Our friends from SecNews.grpublished an extremely interesting interview they took with the Greek hacker [PAOK]. We bring it to you:
![Hacker [PAOK] full interview 1 hacker](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/19171201/hacker1.jpg)
SecNews presents, in a nationwide EXCLUSIVENESS, the interview with the hacker [PAOK] who has carried out numerous politically targeted attacks.
Achieving this was not easy at all. The editorial team faced extraordinary difficulties in achieving secure anonymous communication with him (while confirming his identity) but most importantly, in building, within a short period of time, a relationship of trust so that he could make public to us what he himself wished.
[alert variation=”alert-info”]The young hacker, with mature – despite his age – argumentation but also with a full understanding of his actions regarding their legal/criminal impact, developed his positions within 5 hours of communication.[/alert]
[alert variation=”alert-success”]After all, the reason for the interview that [PAOK] chose to grant to SecNews was precisely that, namely information and not his personal, as he emphasized to us, advancement and promotion.[/alert]
Within 25 questions and in particular detail, [PAOK] gives his stance regarding hacking in Greece and the attacks he has carried out. In addition, he gives clear instructions to companies and individuals, while revealing that he has access to servers & servers that he will use when he deems necessary.
[su_divider top=”no”][/su_divider]The questions of the hacker interview [PAOK] from SecNews
Hacking methods & ways according to [PAOK]
![Hacker [PAOK] full interview 2 hacking1](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20190659/hacking1-300x192.jpg)
There are many parameters that play a role depending on the case….On the other hand, there is what we say “The end justifies the means”.
In other words, if the goal is important, you will “fight” for it as long as humanly possible, until you succeed or fail in the access you wish to gain. There are extremely many hours of searching in the digital game of “thief” and “cop” 🙂
SecNews: Can you tell us about some categories of companies/public bodies or organizations that you have access to and what kind of access is that?
[PAOK]:There are several entities that I still have access to, although several of them “closed” the door to me when they detected the preparatory stages of the attack :). Mainly, however, they are Greek public entities and companies that have to do with the public (either customer relations or collaborating with the public in other sectors).
(Editor's note: During the interview, [PAOK] informed us that during the TIF, it had carried out an attack on the website (of low traffic, of course) of the Thessaloniki Police Union. We have indeed confirmed this [here]).
SecNews: In what ways/procedures do you carry out your attacks? Are there your own tools available or do you use exploits/software weaknesses?
[su_column size=”1/3″]When you “scan” a target, your goal is to find weaknesses that you can exploit to steal data from databases and/or gain shell-level access to the server and beyond… whatever comes up.[/su_column][PAOK]: There are some tools that I use with some of my own modifications or programming additions, but I mainly use the weaknesses that I find.
When you "scan" a target, your goal is to find weaknesses that you can exploit to steal data from databases and/or gain shell-level access to the server and beyond... whatever comes up.
The level of website security in Greece & the Greek hacker community
![Hacker [PAOK] full interview 3 cyber-attack-security-breach-ehackingnews](https://cdnglobal.secnews.gr/wp-content/uploads/2014/01/20232820/cyber-attack-security-breach-ehackingnews-1-300x199.jpg)
[PAOK]: The level of security of websites, as I mentioned above, I cannot say in any case that it is high, at least for my own data. Many sites, companies or individuals are vulnerable, which is to be expected. However, in higher-profile targets (such as banks and multinational companies) things are certainly a little better.
There are clearly steps being taken to upgrade the level of security of websites in Greece, but many times they outsource the construction and hosting of websites to people who cannot adequately protect their customers' data and infrastructure, resulting in sensitive data being leaked to hackers whose intentions no one can know.
SecNews: What do you think about the hackers currently active in Greece
[PAOK]: The hacking community in Greece is not as active as I have seen lately, but that does not mean that there are not many extremely capable hackers in Greece. I believe that the potential exists, but the strong motivation to put them into practice is lacking. And let's not forget that in the times we live in now, time is limited due to the long hours of work to make a living.Hackers, I assure you, are also part of our society who work or study or have families and do not have enough time to deal intensively with their "taste". Despite all this, we have seen several "strong" attacks by Greek hackers from time to time.
SecNews: Tell us a little about yourself, do you carry out the attacks exclusively alone or are you a member of a wider organized group?
[PAOK's] "political" attacks
![Hacker [PAOK] full interview 4 deface.paok](https://www.secnews.gr/wp-content/uploads/2013/01/deface.paok_1.png)
[PAOK]: The goal is none other than for a voice of protest from the youth to be heard, so that it may be heard where it should be.
I do not discriminate, I do not listen to the “colors” of parties and I do not “shove them”, only, in my attacks. Depending on the case, I may also reward an organization/person in my own way if it is right based on its actions towards the general whole of our society. As for whether I have achieved my goals….No, I have not achieved them. There are so many that I do not know if I will ever achieve them, but I will not stop trying for the wishes of the Greek youth. The youth that, as we see in our daily lives, the Greek government has left uneducated and uneducated, without a trace of planning in education. It is obvious that our Education, year after year, Minister after Minister and according to the tastes of each one and not following mature planning and correct decisions, is going from bad to worse.
[PAOK]: Important…I wouldn’t put it that way since I consider all my attacks serious. One of my targets, however, who I focused on from the first moment I heard that famous “We ate them together”, was of course Theodoros Pangalos. The attack had received unexpected publicity at the time, which made me particularly happy, reading the comments from users who applauded my action.
[PAOK]:I always pay attention and take into account the situation so as not to create major problems on the servers that I manage to access. In no case do I have anything against the administrators or the company that manages them.
Usually my goal is to post a message, usually to political figures or services, or to extract some information that might be useful, but I NEVER destroy files or someone's work without a very serious reason... In the event that there is a serious reason (these are rare), the only appropriate solution you can follow is to destroy files at the admin/root level and with such procedures that they cannot be recovered...In short, destroying the server... Bad things!
The fear of arrest and the measures taken.
![Hacker [PAOK] full interview 5 cyber-crime-hackers-arrested](https://cdnglobal.secnews.gr/wp-content/uploads/2014/04/20215925/cyber-crime-hackers-arrested-1.jpg)
[PAOK]: Yes, unfortunately, engaging in hacking puts you in a semi-minor-major illegality situation, depending on what kind of hacking you commit, but everything is in the game and I know the risks I run. I, like most people I imagine, am looking to take as many measures as possible, so as not to get into trouble with the police. So far, nothing like that has happened and I hope it doesn't happen... 🙂
[PAOK]: Reading, is the first thing I can think of. The next thing is testing… lots of testing. Basically, if we look at them in order, you need reading to gain familiarity with the subject and the methods you will want to deal with and then lots of testing. Maybe on your own machines at first, so that you can reach the level of putting into practice what you may have been reading for so long.
At the next level, you can also get in touch with other hackers around the world to exchange opinions, knowledge, methods, etc. But this definitely comes last, because you also need to have some performances, a level to be accepted by such communities. In fact, if you make some high-profile hits, as we say, these communities find you on their own many times.
Tips & Ways to Protect Users & Companies from [PAOK]
![Hacker [PAOK] full interview 6 hacking4](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20190701/hacking4-300x191.jpg)
[PAOK]: A Windows user, who is both the largest mass and the most vulnerable, would be wise not to open/execute files that they do not know what they are/do and who sent them. There are many ways a PC can be infected, especially with this particular operating system. A good antivirus program and a good router setting should now be considered mandatory, so that they are cut off before some things start. Another important thing that users should pay attention to is not to leave their computer open and not to be present in places that a third party, whether known or unknown, may have access to.I believe these are the most basic but effective steps for protecting an everyday user.
[PAOK]: It can keep all the software installed on its server up to date. At very regular intervals, it must distinguish where and with what rights, everyone will be able to access its server, in order to avoid any security problems (RCE, RFI, PHP SHELL, etc.) that it may not know it has. There are several things it can do and usually they have the correspondingly authorized person (security officer) or group of people to do whatever is necessary so that they do not have problems.Those who do not have him, usually have problems and are … worthy of their fate 🙂
[PAOK]:I can't say that there is trust in the hacking community. You can't have trust, because when we talk about hacking, we usually talk about acts that, as we mentioned above, straddle the line between legality and illegality, so you have to be especially careful, because you never know who might be hiding behind an IP. A slightly more trustworthy option might be encrypted messages between hackers who will have previously exchanged public keys with each other in order, at least, to be able to read the message only the one I know has the key.But I can't say that there is trust.
[PAOK]'s first attacks and its “greyhat” approach
![Hacker [PAOK] full interview 7 hacking2](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20190659/hacking2-300x300.jpg)
[PAOK]: My advice is to be careful and to be aware of exactly what it is that they are doing or want to do. I say this because, the digital world, is a world where nothing is erased and nothing is lost. You can always find trouble, even for something that may have happened months or years ago. Hacking is a special occupation, you gain knowledge, you see things with a different eye, but above all you have to know what you are doing and the consequences of it.
[PAOK] : I first got involved in hacking when I was around 15-16. It was a field that always fascinated me and I always wanted to be a part of it. I was always curious about how they do this, how they do that, etc. But I had never seriously considered getting involved in it. Until at some point when I had bought a new computer, I had installed a firewall for protection, etc. and the next day when I was working on it, I started seeing notifications from the firewall about attempts to hack my computer from certain addresses, etc. That was the reason I got involved.
I immediately started trying to find out where these addresses were from, what exactly they were trying to do to me, and one question led to another. Thus, I became part of a community with a lot of reading to begin with and a lot of food for thought later. Although digital, it remains a fascinating world.
SecNews: What motivated you to carry out the attacks? Which category do you classify yourself in (blackhat/greyhat/whitehat hacker)?
But later, as a more active member of society, entering the job market and facing the problems of every citizen of this country, I started to want to express my opinion, perhaps also that of other peers at the same time through hacking. I found that attacking servers was a field where I could express it, a kind of graffiti with a message posted that many people would see.
.So having now acquired the relevant knowledge, I began to alter websites by sending messages in all directions or sought to collect data and documents that I, in my humble opinion, considered important. Iclassify myself as a Greyhat Hacker.
[PAOK]: I don't have an exact opinion right now, but they are quite a few in total. You always need to have access wherever you can in any way. It may come in handy at some point. You can do various things if you have access to servers.
type=”buttonbtn-medium” block=”btn-block”]Description of the attacks. His view on DDoS
[PAOK]: A common process is to collect as much information as you can about a target. Everything… Everything may prove useful along the way. Then you look to find weaknesses in the system that you can “hit” in order to achieve what you want.
Of course, you also look to “cover your back”, as much as possible. Now whether you will succeed or to what point you can reach to achieve it and what techniques you will follow to do so, is personal to each person and differs from case to case.
[PAOK]: It's not easy, most of the time, at least where I'm aiming. It takes a lot of searching and being able to use various techniques. Some of them might help you achieve what you want. We're always talking about a case where you set a target, and not random targeting with automated tools. In cases where a public weakness in a software has been found and you simply search for targets via Google, as most people do, things are much easier there.
[PAOK]: No, I do not participate in such attacks, I prefer to work alone or with someone I know and who thinks the same way and has a common goal.
What does he think about the future?
[PAOK]: My role model is a hacker whom I have admired in very strong attacks, although he is in a “rival” country. This is Agd_Scorp of the Turkish Hacking group Turkguvenligi. A person with a lot of knowledge!
[PAOK]: Fortunately, so far I have not had any adventures with the Cybercrime Prosecution and I hope not. From afar and loved ones 🙂
[PAOK]: What can I tell you… no one knows what will happen in 5 years. I wish I had even more knowledge in the field of computers and security and with stronger High Profile hits.

![Hacker [PAOK] full interview 8 hacking3](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20190700/hacking3-1-300x180.jpg)
![Hacker [PAOK] full interview 9 hacking5](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20190701/hacking5-1-300x169.jpg)