31.10.2012 Views

We are anonymous inside the hacker world of lulzse

We are anonymous inside the hacker world of lulzse

We are anonymous inside the hacker world of lulzse

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

“I’ll go away and hack it, come back with access and let people go mad,” she said. Kayla couldn’t help herself most <strong>of</strong> <strong>the</strong> time anyway. If<br />

she was reading something online she would habitually start playing around with <strong>the</strong>ir parameters and login scripts. More <strong>of</strong>ten than not, she<br />

would find something wrong with <strong>the</strong>m.<br />

Still, working for q gave Kayla a bigger excuse to go after <strong>the</strong> .gov and .mil targets, particularly those <strong>of</strong> third-<strong>world</strong> countries in Africa or<br />

South America, which were easier to get access to than those in more developed countries. Every day was a search for new targets and a new<br />

hack. Kayla never found anything as big as, say, <strong>the</strong> HBGary e-mail hoard for q, but she did, for instance, find vulnerabilities in <strong>the</strong> main<br />

website for <strong>the</strong> United Nations. In April 2011, Kayla started putting toge<strong>the</strong>r a list <strong>of</strong> United Nations “vulns.” This, for example:<br />

http://www.un.org.al/subindex.php?faqe=details&id=57<br />

was a United Nations server that was vulnerable to SQL injection, specifically subindex.php. And this page at <strong>the</strong> time:<br />

http://www.un.org.al/subindex.php?faqe=details&id=57%27<br />

would throw an SQL error, meaning Kayla or anyone else could inject SQL statements and suck out <strong>the</strong> database. The original URL didn’t<br />

have %27 at <strong>the</strong> end, but Kayla’s simply adding that after testing <strong>the</strong> parameters <strong>of</strong> php/asp scripts helped her find <strong>the</strong> error messages.<br />

Kayla eventually got access to hundreds <strong>of</strong> passwords for government contractors and lots <strong>of</strong> military e-mail addresses. The latter were<br />

worthless, since <strong>the</strong> military uses a token system for e-mail that is built into a computer chip on an individual’s ID card, and it requires a PIN<br />

and a certificate on <strong>the</strong> card before anyone is able to access anything.<br />

It was boring and repetitive work, trawling through lists <strong>of</strong> e-mail addresses, looking for dumps from o<strong>the</strong>r <strong>hacker</strong>s, and hunting for<br />

anything government or military related. But Kayla was said to be happy doing it. Every week or so, she would meet on IRC with q and pass<br />

over <strong>the</strong> collected info via encrypted e-mail, <strong>the</strong>n await fur<strong>the</strong>r instructions. If she asked what Julian Assange thought <strong>of</strong> what she was doing,<br />

q would say he approved <strong>of</strong> what was going on.<br />

It turned out that q was good at lying.<br />

Almost a year after Kayla started volunteering for WikiLeaks, o<strong>the</strong>r <strong>hacker</strong>s who had been working with q found out he was a rogue<br />

operator who had recruited <strong>the</strong>m without Assange’s knowledge. In late 2011, Assange asked q to leave <strong>the</strong> organization. Kayla was not <strong>the</strong><br />

only volunteer looking for information for what she thought was WikiLeaks. The rogue operator had also gotten o<strong>the</strong>r <strong>hacker</strong>s to work with<br />

him on false pretenses. And in addition, one source claims, q stole $60,000 from <strong>the</strong> WikiLeaks t-shirt shop and transferred <strong>the</strong> money into<br />

his personal account. WikiLeaks never found out what q was doing with <strong>the</strong> vulnerabilities that Kayla and o<strong>the</strong>r <strong>hacker</strong>s found, though it is<br />

possible he sold <strong>the</strong>m to o<strong>the</strong>rs in <strong>the</strong> criminal under<strong>world</strong>. It seemed, ei<strong>the</strong>r way, like q did not really c<strong>are</strong> about unearthing government<br />

corruption, and Kayla, a master at hiding her true identity from even her closest online friends, had been duped.<br />

None <strong>of</strong> this mattered come February <strong>of</strong> 2011 when Kayla began talking with Tflow, Topiary, and Sabu in <strong>the</strong> exclusive new chat room<br />

that would bring <strong>the</strong>m toge<strong>the</strong>r for a landmark heist on Super Bowl Sunday: <strong>the</strong> attack on HBGary Federal. The bigger secret, which Kayla<br />

didn’t know <strong>the</strong>n, was that Sabu would not only get her deeper into a <strong>world</strong> <strong>of</strong> hacking that would become front-page news, but watch as her<br />

details got passed on directly to <strong>the</strong> FBI.<br />

Chapter 11<br />

The Aftermath<br />

It was February 8, 2011, two days after Super Bowl Sunday. Aaron Barr was grabbing shirts out <strong>of</strong> his closet, quickly folding <strong>the</strong>m, and<br />

placing <strong>the</strong>m into <strong>the</strong> medium-size suitcase that rested on <strong>the</strong> bed in front <strong>of</strong> him. This was no mad rush, but Barr had to move. He had spent<br />

fifteen years in <strong>the</strong> military, and he and his family were now expert travelers. They made <strong>the</strong>ir preparations quickly and with quiet efficiency.<br />

His wife was packing a separate bag, <strong>the</strong> silence interrupted only by <strong>the</strong> occasional question about traveling arrangements. Just two hours<br />

before, Barr had been back in his study catching up on <strong>the</strong> flood <strong>of</strong> news stories about <strong>the</strong> HBGary attack and <strong>the</strong> new, disastrous view <strong>the</strong><br />

media was taking <strong>of</strong> Barr’s proposals to Hunton & Williams against WikiLeaks and Glenn Greenwald.<br />

Learning about <strong>the</strong> Anonymous hack had been stressful for him. But <strong>the</strong> media’s feast on his controversial e-mails was having a definite<br />

effect on his blood pressure. Barr longed to correct each story, but lawyers had told him to stay quiet for now. All he could do was read and<br />

grit his teeth. Occasionally, curiosity would overcome his better judgment and he would dip into <strong>the</strong> AnonOps IRC rooms under a<br />

pseudonym to see what <strong>the</strong> Anons were saying. He was still a laughingstock for <strong>the</strong> hundreds <strong>of</strong> participants hungry to see Barr humiliated in<br />

new ways. There were calls for anyone who lived in Washington, D.C., to drive past Barr’s house and take pictures or to send him things in<br />

<strong>the</strong> mail—he received a blind person’s walking cane and a truckful <strong>of</strong> empty boxes. He also got one pizza. A couple <strong>of</strong> people had randomly<br />

shown up at his front door, and one had tried to take pictures <strong>of</strong> <strong>the</strong> <strong>inside</strong> <strong>of</strong> his house. Barr had been disturbed but had just sent <strong>the</strong>m away,<br />

figuring this was mostly harmless. Then, a couple <strong>of</strong> hours earlier, he had visited Reddit, a snarky forum site that had become increasingly<br />

popular with people who liked 4chan but wanted more intelligent discussion. A user had posted <strong>the</strong> Forbes interview with Barr from <strong>the</strong><br />

preceding Monday, and amid <strong>the</strong> analysis and machismo in <strong>the</strong> 228 resulting comments, <strong>the</strong>re were a few nasty suggestions about Barr’s<br />

kids. It was most likely just talk, but Barr didn’t want to take any more chances. It took only one nutjob to pull a trigger, after all. Minutes<br />

later, he had talked to his wife, and <strong>the</strong> two started packing.<br />

That afternoon <strong>the</strong> family loaded everything into <strong>the</strong>ir car, <strong>the</strong> twins thinking <strong>the</strong>y were about to embark on some exciting road trip. Barr’s<br />

wife and kids drove south to stay with a friend for two weeks while Barr hopped on a plane to Sacramento. This was where HBGary Inc.<br />

was headquartered and where Barr would get into <strong>the</strong> cleanup job and start to help <strong>the</strong> police with <strong>the</strong>ir investigation.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!