FBI Pays Visit to Researcher Who Revealed Yahoo Hack


Illustration: Ross Patton/WIRED[


Jonathan Hall was trying to help the internet. Earlier this week, the 29-year-old hacker and security consultant revealed that someone had broken into machines running inside several widely used internet services, including Yahoo, WinZip, and Lycos. But he may have gone too far.


Hall—the president of a security firm called Future South Technologies—went out of his way to spotlight a network of compromised computer servers that, he says, are controlled by Romanian hackers. He published his findings on his blog, saying he simply wanted to help these companies clean up a nasty computer problem. But with his aggressive investigation, he may have run afoul of the nation’s anti-hacking law, the Computer Fraud and Abuse Act, or CFAA.


“I might wake up tomorrow in handcuffs,” says Hall, who was visited by the FBI on Tuesday.


His uncertainty is an example of the general unease in the computer security community caused by aggressive government prosecutions under the CFAA. Enacted in 1986, the law makes it illegal to access a computer without authorization, but security researchers and federal prosecutors often don’t agree on what that means. Several high-profile hacking cases have played out in this gray area. Andrew “Weev” Auernheimer and Daniel Spitler were charged after writing a script that accessed information on a publicly available AT&T website, Aaron Swartz for downloading a cache of articles that he was permitted to access.


Jonathan Hall

Jonathan Hall



In Hall’s case, he went a little farther. He says he gained access to a server belonging to compression software maker WinZip and issued a command on the machine that displayed the contents of malicious file on his own monitor. After that, he ran a “kill” command on WinZip’s server that terminated the malicious program.


“It was trying to find an active working worm that was already in circulation,” he says. “That brought me to a valid active botnet that was already in use.”


The Honey Pot


His story began late last week, after he set up what’s known as a “honey pot,” a computer—which he could monitor—that appeared to be vulnerable to the recently disclosed Shellshock bug. Hall’s server got attacked, but the attack was coming from an unlikely place, a server that belonged to WinZip.


After a bit of detective work, Hall found the vulnerable server and gained access to it, leveraging the Shellshock vulnerability. He discovered that the server was part of a network of computers, all connecting back to an internet relay chat, or IRC, server that was operated by two Romanian hackers.


By Saturday night, Hall’s budding interest in the internet bug known as Shellshock was becoming a sleepless obsession. He kept digging deeper and deeper, discovering other computers that connected to the IRC server, including machines that belonged to Yahoo, Lycos Internet, and other companies. On Monday, Yahoo confirmed that it had been compromised, although Hall and Yahoo disagree on the exact nature of the compromise. Hall says that it was due to Shellshock; Yahoo says not.


Hall says examining and then killing the malicious code was a kind of justified trespass, much like removing a child from an overheating car. But others are not so sure. “It’s kind of hard to argue that being a public server, they’ve authorized you to kill processes,” says Robert Graham, the CEO of Errata Security, “but on the other hand this law is pretty vague.”


Where is the Line?


Graham himself wrote a script that scanned the internet for servers that were vulnerable to the Shellshock bug. He was doing this for research purposes, querying publicly available servers, but on the face of it, the work he did was a lot like the work that landed Auernheimer and Spitler in the sights of federal prosecutors.


Is an ad network that runs a pop-up JavaScript program on your browser actually authorized to run that code? Maybe not, Graham says. “Where that line is drawn is really hard for us to say,” he says.


The FBI showed up at Hall’s New Orleans house on Tueday, wanting to ask about the research he’d done. To a certain extent, that’s to be expected. Hall says he copied the FBI on his original email notifying Yahoo of its problems. But it isn’t his first run-in with authorities. A decade ago, Hall was charged with doing the technical work in a DDoS for hire operation. He says he had nothing to do with those denial of service attacks, and the charges were eventually dropped.


“I don’t know what they’re going to do,” he says of the FBI’s Tuesday visit. “It was an awkward kind of conversation.”



6 Things to Do in Transylvania Other Than Becoming Undead


Luke Evans as Vlad in Dracula Untold.

Luke Evans as Vlad in Dracula Untold. Jasin Boland/Universal



As the new flick Dracula Untold is here to (un)tell you: Dracula was a real dude. Well, sorta. The version in Untold, opening Friday, is the more fantastical, ghastly version of the man scholars believe Bram Stoker used as inspiration for his iconic vampire: 15th century voivode Vlad ČšepeČ™/Vlad III Dracula/Vlad the Impaler. (That last nickname he got because of his habit of leaving enemies on stakes as deterrent for advancing Ottoman soldiers.) Sound like the kind of guy whose former stomping grounds you want to visit? Good, because Romania would love to welcome you to its vast and beautiful lands.


Despite its lush countryside and lost-in-time quaint villages, the area known as Transylvania isn’t exactly a hot spot for tourists, but those who do go are typically looking for vampires. So, as with any locale that attracts a niche audience, a cottage industry has sprung up to cater to those in search of blood-suckers. We scoured the web to find a couple must-visit spots for the perfect Dracula-themed Halloween getaway.


Bran Castle


Near Brasov (about 100 miles north of Bucharest) you can go Bran Castle, the “only castle in all of Transylvania that actually fits Bram Stoker’s description of Dracula’s Castle.” (Well, phew!) You can visit the castle almost 365 days a year for six euro (students and seniors get a discount) and get a taste of the recently renovated property, where half a million people go each year to enjoy “music festivals, children’s pageants, and food fairs.” There’s also a glass elevator that lets you experience “Dracula’s escape route.” Really want the full Dracula experience? Last spring, the owners hinted they might be willing to sell Bran Castle to the right buyer, so you could theoretically make it your summer vacation home.


House of Dracula Hotel


Aside from the theme and the name there’s no real historical vampire relevance to this place, but it does have a spa. (The tagline is not: “You’ll leave looking ageless!” Missed opportunity.) It also, as Anthony Bourdain once said, looks “as if a Motel 6 had sex with a Renaissance fair and then crammed in a breakfast nook and a crummy bar.” (Honestly, though, it looks a lot more fun than Bourdain gives it credit for.)



Haunting Photos of Parasites Up Close




As a kid, Marcus DeSieno possessed two conflicting qualities: He was a nerd drawn to the natural world, yet “anxious as hell.”


In many ways, he found nature terrifying: After watching Alien at age five, he started obsessively washing his hands because he feared being infected by a parasite, and he avoided certain foods because he feared they’d cause a tapeworm. Still, he loved collecting and indexing bugs, rocks, and fossils.


It’s only natural that he would be drawn to photography, a medium long used to catalog the world around us. And like many before him, DeSieno has followed his curiosity and passion into some truly bizarre places. He’s gotten a prostate biopsy just for the sample tissue. He’s grown bacteria in the trunk of his car. And, about 18 months ago, he started amassing an impressive collection of parasites to photograph.


At first, DeSieno bought them from Etsy and eBay (where there is a thriving “Cabinet of Curiosities” community). Later, as a grad student in the University of South Florida’s studio art program, he started receiving specimens from the National Institute of Health, as well as access to the university’s microscopy lab.


But rather than produce exceedingly sharp images with the methods scientists use to conduct cancer research, DeSieno intentionally makes scientifically dubious, imprecise photographs, ultimately relying on 19th century processes. The goal, he said, is to “subvert the notion of scientific authority by pointing to my role as an amateur.”


At the microscopy lab, DeSieno dehydrates each organism in a chemical bath, them puts it through a scanning electron microscope to create a “really nice dimensional, textural image.” After working with the digital image in Photoshop, he prints a digital positive and exposes it onto dry plate gelatin ferrotype plates. His final images are prints rendered a sickly shade of yellow (“Reminiscent of bodily fluids, puss and vomit.”) using a formula concocted for his developer, fixer, and gelatin. Then he blows them up to 1:1 scale, the better to horrify viewers.


The result is scary, messy and utterly human. Each time he pours chemicals on a plate, it comes out differently, the swirls and patterns part of a language he can’t duplicate. Each image also bears a unique marker: At the edge of each frame, you’ll spot DeSieno’s fingerprint etched into the emulsion.


From a scientific perspective, DeSieno’s images aren’t terribly useful. Precision is not the point. His goal is aesthetic, not informational. Still, he hopes the images instill in viewers a curiosity about science, an interest in “the larger world of which they’re a part.” DeSieno, for his part, has come to find parasites “incredibly endearing,” even “kind of cute.” But just as his childhood curiosity remains with him, so, to does the occasional unease.


“I’d like to stay I’ve gotten over the paranoia, but just last week I was photographing a guinea worm. As I was pulling it out, it wrapped around my wrist and I started freaking out,” he said. “So there may be some lingering anxiety.”