[iwar] [fc:Sudan.Bank.Hacked,.Bin.Laden.Info.Found.-.Hacker]

From: Fred Cohen (fc@all.net)
Date: 2001-09-27 16:00:37


Return-Path: <sentto-279987-2465-1001631554-fc=all.net@returns.onelist.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 by localhost with POP3 (fetchmail-5.1.0) for fc@localhost (single-drop); Thu, 27 Sep 2001 16:02:08 -0700 (PDT)
Received: (qmail 1565 invoked by uid 510); 27 Sep 2001 23:00:54 -0000
Received: from n1.groups.yahoo.com (216.115.96.51) by 204.181.12.215 with SMTP; 27 Sep 2001 23:00:54 -0000
X-eGroups-Return: sentto-279987-2465-1001631554-fc=all.net@returns.onelist.com
Received: from [10.1.1.220] by hh.egroups.com with NNFMP; 27 Sep 2001 23:00:38 -0000
X-Sender: fc@big.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-7_4_1); 27 Sep 2001 22:59:14 -0000
Received: (qmail 37792 invoked from network); 27 Sep 2001 22:59:14 -0000
Received: from unknown (10.1.10.142) by 10.1.1.220 with QMQP; 27 Sep 2001 22:59:14 -0000
Received: from unknown (HELO big.all.net) (65.0.156.78) by mta3 with SMTP; 27 Sep 2001 23:00:37 -0000
Received: (from fc@localhost) by big.all.net (8.9.3/8.7.3) id QAA23087 for iwar@onelist.com; Thu, 27 Sep 2001 16:00:37 -0700
Message-Id: <200109272300.QAA23087@big.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL1]
From: Fred Cohen <fc@all.net>
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Thu, 27 Sep 2001 16:00:37 -0700 (PDT)
Reply-To: iwar@yahoogroups.com
Subject: [iwar] [fc:Sudan.Bank.Hacked,.Bin.Laden.Info.Found.-.Hacker]
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

Sudan Bank Hacked, Bin Laden Info Found - Hacker 
By Ned Stafford, Newsbytes, 9/27/2001
<a href="http://www.newsbytes.com/news/01/170588.html">http://www.newsbytes.com/news/01/170588.html>

A group of U.K.-based hackers have cracked computers at the AlShamal
Islamic Bank in Sudan and collected data on the accounts of the Al Qaeda
terrorist organization and its leader Osama bin Laden, Kim Schmitz, a
flamboyant German hacker/businessman, has claimed. 

Schmitz, who has offered a $10 million reward for the capture of bin
Laden, told Newsbytes that the information has been turned over to the
FBI.  Bin Laden, a millionaire Saudi exile whose base is now
Afghanistan, is suspected of being the driving force behind the deadly
Sept.  11 attacks on the World Trade Center and the Pentagon with
hijacked planes.  Newsbytes could not confirm Schmitz's claim.  An FBI
spokesman in Washington declined to confirm or deny the story, saying
that the agency's policy is not to comment on information and leads it
is receiving. 

"We have received a lot of information on this case," he told Newsbytes. 
"Of course we appreciate the leads we are receiving from the public, but
we cannot confirm what specific information has been provided to us or
by whom."

Schmitz, 27, a former teen hacking prodigy who spent time behind bars
before starting a successful data security business, has been accused of
being press hungry.  He says his recent strong anti-terrorism
pronouncements are not a PR prank, but stem from his strong desire to
wipe out terrorism.  He says he has received death threats from the
Middle East. 

The bank Schmitz claimed was hacked was mentioned Wednesday by Sen. 
Carl Levin, D-Michigan during a Senate Banking Committee hearing. 
According to CNN, Levin referred to a 1996 State Department report that
said bin Laden had provided the AlShamal Islamic Bank with $50 million
in start-up capital. 

Schmitz told Newsbytes that he could not provide details about what
hackers found in AlShamal Islamic Bank's computers or about the hackers
themselves. 

"Sorry, I can't answer your questions in detail," he said.  Nonetheless,
he provided Newsbytes with the following outline of what he says
happened. 

Last week, Schmitz, who lives in Munich, posted letters on his Web site
rallying politicians to the cause of fighting terrorism and offering his
hacking expertise. 

"I received plenty of e-mails from hackers around the world offering
their services," he said. 

Schmitz founded a group that numbers around 23 hackers called "Young
Intelligent Hackers Against Terror." He calls the group YIHAT, which is
similar to the word Jihad, which is Arabic for Holy War. 

Schmitz said that last Friday, a Sudanese banker sent the group an
e-mail after reading about the $10 million reward, informing the group
that Al Qaeda and bin Laden have accounts at AlShamal Islamic Bank.  A
team of U.K.-based hackers sprang into action, and hacked the nameserver
of AlShamal Islamic Bank, he said.  They were able to gain access to the
bank's intranet by exploiting a "checkpoint firewall 1 vulnerability,"
he explained. 

After bypassing the firewall, the hackers achieved "superuser" status on
the server, and "sniffed" eight valid user IDs, and then were able to
collect information on accounts of Al Qaeda and bin Laden.  "This
information was sent to the authorities in the USA," Schmitz said. 
Schmitz sent the following e-mail to the Webmaster at the AlShamal
Islamic Bank:

"dear webmaster of sudans shamalbank, "your bank has been hacked. 
information regarding Al Qaeda's and bin Ladens accounts have been
captured.  all information reached the US authorities.  thanks for using
products from checkpoint (firewall1).  "have a nice day, Kim "Kimble"
Schmitz, Founder of "Young Intelligent Hackers Against Terror" YIHAT"

When asked which authorities received the information from the hackers,
Schmitz said: "FBI."

He said that authorities had not given the hackers a "green light" to
undertake the hacking, that the group had done so on its own initiative. 
Schmitz said the U.K.-based hackers wish to remain anonymous.  "I am the
spokesperson of the group," he said.  "They don't want to be involved
with the press.  What they do is illegal, unless we find a government
that legalizes our activities."

And somewhat mysteriously, he added: "If I would deliver details about
the hacks, I could get arrested.  I am not hacking myself, because that
is illegal.  I must keep myself out of the details to make sure that I
am still able to offer them the communication platform they need to
fight as united hackers of the world against terror."

AlShamal Islamic Bank Home Page: http://www.shamalbank.com/ 
Kim Schmitz's Personal Web Site: http://www.kimble.org/ 
Schmitz Letter to governments around the world:
<a href="http://www.kimble.org/urgent.htm">http://www.kimble.org/urgent.htm> 
Schmitz Reward For Osama Bin Laden:
<a href="http://www.kimble.org./mostwanted.htm">http://www.kimble.org./mostwanted.htm>

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Pinpoint the right security solution for your company- Learn how to add 128- bit encryption and to authenticate your web site with VeriSign's FREE guide!
http://us.click.yahoo.com/yQix2C/33_CAA/yigFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-09-29 21:08:51 PDT