A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the companyโs network said he enters corporate Web sites without permission to satisfy his curiosity.
Adrian Lamo, who has a publicized history of exploring the inner workings of corporate computer networks in search of system weaknesses, said in an interview with Computerworld that he sees himself as helping companies improve their system security by reporting flaws.
โI try to engage in harm reduction when Iโm inside a computer network,โ said Lamo. โIโve never intentionally done damage in a network.โ
Lamo, who lives in San Francisco, said he contacted WorldCom through an intermediary at consulting firm SecurityFocus.com Inc. to advise the telecommunications giant of the vulnerabilities, which he said gave him clear access to the networks of some of WorldComโs largest customers.
WorldCom provides telecommunications and data services to many of the nationโs largest companies.
Lamo said his perusal of WorldCom began several months ago, when a company banner ad caught his eye as he was viewing a Web page. โIt was one of those things where I was in the correct mind-set for doing these kinds of things,โ he said. He began fooling around with the companyโs domain name, adding and removing extra words or numbers until he was able to access internal company Web pages โ including many with sensitive information such as passwords โ that arenโt for public use but are connected to the site.
Until reporting the flaws to WorldCom earlier this month, Lamo said, he was able to dig deep into the companyโs network, gaining access to in-house system tools offering access to the networks of WorldComโs customers. Those customers include AOL Time Warner Inc., Bank of America Corp., Citigroup Inc., McDonaldโs Corp. and Sun Microsystems Inc., he said. His explorations even allowed him to find router numbers and passwords for log-ins and administration that would have allowed him to take control of the routers and shut out WorldCom technicians.
โโAll the information that I needed (to access those networks) was there,โ he said.
WorldCom spokeswoman Jennifer Baker confirmed that Lamo reported the security flaws to the company and that he assisted in ensuring that repairs closed the holes in the network. She said the company appreciated Lamoโs help.
No customer networks were compromised before the repairs were made, Baker said. The problem was apparently due to a human error that allowed a router to use an โinappropriate filter.โ Once the filter was removed, the router was reconfigured to close the hole.
Analysts have other views of Lamoโs actions and even WorldComโs response.
Pete Lindstrom, of the Hurwitz Group Inc. in Framingham, Mass., said he was โflabbergasted and amazedโ by WorldComโs lackadaisical attitude about having its customer networks invaded by a 20-year-old hacker. Then the company went even further, he said, by actually thanking Lamo for uncovering the flaws after entering the companyโs network without permission.
โWhat (WorldCom is) saying here is that security doesnโt matter,โ Lindstrom said. โIf these guys donโt do a full-blown audit of every system on their network,โ it wonโt be acceptable, he said. โThey already know they have to change all passwords and phone numbers for their routers.โ
Lindstrom said he โhopesโ lawsuits will be filed by WorldCom customers in connection with this incident. โIf Bank of America doesnโt sue WorldCom, Iโll be amazed.โ
Lamo should get jail time, and the company should be the subject of a class-action lawsuit for its โnegligence,โ he said. โI am absolutely astounded by the indifference, nay, graciousness, with which a company like WorldCom is treating the hacking nomad, Adrian Lamo.โ
Eric Hemmendinger, an analyst at Aberdeen Group Inc. in Boston, said Lamoโs actions were questionable.
โItโs the equivalent of someone poking around your house from the outside and finding an open door,โ which they enter, Hemmendinger said. โThen they say: โI didnโt take anythingโ.โ
Greg Shipley, a networking and security consultant at consulting firm Neohapsis Inc. in Chicago, said Lamoโs actions walk the delicate line between โblack hatโ hackers who seek to damage networks and โwhite hatโ hackers who point out flaws that need to be fixed.
โThere is an increasing trend of people who walk the โgray hatโ area,โ Shipley said. Part of what they do is legal, while part of it appears to be illegal, he said. โThese guys run the risk of getting in big trouble if they go public with their informationโ that they uncover.
Lamo, who describes himself more as a โsecurity researcherโ than as a hacker, said he neither sought nor received any payment for his information.
He said heโs uncovered similar security lapses in networks run by America Online Inc., Excite@Home Inc., Yahoo Inc. and Microsoft Corp.
He does this kind of work, he said, because he enjoys solving such mysteries. Lamo doesnโt hold a full-time job because, he said, it would be too restrictive and time-consuming. To support himself, he occasionally does networking and other computer work for non-profit groups, with occasional stints in corporate settings. He said heโs never been contacted by any law enforcement agencies in connection with his network and Internet explorations.
โI try to see whatโs out there from all angles that generally arenโt considered by other people,โ he said.