Feeds

Web defacer sentenced, facing deportation

Still that NASA business though...

Providing a secure and efficient Helpdesk

Rafael Nuñez-Aponte will soon be going home to Caracas after spending seven months in a U.S. jail for compromising a computer belonging to the Department of Defense, but only if the National Aeronautics and Space Administration decides not to pursue charges against him.

Last week, a U.S. district court sentenced the Venezuelan security professional to time served - about seven months - for defacing an Air Force training Web site in June 2001 under the monicker "Rafa" as part of the online vandal group, World of Hell. The sentence followed a plea agreement between prosecutors and Nuñez signed in July.

"We were happy with the court's sentence," said Scott T. Varholak, the public defender representing Nuñez. "I think the court took into account Mr. Nuñez's character and that he has done a lot of good things since that time."

U.S. immigration officials have taken custody of Nuñez and he will be deported, Varholak said. The process typically takes about two weeks. However, other security incidents attributed to Rafa could delay his departure from the United States. The National Aeronautics and Space Administration (NASA) could attempt to hold Nuñez responsible for sensitive documents allegedly stolen by Rafa in 2002. Rafa allegedly took over 40MB of data regarding NASA's next-generation launch vehicles from a contractor's computer, according to press reports at the time.

A source at the U.S. Department of Justice stressed that the plea agreement and conviction only apply to the incident involving the U.S. Air Force. The source, who asked not to be named, said that Nuñez could be charged for other crimes. However, NASA investigators refused to comment on any possible future prosecution.

Nuñez's sentencing is the latest success for U.S. prosecutors against online vandals and cybercriminals. In February, prosecutors elicited a guilty plea from Nicolas Lee Jacobsen on charges of unauthorized access into the computers of telecommunications company T-Mobile. Microsoft helped German authorities track down and convict the creator of the Sasser worm, Sven Jaschan. In Europe, prosecutors have brought cases against the alleged online attackers suspected of creating networks of compromised computers, known as bot nets.

U.S. immigration officials arrested Nuñez on April 2 when he arrived in Miami for a conference. Nuñez had been working for Venezuelan telecommunications company CANTV in computer security and had previously worked for the Venezuelan subsidiary of Scientech. Law enforcement officials then moved the 26-year-old Venezuelan to Denver, Colorado, where he was charged.

The plea agreement, announced in July, stipulated that, under the monicker "Rafa," Nuñez joined a hacker group known as World of Hell, which prided itself on highlighting weaknesses in the security of government and corporate computers. A site run by the Defense Information Systems Agency (DISA) for the U.S. Air Force was among the Web sites defaced by Rafa, the agreement stated. Nuñez plead guilty to "intentionally damaging" that computer and causing $10,548 in damage.

"The plea agreement simply addresses his admission regarding this crime," said Jeffrey Dorschner, spokesman for the U.S. Attorney's office in Denver. "The U.S. sentencing guidelines takes into account his prior criminal history and the financial impact of the crime, but also whether he takes responsibility for his actions."

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.