Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 83 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow Crazy-Long Hacker Sentence Upheld in Court
EH-Net
May 23, 2013, 11:36:04 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Crazy-Long Hacker Sentence Upheld in Court  (Read 5907 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« on: July 12, 2006, 10:41:12 AM »

Quote
A federal appeals court upheld a nine-year prison term Monday for a hacker who tried and failed to steal customer credit-card numbers from the Lowe's chain of home improvement stores.

Brian Salcedo, now 23, has been in custody since 2003, when an FBI stakeout caught him and a partner breaking into several Lowe's networks over an unsecured Wi-Fi connection at a suburban Detroit store.

Under Monday's ruling, Salcedo will not be eligible for release until May 2011.

Assistant U.S. attorney Matthew Martens, who prosecuted the case, said the sentence is long, but appropriate. "I hope it achieves, not only justice in this case, but deterrence to other people thinking about doing something similar," Martens said.

Salcedo's partner in the abortive caper, 22-year-old Adam Botbyl, has less than two months left on a sentence of 26 months for his role in the plot. After serving most of that time in custody, Botbyl is now in a halfway house in Detroit.

According to court records, Botbyl stumbled across the unsecured wireless network at the Southfield, Michigan, Lowe's in the spring of 2003, while he and a roommate were wardriving the area in search of Wi-Fi hot spots.

He returned six months later with Salcedo, who was on the last month of a three-year probation term from a juvenile computer crime conviction. Together, the pair discovered they could jump from the Southfield Lowe's to the company's central data center in North Carolina, and from there to the local networks at stores around the country.

Lowe's detected the intrusions and called in the FBI, who staked out the store parking lot. The agents eventually spotted Botbyl's Pontiac Grand Prix, bristling with antennas and occupied by two young men typing on laptops. The agents watched them work for 20 minutes, then trailed them to a Little Ceasar's pizza restaurant and a local multiplex, while Lowe's security team worked to figure out what the hackers had done.

They discovered that at two of the stores -- in Long Beach, California, and Gainseville, Florida -- the pair had modified a proprietary piece of software called "tcpcredit" that Lowe's used to handle credit-card transactions, changing the program so it would stash customer's credit-card numbers where the hackers could retrieve them later. The program had collected only six credit-card numbers when it was discovered.

The FBI arrested Salcedo, Botbyl and -- apparently mistakenly -- Botbyl's roommate, Paul Timmins, who later pleaded guilty to a misdemeanor for using the Wi-Fi network to check his e-mail. Salcedo and Botbyl pleaded guilty to conspiracy and computer fraud in plea agreements with prosecutors.

Though there's no evidence either man saw a single stolen credit-card number, and despite cooperating to help Lowe's boost its security after his arrest, Salcedo was sentenced to what the government described at the time as the longest U.S. prison term for a hacker in history.

For full story:
http://wired.com/news/technology/0,71358-0.html

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Kev
Guest
« Reply #1 on: July 12, 2006, 05:48:41 PM »

Interesting that there is no penalty to the store that had an insecure wifi network.  We trust these places with our personal info!
Logged
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #2 on: July 13, 2006, 01:56:50 AM »

Nowadays there are penalties if compnaies aren't PCI (Payment Card Industry) certified.  If they don't have this compliance they won't be allowed to conduct online transactions.  I am not sure if this compliance existed then.  Lowe's should have been more diligant and agree that there should have been a penalty for them as well.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.