◆ SpookStack

Declassified Document Archive & Reader
Log In Register
Reader Ad Slot
Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.

Adrian Lamo — Part 3

501 pages · May 15, 2026 · Broad topic: General · Topic: Adrian Lamo · 501 pages OCR'd
← Back to feed
Wired News: Lamo Hacks ng Claims Site ¥ Page 1 of 3 [e Home |{ } Technology jf Sreuwre |S Business { @ Politics |( (y Wired Mag |[ > Animation, Tessie AA A A Lamo Hacks Cingular Claims Site By Christopher Null @ | B® Atso by this reporter. 10:55 AM May. 29, 2003 PT Cingular can issue insurance to its mobile-phone customers to protect them against loss and damage, but it apparently can't ensure that hackers won't have full access to their personal data, Adrian Lamo, a hacker who in the past has broken into The New York Times and Yahoo, found a gaping security hole in a website run by a company that issues the insurance to Cingular customers. By accessing the site, Lamo said he could have pulled up millions of customer records had he wanted to. He said he discovered the problem this weekend through a random finding in a Sacramento Dumpster, where a Cingular store had discarded records about a customer's insurance claim for a lost phone. By simply typing in a URL listed on the detritus, Lamo was taken to the customer's claim page on a site run by lock\line LLC, which provides the claim management services to Cingular. Normally, this page should have been reachable only by passing through a password- protected gateway, but by simply entering the valid URL, Lamo discovered that individual claims pages could be accessed, no password authentication needed. Each page contained the customer's name, address and phone number, along with details on the insurance claim being made. Altering the claim ID numbers (which were assigned sequentially) in the URL gave Lamo access to the entire history of Cingular claims processed through lock\line, comprising some 2.5 million customer claims dating back to 1998. Lamo said the hack was similar to his discovery of a security hole at Microsoft in October 2001, where the server was configured to assume that if'a user could reach a certain URL that was otherwise unpublished on the Internet, that user must be authorized to do so and must already be logged in. As with his other hacks, Lamo said he had no intent of profiting from the exploit, just pointing out a security flaw. Lamo first exposed the problem to Wired News. After this reporter pointed out the flaw, Cingular and lock\line closed the hole by Wednesday morning. Cingular spokesman Tony Carter said lock\line has enabled password protection for the site and has now incorporated “obfuscation techniques” that scramble URLs so that, even in the event of a site compromise, additional records should not be easily accessible. bo bIC -1 -1 FBI(19-cv-1495)-1808 http://www.wired.com/news/privacy/0,1848,59024,00.htm1 6/12/2003
OCR quality for this page
Community corrections
First editor: none yet Last editor: none yet
No user corrections yet.
Comments
Document-wide discussion. Follow the Community Standards.
No comments on this document yet.
Bottom Reader Ad Slot
Bottom Reader Ad Slot placeholder
If you would like to support SpookStack without paying out of pocket, please consider allowing advertising cookies. It helps cover hosting costs and keeps the archive free to browse. You can change this choice at any time.

Continue Exploring

Use the strongest next step for this document: continue reading, jump to the topic hub, or move into the matching agency collection.
Continue Reading at Page 198
Jump straight to page 198 of 501.
Reader
Adrian Lamo — Part 2
Stay inside Adrian Lamo with another closely related document.
Topic
FBI Documents & FOIA Archive
Open the FBI agency landing page for stronger archive context.
FBI
Adrian Lamo Topic Hub
See the topic overview, related documents, and linked subtopics.
Hub

Agency Collection

This document also belongs in the FBI Documents & FOIA Archive landing page, which is the stronger starting point for agency-level browsing and for searches focused on FBI records.
FBI Documents & FOIA Archive
Open the agency landing page for introduction text, topic links, and more FBI documents.
FBI

Explore This Archive Cluster

This document belongs to the General archive hub and the more specific Adrian Lamo topic page. Use these hub pages when you want the broader collection context, linked subtopics, and more documents around the same archive thread.
letter bureau
Related subtopics
John Murtha
57 documents · 1471 known pages
Subtopic
Sen Joseph Joe Mccarthy
42 documents · 2653 known pages
Subtopic
D B Cooper
41 documents · 13789 known pages
Subtopic
Kansas City Massacre
38 documents · 5300 known pages
Subtopic
Black Panther Party
36 documents · 3066 known pages
Subtopic
Malcolm X
36 documents · 3932 known pages
Subtopic