<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog Central &#187; Exif</title>
	<atom:link href="http://blogs.mcafee.com/tag/exif/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com</link>
	<description></description>
	<lastBuildDate>Fri, 17 May 2013 22:07:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Hacker Leaves Online Trail, Loses Anonymity</title>
		<link>http://blogs.mcafee.com/mcafee-labs/hacker-leaves-online-trail-loses-anonymity</link>
		<comments>http://blogs.mcafee.com/mcafee-labs/hacker-leaves-online-trail-loses-anonymity#comments</comments>
		<pubDate>Tue, 17 Apr 2012 17:12:33 +0000</pubDate>
		<dc:creator>Francois Paget</dc:creator>
				<category><![CDATA[McAfee Labs]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Exif]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Open Source]]></category>

		<guid isPermaLink="false">http://blogs.mcafee.com/?p=15569</guid>
		<description><![CDATA[Since March 20, the @Anonw0rmer Twitter account has been silent. Its owner, w0rmer, is known as a member of the CabinCr3w group, a hacker team linked to Anonymous. In early February, as part of the Operations PiggyBank and PigRoast, the CabinCr3w members were suspected of hacking various police department- or law enforcement-related websites including: West <a href="http://blogs.mcafee.com/mcafee-labs/hacker-leaves-online-trail-loses-anonymity">Read more...</a>]]></description>
				<content:encoded><![CDATA[<p>Since March 20, the @Anonw0rmer Twitter account has been silent. Its owner, w0rmer, is known as a member of the CabinCr3w group, a hacker team linked to Anonymous.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15571"><img class="alignnone size-medium wp-image-15571" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_1-300x102.jpg" alt="" width="300" height="102" /></a></p>
<p>In early February, as part of the Operations PiggyBank and PigRoast, the CabinCr3w members were suspected of hacking various police department- or law enforcement-related websites including:</p>
<ul>
<li>West Virginia Chiefs of Police Association website (February 5)</li>
<li>Salt Lake City Police Department</li>
<li>Texas Police Association (February 8&#8242;)</li>
<li>Syracuse Police Department</li>
<li>Newark Police Foundation</li>
<li>Wisconsin Chiefs of Police Association</li>
<li>Dallas Police Department</li>
<li>Alabama Department of Public Safety (February 9)</li>
<li>Alabama Houston County (February 20)</li>
</ul>
<p>Among the leaked data are login credentials, badge numbers, addresses, home/mobile/office phones, and social security numbers. They information was  leaked to the public and posted on pastebin, pastebay, or pastehtml. The data  were generally posted on Twitter account @CabinCr3r, which has been silent since March 12.</p>
<p>On February 5, the first post appeared Twitter account @higochoa. More appeared on @Anonw0rmer, which was created the following day.</p>
<p>In the Alabama case, the leaked data were posted on pastehtml by someone named w0rmer. The user&#8217;s Twitter profile picture was at the top of the document. At the bottom, our hacker added a photo exhibiting a woman’s breasts with a sign attached to her belly.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15574"><img class="alignnone size-full wp-image-15574" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_21.jpg" alt="" width="2719" height="1033" /></a></p>
<p>Unfortunately, w0rmer was not concerned with what was revealed by the exchangeable image file format (Exif) metadata that accompanied these images. The police, however, were.</p>
<p>I found that downloading the picture and using <a href="http://www.sno.phy.queensu.ca/~phil/exiftool/">Phil Harvey&#8217;s ExifTool</a> was very informative. I discovered the photo was taken with an iPhone 4 on February 5. Most interesting is the embedded GPS information. It came from a home in Southern Australia.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15576"><img class="alignnone size-full wp-image-15576" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_3.jpg" alt="" width="1166" height="636" /></a></p>
<p>As mentioned in the<a href="http://cryptome.org/2012/04/usa-v-ochoa-complaint.pdf"> affidavit in support of a criminal complaint,</a> the hacker left some other clues that I followed:</p>
<ul>
<li>Two IP addresses assigned to computers located in Galveston, Texas
</li>
<li>Five other images (Exif free) posted on the i.imgur.com website, where one finds the same woman in various states of undress holding various other statements by w0rmer or CabinCr3w
</li>
</ul>
<p><a href="http://blogs.mcafee.com/?attachment_id=15577"><img class="alignnone size-full wp-image-15577" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_4.jpg" alt="" width="1116" height="227" /></a></p>
<p>A screenshot in another image shows a computer desktop running an IRC chat client (KVIrc) at the bottom right. In its window, the user @higochoa is logged on.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15578"><img class="alignnone size-full wp-image-15578" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_5.jpg" alt="" width="1100" height="519" /></a></p>
<p>Following the username, I found two posts retrieved via an open-source search on the website gmane.org. One is signed Higino Ochoa AkA w0rmer.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15581"><img class="alignnone size-full wp-image-15581" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_6.jpg" alt="" width="900" height="280" /></a></p>
<p>I next retrieved a photo via open-source search for @Higochoa that showed an individual geocaching in Texas. This picture, compared with the one displayed on the driver&#8217;s license of the suspect, was of the same individual.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15582"><img class="alignnone size-full wp-image-15582" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_7.jpg" alt="" width="843" height="695" /></a></p>
<p>The same person had a Facebook account and another identifiable portrait. According to the profile, the suspect resides in the Galveston area.</p>
<p><a href="http://blogs.mcafee.com/?attachment_id=15583"><img class="alignnone size-full wp-image-15583" src="http://blogs.mcafee.com/wp-content/uploads/2012/04/FP_BLOG_120416_8.jpg" alt="" width="736" height="612" /></a></p>
<p>On his Facebook profile he states that he is in a relationship with a woman whose Facebook profile indicates she lives in New South Wales, Australia.</p>
<p>Thus we come full circle. Be careful before breaking the law. Using only open-source searches, even an Anonymous member can be unmasked.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.mcafee.com/mcafee-labs/hacker-leaves-online-trail-loses-anonymity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
