THE

SPRAWL

simstimthe dutch hacker video

Released 09/01/1991
Size 344.5 MB
Download hacker_video.avi

The Dutch Hacker Video is a video recording produced by the 2600 Magazine which shows a complete hack of a United States military computer performed by an anonymous Dutch hacker sometime in the late July, 1991. As described by the film's author, Emmanuel Goldstein, the goal of showing this information to the public was to expose shameful security in military computers and to force their owners to do something about it.

The target for the attack was a Xenix machine on the domain tracer.army.mil. The machine had an open telnet port, so the hacker tried several default Unix credentials to get in. Unfortunately this attack vector was not successful.

Next the hacker tried a now classic FTP privilege escalation exploit which allows him to read and write to arbitrary files on the machine as root. For details of the vulnerability check out Improving the Security of Your Site by Breaking Into it by Dan Farmer and Wietse Venema or CA-1988-01 Cert advisory.

At this point all that is left to do is to upload a modified passwd file containing a known user with a blank password and telnet in as that user to gain shell. A nice login banner is displayed warning remote users not to process classified information over this insecure terminal.

With a shell access to the machine, the hacker elevates his privileges on the system to root and starts pillaging machine's contents. At one point the hacker is looking at an email discussing THREATCON Alpha condition and possibility of hostilities in the Persian Gulf. At last the attacker runs a password cracker and finds plenty of easy to guess passwords.

The video was originally recorded to expose security weaknesses in highly sensitive computers of its time. However, this film offers an even more interesting lesson to today's audience about the relevance of exploitation techniques used in the film to modern day systems. Unpatched software and reliance on easy to guess passwords continue to be commonly exploited weaknesses even twenty years later.


sprawlcomments


sprawlsimilar

unauthorized access

Released 12/01/1994

Unauthorized Access is a documentary produced by Annaliza Savage in 1994. Shot in 15 cities and 4 countries, this documentary offers an impressive array of topics dealing with hacking culture. Read more.

Size 98.8 MB
Download unauthorized_access.mp4

hackers 95

Released 08/04/1995

Hackers 95 is an independent documentary by Phone-E and RF Burns shot during the summer of 1995. The documentary covers hacker happenings during that summer including Summercon and Defcon III. There are plenty of interviews and random clips from these two conferences. The documentary also includes a separate segment on Area 51 as well as a Secret Service press release on Operation Cybersnare. Read more.

Size 210.8 MB
Download hackers95.mp4

hacks

Released 12/01/1997

Hacks is an English and German language documentary by Christine Bader. It was shot over a period of four years, starting in 1993 and released in 1997. This documentary deals with social aspects of hacking by covering not only the more traditional “computer” hacks, but expanding the definition to the realms of society, politics, environment, and art. Read more.

Size 186.3 MB
Download hacks.mp4

hack attack

Released 12/23/1994

A 1994 Yorkshire Television Production for Discovery Channel documentary - Hacker Attack, is a well balanced account of the hacker, security, and electronic crime worlds in late 80s and early 90s. It begins by featuring Mark Abene incarcerated in Schuylkill talking about his views on hacking and the story of MoD. Emmanuel Goldstein is displayed throughout the documentary talking about the hacker community during 2600 meetings and on the Off the Hook radio show. Next 'Hacker Attack' turns to the darker side of hacking when we jump into unmarked NYPD surveillance van to track down cloned cellular phones. There is an extensive coverage of credit card fraud, high tech robbery, and industrial espionage. At last we can watch Winn Schwartau and Dan Farmer talk about threats to our financial and military infrastructures. Throughout the documentary, there are snippets of anonymous hackers breaking into various computer systems. Read more.

Size 245.8 MB
Download hack_attack.mp4

new york city hackers

Released 12/01/2000

New York City Hackers is an independent documentary by Stig-Lennart Sorensen released in the year 2000. Most of the filming occurs in in New York at the H2K conference, 2600 meeting and an Off the Hook radio show. There is also a coverage of the original MIT hackers from the TMRC club. Read more.

Size 99.0 MB
Download nyc_hackers.mp4
26
apr
2011

A product of my research into password cracking methods, PACK (Password Analysis and Cracking Kit) is a collection of several utilities to assist in statistical password analysis and generation of cracking rule sets. Read more.

orapass sha1

Version0.1
Size 605 bytes
Download orapass-sha1.py

Orapass SHA1 implements Oracle's newer SHA1-based password hashing algorithm. This script can be used for password strength audit and recovery. Uses Python Hashlib library. Read more.

freedom downtime

Released 09/22/2007

A revealing documentary about two high profile hacker cases: Mark Abene and Kevin Mitnick. The documentary includes interviews with a number of guest speakers including Bruce Sterling, Lewis Depayne, John Markoff, Jeff Moss, Mike Roadancer, Bernie S., and many others. This film is directed by Emmanuel Goldstein of 2600. Read more.

Size 345.1 MB
Download freedom_downtime.mp4

hippies from hell

Released 11/27/2002

This documentary covers Dutch hackers namely organizations such as xs4all, Hippies from Hell, HackTic, and TOOL lockpicking club. Read more.

Size 208.2 MB
Download hippies_from_hell.mp4

walk on the wild side

Released 02/02/1994

A documentary on the UK underground scene. Read more.

Size 173.5 MB
Download walk_on_the_wild_side.mp4
07
aug
2010

I had an opportunity to participate in the "Crack me if you can" password cracking competition during this year's Defcon. It was a fun and educational experience. Using a couple of video cards, decent processors as well as some research into password generation I was able to place 4th in the contest. In this post you can learn more about hardware, software and strategy used to crack about 25k passwords in two days. Read more.

john the ripper

John the Ripper is a multi-platform password cracking tool. Read more.

password analysis and cracking kit

Version0.2
Size 11.8 KB
Download PACK-0.0.2.tar.bz2

PACK (Password Analysis and Cracking Toolkit) is a collection of utilities developed to aid in analysis of password lists and enhancing cracking of passwords using smart rule generation. The toolkit itself is not able to crack password, but instead concentrates on making operation of other tools more efficient. Read more.

16
jan
2010

My article on the Tor control protocol was published in the Winter 2009-2010 issue of the 2600 Magazine. Read more.

orapass des

Version0.1
Size 1.6 KB
Download orapass-des.py

Orapass implements Oracle's older DES-based password hashing algorithm. This script can be used for password strength audit and recovery. Uses Python Crypto library. Read more.