Xref: utcsri comp.security.unix:14448
Path: utcsri!newsflash.concordia.ca!news.mcgill.ca!mcrcim.mcgill.edu!bloom-beacon.mit.edu!pad-thai.cam.ov.com!news.ov.com!news.cerf.net!usc!howland.reston.ans.net!swrinde!elroy.jpl.nasa.gov!decwrl!purdue!yuma!lamar.ColoState.EDU!barria
From: barria@lamar.ColoState.EDU (Jose Barria)
Newsgroups: comp.security.unix
Subject: Re: The Scoop on Mitnick?
Date: 6 Apr 1995 02:03:56 GMT
Organization: Colorado State University, Fort Collins, CO  80523
Lines: 1123
Message-ID: <3lvi6c$1h5l@yuma.ACNS.ColoState.EDU>
References: <3lqemt$8g6@blackice.winternet.com>
NNTP-Posting-Host: lamar.acns.colostate.edu
X-Newsreader: TIN [version 1.2 PL2]

Michael Bresnahan (gudu@klondike.winternet.com) wrote:
: I keep hearing references to Kevin Mitnick on and off the net, but I
: have as yet to find any detailed information on him or any the
: happenings that have made his name popular.  Could someone point me to
: a newspaper article, magazine article, on-line doc, or whatever on the
: subject or just fill me in with a post or email?

: Any help would be most warm heartedly accepted.

: MikeB

Ten (or more) articles follow ... BTW, read alt.2600 ... it usually
has the breaking 'hack' stories ...

Joao

-------------------------------------------------------------------------
~From: emmanuel@well.sf.ca.us (Emmanuel Goldstein)
~Newsgroups: alt.2600
~Subject: Mitnick comments from the past
~Date: 19 Feb 1995 23:22:19 GMT

Back in 1991, Kevin wrote a commentary for 2600 on the Katie Hafner/
John Markoff book Cyberpunk. As far as I know, this is is the only
time he ever made a public comment on any of this.

*****

I am sad to report that part one of the book Cyberpunk, specifically
the chapters on "Kevin: The Dark Side Hacker", is 20 percent fabricated
and libelous. It seems that the authors acted with malice to cause me
harm after my refusal to cooperate. Interestingly enough, I did offer
to participate as a factual information source if I was compensated
for my time, but the authors refused, claiming it would taint my
objectivity. So consequently, I declined to cooperate.
However, my co-defendant, Lenny Dicicco, of Data Processing Design,
chose to participate probably in the hopes of being recognized as a
"hero" who was responsible for bringing me to justice. Lenny seemed to
have gained unquestionable credibility when he turned us both into
Digital and the U.S. government. Surprisingly, he who "snitches"
first is believed to be totally credible by the U.S. government.
Case in point: most of the U.S. government's argument to hold me
without bail was based on false information (this was later admitted
by the U.S. government). This information, I believe, was mainly from
Lenny Dicicco and his cronies (Steven Rhoades of Pasadena, CA). So once
Lenny lied to the U.S. government he couldn't change his story, since
he could risk violating his plea agreement or being indicted on federal
perjury charges. Unfortunately, this probably resulted in a lot of false
material being introduced by Lenny Dicicco, and Katie Hafner printing it
as factual information in Cyberpunk.
Katie probably wasn't happy with me for refusing to help her, so
part one of the book was written with a strong anti-Mitnick,
pro-Dicicco bias. This bias rewarded Lenny for his participation
but robbed the readers of the real truthful facts! Lenny was described
simply as an "errand boy" in our hacking exploits. This is the furthest
thing from the truth! Lenny was just as culpable as me; we were hacking
partners for over 10 years. What do you believe?
Let's examine some interesting cover-ups Katie Hafner did for Lenny
Dicicco:
1) In the galley copy of Cyberpunk, Katie Hafner wrote that Lenny Dicicco
 was going to work for DEC as a computer security consultant in lieu of
 court ordered restitution ($12,000). Why was the information eliminated
 from the final printed copy? Probably DEC wouldn't be happy with Lenny -
 he did provide Katie with enormous detail regarding the DEC break-in.
 Not to mention the controversial issue regarding DEC hiring the person
 that penetrated their network.
2) On page 80, Katie wrote that Lenny Dicicco obtained a false identity
 to obtain a job that required a "clean" driving record. The name Katie
 printed was "Robert Andrew Bollinger". This is false! The name of the
 "false" identity was "Russell Anthony Brooking". But why would Katie
 print this erroneous information? I know why! Lenny was working under
 the fraudulent identity (Russell Anthony Brooking) while he was
 collecting unemployment under his real name (Leonard Mitchell Dicicco)
 thereby defrauding the State of California! Now Katie wouldn't want the
 "truth" to be known - it might cause Lenny to refuse to participate in
 possible upcoming interviews and talk shows promoting her book.
I could go on and on, even simple verifiable information. For example,
on page 84, Katie describes a scenario where I asked Bonnie out on a
date. To paint an unsavory picture, she stated that I was always eating
in the computer room when talking with Bonnie. Very interesting, since
at the Computer Learning Center of Los Angeles, no food or drinks can
ever be brought into the computer room. Even though this scenario is
pretty insignificant, it demonstrates the introduction of inaccurate and
misrepresented facts.
Again, when describing my arrest at USC in 1982, Katie wrote on page 71
that I taunted Mark Brown (USC System Manager) in his investigative
techniques. This is truly amazing, since I never spoke with Mark Brown.

There are many, many false statements, misrepresentations, and inaccurate
stories in part one of this book. I could only say it is sad that the
authors were too cheap to compensate me for my time. Instead they hid
under the ruse of "tainted objectivity". This resulted in my refusal to
participate.
In summary, Cyberpunk is an interesting read-through as long as readers
understand this purported non-fiction book is not what it claims to be.
Part one of the book is 20 percent inaccurate. I believe the authors
acted with malice due to my refusal to participate for free. Katie
Hafner's only hope was seeking the cooperation of my convicted
co-defendant, Lenny Dicicco. She did gain his full cooperation which
resulted in a strong bias and misrepresentation of facts.

----------------------------------------------------------------------------
~From: rm09216@picasso.math.swt.edu (Robert Martin)
~Newsgroups: alt.2600
~Subject: Re: Mitnick arrested???
~Date: 16 Feb 1995 05:58:26 GMT

This can be found at http://www.nando.net/newsroom/nt/nation7.html:

Slippery cybervandal caught in his own electronic web
-----------------------------------------------------

(c) Copyright the News & Observer Publishing Co.
How a computer sleuth traced a digital trail

New York Times

RALEIGH, N.C. (9:05 p.m.) -- After a search of more than two years, a team
of FBI agents early Wednesday morning captured a 31-year-old computer
expert accused of a long crime spree that includes the theft of thousands
of data files and at least 20,000 credit card numbers from computer systems
around the nation.

The arrest of Kevin D. Mitnick, one of the most wanted computer criminals,
followed a 24-hour stakeout of a Raleigh apartment building here.

A convicted computer felon on the run from federal law enforcement
officials since November 1992, Mitnick has used his sophisticated skills
over the years to worm his way into many of the nation's telephone and
cellular telephone networks and vandalize government, corporate and
university computer systems. Most recently, he had become a suspect in a
rash of break-ins on the global Internet computer network.

"He was clearly the most wanted computer hacker in the world," said Kent
Walker, an assistant U.S. attorney in San Francisco who helped coordinate
the investigation. "He allegedly had access to corporate trade secrets
worth billions of dollars. He was a very big threat."

But federal officials say Mitnick's confidence in his hacking skills may
have been his undoing. On Christmas Day, he broke into the home computer of
a computer security expert, Tsutomu Shimomura, a researcher at the
federally financed San Diego Supercomputer Center.

Shimomura then made a crusade of tracking down the intruder, an obsession
that led to Wednesday's arrest.

It was Shimomura, working from a monitoring post in San Jose, Calif., who
determined last Saturday that Mitnick was operating through a computer
modem connected to a cellular telephone somewhere near Raleigh, N.C.

Sunday morning, Shimomura flew to Raleigh, where he helped telephone
company technicians and federal investigators use cellular-frequency
scanners to home in on Mitnick.

Mitnick was arrested at 2 o'clock Wednesday morning in his apartment in the
Duraleigh Hills neighborhood of northwest Raleigh, after FBI agents used
their scanners to determine that Mitnick, in keeping with his nocturnal
habits, had connected once again to the Internet.

Shimomura was present Wednesday at Mitnick's pre-arraignment hearing at the
federal courthouse in Raleigh. At the end of the hearing, Mitnick, who now
has shoulder-length brown hair and was wearing a black sweat suit and
handcuffs, turned to Shimomura, whom he had never met face to face.

"Hello, Tsutomu," Mitnick said. "I respect your skills."

Shimomura, who is 30 and also has shoulder-length hair, nodded solemnly.

Mitnick, already wanted in California for a federal parole violation, was
charged Wednesday with two federal crimes. The first, illegal use of a
telephone access device, is punishable by up to 15 years in prison and a
$250,000 fine.

The second charge, computer fraud, carries potential penalties of 20 years
in prison and a $250,000 fine. Federal prosecutors said they were
considering additional charges related to Mitnick's reported Internet
spree.

Federal officials say Mitnick's motives have always been murky. He was
recently found to have stashed thousands of credit card numbers on
computers in the San Francisco Bay area -- including the card numbers of
some of the best-known millionaires in Silicon Valley. But there is no
evidence yet that Mitnick had attempted to use those credit card accounts.

Indeed, frequently ignoring the possibility of straightforward financial
gain from the information he has stolen, Mitnick has often seemed more
concerned with proving that his technical skills are better than those
whose job it is to protect the computer networks he has attacked.

Federal officials say the arrest of Mitnick does not necessarily solve all
the recent Internet crimes, because his trail of electronic mail has
indicated that he may have accomplices. One of them is an unknown computer
operator, thought to be in Israel, with whom Mitnick has corresponded
electronically and boasted of his Internet exploits, investigators said.

Still, the capture of Mitnick gives the FBI custody of a notoriously
persistent and elusive computer break-in expert. Raised in the San Fernando
Valley near Los Angeles by his mother, Mitnick has been in and out of
trouble with the law since 1981.

It was then, as a 17-year-old, that he was placed on probation for stealing
computer manuals from a Pacific Bell telephone switching center in Los
Angeles.

Those who know Mitnick paint a picture of a man obsessed with the power
inherent in controlling the nation's computer and telephone networks.

The recent break-ins he is accused of conducting include forays into
computer systems at Apple Computer Inc. and Motorola Inc. and attacks on
commercial services that provide computer users with access to the
Internet, including the Well in Sausalito, Calif., Netcom in San Jose,
Calif., and the Colorado Supernet, in Boulder, Colo.

To make it difficult for investigators to determine where the attacks were
coming from, Mitnick is said to have used his computer and modem to
manipulate a local telephone company switch in Raleigh to disguise his
whereabouts.

In recent weeks, as an elite team of computer security experts tightened an
invisible electronic net around the fugitive, Mitnick continued to taunt
his pursuers, apparently unaware of how close they were to capturing him.

About 10 days ago, for example, someone whom investigators believe to have
been Mitnick left a voice-mail message for Shimomura, a Japanese citizen.
The message reprimanded Shimomura for converting the intruder's earlier
voice-mail messages into computer audio files and making them available on
the Internet.

"Ah Tsutomu, my learned disciple," the taunting voice said. "I see that you
put my voice on the Net. I'm very disappointed, my son."

But the continued attempts at one-upmanship simply gave the pursuers more
electronic evidence.

"He was a challenge for law enforcement, but in the end he was caught by
his own obsession," said Kathleen Cunningham, a deputy marshal for the U.S.
Marshals Service who has pursued Mitnick for several years.

Mitnick first came to national attention in 1982 when, as a teen-age prank,
he used a computer and a modem to break into a North American Air Defense
Command computer.

He subsequently gained temporary control of three central offices of
telephone companies in New York City and all the phone switching centers in
California.

This gave him the ability to listen in on calls and pull pranks like
reprogramming the home phone of someone he did not like so that each time
the phone was picked up, a recording asked for a deposit of a coin.

But the break-ins escalated beyond sophomoric pranks. For months in 1988,
Mitnick secretly read the electronic mail of computer security officials at
MCI Communications and Digital Equipment Corp., learning how their
computers and phone equipment were protected.

Officials at Digital later accused him of causing $4 million in damage to
computer operations at the company and stealing $1 million of software. He
was convicted in July 1989 and sentenced to a year in a low-security
federal prison in Lompoc, Calif.

One of his lawyers convinced the court that Mitnick had an addiction to
computers. In July 1989, after his release from prison, he was placed in a
treatment program for compulsive disorders, the Beit T'Shuvah center in Los
Angeles. During his six months there, he was prohibited from touching a
computer or modem.

That restriction was a condition of his probation when he was released in
mid-1990, and it was for reportedly violating this condition that federal
officials were pursuing him when he dropped out of sight in November 1992.

In September 1993, the California Department of Motor Vehicles also issued
a warrant for his arrest. The warrant stated that Mitnick had wiretapped
calls from FBI agents. He then used law-enforcement access codes obtained
by eavesdropping on the agents to illegally gain access the drivers'
license data base in California.

Federal law enforcement officials believe that Mitnick has conducted a long
string of computer and phone telephone network break-ins during more than
two years on the run.

And they say his ability to remain at large until now illustrates the new
challenges that law enforcement officials face in apprehending criminals
who can cloak themselves behind a curtain of forged electronic data.

------------------------------------------------------------------------------
~Newsgroups: alt.2600
~From: TomPoltor@aol.com
~Subject: New York Times article II
~Date: Sat, 18 Feb 1995 15:35:04 -0500

HACKING: How a Computer Sleuth Traced a Digital Trail

Feb 16, 1995

By John Markoff

   RALEIGH, N.C. - It takes a computer hacker to catch one.

  And if, as federal authorities contend, 31-year-old computer outlaw Kevin
D. Mitnick is the person behind a recent spree of break-ins to dozens of
corporate, university and personal computers on the global Internet, his
biggest mistake was raising the interest and ire of Tsutomu Shimomura.

  Shimomura, who is 30, is a computational physicist with a reputation as a
brilliant cyber-sleuth in the tightly knit community of programmers and
engineers who defend the country's computer networks.

  And it was Shimomura who raised the alarm in the Internet world after
someone used sophisticated hacking techniques on Christmas Day to remotely
break into the computers he keeps in his beach cottage near San Diego and
steal thousands of his data files.

  Almost from the moment Shimomura discovered the intrusion, he made it his
business to use his own considerable hacking skills to aid the FBI's inquiry
into the crime spree.

  He set up stealth monitoring posts, and each night over the last few weeks,
Shimomura used software of his own devising to track the intruder, who was
prowling around the Internet. The activity usually began around
mid-afternoon, Eastern time, broke off in the early evening, then resumed
shortly after midnight and continued through dawn.

  Shimomura's monitoring efforts enabled investigators to watch as the
intruder commandeered telephone company switching centers, stole computer
files from Motorola, Apple Computer and other companies, and copied 20,000
credit-card account numbers from a commercial computer network used by some
of the computer world's wealthiest and technically savviest people.

  And it was Shimomura who concluded last Saturday that the intruder was
probably Mitnick, whose whereabouts had been unknown since November 1992, and
that he was operating from a cellular telephone network in Raleigh, N.C.

  Sunday morning, Shimomura took a flight from San Jose to Raleigh-Durham
International Airport. By 3 a.m. Monday, he had helped local telephone
company technicians and federal investigators use cellular-frequency scanners
to pinpoint Mitnick's location: a 12-unit apartment building in the northwest
Raleigh suburb of Duraleigh Hills.

  Over the next 48 hours, as the FBI sent in a surveillance team from
Quantico, Va., obtained warrants and prepared for an arrest, cellular
telephone technicians from Sprint Corp. monitored the electronic activities
of the man they believed to be Mitnick.

  The story of the investigation, particularly, Shimomura's role, is a tale
of digital detective work in the ethereal world known as cyberspace.

A Computer Sleuth Becomes a Victim

   On Christmas Day, Tsutomu Shimomura was in San Francisco, preparing to
make the four-hour drive to the Sierra Nevadas, where he spends most of each
winter as a volunteer on the cross-country ski patrol near Lake Tahoe.

   But the next day, before he could leave for the mountains, he received an
alarming telephone call from his colleagues at the San Diego Supercomputer
Center, the federally funded research center that employs him. Someone had
broken into his home computer, which was connected to the center's computer
network.

   Shimomura returned to his beach cottage near San Diego, in Solana Beach,
Calif., where he found that hundreds of software programs and files had been
taken electronically from his powerful work station. This was no random
ransacking: the information would be useful to anyone interested in breaching
the security of computer networks or cellular phone systems.

   Taunting messages for Shimomura were also left in a computer-altered voice
on the Supercomputer Center's voice-mail system.

   Almost immediately, Shimomura made two decisions. He was going to track
down the intruders. And Lake Tahoe would have to wait awhile this year.

   The Christmas attack exploited a flaw in the Internet's design by fooling
a target computer into believing that a message was coming from a trusted
source.

   By masquerading as a familiar computer, an attacker can gain access to
protected computer resources and seize control of an otherwise well-defended
system. In this case, the attack had been started from a commandeered
computer at Loyola University of Chicago.

   Though the vandal was deft enough to gain control of Shimomura's
computers, he, she or they had made a clumsy error. One of Shimomura's
machines routinely mailed a copy of several record-keeping files to a safe
computer elsewhere on the network - a fact that the intruder did not notice.

   That led to an automatic warning to employees of the San Diego
Supercomputer Center that an attack was under way. This allowed the center's
staff to throw the burglar off the system, and it later allowed Shimomura to
reconstruct the attack.

   In computer-security circles, Shimomura is a respected voice. Over the
years, software security tools that he has designed have made him a valuable
consultant not only to corporations, but also to the FBI, the Air Force and
the National Security Agency.


Watching An Attack From a Back Room

   The first significant break in the case came on Jan. 28, after Bruce
Koball, a computer programmer in Berkeley, Calif., read a newspaper account
detailing the attack on Shimomura's computer.

  The day before, Koball had received a puzzling message from the managers of
a commercial on-line service called the Well, in Sausalito. Koball is an
organizer for a public-policy group called Computers, Freedom and Privacy,
and the Well officials told him that the group's directory of network files
was taking up millions of bytes of storage space, far more than the group was
authorized to use.

  That struck him as odd, because the group had made only minimal use of the
Well. But as he checked the group's directory on the Well, he quickly
realized that someone had broken in and filled it with Shimomuru's stolen
files.

  Well officials eventually called in Shimomura, who recruited a colleague
from the Supercomputer Center, Andrew Gross, and an independent computer
consultant, Julia Menapace.

  Hidden in a back room at the Well's headquarters in an office building near
the Sausalito waterfront, the three experts set up a temporary headquarters,
attaching three laptop computers to the Well's internal computer network.

  Once Shimomura had established his monitoring system, the team had an
immediate advantage: it could watch the intruder unnoticed.

  Though the identity of the attacker or attackers was unknown, within days a
profile emerged that seemed increasingly to fit a well-known computer outlaw:
Kevin D. Mitnick, who had been convicted in 1989 of stealing software from
Digital Equipment Corp.

  Among the programs found at the Well and at stashes elsewhere on the
Internet was the software that controls the operations of cellular telephones
made by Motorola, NEC, Nokia, Novatel, Oki, Qualcomm and other manufacturers.
That would be consistent with the kind of information of interest to Mitnick,
who had first made his reputation by hacking into telephone networks.

  And the burglar operated with Mitnick's trademark derring-do. One night, as
the investigators watched electronically, the intruder broke into the
computer designed to protect Motorola Corp.'s internal network from outside
attack.

  But one brazen act helped investigators. Shimomura's team, aided by Mark
Seiden, an expert in computer fire walls, discovered that someone had
obtained a copy of the credit-card numbers for 20,000 members of Netcom
Communications Inc., a service based in San Jose that provides Internet
access.

  To get a closer look, the team moved its operation last Thursday to
Netcom's network operation center in San Jose.


High-Tech Tools Force an Endgame

  Netcom's center proved to be a much better vantage point for watching the
intruder. To let its customers connect their computer modems to its network
with only a local telephone call, Netcom provides dozens of computer dial-in
lines in cities across the country.

  Hacking into the long-distance network, the intruder was connecting a
computer to various dial-in sites to elude detection. Still, every time the
intruder would connect to the Netcom system, Shimomura was able to capture
the computer keystrokes.

  Late last week, FBI surveillance agents in Los Angeles were almost certain
that the intruder was operating somewhere in Colorado. Yet calls were also
coming into the system from Minneapolis and Raleigh.

  The big break came late last Saturday night in San Jose, as Shimomura and
Gross, red-eyed from a 36-hour monitoring session, were eating pizza.
Subpoenas issued by Kent Walker, the U.S. assistant attorney general in San
Francisco, had begun to yield results from telephone company calling records.

  And now came data from Walker showing that telephone calls had been placed
to Netcom's dial-in phone bank in Raleigh through a cellular telephone modem.

  The calls were moving through a local switching office operated by GTE
Corp. But GTE's records showed that the calls had looped through a nearby
cellular phone switch operated by Sprint.

  Because of someone's clever manipulation of the network software, the GTE
switch thought that the call had come from the Sprint switch, and the Sprint
switch thought that the call had come from GTE. Neither company had a record
identifying the cellular phone.

  When Shimomura called the number in Raleigh, he could hear it looping
around endlessly with a "clunk, clunk" sound. He called a Sprint technician
in Raleigh and spent five hours comparing Sprint's calling records with the
Netcom log-ins. It was nearly dawn in San Jose when they determined that the
cellular phone calls were being placed from near the Raleigh-Durham
International Airport.

  By 1 a.m. Monday, Shimomura was riding around Raleigh with a second Sprint
technician, who drove his own car so as not to attract attention. From the
passenger seat, Shimomura held a cellular-frequency direction-finding antenna
and watched a signal-strength meter display its readings on a laptop computer
screen. Within 30 minutes the two had narrowed the site to the Players Court
apartment complex in Duraleigh Hills, three miles from the airport.

  At that point, it was time for law-enforcement officials to take over. At
10 p.m. Monday, an FBI surveillance team arrived from Quantico, Va.

  In order to obtain a search warrant it was necessary to determine a precise
apartment address. And although Shimomura had found the apartment complex,
pinning down the apartment was difficult because the cellular signals were
creating a radio echo from an adjacent building. The FBI team set off with
its own gear, driven by the Sprint technician, who this time was using his
family van.

  On Tuesday evening, the agents had an address - Apartment 202 - and at 8:30
p.m. a federal judge in Raleigh issued the warrant from his home. At 2 a.m.
Wednesday, while a cold rain fell in Raleigh, FBI agents knocked on the door
of Apartment 202.

  It took Mitnick more than five minutes to open it. When he did, he said he
was on the phone with his lawyer. But when an agent took the receiver, the
line went dead.

----------------------------------------------------------------------------

~From: fisher@chr27 (Lawrence W. Fisher)
~Newsgroups: comp.org.decus,comp.security.misc,alt.2600
~Subject: Re: Kevin Mitnick arrest
~Date: 21 Feb 95 13:04:38 GMT

Many people have been debating whether or not the things Kevin has done merit
such a stern sentence.  People have to look past this latest incident, to the
full pattern of how Kevin works, his vindictive nature, and his disregard for
society, to see why this individual needs to be kept away from society for our
own and his own protection.

Here is an article from a previous arrest, from several years ago.  It gives
some specifics about Kevin that the media has failed to pick up in this latest
arrest:

[Los Angeles Times article, dated Friday, December 16, 1988]

Ex-Computer "Whiz Kid" Held on New Fraud Counts

By Kim Murphy, Times Staff Writer

Kevin Mitnick was 17 when he first cracked Pacific Bell's computer system,
secretly channeling his computer through a pay phone in a San Fernando
Valley parking lot to alter telephone bills, penetrate other computers,
and steal $200,000 worth of data from a San Francisco corporation.

A Juvenile Court judge at the time sentenced Mitnick to six months in a youth
facility, and he was released on probation after serving his sentence.
Suddenly, his probation officer found that her phone had been disconnected
and the phone company had no record of it.

A judges credit record at TRW Inc. was inexplicably altered.  Police computer
files on the case were accressed from outside.  A new warrant for Mitnick's
arrest was issued, accusing him of breaking into TRW's computer, but he fled
to Isreal.

Upon his return, there were new charges filed in Santa Cruz, accusing Mitnick
of stealing software under development by Microport Systems, and federal
prosecuters have a judgment showing Mitnick was convicted on the charge.
There is, however, no record of the conviction in Santa Cruz's computer
files.

On Thursday, Mitick, now 25, was charged in two new crimpinal complaints
accusing him of causing $4 million damage to a Digital Equipment Corp.
computer, stealing a highly secret computer security system and gaining
access to unauthorized MCI long-distance codes through university computers
in Los Angeles and England.

U.S. Magistrate Venetta Tassopulos took the unusual step of ordering the
young Panorama City computer whiz held without bail, ruling that when
armed with a keyboard he posed a danger to the community.

"This thing is so massive, we're just running around trying to figure
out what he did," said Assistant U.S. Atty. Leon Weidman, who is prosecuting
the case.  "This person, we believe, is very, very dangerous, and he needs
to be detained and kept away from a computer."

Investigators from the FBI, the Los Angeles County district attorney's office
and the Los Angelese Police Department say they are only now beginning to
put together a picture of Mitnick and his alleged high-tech escapades.

"He's several levels above what you would characterize as a computer hacker."
said Detective James K. Black, head of the Police Department's computer
crime unit.  "He started out with a real driving curiosity for computers
that went beyond personal computers . . . He grew with the technology."

Mitnick's lawyer, Anthony J. Patti, said he would have no comment on the
case pending Mitnick's arraignment on two counts of computer fraud.  The
case is believed to be the first in the nation under a federal law that
makes it a crime to gain access to an interstate computer network for 
criminal purposes.

He faces a maximum of 20 years in prison and a $500,000 fine.

Federal prosecuters also obtained a court order Thursday restricting Mitnick's
telephone calls from jail, fearing he might gain access to a computer over the
phone lines.  At Mitnick's request, Tassopulos authorized him to telephone
his lawyer, his wife, his mother and his grandmother under jail officials
supervision.

Los Angeles police are trying to determine what other damage Mitnick may have
done with his computer terminal, Black said.

[End of Los Angeles Times article, dated Friday, December 16, 1988]

-----------------------------------------------------------------------------


~From: raustin@nyx.cs.du.edu (Ronald Austin)
~Newsgroups: alt.2600,alt.journalism,alt.news-media,alt.internet.media-coverage,comp.org.eff.talk,comp.security.unix,comp.security
~Subject: Markoff Aids Mitnick Investigation
~Date: 20 Feb 1995 04:22:48 -0700

Los Angeles Times, Feb. 19, 1995 
---------------------------------------
The group tracking Mitnick had now grown to include New York Times
reporter John Markoff, who had written a book about Mitnick and other
hackers.  "John was our Kevin expert," Shimomura said.  For instance, 
Menapace said, if Mitnick's signal went silent, they would ask what 
Mitnick would probably be doing now.  If he was eating, where would
he go?  Markoff acknowledged trading information with Shimomura, but
denied being a member of the team.  "I wasn't involved.  I am a reporter.
Tsutomu and Julia call me a member of their team, and that's fine if they
want to call me that.  But I was a reporter," Markoff said.  He said he
gave them nothing beyond what was available in his book.
---------------------------------------
 
The reason that Mr. Markoff has to strictly deny helping Mr. Shimomura
and his 'team' is that the behavior as reported is a serious violation
of journalistic ethics.  How can he acknowledge "trading information" 
yet say he was not involved?  The fact is that not only was Mr. Markoff
involved, he was present in North Carolina at the time of the location
and capture of Mr. Mitnick giving advice and aiding in his apprenhenison.  
While apprehension of a federal fugitive is desirable, it is not Mr. 
Markoff's place to aid in the investigation and he knows it.  There is a 
factor here which did not manage to make the front page of the New York 
Times and that is Mr. Markoff's sequel to his book "Cyberpunk".  He has
created the story for that sequel by abusing his position and perpetrating
a hoax on the public.
 
A few months ago Mr. Markoff printed a front page story about Kevin
Mitnick.  Recall that Markoff co-authored a book with Katie Haffner
of which Kevin Mitnick was a subject.  Shortly thereafter, Mr. Markoff 
brought us yet another front page story - this time about what was
seemingly the biggest threat to internet security in a decade.  The
fact is, the bug being exploited was a decade old, and Mr. Markoff
obtained the CERT advisory days before it was released to the general
public.  The CERT advisory dealt with the break-in on Tsutomu Shimomura's
computer.  While Mr. Markoff's latest article would have us believe that
Kevin Mitnick was only considered a suspect in that break-in on February 
12th, the fact is that Mitnck's name was mentioned at the Sonoma conference 
at which Shimomura gave the talk that was the basis for the CERT advisory.
How did Markoff get a copy of the CERT advisory before anyone else?
Was this really such a big threat to internet security that it was worthy
of all of the coverage it recieved?  The Feb. 19th L.A. Times also quotes Mr. 
Shimomura as saying that Mitnick "did nothing imaginative.  I can see 
nothing new."  But wasn't the break in on Mr. Shimomura's machine so new 
and imaginitive that it made the front page of the country's largest 
newspaper?  And didn't Mr. Markoff, in fact, suspecting that the break-ins 
were comitted by Mitnick, feed us this article only so that he could later 
break the big story that it was the subject of his book and previous front 
page article that committed this most heinous act?
 
Every bit of information that is publically available about Kevin Mitnick
seems to come to us, in one way or another, from John Markoff.  All of
the quotes come from 'Cyberpunk'.  Markoff even quotes his own book in his
articles without making reference to the fact that he wrote the book.
All of the articles that come to us about the recent incident are simply
lifted from Mr. Markoff's article.  With this in mind, let us examine
the media blitz of this "Clash of the Titans in Cyberspace".  Since Mr.
Markoff was part of the investigation he had a leg up on everyone else
and shaped the way the story unfolded.  While Mr. Shimomura is without a
doubt worthy of a great deal of praise here, the more infomation that
comes from sources other than the New York Times the more it appears that
Shimomura was not a lone wolf intent on settling the score as Mr. Markoff 
would have us believe.  Instead of Shimomoura laying all of the groundwork 
only to call in law enforcement at the last minute to make the arrest as 
Markoff has told us, it appears that there was a longstanding investigation 
going on that encompassed many agencies and internet providers and that it 
was Mr. Shimomura who stepped in at the last minute to help out.  
But the groundwork had been done to pave the way for this particular hero
to step into the roll.  In the February 6th edition of Newsweeek, where
Katie Haffner is now employed, a feature on Shimomura was done which
included a large picture of what Markoff now calls our "cybersleuth" posing
in front of his laptop.  Bear in mind that at this point, supposedly, 
Shimomura had no idea that he was dealing with Mitnick.  Also remember that
Katie Haffner at Newsweek was the co-author along with Mr. Markoff 
on Cyberpunk.  But for Shimomura to be cast as one of a team just won't do 
for the book. A hero is vital and the personal details provided to us about 
Mr. Shimomura's life and hobbies, while not relevent at all to the story of 
a manhunt, give Mr. Markoff something to take to the bargaining table when 
selling his sequel. 
 
I think it is incumbent upon the New York Times to launch an investigation
into all of this.  This is the most serious violation of journalistic
ethics I have ever seen.  I find myself wondering who is really more
dangerous when left unchecked - Kevin Mitnick or John Markoff.

---------------------------------------------------------------------------

~From: emmanuel@well.sf.ca.us (Emmanuel Goldstein)
~Newsgroups: alt.2600
~Date: 17 Feb 1995 11:23:57 GMT

HERE IT IS, WITHOUT COMMENT:

NETCOM HELPS PROTECT THE INTERNET

- A Letter from CEO Bob Rieger to Our Customers -


I know many of you are interested in NETCOM's involvement with the arrest
of Kevin Mitnick, and how this may impact you, if at all, as a NETCOM
subscriber.  First, let me supply a chronology of events:

1. In a routine security check, NETCOM discovered a misappropriated file.
As a result, we began an investigation to trace what appeared to be a
security breach.

2. At about the same time, the WELL (a small Sausalito-based on-line
provider) was investigating an account with an unexpectedly large amount
of disk usage. In the course of this investigation, they discovered
suspicious material which included items believed illicitly obtained from
well-known network security expert Tsutomu Shimomura's computer.
Mr. Shimomura performed network monitoring at the WELL, and determined that
the account was being accessed from a number of sites, including NETCOM.

3. The WELL contacted NETCOM for assistance in tracking the source of the
security breach.

4. A day or two later, the FBI contacted NETCOM and requested NETCOM's
active involvement in the broadening investigation of the suspicious
activities at the WELL.

5. NETCOM caucused with representatives of the WELL, the FBI, the U.S.
Attorney's Office, Mr. Shimomura, and Julia Menapace (an independent
computer consultant and associate of Mr. Shimomura).

6. Following the conversation, it was decided that the best vantage point
for further tracking of these activities was NETCOM's Network Operations
Center.

7. NETCOM operations staff joined their efforts with Mr. Shimomura and
his associates to trace the suspect intrusions to a particular telephone
modem in NETCOM's Raleigh, N.C. site.

8. At that point, the U.S. Justice Department subpoenaed the local
telephone carrier for records of dial-ins at specific times to this
modem. It became apparent that the telephone company's switch equipment
had been compromised, so that these records could not be obtained.
However, the Justice Department found another method for making a match.

9. With this information, the Justice Department knew the approximate
location of the originating call.

10. Mr. Shimomura flew to Raleigh and used cellular tracking equipment to
locate the apartment building the calls were coming from. Eventually, the
calls were traced to an individual apartment, and Mr. Mitnick was arrested.


I hope this detailed recounting helps explain the necessity for silence
and discretion on NETCOM's part while the investigation was ongoing.
Similarly, we need to be appropriately discrete during the
continuing investigation of Mr. Mitnick's alleged illegal activities.
While respecting these legitimate restraints, we will provide
as much information as possible on a timely basis to you. (As an aside,
you may have noticed that I recently promoted Mr. Kael Loftus to the
position of Customer Liaison.  Mr. Loftus has already proven very
helpful in facilitating communication between our customers and NETCOM.)

There has been some concern expressed about the security of NETCOM
customers' credit card numbers. While this incident may have involved the
duplication of some credit card numbers, this would apply only to UNIX
shell accounts. NETCOM has always made system security its top priority,
but every UNIX system has loopholes that can potentially be exploited by
an expert cracker. However, to provide additional security for our UNIX
accounts, we have further isolated these customers' billing information,
including credit card data. This is why the "ccupdate" feature for the
UNIX shell accounts has been disabled, and why the "quota" program
currently says,"Your account balance is temporarily unavailable." These
features will be reinstated when we are able to do so in a secure fashion.

As a practical matter, at this time we have absolutely no indication that
any of our UNIX shell customers' credit card numbers have been used
illicitly.

Naturally, we encourage all customers to check their credit card billing
statements carefully. If there is any hint of inappropriate billing, this
should be brought to the immediate attention of the credit card issuer
for reversal of those charges.

The incident did not involve NetCruiser accounts, which make up the vast
majority of NETCOM accounts. Fortunately, the security firewalls built-in
to NetCruiser's system architecture makes such a compromise far more
difficult.

The big story in all of this is that the Internet is maturing into an
extraordinarily efficient means of communication that millions of people
use and depend on daily. NETCOM will do everything in its power to help
assure the security of our network. We will spend the money and employ
the technology, but deterrence is our real goal.

Common thieves should know that NETCOM will be ever vigilant in seeking
their identification and prosecution.

----------------------------------------------------------------------------

~From: deadpig@fbi.com
~Newsgroups: alt.2600
~Subject: !!! Mitnick Newstorys !!!
~Date: 18 Feb 1995 05:45:13 GMT

These storys were found by me on *some* online news service.. enjoy.

*****************************************************************************

16:04 Master cyberthief appears in court

RALEIGH, North Carolina, Feb 17 (AFP) - A man described as the world's most
dangerous computer hacker was ordered held without bond when he appeared
Friday before a federal magistrate. 

The master cyberthief, Kevin Mitnick, 31, appeared in court in leg irons as he
waived his right to a probable cause hearing before Magistrate Wallace Dixon. 

Mitnick, who has broken into military defense computers, credit card data
banks and telephone company systems, was arrested by the FBI this week after a
two-week nationwide electronic manhunt by law enforcement agents and computer
specialists. 

"I'm curious to know what's broken in him ... why he feels compelled to do
this," said Tsutomu Shimomura, a 30-year-old computer security specialist with
the San Diego Supercomputer Center in California, who helped set up the web
that nabbed Mitnick. 

Mitnick is charged with computer fraud and illegal use of a telephone access
device, federal crimes that could lead to up to 20 years in prison. 

Mitnick had been wanted since November 1992, but the search began in earnest
in the last few weeks when authorities enlisted the help of Shimomura and his
team of experts, who traced Mitnick to an Internet provider and eventually
determined his calls were coming from a cellular phone in North Carolina. 

The FBI and local telephone technicians drove around the city of Raleigh 
Monday with Shimomura and a directional antenna to trace the calls to 
Minnick's apartment complex. 

Mitnick, one of the first people indicted under the Computer Security Act of
1987, was convicted in 1989 of breaking into MCI Corp.'s computer to gain
long-distance access codes and of causing four million dollars in damage to
Digital Equipment Corp. He served one year in prison and underwent
court-ordered therapy 

His former therapist, Harriet Rosetto, dismissed claims that Mitnick was a
dangerous cyberspace criminal. 

Rosetto said she sees Mitnick as "a sad, lonely, angry, isolated boy  ... That
he's become public enemy No. 1 is kind of laughable." 

Mitnick's arrest underlines the problem of fraud and other illicit activity on
the Internet and other computer networks, analysts said. Last month, the US
administration established a Computer Emergency Response team to help guard
against piracy on the government-operated Intenet. 

Industry experts say some of the largest US companies, including IBM, General
Electric and Sprint have been victimized by hackers using on-line networks. 

rl/ak

End of story, <Enter> for list: 2

--------------------------------------------------------------------------

15:54 CTIA PRAISES USE OF CELLULAR FRAUD TECHNOLOGY, INDUSTRY & 
      LAW ENFORCEMENT TEAMWORK IN ARREST OF FBI 'MOST WANTED'

 WASHINGTON, Feb. 17 /PRNewswire/ -- Cellular Telecommunications Industry
Association (CTIA) President Thomas E. Wheeler, today praised the cooperative
efforts of the FBI and the cellular industry in the recent capture of computer
hacker, Kevin Mitnick, who was arraigned today in Raleigh-Durham, North
Carolina.  Mitnick, described as one of the most wanted hackers in the world,
was captured on Wednesday with the assistance of the local wireless carrier,
Sprint Cellular. 

"We commend the FBI and Sprint Cellular for this important arrest and are
proud that Mitnick was located and apprehended through the use of state of the
art cellular tracking equipment and the technical expertise of cellular
employees," said Wheeler. 

"While this expertise represents the wireless industry's steadfast commitment
to shut down cellular fraud, Mitnick's arrest demonstrates how electronic
technology can be used to combat hackers and the other electronic criminals of
the Nineties." 

Richard Ress, supervisor special agent, national computer crime squad 
Washington, Metropolitan Field Office of the FBI, stated that "this 
investigation is a prime example of how telecommunications resources have
assisted in the efforts to locate individuals operating outside the law." 

Ress added that in the age of rapidly changing technology, "it is important
going into the 21st century that law enforcement specialist, 
telecommunications and computer industry personnel continue working together." 

According to Wheeler, Mitnick's ability to circumvent computer and 
telecommunications systems has long been known by the industry. 

In an effort to protect against such activity, the telecommunications industry
has established a technical analysis laboratory to examine such attacks and
provide recommendations to defend against such attacks.  The results of the
research is provided to cellular phone manufacturers to assist in developing a
more secure phone. 

In 1991, CTIA established the Fraud Task Force to facilitate a coordinated,
comprehensive effort by the cellular carriers to detect, manage, and prevent
technical and non-technical attacks on the cellular system. 

CTIA, formed in 1984, is the national organization of the wireless 
communications industry, both wireless carriers and manufacturers.  The 
membership of the association has been expanded to cover all Commercial Mobile
Radio Service providers, including cellular, personal communications services,
enhanced specialized mobile radio, and mobile satellite services. 

-0-                      2/17/95 /CONTACT:  Mike Houghton of the Cellular
Telecommunications Industry Association, 202-736-3207/ 
 CO:  Cellular Telecommunications Industry Association ST:  District of 
Columbia IN:  CPR SU:

----------------------------------------------------------------------------

~From: cocksuck@netcom.com
~Newsgroups: alt.2600
~Subject: !!! More Mitnick Storys !!! :)
~Date: 18 Feb 1995 05:47:09 GMT

10:20 California Computer Security Expert Helps Agents Track Fugitive Hacker

By David Bank, San Jose Mercury News, Calif. 
Knight-Ridder/Tribune Business News 

SAN JOSE, Calif.--Feb. 17--Tsutomu Shimomura took the Christmas Day attack on
his computer system personally. It wasn't simply that a hacker had penetrated
the electronic defenses that the 30-year-old security expert - one of the
world's best - had installed on his computers at the San Diego Supercomputer
Center. That was, 
perhaps, inevitable in the escalating combat between those who protect 
computer data on the Internet and those who steal it. 

This attack was becoming a major affront. For starters, it began almost under
his nose. Shimomura was visiting a friend in San Francisco when the intruder
remotely commandeered a workstation housed in the same apartment and used it
to send the first electronic probes to Shimomura's home computer near San
Diego. 

Second, the intruder made off with a huge cache of files, including high- 
powered software tools developed by Shimomura that were used in subsequent 
break-ins during an eight-week cyberspace crime spree that rattled the 
computer network establishment. 

Third, the hacker left a series of taunting messages on Shimomura's voice-mail.

And finally, Shimomura's relentless tracking of the perpetrator kept him away
from the backcountry ski trails around Lake Tahoe during one of the best ski
seasons in years. 

Shimomura's efforts led to Wednesday's capture of Kevin Mitnick, the country's
most notorious hacker. Mitnick, known as "Condor," had been a fugitive from
justice for more than two years. With Shimomura's help, federal agents
arrested Mitnick at an apartment in Raleigh, N.C. 

"Kevin was a pain in the ass," Shimomura said by telephone Thursday. "He cost
a lot of people a lot of time and effort. I'd rather go ski." 

The savvy and software skills demonstrated during weeks of tracking Mitnick
across the Internet have made Shimomura a celebrity in the normally shadowy
world of computer network security. 

"You've got to paint him as the knight in shining armor," said Jim Settle,
former head of the FBI's computer crimes squad and now a private computer
security consultant. "He had all the smarts needed to know how to solve it." 

Brilliant and intense, Shimomura keeps a foot in both the world of the 
computer security establishment and the loose-knit fraternity of hackers. He's
a regular at the annual Hackers' Convention but unlike many of his friends
also undertakes research projects for government agencies such as the Air
Force and the National Security Agency. 

Though Shimomura is on the side of the law, friends say he has broken into
computers around the country to demonstrate weaknesses in the systems' 
security. He has insisted on publicizing the Internet's security flaws, even 
when others feared such disclosures could lead to additional break-ins. 

Shimomura has long lived by his own rules. As a high school student in New
Jersey, Shimomura skipped school and attended classes at Princeton instead.
Without even a high school diploma, he was given a position at the Los Alamos
National Laboratory in New Mexico. Since 1992, he has been a senior research
fellow at the supercomputer center, which is affiliated with the University of
California. 

Appearing before a congressional committee last year, Shimomura demonstrated
the ease with which a conventional cellular phone could be turned into a
scanner - and then proved the point by tuning in to calls being made around
the Capitol. 

Though the software tools he has developed are among the most sophisticated in
the field, Shimomura prefers to spend his time cross-country skiing and
roller-blading. 

Shimomura, trained in physics and computational theory, first became 
interested in computer network security as an interesting sidelight. 

"He's a sculptor. He's a design theorist," said John Gage, chief of the 
science office at Sun Microsystems Inc. in Mountain View. "He thinks about how
things work in computers constantly. It's his total focus. 

"He tries to model how computers work as a physicist would. Then he can see
the holes that are implied by the structure of that computer. Then he can see
how to use those holes, or how to plug those holes." 

Those skills made him a prime target for hackers. In the wrong hands, the same
software tools he developed to bolster network security could be potent 
weapons for attacking computer systems. 

Among the programs taken from his computer in the Christmas Day attack was a
network monitoring tool that Shimomura modified under a grant from the 
National Security Agency, according to an affidavit filed by an FBI agent in 
the case. The tool is unique because it can be installed in a computer 
operating system without needing to shut down the machine. 

"Tsutomu's tools were designed to be invisible," Gage said. "Of course, that
gives people the power for good and evil." 

Shimomura put the same tools to use to catch Mitnick. The hacker had tried to
cover his tracks, but Shimomura was able to reconstruct the sequence of the
attack from traces left behind. He described his forensic methods to a group
of high-level corporate security experts in Palm Springs earlier this month. 

"It was quite impressive to those around the room, and it was quite a group of
people to be impressed," said Larry Smarr, director of the National Center for
Supercomputing Applications, who was at the conference. "It wasn't just the
techniques, the software tools. It was the smarts. People said, 'Gee, it never
would have occurred to me to use the sequence he did.'" 

Shimomura, in weeks of tracking Mitnick's activities, used sophisticated 
network "sniffers" to monitor the flow of data packets over the Internet. At 
times, Shimomura's team wrote new software on the spot. Mitnick was outmatched.

"None of those sophisticated tools that he's got could prevent us from finding
him," Shimomura said. "Perhaps we can't stop him from breaking in. But I can't
think of a lot he can do to stop us from finding him." 

Finally, when Shimomura and his associates tracked Mitnick to Raleigh, he used
a radio signal meter to locate the building. Federal agents took it from there.

Shimomura said the capture of Mitnick would not stop the growing number of
attacks on computer networks, which are a result of weaknesses inherent in 
computer operating systems and protocols. 

"The real problem is still there," he said. "He was just exploiting it." 
Shimomura said he hoped Mitnick's capture sent a message: "This is not 
acceptable behavior. It will not be tolerated." 

The ability to enforce that message makes Shimomura a valuable asset to the
private companies and government agencies seeking to make the Internet and
other computer networks safe for electronic commerce. 

Shimomura's associates say he is considering a move from the academic world to
the private sector, but Shimomura has not disclosed his plans. 

"I'm going to go back and ski," he said.  END!R$3?SJ-HACKER-COP

----------------------------------------------------------------------------

~From: emmanuel@well.sf.ca.us (Emmanuel Goldstein)
~Newsgroups: alt.2600
~Subject: Mitnick Affidavit
~Date: 17 Feb 1995 14:10:13 GMT

Part Two - more of the affidavit filed 2/14

On February 2, 1995, I was advised by Gross a computer at The Well
(an internet provider), San Francisco, California, was compromised.
GROSS reported that the machine compromised at the Well was well.well.com
(aka well.sf.ca.us). The account used to gain access is called "dono."
The logged session contained many ftp transfers (ftp being a program
for moving files form [sic] one machine to another in either direction)
to the account "dono." The intruder had previously eliminated any other
traces of activity that would have similar logs.

In the home directory of the account "dono," there are several files
of an unusual nature. "Wietse" is a file of personal E-mail from
DAN FARMER to WIETSE VENEMA (two well known authorities in computer
security). The file "0108.gz" is a compressed file that contains copies
of credit card numbers from the Internet provider Netcom. The files
"newoki.tar.Z" and "okitsu.tar.Z" match files found at Loyola
University by Tom Reynolds that were confirmed to have been copied
from Tsutomu Shimomura's machine ariel.sdsc.edu. The remaining files
contain tools for breaking into computers (obtaining root access, e.g.
full access to the machine and all user data), tools for hiding the
intruder's tracks, electronic mail from several sources, and source
code which has not been identified yet.

Gross advised that the majority of activity in the "dono" account
originated from the machine teal.csn.org which belongs to the
Colorado Supernet (CSN) (an Internet provider). The session 
documented on January 31, 1995, shows that the person using the
"dono" account had knowledge of the files taken from Shimomura's
machine and in one case the person in question renames one of the
files to a more memorable name.

Gross provided a copy of one full session from teal.csn.org wherein
the person logs in and uses the "newgrp" command which has been 
replaced with a hacker version of newgrp that allows root access
(Superuser). The "zap2" program is then run to delete the
corresponding accounting records in the log files. The intruder
then goes to the "nascom" directory, looks at the files, renames
one of the files (indicating prior knowledge of their existence),
and then users [sic] the "last" command to make sure the accounting
log files are clean.

Gross also provided a detailed listing of the files in the nascom
directory. The files are copies of the originals taken form [sic]
Tsutomu Shimomura's machine ariel.sdsc.edu on December 25-26, 1994.
The files also match the copies found at Loyola University.

--------------------------------------------------------------------

