Feeds

Hackers eyed sale of celebrity iPad data

Feds charge Goatse trolls

The Essential Guide to IT Transformation

Destroying the evidence

Prosecutors claim that Spitler wrote a script called Account Slurper that attempted to siphon customer data by randomly plugging ICC-IDs into URLs on the AT&T website. When the script used an ID contained in the database, it would automatically open a page containing the customer’s name, email address, and other details. The charges for the equivalent of electronic trespass come even as security experts have roundly criticized AT&T for failing to property lock down the sensitive information.

“The issue it raises is the difference between I can and I may,” said March Rasch, a former federal prosecutor who is now director of cyber security and privacy at CSC, a technology consulting firm in Falls Church, Virginia. “Very frequently, people believe that if they are physically capable of obtaining information off of a webserver that it is the fault of the developer for creating a vulnerability and therefore they are perfectly allowed to exploit that vulnerability and then do anything they want with the information they've obtained. They view it as an unlocked door or even a door that is open.”

That is frequently not the case if the servers store sensitive information that the developers have taken steps to secure, he said.

What's more, the chat transcripts, which included 150 pages provided by a confidential informant, show Auernheimer and Spitler discussing the legal risks of the hack as well as the possibility of destroying the evidence to cover their tracks.

“I would like get rid of your shit like are we gonna do anything else with this data?” Auernheimer wrote in a message on June 10, some 24 hours after the breach became public knowledge.

“No should i toss it?” Spitler responded. The conversation continued:

Auernheimer: I don't think so either might be best to toss.

Spitler: yeah, I don't really give a fuck about it the troll is done

Auernheimer: yes we emerged victorious

Spitler: script is going byebye too.

The discussion could come back to harm the cases of the two men, Rasch told The Register.

“The problem that we have is we have this society of tinkerers that we call hackers and some of them are evil and some of them are what we call greyhat hackers,” he explained. “The greyhat hackers go around and jiggle the doors and jiggle the locks to find out how the locks work. So a lot of it has to do with what you do afterwards.” ®

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
Brit celebs' homes VANISH from Google's Street View
Tony Blair's digs now a Tone-y Blur
Computing student jailed after failing to hand over crypto keys
Sledgehammer once again used to crack a nut
Doctor Who season eight scripts leak online
BBC asks fans to EXTERMINATE copies before they materialise
Snowden leaks latest: NSA, FBI g-men spied on Muslim-American chiefs
US Navy veteran? Lawmaker? Academic? You're all POTENTIAL TERRORISTS
Insecure AVG search tool shoved down users' throats, says US CERT
Sneaky 'foistware' downloads install things you never asked for
That 'wiped' Android phone you bought is stuffed with NAKED SELFIES – possibly
Infosec bods sound alarm after copping eyefuls of nudie pics
Russian MP fears US Secret Service cuffed his son for Snowden swap
Seleznev Jnr is 'prolific trafficker in stolen credit card data', it is alleged
'I don't want to go on the cart' ... OpenSSL revived with survival roadmap
Heartbleed-battered crypto library reveals long path back to health
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
The Power of One eBook: Top reasons to choose HP BladeSystem
Only the Power of One delivers leading infrastructure convergence, availability and scalability with federation, and agility through data center automation.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.