Welcome | Sign In
ECommerceTimes.com
Network Intrusion

Alien-Hunting UK Hacker Coming to America

Print Version
E-Mail Article
Reprints
Alien-Hunting UK Hacker Coming to America

A UK hacker of modest abilities who allegedly broke into secure U.S. government computer systems in search of UFO conspiracy-theory evidence has lost his fight against extradition. The British House of Lords was unmoved by Gary McKinnon's argument that he would be subject to U.S. terrorist sentencing guidelines, but McKinnon still has one avenue of appeal: the European Court of Human Rights.


The British House of Lords has decided to extradite Gary McKinnon, a British citizen who hacked his way into several U.S. military, defense and NASA computers, to the United States to stand trial. McKinnon has been fighting extradition since the discovery in 2002 that he was the one who broke into the U.S. government's most sensitive networks -- reportedly from a friend's aunt's house -- between 2001 and 2002. He allegedly caused US$900,000 in damages to computers located in 14 states.

What is remarkable about McKinnon's case is that he managed this feat with little high-level hacker expertise -- and that his quest was not for military secrets or sensitive design plans, but for secret documents that would reveal the existence of alien life. In interviews with news media, McKinnon claims his search was successful, uncovering photographs of alien spacecraft and the names and ranks of "non-terrestrial officers."

Terrorist Charges

The U.S. government does not place much weight on McKinnon's odd motives. McKinnon reportedly left a note on an Army computer criticizing U.S. foreign policy as government-sponsored terrorism.

In the indictment against him, the U.S. government accuses McKinnon of handicapping it in the aftermath of September 11.

"The entire network of 300 computers at NWS Earle, located in Colts Neck, N.J., was effectively shut down for an entire week. ... [F]or another three weeks afterward, military personnel and government civilian employees at NWSE were only able to send and receive internal e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse. It was only approximately a month after McKinnon's last intrusion into the network that NWS Earle was able to automatically route Naval message traffic and access the Internet," according to the indictment.

In fighting extradition, McKinnon maintained that a trial in the U.S. could subject him to terrorist sentencing guidelines. With the House of Lords rejecting that argument, he has just one other option: appealing to the European Court of Human Rights.

Patchy Security

That McKinnon was able to access secure government information using basic hacking software is not all that remarkable, said Matt Shanahan, SVP of marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales and strategy for AdmitOne Security.

"In most cases, when people hack into a system -- the vast majority of the time -- they are able to get in because reasonable controls were not in place," he told TechNewsWorld. "In the case of McKinnon, there were a number of devices the systems administrator had not set."

A highly fragmented systems administration environment, together with the fact that a lot of controls are manual, usually results in some vulnerability, Shanahan said.

"People usually forget to set something, or they are using a virtual machine that might not have been set up correctly and then copies the same mistake 100 times," he explained. "McKinnon was able to find, and then take advantage of, these vulnerabilities."

The answer is reducing fragmentation as much as possible, Shanahan suggested, and automating the process instead of relying on individuals to make necessary adjustments.

No doubt, a red-faced U.S. administration has patched the vulnerabilities that McKinnon was able to exploit.

Still Vulnerable

What is worrisome is that high-level professional hackers still have ways to access these systems if they want to, said Bill Johnson, CEO of TDI.

"We have become a big proponent of securing the computer baseboard manager controller, or BMC," he told TechNewsWorld.

The BMC is network-accessible once a hacker can get past the firewall, and it allows command and control of the main motherboard, he said.

"Even systems in NASA would be vulnerable to this method of attack," noted Johnson.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Roku Channel Store Hangs Out Shingle
November 23, 2009
Roku's new channel store is based on a "one screen in the cloud" business model, said Michael Gartenberg, vice president of strategy and analysis with Interpret. "Essentially, what they are doing is taking the TV set -- whether it is a standard appliance or a high-def monster -- and enhancing it with content the consumer wants to see."
Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network