Wednesday, September 26, 2007

Robert Moore Tells How He Broke Into Routers And Stole VoIP Services

Sharon Gaudin writes on InformationWeek:

Convicted hacker Robert Moore, who is set to go to federal prison this week, says breaking into 15 telecommunications companies and hundreds of businesses worldwide was incredibly easy because simple IT mistakes left gaping technical holes.

Moore, 23, of Spokane, Wash., pleaded guilty to conspiracy to commit computer fraud and is slated to begin his two-year sentence on Thursday for his part in a scheme to steal voice over IP services and sell them through a separate company. While prosecutors call co-conspirator Edwin Pena the mastermind of the operation, Moore acted as the hacker, admittedly scanning and breaking into telecom companies and other corporations around the world.

"It's so easy. It's so easy a caveman can do it," Moore told InformationWeek, laughing. "When you've got that many computers at your fingertips, you'd be surprised how many are insecure."

Pena, who is charged with acting as a legitimate wholesaler of Internet-based phone services as part of what the government called a "sophisticated fraud," fled the country a year ago and is wanted as a fugitive. Assistant U.S. Attorney Erez Liebermann said Pena allegedly stole and then sold more than 10 million minutes of service at deeply discounted rates, netting more than $1 million from the scheme.

More here.

Tuesday, July 29, 2008

Metasploit Creator a Victim of His Own Creation - UPDATE

Robert McMillan writes on PC World:

HD Moore has been owned.

That's hacker talk, meaning that Moore, the creator of the popular Metasploit hacking toolkit has become the victim of a computer attack.

It happened on Tuesday morning, when Moore's company, BreakingPoint had some of its Internet traffic redirected to a fake Google page that was being run by a scammer. According to Moore, the hacker was able to do this by launching what's known as a cache poisoning attack on a DNS server on AT&T's network that was serving the Austin, Texas area. One of BreakingPoint's servers was forwarding DNS (Domain Name System) traffic to the AT&T server, so when it was compromised, so was HD Moore's company.

When Moore tried to visit Google.com, he was actually redirected to a fake page that served up a Google page in one HTML frame along with three other pages designed to automatically click on advertisements.

More here.

UPDATE: 10:49 PDT, 30 July 2008: HD Moore has written his account of this interview, and takes issue with several points. -ferg

Thursday, February 19, 2009

FBI: Computer Hacker Fugitive Apprehended and Indicted for Fraud that Victimized Phone Service Providers

Via FBI.gov.

A Miami man charged in 2006 with secretly hacking into the computer networks of unsuspecting Internet phone service providers was indicted today by a federal grand jury, Acting U.S. Attorney Ralph J. Marra announced.

The indictment of Edwin Andres Pena follows his apprehension on Feb. 6 in Mexico, where he now is in custody and awaits extradition. Pena has been a fugitive since posting bond and fleeing prosecution after his arrest in June 2006 in Miami.

Pena, 26, was indicted on fraud and computer hacking charges for his role in a scheme to defraud Voice Over Internet Protocol (VoIP) telephone service providers. Pena, who purported to be a legitimate wholesaler of these Internet-based phone services, allegedly sold discounted service plans to his unsuspecting customers. The Indictment alleges that Pena was able to offer such low prices because he would secretly hack into the computer networks of unsuspecting VoIP providers, including one Newark-based company, to route his customers’ calls.

Through this scheme, Pena is alleged to have sold more than 10 million minutes of Internet phone service to telecom businesses at deeply discounted rates, causing a loss of more than $1.4 million in less than a year. The victimized Newark-based company, which transmits VoIP services for other telecom businesses, was billed for more than 500,000 unauthorized telephone calls routed through its calling network that were “sold” to the defendant’s unwitting customers at those deeply discounted rates, according to the Indictment.

Pena, 26, a permanent legal resident of the United States of Venezuelan origin, allegedly enlisted the help of others, including a professional “hacker” in Spokane, Washington. The hacker, named in the Indictment as Robert Moore, 24, pleaded guilty in the District of New Jersey on March 7, 2007, to federal hacking charges for assisting Pena in this scheme. Moore was sentenced to 24 months in prison on March 8, 2008, and is currently incarcerated. Moore admitted at his plea hearing to conspiring with Pena and to performing an exhaustive scan of computer networks of unsuspecting companies and other entities in the United States and around the world, searching for vulnerable ports to infiltrate their computer networks to use them to route calls.

Pena was first charged on June 6, 2006, in the District of New Jersey in a criminal Complaint that set forth the scheme described in today’s indictment. He was arrested on that Complaint on June 7, 2006, and released the next day on $100,000 bail set by a federal magistrate judge in Florida. Pena appeared in Court in New Jersey on June 29, 2006, and on approximately Aug. 12, 2006, Pena allegedly fled the country to avoid prosecution. He was apprehended by Mexican authorities on Feb 6, 2009, and is currently being held in Mexico on the District of New Jersey’s charges. The United States intends to seek extradition.

More here.

Wednesday, June 07, 2006

Man Carged With Selling Hacked VoIP Services

Ingenious, but (obviously, and needless to say) illegal.

Robert McMillan writes on InfoWorld:

A Miami man was charged Wednesday with stealing more than 10 million minutes of VOIP (Voice over Internet Protocol) telephone service and then selling them to unsuspecting customers for as little as US$0.004 per minute.

Edwin Pena paid a Washington State computer hacker named Robert Moore about $20,000 to help him illegally route Internet telephone calls through the networks of more than 15 unnamed VOIP companies, according to criminal complaints made available by the U.S. Attorney's Office.

Pena presented himself as a legitimate telecommunications wholesaler, while at the same time using hacking techniques to steal networking services valued at as much as $300,000 from each of the carriers.

"They had hoped they had engineered a brilliant toll-free calling network for themselves," said Newark FBI Special Agent Charge Leslie Wiser Jr. in the statement. "They hoped wrong."

More here.

Tuesday, February 10, 2009

Feds Find, Arrest Fugitive Hacker On The Run in Mexico

Sharon Gaudin writes on ComputerWorld:

A Miami man, on the run for more than two years after being arrested and charged with stealing and reselling VoIP services, has been caught in Mexico.

Edwin Pena was arrested in June of 2006 on computer and wire fraud charges. The government charges that from November 2004 to May 2006 Pena and a cohort hacked into the computer networks of VoIP service providers and routed calls of Pena's customers' through them.

According to a criminal complaint filed in U.S. District Court in New Jersey, Pena and co-conspirator Robert Moore of Spokane, Wash., sold more than 10 million minutes of VoIP service stolen from 15 telecommunications providers.

Pena, who is charged with one count of computer fraud and one count of wire fraud, faces a maximum of 25 years in prison.

More here.

Friday, August 10, 2007

VoIP Hacker: Service Provider Nets Easy Pickings

Tim Greene writes on NetworkWorld:

A combination of simple dictionary and brute-force attacks in combination with Google hacking enabled a criminal pair to break into VoIP-provider networks and steal $1 million worth of voice minutes, says one of the duo who has pleaded guilty to his crimes.

Had his victims observed security basics, most of the attacks would have been unsuccessful, says Robert Moore, the 23-year-old hacker from Spokane, Wash., who has been sentenced to two years in federal prison and fined $150,000.

More here.

Tuesday, July 22, 2008

With DNS Flaw Now Public, Attack Code Imminent

Robert McMillan writes on PC World:

One day after a security company accidentally posted details of a serious flaw in the Internet's Domain Name System (DNS), hackers are saying that software that exploits this flaw is sure to pop up soon.

Several hackers are almost certainly already developing attack code for the bug, and it will most likely crop up within the next few days, said Dave Aitel, chief technology officer at security vendor Immunity. His company will eventually develop sample code for its Canvas security testing software too, a task he expects to take about a day, given the simplicity of the attack. "It's not that hard," he said. "You're not looking at a DNA-cracking effort."

The author of one widely used hacking tool said he expected to have an exploit by the end of the day Tuesday. In a telephone interview, HD Moore, author of the Metasploit penetration testing software, agreed with Aitel that the attack code was not going to be difficult to write.

More here.