◆ SpookStack

Declassified Document Archive & Reader
Log In Register
Reader Ad Slot
Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.

Adrian Lamo — Part 1

444 pages · May 15, 2026 · Broad topic: General · Topic: Adrian Lamo · 444 pages OCR'd
← Back to feed
THUUNITESSIAL ALL INFORMATION 7 HEREIN If Ut TATE 02-15 02/26/2002 07:37 PM To: cc: Sudject: some hints to the WorldCom hacking that might apply to us from that same article. _http:/fonline.securityfocus.com/news/296 did he do the same on NYT Co's intranet? The Problem with Proxies As he has with other networks, Lamo found the keys to WorldCom's kingdom in open Internet proxy servers. In normal operation, a proxy server is a dedicated machine that sits between a local network and the outside world, passing internal surfers’ Web requests out to the Internet, often caching the results to speed up subsequent visits to the same URL. But it's easy and common for administrators to inadvertently misconfigure proxy servers, allowing anyone on the Internet to channel through them. Sometimes companies and organizations even unknowingly run proxies. Hackers and Privacy-conscious netizens catalog these open proxies, using them to anonymize their surfing. Lamo has perfected a different use: jumping through them to pose as a node ona company's internal network. Using a common hacker tool called "Proxy Hunter," Lamo scanned WorldCom's corporate Internet address space, and quickly found five open proxies -- one of them hiding in plain site at wireless.wcom.com. From there, he needed only to configure his browser to use one of the proxies, and he could surf WorldCom's private network as an employee. Once inside, he found other layers of security protecting various intranet sites from employees who might exceed their authorized access. But after a couple of months of sporadic exploring, Lamo has made substantial inroads. He can use WerldCom human resources system to list names and matching social security numbers for any or all of the company's 86,000 employees. With this information, all he needs is a birth date (he swears by anybirthday.com) and-he can reset an employee's password and access his or her payroll records, including information like their salary, emergency contacts, and direct deposit instructions, complete with bank account numbers. He could even modify the employee's direct deposit bank account, and divert a paycheck to his own account, if he wanted to. "A lot of people would be willing to blow town for a couple hundred thousand dollars,” says Lamo. FBI(19-cv-1495)-99
OCR quality for this page
Community corrections
First editor: none yet Last editor: none yet
No user corrections yet.
Comments
Document-wide discussion. Follow the Community Standards.
No comments on this document yet.
Bottom Reader Ad Slot
Bottom Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.

Continue Exploring

Use the strongest next step for this document: continue reading, jump to the topic hub, or move into the matching agency collection.
Continue Reading at Page 76
Jump straight to page 76 of 444.
Reader
Adrian Lamo — Part 3
Stay inside Adrian Lamo with another closely related document.
Topic
FBI Documents & FOIA Archive
Open the FBI agency landing page for stronger archive context.
FBI
Adrian Lamo Topic Hub
See the topic overview, related documents, and linked subtopics.
Hub

Agency Collection

This document also belongs in the FBI Documents & FOIA Archive landing page, which is the stronger starting point for agency-level browsing and for searches focused on FBI records.
FBI Documents & FOIA Archive
Open the agency landing page for introduction text, topic links, and more FBI documents.
FBI

Explore This Archive Cluster

This document belongs to the General archive hub and the more specific Adrian Lamo topic page. Use these hub pages when you want the broader collection context, linked subtopics, and more documents around the same archive thread.
letter bureau
Related subtopics
John Murtha
57 documents · 1471 known pages
Subtopic
Sen Joseph Joe Mccarthy
42 documents · 2653 known pages
Subtopic
D B Cooper
41 documents · 13789 known pages
Subtopic
Kansas City Massacre
38 documents · 5300 known pages
Subtopic
Black Panther Party
36 documents · 3066 known pages
Subtopic
Malcolm X
36 documents · 3932 known pages
Subtopic