Security holes everywhere, living out of a backpack.
In 1997, AOL introduced one of the first instant messaging services, after ICQ in 1996 and the dot.com bubble was starting to form. Adrian was watching the explosion of activity on the Internet with a mixture of excitement and worry about the dangers that no one could see.
Living out of a backpack, he would then spend a couple of years traveling the country on a bus, sleeping in abandoned buildings and on friends’ couches while getting online from university libraries and Kinko’s laptop stations.
During this time, he’d been sleeping in an abandoned building underneath Philadelphia’s Ben Franklin Bridge when he discovered security vulnerabilities at Excite@Home, he would inform the executives but no action was taken at first. He would even start helping customers and trying to fix their problems that were reported as helpdesk tickets when the co[...]
Black Hat Ethical Hacking
Cisco ASA Bug Now Actively Exploited as PoC Drops
Cisco ASA Bug Now Actively Exploited as PoC Drops
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: Andrian Lamo – The ‘homeless’ Hackerhttps://www.blackha…
mpany was not even taking action for them.
His first ISP was AOL, and he was curious to know what went on behind the scenes. He found multiple vulnerabilities and he was able to crack into the company’s network.
As a teenager, Adrian became known in the early 2000s with a string of attacks against large companies, mostly harmless though. Trying to prove a point, that if someone like Andrian Lamo, who was borrowing internet from a local Kinko’s could crack into companies like AOL, Yahoo, Microsoft, and even New York Times with such ease, anyone could. He was cracking misconfigured proxy servers, allowing him to bypass the corporate firewalls. He got into an unprotected CMS tool at Yahoo’s news site, and tried to alert the company, just like he did with the other vulnerabilities he found on other companies but no one was giving him attention. The only way to give attention and fix their problems was to go to the press and make the story known. Reuters wrote the story and things got heated quickly.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Lamo-Mitnick-Poulsen.png
Adrian Lamo (left) and Wired's Kevin Poulsen (right) in 2001. The person in the middle, Kevin Mitnick, had no involvement in the Manning case. - source: Wikipedia
New York Times hack and charges from the FBI
In 2002, he penetrated the internal network of the well-known newspaper, ‘The New York Times’, and decided to have some fun. He managed to give himself admin credentials and gained access to a database containing data of over 3000 contributors of the newspaper. He then added himself to the paper’s internal database of experts, as a “hacking expert”. The Times was not having any of it and contacted the FBI to begin the investigation. In 2003, the FBI issued a warrant for Adrian’s arrest and in 2004 he pleaded guilty, resulting in a fine and six months of home detention, followed by two years of probation. But he knew that even after that, that the federal authorities were constantly monitoring him.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker.gif
FBI Report: HOPE conference 2010 - source: www.npr.org
Asperger’s Syndrome Diagnosis
In 2010, Lamo joined the growing list of computer hackers who’ve been diagnosed with Asperger’s, like Gary McKinnon and Albert Gonzalez.
Usually, the diagnosis comes when the hacker faces the criminal justice system for the first time, rather than six years later, like Lamo’s case. The article was written by the reporter Kevin Poulsen, who was himself a former hacker and published by Wired.
WikiLeaks – Chelsea Manning case
Chelsea Manning was a former US soldier (formerly Bradley Manning) and known for being an activist and a whistleblower.
In 2010, Chelsea, who was in Baghdad at the time, was already pending discharge for “adjustment disorder” (gender identity disorder) because she expressed her uncertain feelings over her (his at the time) gender identity, causing her to lose her job as a soldier.
She contacted Adrian on May 20th, 2010 via encrypted emails because she was already aware of his hacking incidents back in the 2000s. She felt isolated and fragile and she thought Adrian was someone that might understand her situation.
He was unable to decrypt them but replied anyway, and invited the emailer (Chelsea) to chat on AOL messenger. In a series of chats between May 21 and May 25, Chelsea, using the nickname bradass87, and introducing herself as an Army intelligence officer, without waiting for a reply, alluded the leaks to Adrian. He then replied to her, and talk about restricted material in general. She then referenced a version of Wikipedia’s article on Wikileaks and indicated that some of the sections about the leaked Baghdad airstrike video were her leaks as well.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/chats1-1024x153.png https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/chats2.png [...]
His first ISP was AOL, and he was curious to know what went on behind the scenes. He found multiple vulnerabilities and he was able to crack into the company’s network.
As a teenager, Adrian became known in the early 2000s with a string of attacks against large companies, mostly harmless though. Trying to prove a point, that if someone like Andrian Lamo, who was borrowing internet from a local Kinko’s could crack into companies like AOL, Yahoo, Microsoft, and even New York Times with such ease, anyone could. He was cracking misconfigured proxy servers, allowing him to bypass the corporate firewalls. He got into an unprotected CMS tool at Yahoo’s news site, and tried to alert the company, just like he did with the other vulnerabilities he found on other companies but no one was giving him attention. The only way to give attention and fix their problems was to go to the press and make the story known. Reuters wrote the story and things got heated quickly.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Lamo-Mitnick-Poulsen.png
Adrian Lamo (left) and Wired's Kevin Poulsen (right) in 2001. The person in the middle, Kevin Mitnick, had no involvement in the Manning case. - source: Wikipedia
New York Times hack and charges from the FBI
In 2002, he penetrated the internal network of the well-known newspaper, ‘The New York Times’, and decided to have some fun. He managed to give himself admin credentials and gained access to a database containing data of over 3000 contributors of the newspaper. He then added himself to the paper’s internal database of experts, as a “hacking expert”. The Times was not having any of it and contacted the FBI to begin the investigation. In 2003, the FBI issued a warrant for Adrian’s arrest and in 2004 he pleaded guilty, resulting in a fine and six months of home detention, followed by two years of probation. But he knew that even after that, that the federal authorities were constantly monitoring him.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker.gif
FBI Report: HOPE conference 2010 - source: www.npr.org
Asperger’s Syndrome Diagnosis
In 2010, Lamo joined the growing list of computer hackers who’ve been diagnosed with Asperger’s, like Gary McKinnon and Albert Gonzalez.
Usually, the diagnosis comes when the hacker faces the criminal justice system for the first time, rather than six years later, like Lamo’s case. The article was written by the reporter Kevin Poulsen, who was himself a former hacker and published by Wired.
WikiLeaks – Chelsea Manning case
Chelsea Manning was a former US soldier (formerly Bradley Manning) and known for being an activist and a whistleblower.
In 2010, Chelsea, who was in Baghdad at the time, was already pending discharge for “adjustment disorder” (gender identity disorder) because she expressed her uncertain feelings over her (his at the time) gender identity, causing her to lose her job as a soldier.
She contacted Adrian on May 20th, 2010 via encrypted emails because she was already aware of his hacking incidents back in the 2000s. She felt isolated and fragile and she thought Adrian was someone that might understand her situation.
He was unable to decrypt them but replied anyway, and invited the emailer (Chelsea) to chat on AOL messenger. In a series of chats between May 21 and May 25, Chelsea, using the nickname bradass87, and introducing herself as an Army intelligence officer, without waiting for a reply, alluded the leaks to Adrian. He then replied to her, and talk about restricted material in general. She then referenced a version of Wikipedia’s article on Wikileaks and indicated that some of the sections about the leaked Baghdad airstrike video were her leaks as well.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/chats1-1024x153.png https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/chats2.png [...]