HomeSecurityThe Greek "pirates" of the Internet

The Greek "pirates" of the Internet

Report: YIANNIS PAPADOPOULOS, Photos: ENRI CANAJ

In an apartment in Neo Faliro, in a small living room lit only by the screens of two computers, Giorgos is preparing for the demonstration. He has set up the laptops so that one is the attacker and the other the victim. Using ready-made tools provided by a Linux-based operating system, he attacks from one device to another. Within a few minutes he gains access to files and applications, shows how he could intercept passwords and conversations.

_mg_8375-thumb-large

“Antivirus programs are like a poster with a police officer shouting ‘don’t do it!’” he says. “If a hacker wants to mess with you, there’s no way you can let them out.”.

George has already finished one coffee when we meet and is preparing the next one. He is 34 years old and has been involved in hacking since his teenage years. “It’s a way of life,” he says. “I was 14 years old and I wanted to download winzip (a program) that wasn’t available for free at the time. You could only try it for 30 days and that was getting on my nerves. But someone sent me instructions to crack the codes and install it. That’s how I started.” In the two decades that have passed since then, George has witnessed the evolution of the Greek hacker community. From the early years of attacks on ministry websites to the latest incident that concerned the Prosecution of Electronic Crime, with the two young people who broke Facebook’s security measures.

George, as well as two other younger and one older hackers that “K” met, agreed to speak without their real names or their online aliases being published. They all explain how exposed we are to cyberattacks and make it clear that the term “hacker” has been misunderstood. “It is not always synonymous with illegality. We use it for research purposes, to point out the gaps that exist,” says George, who currently works as a security auditor. He tests the strength of networks after receiving written approval from companies. Then, he presents them with the weaknesses of

Beginning with pranks

dimokritos-thumb-large

In 1999, for the first time, Greek hackers acquired the website hack.gr as a point of reference. There, they posted a protest resolution against the high prices charged by OTE. At the same time, they published news about hackers abroad, exchanged opinions and knowledge, and presented detailed “defacements.” Indicatively, in January 2001, they reported as victims the websites of the Ministry of Interior, the 8th Gymnasium of Thessaloniki, the 1st TEE of Serres, and the Pharmacists Association of Thessaloniki.

Several of these attacks are being mocked by other users. One of them writes on the forum regarding the defacement of the King Fm radio station website: "Hey guys, do you really think that by hacking the website of a radio station with an infinitesimal audience you will free Öcalan? Take it seriously.".

In the list of Greek attacks, the attack on the website of the Ministry of Foreign Affairs in February '99 stands out. Unknown individuals wrote on the main page: "Welcome to the Ministry of Depravity." The reason for the attack was the Öcalan case.

In 2000, the US requested assistance from Greek authorities after the codes of a military research center in Arizona were broken. At the time, the breach appeared to have been carried out from university terminals in Athens, Crete, and Thessaloniki.

A few months later, the first arrest of a Greek hacker followed in another case. The Athens District Court Prosecutor's Office then prosecuted a felony against a senior student for "continuous computer fraud." According to the authorities, the alleged perpetrator had hacked into public organization computers and charged the National Research Foundation's phone bills with exorbitant amounts from calls to "pink" lines in the Papuan islands.

His lawyers argued that there was no evidence against him and that the decision to remand the young man in custody had been taken to set an example for other hackers. Ultimately, the student was released from prison in less than ten days, as employees of the Ministry of Foreign Affairs and other public bodies assured the interrogator that their systems had not been affected by his actions. In two months, the restrictive condition of banning him from leaving the country that had been imposed on him was lifted and in six months he was fully acquitted of all charges by a unanimous acquittal by the Supreme Court.

“That’s when I realized they were starting to take us seriously,” says George about the first hacker arrest in Greece. “They were now recognizing that this phenomenon existed in our country as well. Our work was awe-inspiring.”.

Archive material from hack.gr is still available on the Internet today. The website seems to have continued to operate until 2005. In fact, on January 7th of that year, its members had posted an invitation for a meeting between Stournaris and Patision at the Papasotiriou bookstore. Today, the new generation of hackers regularly visits the secnews.gr website. There, incidents from the activities of Greek hackers are published, in order to immediately inform organizations and companies about the security gaps they may have.

How the community was divided

Gradually, divisive tendencies emerged within the Greek hacker community. A splinter group became involved in discovering vulnerabilities in company networks. They then demonstrated them in the hope of being hired. This is how, according to testimonies, at least two hackers found work before graduating from their schools.

Today, there are no corresponding prospects for professional rehabilitation. Competition is more intense. As former hackers point out, there are now many university graduates available on the job market. In a recent open letter, 19 university and technical education professors call on young people not to be swayed by the sirens of the “easy solution” of hacking. “Most likely, they will not lead them to a safe professional harbor, but rather to entanglements with the Justice System,” they write.

Since the split in the hacker community, two other groups have emerged. One insisted on nationalist-style attacks targeting Turkish websites. The other is still involved in “hacktivism” to this day. This category includes the barrage of attacks by hackers against Greek ministries in February 2012, as part of the actions of the international network Anonymous. 25-year-old Eleni also participated in those attacks. She is studying Computer Science. But her main occupation today is finding information on the Internet about people who abuse animals and anonymously reporting them to the authorities.

Today, younger hackers rarely write code, and when they do, they don't share their knowledge, older hackers tell "K." There is no flow of information like in the IRC years. Most use readily available hacking software that they either buy for 50-100 euros or find for free. "We, the younger ones, haven't learned to search. We are the generation of the fast," says 20-year-old Fotis, who is now trying to break into the hacking world. He started working in the summer after the national exams, trying, he says, to crack mobile phone applications to understand how they work. He continued focusing on computer applications and met older hackers on online forums.

The rules of ethics, cyber defense, the illusion of antiviruses

Older hackers tell "K" that their generation followed certain ethical rules. For example, they did not target hospitals. However, a year and a half ago, the People's Hospital was attacked.

"We were informed by the Cybercrime Investigation Unit. Unknown individuals appeared to have hacked into some terminals. Eventually, we saw that they had compiled a list of doctors on duty at other hospitals. They created the illusion that they had entered the system and upset us," says Yiannis Zisis, head of network security at Laiko. This incident, however, was the reason for basic security measures to be taken at the hospital. Now, users of the network at Laiko cannot install programs on their computers without the approval of the technicians.

And national exercise

In 2010, the website of the Hellenic National Defense General Staff was also attacked. “We reacted quickly then. They did not spread within the network and did not gain access to important data. Besides, we do not put classified documents on the Internet,” the Cyber ​​Defense Directorate of the Hellenic National Defense General Staff told “K”. This service began its operation in 2005 and shields the armed forces and the Ministry of National Defense from attacks. Every May, it carries out the national exercise “Panoptes” during which attacks are simulated. Universities also participate in the exercise.

The National Intelligence Service deals with the security of networks of other public organizations and ministries, while the Police's Cybercrime Prosecution Unit has the main role of identifying and arresting perpetrators.

There is constant communication between the services, however, the national policy and responsibilities in cyber defense issues are still not clear in our country, as when someone broke into the PPC network and regulated the distribution of electricity at will. "Security is not a simple matter. It is a constant struggle and the training of specialists," they explain at the Cyber ​​Defense Directorate.

The weakest link

No matter how many security measures are taken, at any level, the weak link remains the human. George says that computer antivirus programs provide an illusion of security. He explains that the malicious hacker focuses on the person behind the system and shows me how an attack on an organization or company is planned. He opens a special software on his laptop. His supposed target is the website of “Kathimerini”.

After giving the appropriate commands, it is shown the journalists' emails (not their content), while the program searches for doors in the system that may have been left open. As long as it continued to collect data on the newspaper's editors - even on the social media where they have accounts - it could, he says, create fake emails with malware and send them targeted. From there, it is up to the recipient whether they suspect the danger.

“Humans and their curiosity are the biggest vulnerabilities in a system,” says George. At some point, the secretary of a company or organization that receives hundreds of e-mails daily may open the wrong message.


The terminology:

Hacker: They are divided into White Hats and Black Hats. The former are dedicated to network security and legitimate troubleshooting, while the latter (otherwise known as crackers) illegally gain access to systems for data theft and other selfish purposes.

Phreaking: A form of hacking into telephone networks.

Phishing: The theft of data, passwords, credit card numbers.

Exploit: A piece of software or a sequence of commands that exploits a vulnerability to take control of a computer.

Pivoting: A method that uses a compromised system to attack other systems on the same network.

Source: kathimerini.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS