Feeds

Man admits writing script that slurped celebrity iPad data

Goatse troll first to fall

Providing a secure and efficient Helpdesk

A San Francisco man has admitted writing the code that plucked personal data of 120,000 early iPad adopters from servers AT&T had left wide open to the attack.

Daniel Spitler, 26, pleaded guilty in federal court in New Jersey to one count each of identity theft and conspiracy to gain unauthorized access to internet-connected computers, prosecutors said. A member of the troll and griefer collective known as Goatse Security, he surrendered to authorities in January, when he and alleged accomplice, Andrew Auernheimer, were criminally charged in the hack.

Auernheimer, aka Weev, has pleaded not guilty.

According to prosecutors, Spitler, Auernheimer, and other Goatse members identified a vulnerability on AT&T's servers that mapped an iPad's ICC-ID, or integrated circuit card identifier, to the name and email address of its owner.

Spitler admitted he was the one who wrote the "iPad 3G Account Slurper" script, which exploited the flaw to harvest as much data as possible. It worked by injecting large numbers of possible ICC-IDs into AT&T web addresses and recording the information that was returned each time it successfully guessed a valid number. For the attack to work, Spitler had to make his code mimic characteristics of the iPad.

In all, the attack mined the names and email addresses of about 120,000 elite iPad owners, including senior members of the White House, celebrities, journalists and wealthy financiers. The list also included top people inside some of the nation's most sensitive organizations, including William Eldredge, who commanded the largest strategic bomber group in the US Air Force.

By exposing their names and private email addresses, the vulnerability could have opened the iPad owners up to spear phishing attacks.

AT&T closed the vulnerability only after it was brought to their attention by Gawker, the publication that first reported the attack. The underlying bug, known as an insecure direct object reference, is the same kind of sloppy oversight that led to the recent leak banking data for more than 360,000 customers of Citigroup.

Spitler faces a maximum penalty of five years in federal prison and a $250,000 fine at sentencing, which is scheduled for September 28.

A sentence that stiff is probably overkill, considering there is no public evidence the hackers victimized any of the people whose information was needlessly leaked. (There is evidence some members considered spamming them, however.) Indeed, by bragging of their conquest to the media, they helped make sure AT&T fixed the vulnerability quickly. A more hardened gang of attackers would have been more tight lipped about the theft so the data could be used to mount stealthy attacks.

That doesn't mean Spitler and his alleged accomplices didn't break the law. And any time White House staffers and other powerful people are targeted in a hacking crime, you can be sure there will be consequences.

Members of other hacker collectives, take note. ®

New hybrid storage solutions

More from The Register

next story
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.