Welcome | Sign In
ECommerceTimes.com
Network Intrusion

Alien-Hunting UK Hacker Coming to America

Print Version
E-Mail Article
Reprints
Alien-Hunting UK Hacker Coming to America

A UK hacker of modest abilities who allegedly broke into secure U.S. government computer systems in search of UFO conspiracy-theory evidence has lost his fight against extradition. The British House of Lords was unmoved by Gary McKinnon's argument that he would be subject to U.S. terrorist sentencing guidelines, but McKinnon still has one avenue of appeal: the European Court of Human Rights.


Tips to Integrate Social Media into Your Day-to-Day Media Monitoring
Is social media part of your PR and marketing strategy? This white paper is filled with tips on how to listen to conversations about your brand in the media (social media, print, TV and internet) using the latest tools and techniques. Download Now.

The British House of Lords has decided to extradite Gary McKinnon, a British citizen who hacked his way into several U.S. military, defense and NASA computers, to the United States to stand trial. McKinnon has been fighting extradition since the discovery in 2002 that he was the one who broke into the U.S. government's most sensitive networks -- reportedly from a friend's aunt's house -- between 2001 and 2002. He allegedly caused US$900,000 in damages to computers located in 14 states.

What is remarkable about McKinnon's case is that he managed this feat with little high-level hacker expertise -- and that his quest was not for military secrets or sensitive design plans, but for secret documents that would reveal the existence of alien life. In interviews with news media, McKinnon claims his search was successful, uncovering photographs of alien spacecraft and the names and ranks of "non-terrestrial officers."

Terrorist Charges

The U.S. government does not place much weight on McKinnon's odd motives. McKinnon reportedly left a note on an Army computer criticizing U.S. foreign policy as government-sponsored terrorism.

In the indictment against him, the U.S. government accuses McKinnon of handicapping it in the aftermath of September 11.

"The entire network of 300 computers at NWS Earle, located in Colts Neck, N.J., was effectively shut down for an entire week. ... [F]or another three weeks afterward, military personnel and government civilian employees at NWSE were only able to send and receive internal e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse. It was only approximately a month after McKinnon's last intrusion into the network that NWS Earle was able to automatically route Naval message traffic and access the Internet," according to the indictment.

In fighting extradition, McKinnon maintained that a trial in the U.S. could subject him to terrorist sentencing guidelines. With the House of Lords rejecting that argument, he has just one other option: appealing to the European Court of Human Rights.

Patchy Security

That McKinnon was able to access secure government information using basic hacking software is not all that remarkable, said Matt Shanahan, SVP of marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales and strategy for AdmitOne Security.

"In most cases, when people hack into a system -- the vast majority of the time -- they are able to get in because reasonable controls were not in place," he told TechNewsWorld. "In the case of McKinnon, there were a number of devices the systems administrator had not set."

A highly fragmented systems administration environment, together with the fact that a lot of controls are manual, usually results in some vulnerability, Shanahan said.

"People usually forget to set something, or they are using a virtual machine that might not have been set up correctly and then copies the same mistake 100 times," he explained. "McKinnon was able to find, and then take advantage of, these vulnerabilities."

The answer is reducing fragmentation as much as possible, Shanahan suggested, and automating the process instead of relying on individuals to make necessary adjustments.

No doubt, a red-faced U.S. administration has patched the vulnerabilities that McKinnon was able to exploit.

Still Vulnerable

What is worrisome is that high-level professional hackers still have ways to access these systems if they want to, said Bill Johnson, CEO of TDI.

"We have become a big proponent of securing the computer baseboard manager controller, or BMC," he told TechNewsWorld.

The BMC is network-accessible once a hacker can get past the firewall, and it allows command and control of the main motherboard, he said.

"Even systems in NASA would be vulnerable to this method of attack," noted Johnson.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network