HomeInvestigationsEXCLUSIVE: The hacker, in a full-length interview, also reveals...

EXCLUSIVE: The hacker [PAOK] in a full-length interview, reveals and is revealed!

PAOK hacker

SecNews presents, in a nationwide EXCLUSIVENESS, the interview with the hacker [PAOK] who has carried out numerous politically targeted attacks.

Achieving this was not easy at all. The editorial team faced extraordinary difficulties in achieving secure anonymous communication with the well-known hacker (while confirming his identity) but most importantly, in building a relationship of trust within a short period of time so that he could disclose to us what he wished.

[alert variation=”alert-info”]The young hacker, with mature – despite his age – argumentation but also with a full understanding of his actions regarding their legal/criminal impact, developed his positions within 5 hours of communication.[/alert]

SecNews publishes the report, which we believe will help security experts in companies and organizations understand the psychology and way of thinking of greyhat hackers , as well as their methods and practices in order to protect themselves.

 

[alert variation=”alert-success”]After all, the reason for the interview that [PAOK] chose to grant to SecNews was precisely that, namely information and not his personal, as he emphasized to us, advancement and promotion.[/alert]

The interview, for security reasons, as the interviewee wished, was conducted remotely, taking all the necessary security measures that he considered necessary, so that his identity would not be revealed in any way. At the beginning of the interview, he was particularly cautious, something that changed over the course and slowly outlined to us the world of hackers, from the inside.
Within 25 questions and in great detail, the hacker  [PAOK] gives his opinion regarding hacking in Greece, as well as the attacks he has carried out. In addition, he gives clear instructions to companies and individuals, while revealing that he has access to servers & servers that he will use when he deems necessary.
[hero heading=”PAOK interview“]The questions of the hacker interview [PAOK] by SecNews[/hero]

SecNews: In your opinion, what is it that makes young people get involved in hacking in Greece?

[PAOK]: I think it's a bit of curiosity, about whether they are able to carry out a successful attack and mainly it's a means of reaction for the youth which in itself is a motivation for someone to get involved.

 

type=”buttonbtn-medium” block=”btn-block”]The methods & ways of hacking according to [PAOK]
 hacking1
SecNews: How difficult is it to gain access to a company or organization? 

[PAOK]: The answer here will have to be very vague by necessity… You never know what you'll encounter when scanning a server or an organization's network. Sometimes it's easier and sometimes much harder than you initially thought.

There are many parameters that play a role depending on the case….On the other hand, there is also what we say “The end justifies the means”.
In other words, if the goal is important, you will “fight” for it as much as humanly possible, until you succeed or fail in the access you wish to gain. There are extremely many hours of searching in the digital game of “thief” and “policeman” 🙂

 

SecNews: Can you tell us about some categories of companies/public bodies or organizations that you have access to and what kind of access is that?

[PAOK]: There are several bodies that I still have access to, although several of them “closed” the door to me when they detected the preparatory stages of the attack :). Mainly, however, they are Greek public bodies and companies that have to do with the public (either customer relations, or collaborating with the public in other sectors).

(Editor's note: During the interview, the hacker informed us that during the TIF, he had carried out an attack on the website (of low traffic, of course) of the Thessaloniki Police Union. We have indeed confirmed this [here]).

SecNews: In what ways/procedures do you carry out your attacks? Are there your own tools available or do you use exploits/software weaknesses?

[PAOK]: There are some tools that I use with some of my own modifications or programming additions, but I mainly use the weaknesses that I find.

When you "scan" a target, your goal is to find weaknesses that you can exploit to steal data from databases and/or gain shell-level access to the server and beyond... whatever comes up.

Some methods are more time-consuming, requiring patience (such as xss, cookie stealing, social engineering , etc.) and some are more direct (such assql injection, shell uploading , etc.). However, I have been impressed that in Greece, large companies and organizations in 2014 have not realized the importance of SQL Injection fixes, resulting in them remaining vulnerable for many, many years!!!

 

type=”buttonbtn-medium” block=”btn-block”]The level of website security in Greece & the Greek hacker community
 cyber-attack-security-breach-ehackingnews
SecNews: What is your assessment of the level of security of websites/infrastructures and public utility services in Greece?

[PAOK]: The level of security of websites, as I mentioned before, I cannot say in any way that it is high, at least for my own data. Many sites, companies or individuals are vulnerable, which is to be expected if you like. However, in higher-profile targets (such as banks and multinational companies) things are certainly a little better.
There are clearly steps being taken to upgrade the level of security of websites in Greece, but many times they outsource the construction and hosting of websites to people who cannot adequately protect their customers' data and infrastructure, resulting in sensitive data being leaked to hackers whose intentions no one can know.

 

SecNews: What do you think about the hackers currently active in Greece?

[PAOK]: The hacking community in Greece is not as active as I have noticed lately, but that does not mean that there are not many extremely capable hackers in Greece. I believe that the potential exists, but the strong motivation to put it into practice is lacking. And let's not forget that in the times we live in now, time is limited due to the long hours of work to make a living. Hackers, I assure you, are also part of our society, who work or study or have families and do not have time to deal intensively with their "taste". Nevertheless, we have seen quite a few "strong" attacks by Greek hackers from time to time.

 

SecNews: Tell us a little about yourself, do you carry out the attacks exclusively alone or are you a member of a wider organized group?

 [PAOK]: [blockquote]I “work” on most of the hacks alone….not for any specific reason, but because I just didn’t happen to end up being an active member of a group. It’s really nice to be in a group of people who share your interests, but in my case it didn’t happen due to other obligations that keep me away from hacking from time to time. I clearly showed my support for the Greek hacking scene in several of my hacks but I can’t say that we did any organized hacks as a group.[/blockquote]

 

type=”buttonbtn-medium” block=”btn-block”]The “political” attacks of [PAOK]
SecNews: We have seen in the past that your attacks have an apolitical purpose and you send a message in all directions, targeting malicious texts with many recipients. Tell us what is the goal of the attacks you have carried out so far. Do you consider that you have achieved your goals?

[PAOK]: The goal is none other than for a voice of protest from the youth to be heard, so that it may be heard where it should be.
I do not discriminate, I do not listen to party “colors” and I do not “shove them”, only, in my blows. Depending on the case, I may also reward an organization/person in my own way if it is right based on its actions towards the general whole of our society. As for whether I have achieved my goals….No, I have not achieved them. There are so many that I do not know if I will ever achieve them, but I will not stop trying for the wishes of the Greek youth. The youth that, as we see in our daily lives, the Greek government has written off and uneducated, without a trace of planning in education. It is obvious that our Education, year after year, Minister after Minister and depending on each person's tastes and not following mature planning and sound decisions, is going from bad to worse.

 

SecNews: Tell us about one of your most important achievements, according to you.

[PAOK]: Important…I wouldn’t put it exactly like that, since I consider all my attacks serious. However, one of my targets, who I focused on from the first moment I heard that famous “We ate it together”, was of course Theodoros Pangalos. The attack had received unexpected publicity at the time, which made me particularly happy, reading the comments of users who applauded my action.
I would really like Mr. Pangalos to explain to us how we all ate them together, at a time when we didn't even have an opinion and were just kids or even unborn, when he and his group were already devouring and still devouring the efforts and sacrifices of the Greek people. That's why, if you noticed, in that attack I was a little more aggressive than I usually am... I was in a state of soul boiling 🙂.
Something similar was the case of Tsovolas , who again heard something famous at the time, “Tsovola, give it all”, for which we are still paying the money that we borrowed at the time to “give it all”….There are some things that simply make you angry and then they tell you that we ate them together. In the Greek world, I believe that these were blows that someone simply had to make.

 

SecNews: From the attacks you have carried out, overall, you do not cause any damage to the servers. Is this something you pay attention to when carrying out the attacks or is it just a random event?

[PAOK]: I always pay attention and take the situation into account so as not to create major problems on the servers I manage to access. In no case do I have anything against the administrators or the company that manages them.
Usually my goal is to post a message, usually to political figures or services, or to extract some information that might be useful, but I NEVER destroy files or someone's work without a very serious reason... In the event that there is a serious reason (these are rare), the only appropriate solution you can follow is to destroy files at the admin/root level and with such procedures that they cannot be recovered...In short, destroying the server... Bad things!

 

type=”buttonbtn-medium” block=”btn-block”]The fear of arrest and the measures taken.

cyber-crime-hacker
The young hacker has carried out numerous politically targeted attacks.
SecNews: In any case, your activity often straddles the line between legality and illegality. There is certainly always the fear of arrest. What do you think about this? Are you taking any measures?

[PAOK]: Yes, unfortunately, engaging in hacking puts you in a semi-minor-major illegal situation, depending on what kind of hacking you commit, but everything is in the game and I know the risks I run. I, like most people I imagine, am looking to take as many measures as possible, so as not to get into trouble with the police.
For example, you can use VPN, TOR Network, TOR Tunneling via SSH/VPN, RDP, VPS, Hacked/ROOTed servers, MAC address spoofing, etc. There are many measures that one can take to protect themselves as much as possible, as long as they have the knowledge to do so or are willing to sit down and search and read how to do it.
The fear of being arrested is always there, but...?)

 

SecNews: As one of the most "productive" in hacker attacks, how did you acquire all this knowledge? By exchanging information with other hackers in Greece & abroad and if so, in what ways is this done?

[PAOK]: Reading, that's the first thing I can think of. The next thing is testing... lots of testing. Basically, if we look at them in order, you need reading to get familiar with the subject and the methods you want to work on, and then lots of testing. Maybe on your own machines at first, so you can reach the level of putting into practice what you've been reading for so long.
At the next level, you can also get in touch with other hackers around the world to exchange opinions, knowledge, methods, etc. But this definitely comes last, because you also need to have some performances, a level to be accepted by such communities. In fact, if you do some high-profile hits, as we say, these communities find you on their own many times.
One of the most common ways to get in touch is through forums, but many times the strongest and most valuable forums are invitation only and you can only enter after being invited by an existing member, who will have recommended your registration. Others, however, are not closed and you can enter freely to exchange views. Nowadays, many people also use more official means, such as Twitter, mainly when we want to learn news from a Hacking group or individual hacker or even open a dialogue with him for any exchange of views.

 

type=”buttonbtn-medium” block=”btn-block”]Tips & Ways to Protect Users & Companies from [PAOK]
hackers 4
SecNews: What can a user do to protect themselves from similar hacker attacks?
[PAOK]: A Windows user, who is both the largest mass and the most vulnerable, would be wise not to open/execute files that he does not know what they are/do and who sent them. There are many ways that a PC can be infected, especially with this particular operating system. A good antivirus program and a good router setting should now be considered mandatory, so that they are cut off before some things start. Another important thing that users should pay attention to is not to leave their computer open and not to be present in places that a third party, whether known or unknown, may have access to. I believe these are the most basic, but also effective steps, for the protection of an everyday user.

 

SecNews: What can a company or organization do to protect itself from similar hacker attacks?

[PAOK]: It can keep all the software installed on its server up to date. At very regular intervals, it must distinguish where and with what rights, everyone will be able to access its server, in order to avoid any security problems (RCE, RFI, PHP SHELL, etc.), which it may not know it has. There are several things it can do and usually they have the correspondingly authorized person (security officer), or group of people, to do whatever is necessary so that they do not have problems. Those who do not have him, usually have problems and are … worthy of their fate 🙂

 

SecNews: Is there finally trust in the hacking community?

[PAOK]: I can't say that there is trust in the hacking community. You can't have trust, because when we talk about hacking, we usually talk about acts that, as we mentioned above, straddle the line between legality and illegality, so you have to be especially careful, because you never know who might be hiding behind an IP. A slightly more trustworthy option might be encrypted messages between hackers who will have previously exchanged public keys with each other, with the aim, at least, that only the person I know has the key can read the message. But I can't say that there is trust.

type=”buttonbtn-medium” block=”btn-block”][PAOK]'s first attacks and its “greyhat” approach.

hacker 69
My role model is a hacker whom I have admired in very strong attacks, although he is in a “rival” country. This is Agd_Scorp of the Turkish Hacking group Turkguvenligi. A person with a lot of knowledge!
SecNews: What advice do you have for young people who are involved in security and/or hacking?

[PAOK]: My advice is to be careful and to realize exactly what it is that they are doing or want to do. I say this because, the digital world, is a world where nothing is erased and nothing is lost. You can always find trouble, even for something that may have happened months or years ago. Hacking is a special occupation, you gain knowledge, you see things with a different eye, but above all you have to know what you are doing and the consequences of it.
SecNews: Can you remember the first time you got involved in hacking?
[PAOK] : I first got involved in hacking when I was around 15-16. It was a field that always fascinated me and I always wanted to be a part of it. I was always curious about how they do this, how they do that, etc. But I had never seriously considered getting involved in it. Until at some point when I had bought a new computer, I had installed a firewall for protection, etc. and the next day when I was working on it, I started seeing notifications from the firewall about attempts to hack my computer from certain addresses, etc. That was the reason I got involved.

I immediately started trying to find out where these addresses were from, what exactly they were trying to do to me, and one question led to another. Thus I became part of a community with a lot of reading to begin with and a lot of food for thought later. Although digital remains a fascinating world.

 

SecNews: What prompted you to carry out the attacks? In which category do you classify yourself (blackhat/greyhat/whitehat hacker)?

[PAOK]: I have never attacked servers. At first I was content with having fun, my hobby as they say, with private computers.
But later, as a more active member of society, entering the job market and facing the problems of every citizen of this country, I started to want to express my opinion, perhaps also that of other peers at the same time through hacking. I found that attacking servers was a field where I could express it, a kind of graffiti with a message posted that many people would see.
So, having now acquired the relevant knowledge, I began to alter websites by sending messages in all directions or sought to collect data and documents that I, in my humble opinion, considered important. I classify myself as a Greyhat Hacker.
You never know how you'll react to something you find or read, and some people don't want you to read it, for example.
SecNews: Do you have an estimate of how many servers you have under your control?

[PAOK]: I don't have an exact opinion right now, but there are quite a few of them in total. You always need to have access wherever you can, in any way. It might come in handy at some point. You can do things if you have access to servers.

type=”buttonbtn-medium” block=”btn-block”]Description of the attacks. His view on DDoS

hackers 4
SecNews: Can you describe the attack process in simple terms (without, of course, revealing details that should not be made public)?

[PAOK]: A common process is to collect as much information as you can about a goal. Everything… Everything can be useful along the way. Then you look to find weaknesses in the system that you can “hit” in order to achieve what you want.
Of course, you also look to “cover your back” as much as possible. Now whether you will succeed or to what point you can reach to achieve it and what techniques you will follow to do so, is personal to each person and differs from case to case.

 

SecNews: How easy is it to actually carry out an attack?

[PAOK]: It's not easy, most of the time, at least where I'm aiming. It requires a lot of searching and being able to use various techniques. Some of them might help you achieve what you want. We're always talking about a case where you set a target, and not random targeting with automated tools. In cases where a public weakness in a software has been found and you simply search for targets via Google, as most people do, things are much easier there.

 

SecNews: Do you participate in other types of attacks such as DDoS?

[PAOK]: No, I don't participate in these kinds of attacks, I prefer to work alone or with someone I know and we think the same way and have a common goal.

type=”buttonbtn-medium” block=”btn-block”]What does he think about the future?

hacker 5
The young hacker, with mature – despite his age – argumentation but also with a full understanding of his actions regarding their legal/criminal impact, developed his positions within 5 hours of communication.
SecNews: Do you have any role models from Greece or abroad?

[PAOK]: My role model is a hacker whom I have admired in very strong attacks, although he is in a “rival” country. This is Agd_Scorp of the Turkish Hacking group Turkguvenligi. A person with a lot of knowledge!
SecNews: Have you ever had any legal troubles or been involved in any cases due to your involvement in hacking?

[PAOK]: Fortunately, so far I have not had any adventures with the Cybercrime Prosecution and I hope not. From afar and beloved 🙂
SecNews: How do you see yourself after 5 years?

[PAOK]: What can I tell you… no one knows what will happen in 5 years. I wish I had even more knowledge in the field of computers and security and with stronger High Profile hits.
 [signoff icon=”icon-target”]The editor of SecNews found that [PAOK] presents himself as a “hacker with a cause”. Of course, on the other hand, the issues that arise regarding the criminal & legal aspects of the aforementioned acts cannot be ignored, especially those related to personal data. The main concern of a well-organized state is to use such skills for the good of society and the country, adequately protecting young people from delinquent behavior. This is possible if the potential of young people like [PAOK] and many others involved in “hacking” is directed in the right direction (as has been done in China and the USA). SecNews thanks [PAOK] for granting the interview.[/signoff]
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS