zlacker

[return to "Kevin Mitnick has died"]
1. josh26+W3[view] [source] 2023-07-20 00:24:24
>>thirty+(OP)
Mitnick was a hacker hero of mine in my youth. I think I’ve understood his role as jester prior to conviction less as I’ve grown older, but there’s something about the boyhood charm of being so divorced from the potential consequences of one’s actions that is almost unique.

Mitnick had so many stories that entranced the people around him. I heard one second hand of Mitnick dealing with a bank who had early voice verification software. Upon meeting the CEO he gave the executive his card and departed for the evening. Arriving back at his hotel, he called the CEO and asked him to read his phone number to him. The phone number contained all ten digits which Mitnick had neatly tape recorded so as to make the CEO’s voice reproducible. He then proceeded to use the bank’s vocal banking system to transfer $1 from the CEO’s account to his as the authentication mechanism was reading out your own account number in your voice.

When Mitnick arrived back in the board room the architect of the voice verification system was crestfallen and the bank CEO delivered a check on a silver platter.

Now how much of that tale is embellished I will never know as it was second hand, but that was the kind of whimsy Mitnick brought to our world.

Rest in Power.

◧◩
2. tomjak+A5[view] [source] 2023-07-20 00:38:02
>>josh26+W3
How would he have known the CEO's bank account number? Did the CEO write him a check at some point? Or maybe a bank's CEO traditionally gets account number 1…
◧◩◪
3. gabere+E6[view] [source] 2023-07-20 00:46:53
>>tomjak+A5
He used the CEO’s voice to access AN account, I don’t think it was the CEO’s specifically. But just an account, verified by the CEO’s voice, to his.
◧◩◪◨
4. jhugo+3J[view] [source] 2023-07-20 08:05:53
>>gabere+E6
I doubt the bank’s authentication system is built to allow the CEO’s voice to authenticate a transfer out of any account
◧◩◪◨⬒
5. LawTal+IO2[view] [source] 2023-07-20 20:07:52
>>jhugo+3J
When you do pen testing you're given a limited list of valid targets.

I imagine that the mission parameters were that he take a check and remove money from the account.

It would also make sense that this is the CEO's account, or one he also controls, because he's in on the test and can give informed consent. Also, probably the CEO doesn't have any special access so breaking into his identity wouldn't impact the bank the way breaking into the IT manager's account might.

If this was a fake account (one with no real user) then they wouldn't have discovered this flaw because Mitnick couldn't have called the user. Having a real person be exploitable is essential to proper discovery of the full scope of the problems.

◧◩◪◨⬒⬓
6. gabere+2i3[view] [source] 2023-07-20 22:49:41
>>LawTal+IO2
This is probably closer to the truth. That it was a test all along.
[go to top]