Reader Ad Slot
Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.
Adrian Lamo — Part 3
Page 3
3 / 501
TRATIETEIINI
b6é -1,2
02/26/2002 08:11 PM b7c -1,2
To:
ce:
Subject: NYT Hacker Article just posted --
http://online.securityfocus.com/news/342NEWS
New York Times Internal Network Hacked
How open proxies and default passwords led to Adrian Lamo padding his rolodex with
information on 3,000
op-ed writers, from William F. Buckley Jr. to Jimmy Carter.
By Kevin Poulsen
Feb 26 2002 4:15PM PT
Security holes in the New York Times internal network left sensitive databases exposed to
hackers, ineluding a file
containing social security numbers and home phone numbers for contributors to the Times op-ed
page, SecurityFocus °
Online has learned.
In a two-minute scan performed on a whim, twenty-one-year-old hacker and sometimes-security
consultant Adrian Lamo .
discovered no less than seven misconfigured proxy servers acting as doorways between the
public Internet and the
Times' private intranet, making the latter accessible to anyone capable of properly configuring
their Web browser. -
“The very first server | looked at was running an open proxy," says Lamo. “The server
practically approached me."
Once on the newspaper's network, Lame exploited weaknesses in the Times password
policies to broaden his access, eventually browsing such disparate information as the
names and social security numbers of the paper's employees, logs of home delivery
customers’ stop and start orders, instructions and computer dial-ups for stringers to file
stories, lists of contacts used by the Metro and Business desks, and the “WireWatch"
keywords particular reporters had selected for monitoring wire services.
But measured by sheer star power, the hack is most notable for Lamo's access to a
database of 3,000 contributors to the Times op-ed page, the august soap box of the
cultural elite and politically powerful.
The roster includes social security numbers for former U.N. weapons inspector Richard Butler,
Democratic operative
James Carville, ex-NSA chief Bobby Inman, Nannygate veteran Zoe Baird, former secretary of
state James Baker,
FBI(19-cv-1495)-1607
Reveal the original PDF page, then click a word to highlight the OCR text.
Community corrections
No user corrections yet.
Comments
No comments on this document yet.
Bottom Reader Ad Slot
Bottom Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.
Continue Exploring
Reader
Topic
Agency Collection
Explore This Archive Cluster
Broad Topic Hub
Topic Hub
letter
bureau
Related subtopics
Subtopic
Subtopic
Subtopic
Subtopic
Subtopic
Subtopic