AT&T Concerned About H2K2
****************************************************************
AT&T Network Fraud Advisory
July 11, 2002
****************************************************************
Possible Hacker Social Engineering Attempts
Friday July 12 - Sunday July
14, 2002
===================================================
Caution:
------------
Be careful about giving information to anyone you don't know and those
making unusual information requests by claiming to be an AT&T employee or
customer.
The H2K2 (Hackers on Planet Earth 2002) Hacker Conference will take place
this weekend, Friday, July 12 to Sunday to July 14, 2001, [ed. note: 2001?] in New York
City. This conference will be a gathering of over five thousand computer
hackers, guest speakers, and computer enthusiasts. http://www.h2k2.net
In 1994, 1997 and 2000 at the previous Hope (Hackers on Planet Earth)
Conferences, live demonstrations of "social engineering" techniques were
performed in front of thousands of hackers and other attendees. The hacker
panel dialed live into AT&T offices and centers and demonstrated how to
get proprietary information by pretending to be an AT&T employee and
customer. These calls were recorded and videotaped by the hackers and are
sold as instructional material at future hacker conferences. There is a
very high likelihood that AT&T will be a target again this weekend.
The social engineering contest is scheduled for Sunday July 14th, at 4
P.M. ET, (1 PM PT). During this period hackers may be dialing into AT&T
to get information.
AT&T Network Security would like to warn our employees to be on guard this
entire weekend for any unknown person calling and claiming to be an AT&T
employee to request proprietary information or claiming to be an AT&T
customer with unusual requests.
Remember, if anyone, who is unknown to you calls for proprietary
information or make unusual requests, please follow your procedure by
requesting additional information to ensure the person is who they say
they are before giving out any information.
If the person is claiming to be an AT&T employee, please request name,
callback and HRID #. Then verify through POST or the email global address
list if the information is correct and even request to call the employee
back at their contact number.
If the person is claiming to be an AT&T customer verify this by requesting
additional info on their account like address and SS# and even request to
call the person back at their contact number listed on the account.
Please be on guard for any unusual requests. Verify the person is an AT&T
employee or a legitimate customer and if they have a need to know the
information they are asking. If you can't verify employment or number,
don't give out the information. If you are still in doubt regarding the
legitimacy of the caller, then speak to a supervisor regarding the
situation before proceeding further and inform the caller you will call
them back. If you still have questions you can call the Security Hotline
1-800-822-9009.
Remember you do not want to be the lucky guest of honor on a telephone
call from the hacker conference this weekend with thousands of hackers
listening to you and attempting to scam AT&T out of proprietary
information. Please be on guard.
- - - - - - - - - - - - - - - - - - - - - - - - -
Source: AT&T Network Security
*******************************************************************
If you still have questions you can call the Security Hotline 1-800-822-9009.
Can't the hackers who read slashdot (probably most of them) just call this number instead now?
Furthermore, why doesn't Microsoft have a security hotline?
I regularly get emails saying "A person has been seen acting suspiciously on campus, and ran away when challenged. There has been a spate of robberies by extra vigilant," and nothing is made about it. It doesn't mean we're not to be vigilant the rest of the time, just a timely and worthwhile heads up.
What makes this different except the criminals involved are 'l33t and say stuff like "Mad propz".
Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
"I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
Dear Employees:
The previous memo failed to mention another warning sign of hacker social engineering attempts. If you hear the song "Halcyon-On and On" by the music group Orbital, hang up the telephone immediately. We will be holding information sessions at all regional offices for telephone support personnel, where you will be trained to recognize this music within several seconds. DO NOT confuse this warning sign with the last five minutes of Mortal Kombat! It is better to be safe than sorry. Thank you for your cooperation, and stay Hacker-Free(tm) during this period of "l337n355".
...
- the resolution procedures in case of doubt about a callers identity
- the "security hotline" phone number.
Nice going, AT&T.
CEE5210S The signal SIGHUP was received.
At my employer's firm, we have perfected the art of repelling those out to gain information by a 2-pronged approach. We run the callers through a maze of automated phone forwarding recordings to (eventually) a person who has no clue about anything.
If we're forced to follow basic security procedures, it means the hackers have already won.
Best Windows Freeware
I bet AT&T would just love to get their hands on the person that posted this. AT&T did a very responsible thing: they saw a potential threat to the security of their customers, i.e., a lot of people who are reading this (and even if you don't pay AT&T directly, you might use their lines if you have a cable modem), and sent out a warning to remind their people. They included reminders of proper secure behavior. And what is the first thing an employee do? Leak the number and protocols to an outlet read by the people who are most likely to try and breach security. If you were my employee you'd get in some serious trouble.
Many people who do the social engineering hack make fun of companies for having clueless employees or employees that don't follow basic guidelines. So for those few who make fun of AT&T for doing this, I'd say you can't have it both ways.
We should be applauding AT&T for reminding their people of basic security precautions.
That e-mail proves the meeting has acomplished one of its goals. Thanks to H2K2 AT&T is being more careful with the private info.
Isn't that what we all want? At least that's the reason why I support those kind of things.
Life isn't like a box of chocolates. It's more like a jar of jalapenos. What you do today, might burn your ass tomorrow.
In about 1980, when I was in high school, I discovered an unused phone extension line in my bedroom closet and started experimenting with it. I quickly figured out the basics and built a little homemade phone. Later, I got the idea of using a thirty-foot spool of wire and a couple of alligator clips to quickly tap into someone's line outside of their house to steal long distance phone calls from the safety of my car. This is really trivial stuff, I know, but I thought I was clever.
But not clever enough. I called my cousin long-distance by connecting to what turned out to be the phone line of a little old lady who'd never made a long-distance phone call in her life. Her church was helping her pay her bills and noticed the phone call immediately. They called AT&T, and AT&T merely checked to see who else in my small New Mexico town had ever called that California number. Then they called my mom.
Once AT&T security found out that I hadn't actually done anything sophisticated or interesting, they just made my parents pay for the call and dropped the matter.
None of this, of course, shows that AT&T security was especially astute. But a few years later I was working as a radio disc-jockey, and I told this story to the station's chief broadcast engineer. He told me that he had worked for AT&T and that AT&T Security were among the best private security experts in the world. In his words: "Don't fuck with AT&T Security". That made an impression on me.
Later on, when I first read about the phone phreaking era, I felt lucky that a) I wasn't ingenious enough to get myself in any real trouble, and b) I didn't know anyone who was.