Live data from Hacker News

Is This The Girl That Hacked HBGary?

blogs.forbes.com

41–50 of 135 posts

Re: Is This The Girl That Hacked HBGary?

#41
> In December 2008, she wrought havoc on one of the most famous forums of all, 4chan’s notorious /b/ channel, finding and exploited an SQL injection bug on its content management system, hacking in and causing mayhem on the forum for a few hours.

I don't remember any such exploit. You could produce that image by posting a lot.

Re: Is This The Girl That Hacked HBGary?

#42
post #8

This could very likely be a carefully (and cleverly constructed) identity. This girl might not exist; but because we all really really want a 16 year old girl to be the hacker the discrepancies are glossed over (the art of a good lie is not giving too much detail and letting other people's imagination fill the gaps). On the other hand the personality strikes me strongly as female, so if it is an facade it is a very w…

Yeah, it's interesting to guess.. There are mild grammar errors in each longer sentence she's quoted with.. and two of them conflict strangely (she uses 'into' correctly once, but not again). I'm just playing detective, but either smells like someone young.. or like someone intentionally peppering grammar issues to sound it. I dunno. If I had to vote I'd call BS. I think it's someone older.

Re: Is This The Girl That Hacked HBGary?

#44
post #6

Earlier quoted context omitted.

>Each night she wipes every one of her web accounts and deletes every email in her inbox ... If that is true, online account operators, email providers could link this type of behavior to one of their members quite quickly.

That is what I was thinking. Ya know, you probably don't want to disclose your operational security procedures because well, they aren't common and not being common, their trackable. And then I was thinking about how the police sometimes "leak" that the suspect in some crime is weak, pathetic, individual which nobody really cares about, in hopes that they will offend the real suspect who will then self identify in de…

> how the police sometimes "leak" that the suspect in some crime is weak, pathetic, individual

Except that the "you just got hacked by a 16-year old girl" taunt was apparently started in Anonymous circles soon sfter the attack. Not to say any of this is true or not fabricated, just that its not likely being fabricated from outside for those kinds of reasons.

Re: Is This The Girl That Hacked HBGary?

#45
My bs meter was high for a number of reasons. This paragraph was the most notable:

"Meanwhile she refuses to be chained to her computer, limiting herself to a few hours a night online. She rarely visits online forums "they’re boring"and a few days a week takes a course in college to further her goal of being a teacher. She lives in an English-speaking country not the U.K.but won’t say more about it"

So the previous paragraph stated she was "memorizing Windows Opcodes and scouring source code for exploitable bugs", but then suddenly she only spends a few hours online? Not likely. Most hardcore hackers I know don't just drop off the radar. The hunt to break into systems is like a drug. I have yet to read about, or know any hacker who simply spends a few hours online a day. At the speed internet security moves, this person's knowledge would be useless inside of 6 months.

Also, how does this person maintain her expert hacker knowledge with a few cursory hours a day on the internet? Literally impossible. Add in the admission she deletes all her emails and wipes all her drives clean? Really? Does this person memorize every line of code she uses then?

My conclusion? A carefully crafted profile of an Anon personality. Although I have no doubt this person probably exists, it certainly is not a 16 year old girl, and a majority of the information in the article is total BS. When you apply some very basic logic, the story just falls apart.

Re: Is This The Girl That Hacked HBGary?

#46

Is the phrase "Windows Opcodes" (from the article) a subtle troll on the part of "k" or a journalistic goof? I'm no programmer by any stretch, but that phrase jumped out at me as phony. I know there are system calls for operating systems, and opcodes are processor instructions, so this use of the term raised my b.s. meter a notch.

Hate to break it to you but that actually means something. The technical details are surprisingly on target for being written by a tech journalist.

Ex. http://www.metasploit.com/users/opcode/syscalls.html

Re: Is This The Girl That Hacked HBGary?

#47
post #8

This could very likely be a carefully (and cleverly constructed) identity. This girl might not exist; but because we all really really want a 16 year old girl to be the hacker the discrepancies are glossed over (the art of a good lie is not giving too much detail and letting other people's imagination fill the gaps). On the other hand the personality strikes me strongly as female, so if it is an facade it is a very w…

When I had a lot more time, I would go into Yahoo chat and basically phish for pedophiles usernames/passwords. I can tell you that a "hehe" after anything will set the hook.

I could on average phish about an account a minute and I was never figured out. I only fell out of character once to warn an 18 year old kid, that talking to 14 year old girls sexually online wasn't the best use of his time. He freaked out and thought I was a cop!

It's relatively trivial to do this, most people will ignore minor slip ups provided you have the right context. I would set context by doing the following:

1. I would set my profile to the geolocation of the room I intended to work. I would then find a school and neighborhood to say I was from.

2. I would suggest I was home sick (and thus alone).

3. I would use an innocent, although, sexual name in my username like "booty"

4. I would use emoticons and "hehe" on probably 75% of all messages sent.

5. I would let them contact me first. If you contact them they get scared. If they contact you, they feel like they are in control.

For example, I could tell them the wrong name and many wouldn't notice, or if they did simply saying, "Oh, that's my middle name" is usually sufficient.

With all that said, anyone know of a way I could use my experiences and ability at social engineering online in a legit manner?

Re: Is This The Girl That Hacked HBGary?

#48
post #9

Wait, Forbes actually linked to http://encyclopediadramatica.com/Lulz ? HAH.

I'd really like to see the look on the face of the average Forbes reader after clicking on an ED link.

And "ED" likely means something entirely different to what I imagine the typical Forbes reader to be.

Re: Is This The Girl That Hacked HBGary?

#49
post #2

Each night she wipes every one of her web accounts and deletes every email in her inbox. She has no physical hard drive and boots her computer from a microSD card. “I could hide this card anywhere or chew into a million pieces in a few seconds,” she says by e-mail. She keeps her operating system on a USB stick and uses a virtual machine (VM) to carry out her online shenanigans. And people call me paranoid. :)

In light of recent Anon-related police raids, I would hope that anyone supposedly as savvy as "k" would rely on full-disk crypto as opposed to foolishly going the destruction of evidence route. I've used FDE for many years simply out of precaution against theft.

In the US fill disk crypto is useless. They will just hold you in jail until you hand them the password.

Re: Is This The Girl That Hacked HBGary?

#50
post #40

Using the quotes from the article, however too few words to analyze properly, so inconclusive, but still... From http://www.hackerfactor.com/GenderGuesser.php Genre: Informal Female = 171 Male = 182 Difference = 11; 51.55% Verdict: Weak MALE Weak emphasis could indicate European. From http://bookblog.net/gender/analysis.php Female Score: 94 Male Score: 133 The Gender Genie thinks the author of this passage is: male!

Everything I write comes out as female and I'm... not. I wouldn't trust that (or maybe I should question my gender...)
Post reply on HN