4 ms·
It seems a bit far fetched that Microsoft has thousands of servers you can access publicly via default passwords. They raided his home and took all of his stuf
by rodly 14y ago
It seems a bit far fetched that Microsoft has thousands of servers you can access publicly via default passwords.
They raided his home and took all of his stuff, but didn't arrest him? How is that legal? Shouldn't he get his stuff back if they don't have any case within X hours for prosecution?
I'm sure he's playing the victim here pretty hard because he states that he doesn't believe he has done anything wrong and yet has tried selling a Durango development kit on eBay in the past. He's probably done a lot more than that to prompt an FBI agent across the world to his doorstep.
- bonzoesc 14y agoThis happened in Australia so it might be totally different, but if it happened in the US: a warrant for search and seizure of evidence requires less cause than a warrant for arrest, especially in the case where it's digital evidence that can be destroyed without a trace quite easily.
- AlexDanger 14y agoIANAL, but I believe they can seize the evidence if they have probable cause that a crime has been committed. In this case it would be easy to establish probable cause given how open this guy has been with his hacking. What I'm not sure of is how long its reasonable for the police to retain the seized equipment. Although the guy said he was unemployed, I think most IT people could make a case that the seizure of all computing equipment impedes their ability to earn a living. That doesnt seem fair if no charge s have been laid.
- Zaephyr 14y agoMy guess is that it's the power management system for the servers that is accessible and using default passwords. Usually there are outlet groups or such that can be controlled from an interface like the one in the screencap. The servers will talk to and trust the power system so that if there is a problem or outage they can be turned off. Being able to reboot is useful remote admin option. So like a lot hacks, primary access has been secured but someone forgot about the trusted secondary.