15 year old six counties male arrested for Talk Talk hacking

Started by T Fearon, October 26, 2015, 08:10:59 PM

Previous topic - Next topic

deiseach


AZOffaly


Bingo

Quote from: heganboy on October 27, 2015, 03:43:06 AM
maybe I remember it differently, but at 15 you didn't get caught - you were invincible.

the numpties at TT are admitting to no encryption of customer data, so the fact that they may have fallen to a DDOs with and SQLi is a bloody disgrace. That they asked for 80k in Bitcoin is hilarious, and that they showed Krebs the db table copies is even funnier.

a bit of social engineering, and a AWS / GCE account go a long way. you would have said that the odds were on the side of brute force with low primes, but that they (TT) are saying they have no obligation to encrypt data is going to see them burn... SQLi it is.

People are going to jail, and it really shouldn't be the 15 year old (who will be absolutely hired when he gets out, initiative goes a long way these days)

Not in this or any other world do I have the slightest clue as to what you are saying.

JoG2

Quote from: Bingo on October 27, 2015, 03:41:47 PM
Quote from: heganboy on October 27, 2015, 03:43:06 AM
maybe I remember it differently, but at 15 you didn't get caught - you were invincible.

the numpties at TT are admitting to no encryption of customer data, so the fact that they may have fallen to a DDOs with and SQLi is a bloody disgrace. That they asked for 80k in Bitcoin is hilarious, and that they showed Krebs the db table copies is even funnier.

a bit of social engineering, and a AWS / GCE account go a long way. you would have said that the odds were on the side of brute force with low primes, but that they (TT) are saying they have no obligation to encrypt data is going to see them burn... SQLi it is.

People are going to jail, and it really shouldn't be the 15 year old (who will be absolutely hired when he gets out, initiative goes a long way these days)

Not in this or any other world do I have the slightest clue as to what you are saying.

this may shed a little light Bingo. The young guy, working solo I'd say prob set up a self-mining PTC/PUL advanced algorithm but forget to add a stealth avoidance advanced yellow primer script (quite literally a schoolboy error)

Pub Bore

Quote from: JoG2 on October 27, 2015, 03:49:45 PM
Quote from: Bingo on October 27, 2015, 03:41:47 PM
Quote from: heganboy on October 27, 2015, 03:43:06 AM
maybe I remember it differently, but at 15 you didn't get caught - you were invincible.

the numpties at TT are admitting to no encryption of customer data, so the fact that they may have fallen to a DDOs with and SQLi is a bloody disgrace. That they asked for 80k in Bitcoin is hilarious, and that they showed Krebs the db table copies is even funnier.

a bit of social engineering, and a AWS / GCE account go a long way. you would have said that the odds were on the side of brute force with low primes, but that they (TT) are saying they have no obligation to encrypt data is going to see them burn... SQLi it is.

People are going to jail, and it really shouldn't be the 15 year old (who will be absolutely hired when he gets out, initiative goes a long way these days)

Not in this or any other world do I have the slightest clue as to what you are saying.

this may shed a little light Bingo. The young guy, working solo I'd say prob set up a self-mining PTC/PUL advanced algorithm but forget to add a stealth avoidance advanced yellow primer script (quite literally a schoolboy error)

Jaysus, deserves to spend the rest of his life in prison for that alone ;)

johnneycool

Bingo is about to go watch swordfish again to see if it begins to make sense.

8)

JoG2

Quote from: Pub Bore on October 27, 2015, 03:52:33 PM
Quote from: JoG2 on October 27, 2015, 03:49:45 PM
Quote from: Bingo on October 27, 2015, 03:41:47 PM
Quote from: heganboy on October 27, 2015, 03:43:06 AM
maybe I remember it differently, but at 15 you didn't get caught - you were invincible.

the numpties at TT are admitting to no encryption of customer data, so the fact that they may have fallen to a DDOs with and SQLi is a bloody disgrace. That they asked for 80k in Bitcoin is hilarious, and that they showed Krebs the db table copies is even funnier.

a bit of social engineering, and a AWS / GCE account go a long way. you would have said that the odds were on the side of brute force with low primes, but that they (TT) are saying they have no obligation to encrypt data is going to see them burn... SQLi it is.

People are going to jail, and it really shouldn't be the 15 year old (who will be absolutely hired when he gets out, initiative goes a long way these days)

Not in this or any other world do I have the slightest clue as to what you are saying.

this may shed a little light Bingo. The young guy, working solo I'd say prob set up a self-mining PTC/PUL advanced algorithm but forget to add a stealth avoidance advanced yellow primer script (quite literally a schoolboy error)

Jaysus, deserves to spend the rest of his life in prison for that alone ;)

I know ! if there was a cross-eyed smiley face, I'd add it

Bingo

Quote from: JoG2 on October 27, 2015, 03:49:45 PM
Quote from: Bingo on October 27, 2015, 03:41:47 PM
Quote from: heganboy on October 27, 2015, 03:43:06 AM
maybe I remember it differently, but at 15 you didn't get caught - you were invincible.

the numpties at TT are admitting to no encryption of customer data, so the fact that they may have fallen to a DDOs with and SQLi is a bloody disgrace. That they asked for 80k in Bitcoin is hilarious, and that they showed Krebs the db table copies is even funnier.

a bit of social engineering, and a AWS / GCE account go a long way. you would have said that the odds were on the side of brute force with low primes, but that they (TT) are saying they have no obligation to encrypt data is going to see them burn... SQLi it is.

People are going to jail, and it really shouldn't be the 15 year old (who will be absolutely hired when he gets out, initiative goes a long way these days)

Not in this or any other world do I have the slightest clue as to what you are saying.

this may shed a little light Bingo. The young guy, working solo I'd say prob set up a self-mining PTC/PUL advanced algorithm but forget to add a stealth avoidance advanced yellow primer script (quite literally a schoolboy error)

Not as clever as he though he was then, the wee bollix!

If he had turned it off and restarted would that have helped? 

armaghniac

QuoteI doubt he got all this through sql injection or the like. Spoofing / brute force or something like that.

Brute force spoofing, anyone on GAABoard could understand that.

No doubt it was a case of Talk Talk not bothering to protect against attacks that were around before Armagh invented football.
There probably should be legally mandated testing regime for such organisations so that they have to show that they made some effort, although there will always be innovative attacks that are hard to stop.
If at first you don't succeed, then goto Plan B

michaelg


heganboy

Never underestimate the predictability of stupidity

Orior

Cover me in chocolate and feed me to the lesbians