LAS VEGAS — Two teams of hackers worked for close to three hours, steadily penetrating increasingly difficult layers of financial institution security until they gained remote access to workstations.
Luckily, those "hackers" actually wore white hats-they were representatives from credit unions all over the country competing in the second annual Extreme Hacker Challenge. The event was hosted by NAFCU during its recent Technology and Security Conference here, in conjunction with San Antonio-based security consultancy Digital Defense.
Tom DeSot, EVP and chief compliance officer for Digital Defense, told Credit Union Journal the goal of the Extreme Hacker Challenge was to obtain privileged access to as many targets as possible during a set time. Points were awarded to the two teams of three "hackers" each based on exploitation difficulty.
"We set up a target farm simulating systems typically found on a financial institution's network," DeSot explained. "We act as a resource, just as hackers would use the Internet and chat rooms for their research."
Mark Bell, Digital Defense's EVP-operations, offered periodic hints to the competitors, and tallied the points for each successful hack. Bell kept the audience informed as to the teams' progress. For example, the teams earned one point each for accessing Windows 2000 workstations-one group by solving an easily guessable password (same as the user name: administrator), while the other exploited a Microsoft security bulletin (the same used by the MS Blaster worm).
With just six minutes left on the clock and the score tied at four points apiece, "Team 1" successfully accessed what Digital Defense identified as a Level 3 machine (difficult) for five huge points. Team 1 members Michael Holmes, of Fed Choice FCU in Lanham, Md., and Tim Kenney, of Services Center FCU in Yankton, S.D., credited Ray Robertson of Tyndall FCU in Panama City, Fla., with the winning hack.
Team 2 consisted of Chuck Caldwell of AllSouth FCU in Columbia, S.C., Farhad Tajali of AFTRA-SAG FCU in Burbank, Calif., and Andy Reed of Arkansas FCU in Jacksonville, Ark.
DeSot said the EHC demonstrates the types of exploitable vulnerabilities that exist in the real world. "I thought it went well," he assessed afterward. "All of the participants were really engrossed and they thought it was a learning experience."
Added Bell: "It went great. All of these guys are on the defense side of security, so it was good for them to be on the dark side and see the techniques hackers use."









