Hacker facing an 8-year jail term for exposing vulnerabilities in Magyar Telekom
cyware.com
cyware.com
(it was translated to English by me, sorry for any mistakes):
- he was invited to visit Telekom's office (the expenses was on him), and wanted to give them the details
- he was not convinced by the meeting that they'll solve it (close the doors): tried again, successfully (yep, that's a bit grey hat).
There are several issues not with the hacking, according to the Hungarian Civil Liberties Union:
- the prosecutors used a way too generic accusation which missed several important details, like [regarding the crime] when, how, etc.
- the accusation claimed that the hack was done by using the Internet (seriously).
- they (the prosecutors) offered a deal of "admit the crime == free to leave" but when the guy denied they asked for more prison.
- the prosecutor stated: "we are not IT people but we know from the media (!) that with Internet and certain competence he could have hidden more of his digital footprints". And the prosecutors didn't asked for expert advisory for more than one an a half year long.
- they asked for 8 years because the hacker should have been able to disturb a public interest service, though the company claimed that this server/service was not affected any of their customers.
The guy was not sentenced yet, likely won't be, but given how incompetent everyone involved one can not be sure.
Telekom does not want to press charges as far as I know, so despite their gross technical incompetence, at least their they have that going for them.
Hungary recently had a bunch of ethical hackers getting into trouble, but fortunately the people are so outraged at the powers that be trying to jail them that they don't get harmed.
Does the public prosecutor in Hungary have a poor conviction rate? I know nothing about your country, but if I were facing a similar charge in the US I would be very concerned.
BKK then tried to prosecute him but quickly dropped the case since there was a huge public outrage. The website and the related services has been down ever since the incident.
So this is why people suspect they will drop the case soon again, but as an other commenter already said, they are incompetent and corrupt to the bones, so who knows?
But Hungary is a very tense country, it only needs a spark to blow up (last time internet tax triggered a massive massive protest), so I don't think the political elite wants to risk protests and outrage.
Not if you are a politician. In the last two terms of Fidesz 1 low figure guy was convicted. I find that ridiculous since we are the poster child of corruption in the EU.
It is because the Chief Prosecutor[1] is a good old friend of Orban.
The article says the prosecutor's recommending an 8-year jail term, but since the court hasn't decided on the case — how did the hacker "get" a jail term?
Is the article wrong, or is the Hungarian legal system different from what I'm used to?
And if you really care about reputation building, you could use an ~anonymous pseudonym plus the sha256 or sha512 hash of some string. If it all works out, you just share the string, and reap the credit.
Why not publish the leak online to force the company to fix it asap?
Source: https://hungarytoday.hu/ethical-hacker-faces-8-years-in-pris...
As someone having worked in pentesting, I have mixed feelings about this situation. Whitehat or not, the hacker knew that what he was doing was illegal. Of course this gives the hacker a dilemma, as not disclosing might result in a blackhat exploiting the same vuln.
Oh gee, a “blackhat” exploits it. Moral dilemma! Who cares? You can’t control what other people will do on the internet and if it’s a target worth more than pennies of crypto cpu someone else has most likely done it already. 9/10 there’s like a dozen webshells on that box if there’s a good bug to be had.
I srsly don’t get the hand wringing folks do. Shells are shells and you know what you be doing.
But every year there are more summer children and I suppose we should look after them.
- If you do, be very careful about how you report it; must be to a recognised bug bounty program
- Especially don't do this in a repressive state
I understand that he did not want to admit wrongdoing, since he believed it should be considered an extenuating circumstance where public interest requires such action.
Maybe it's time for solo security researchers to stop being the nice guys. I'm not saying they should start behaving like blackhats, simply that self-preservation must come first and when you are faced with an industry who treats what I'd consider acts of generosity with contempt and legal action, then fuck them.
> the first vulnerability allowed the hacker to obtain an administrator password through a public-facing service. The second bug allowed him to "create a test user with administrative privileges."
Translated source article with much more information: https://translate.google.com/translate?sl=auto&tl=en&u=https...
> She browsed and found a user guide in a PDF file on the Telekom website that contained the IP address of a DNS server. Performed a routine scan for this IP address and then surprised to find that it was relatively easy to get an administrator password from here.
https://portswigger.net/daily-swig/hungarian-ethical-hacker-...
This is outrageous and ridiculous. Magyar Telekom is a bunch of crooks anyway, why in western Europe phones plans are so much cheaper?
Everything costs more than in Western Europe (except rents and services), yet people make 1/6th of the money. Hence why third of the working population left the country.
- https://www.jacobinmag.com/2018/03/viktor-orban-hungary-fide...
- https://www.jacobinmag.com/2018/04/fidesz-viktor-orban-hunga...