You are here: silicon.com > Software > Security Strategy

Security Strategy

Botched hack brings down major US port

But accused UK man claims hackers took control of his PC to launch the attack

Tags: port of houston, aaron, chatrooms, iis

By Andy McCue

Published: 7 October 2003 14:57 GMT

A UK hacker brought down the computer system of a major US port in a botched and potentially "catastrophic" denial of service revenge attack on another chatroom user, Southwark Crown Court heard today.

The Port of Houston in Texas had its servers hijacked by Aaron Caffrey, 19, from Shaftesbury in Dorset, who used a well-known 'Unicode' exploit to take advantage of security vulnerabilities in Microsoft's IIS web server software, the prosecution claimed.

The denial of service attack on 20 September 2001, which was traced to a computer at Caffrey's home by US police, was allegedly aimed at taking a South African chatroom user called 'Bokkie' offline after she had made comments on IRC attacking the US. Caffrey allegedly took offence at the comments because his girlfriend at the time, Jessica, was American.

Chatroom logs read out at Southwark Crown Court today heard that a user calling himself "Aaron" told another chatroom user on the night of the attack: "She [Bokkie] hates America. She was probably one of the people cheering when Bin Laden attacked the USA. I want to see her time-out. If she hates America, she hates Jessica. That is a no no."

The chat logs also revealed that "Aaron" used a list of unpatched servers downloaded from the internet to hijack the machines and launch a denial of service attack on Bokkie. But it almost ended in disaster when it crashed the Port of Houston's systems under the weight of 100,000 requests to ping data at Bokkie's computer, leaving vital navigation and weather data inaccessible.

US police traced the source of the attack to a computer at Caffrey's home in Dorset and the IIS Unicode denial of service tool "coded by Aaron" was found on Caffrey's computer during forensic examination.

Caffrey, who suffers from the autistic disorder Asperger syndrome, denies he was responsible for the attack and in police interviews claimed his computer was hijacked by other hackers. In the interviews Caffrey said he had only ever run exploits on his own website which runs on Microsoft's IIS server and that he has never modified data.

"My OS supports remote admin and remote assistance. At that time, the patches were not available. Anyone could control it. Windows Media Player was also unpatched. Someone has either hacked me or edited those log files. They have planted it or added to it," he said in police interviews.

With reference to the IRC logs he said hackers – often Turkish – regularly took over chatrooms with other users names and when quizzed about the Unicode hacking tool "coded by Aaron" found on his PC he said: "Aaron is a very, very common name".

But DC Stunt investigating the case, said in court today: "I see no evidence of your machine being exploited."

The case continues.

ZDNet UK's Munir Kotadia contributed to this report.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Business Objects Developer with Exposure to SAP BW - Urgently Required

If you have the relevant experience please apply or call Harry Blackhurst ASAP on 0207 469 to be considered for interviews this week. You will be ...

Salesforce.com Developers / Technical Architects (SFDC, CRM, SaaS)

Salesforce.com Developers / Technical Architects sought by an internationally recognised SFDC partner with offices throughout the America’s, ...

User Experience Architect - London - Permanent - Digital Agency

In terms of the experience required, it is essential that you have a proven track record/experience in the following: creating information ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: