Security experts' sites hacked on eve of Black Hat conference

By Elinor Mills, CNET News.com
Thursday, July 30, 2009 10:37 AM

Web sites of a handful of security experts and groups were hacked and passwords, e-mail messages, IM chats and other information was posted on the Internet on Tuesday, the eve of the Black Hat security conference.

Targeted were Dan Kaminsky, known for his discovery of a high-profile flaw in the domain name system last year; Kevin Mitnick, one of the first hackers to be prosecuted for computer crimes; and the PerlMunks programmer community, among others.

A long treatise was posted to Kaminsky's Web site with the data and criticisms accusing the victims of hyping security threats to advance their careers and lacking security expertise. It's unclear how the sites were breached, but several of the blogs attacked were running on WordPress and there were allusions to vulnerabilities in the software.

"It's just drama," Kaminsky said when asked to comment.

"If there was anything technically interesting to discuss, cool. But I hope that my dating life was interesting," said Kaminsky, who was preparing for an afternoon presentation on problems with X.509, an encryption standard for public key infrastructure. "The impacts of a single event are whatever. There's actual research going on."

Mitnick said someone using a European IP address hacked into his Web hosting provider about 10 days ago and redirected traffic to a site displaying a photo-shopped pornographic image of him. A week later his Web site was breached and the files deleted, most likely by the same people and probably via back doors left behind in the first breach, he said.

"They looked through my Web server but I never keep e-mail or personal files there, only publicly available information," Mitnick said. His hosting provider, a friend, has asked him to leave because of the repeated attacks and erasure of his and other customers' data, he said. As a result, he's switching to FireHost, a host that specializes in security.

Kaminsky, had the "illusion of invulnerability", keeping all his e-mail, research, and personal files on a server connected to the Internet, Mitnick said.

Mitnick, whose site has been successfully hacked four times, said he doesn't host his own Web site so that he can keep his public site separate from his corporate network.

"It was a jackpot," he said of the attack on Kaminsky. "I really respect the guy and I think he's super intelligent in security and yet he was victimized. On a public-facing box you don't keep anything confidential on there."

This article was first published as a blog post on CNET News.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web