Reader Ad Slot
Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.
Adrian Lamo — Part 2
Page 291
291 / 363
SecurityFocus HOME News: ; Lamo charged with computer ime Page 2 of 5
company of a camera crew producing a television documentary on hackers.
“T have always said that actions have consequences, and this is something that I was always aware might
happen," said Lamo. “I don't intend to deny anything that I have done, but I do intend to defend myself
vigorously.”
The 22-year-old Lamo has become famous for publicly exposing gaping security holes at large
corporations, then voluntarily helping the companies fix the vulnerabilities he exploited -- sometimes
visiting their offices or signing non-disclosure agreements in the process.
Until now, his cooperation and transparency have kept him from being prosecuted. Lamo’s hacked
Excite@Home, Yahoo, Blogger, and other companies, usually using nothing more than an ordinary Web
browser. Some companies have even professed gratitude for his efforts: In December, 2001, Lamo was
praised by communications giant WorldCom after he discovered, then helped close, security holes in their
intranet that threatened to expose the private networks of Bank of America, CitiCorp, JP Morgan, and
others.
Lamo believes the arrest warrant is for his most high-profile hack. Early last year he penetrated the New
York Times, after a two-minute scan turned up seven misconfigured proxy servers acting as doorways
between the public Internet and the Times private intranet, making the latter accessible to anyone
capable of properly configuring their Web browser.
RELATED STORIES
e Panel Debates Hacker
Once inside, Lamo exploited weaknesses in the Times password
Amnesty policies to broaden his access, eventually browsing such disparate
e New York Times internal information as the names and Social Security numbers of the paper's
Network Hacked employees, logs of home delivery customers' stop and start orders,
» Who Is Adrian Lamo? instructions and computer dia!-ups for stringers to file stories, lists of
: Yahoo! News Hacked contacts used by the Metro and Business desks, and the “WireWatch"
Excite@Home Data keywords particular reporters had selected for monitoring wire
services.
He also accessed a database of 3,000 contributors to the Times op-ed page, containing such information
as the social security numbers for former U.N. weapons inspector Richard Butler, Democratic operative
James Carville, ex-NSA chief Bobby Inman, Nannygate veteran Zoe Baird, former secretary of state
James Baker, Internet policy thinker Larry Lessig, and thespian activist Robert Redford. Entries with home
telephone numbers include Lawrence Walsh, William F. Buckley Jr., Jeanne Kirkpatrick, Rush Limbaugh,
Vint Cerf, Warren Beatty and former president Jimmy Carter.
In February, 2002, Lamo told the Times of their vulnerability through a SecurityFocus reporter. But this
time, no one was grateful, and by May federal prosecutors in New York had begun an investigation.
“I think this is unsporting of the New York Times," Lamo said Thursday.
Lamo's mother said she has no opinion on her son's exploits. She's just worried about him.
"I don't really know much of anything about computers,” says Mary Lamo. "He’s my son. Right now, all I
can worry about is how I can help him.”
"I hope there will be a time when Adrian can do positive things that everyone agrees are positive," she
adds.
ded, pa ee
http:/Awww.securityfocus.com/news/6888 9/8/2003
FBI(19-cv-1495)-1064
Reveal the original PDF page, then click a word to highlight the OCR text.
Community corrections
No user corrections yet.
Comments
No comments on this document yet.
Bottom Reader Ad Slot
Bottom Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.
Continue Exploring
Agency Collection
Explore This Archive Cluster
Broad Topic Hub
Topic Hub
letter
bureau
Related subtopics
Subtopic
Subtopic
Subtopic
Subtopic
Subtopic
Subtopic