Michael Cooney
Senior Editor

Texas A&M grad who hacked school’s VPN faces five years in prison

Opinion
Sep 14, 20073 mins

Apparently his computer science degree didn’t include a morals minor. The FBI today said a graduate of

Texas A & M University was convicted of recklessly accessing and causing damage to the protected computer system of his former alma mater.

Luis Castillo, 23, who graduated with a Bachelor’s degree in computer science from Texas A & M University in December 2006, admitted to recklessly gaining unauthorized access to the University’s network and capturing 133,000 student and employees Net ID’s and passwords.

According to the FBI, on February 28, 2007, Texas A & M University officials discovered that the domain controller of its virtual private network, code named “Ajax,” had suffered multiple unauthorized computer intrusion incidents. Steps were taken by the University to prevent the illegal or fraudulent use of the captured information and a criminal investigation was initiated by the FBI with the assistance of the University’s administration and law enforcement authorities.

Through their joint investigation, agents learned that in mid-February 2007, Castillo logged on to the University’s VPN utilizing his own ID and password from a wireless account located at an apartment in Oregon where Luis Castillo was living while working in the area.

Thereafter, Castillo began logging on to the protected system from the same computer using unauthorized netIDs and passwords and ultimately accessed the University’s VPN server to gain unauthorized access to “Ajax.” Once access to the Domain Controller “Ajax” was established on February 24, 2007, Castillo injected malware computer programs into the University’s protected computer system which then captured 133,000 netID’s and passwords of unsuspecting students and employees of the University. Thereafter, the program dumped the captured netIDs and passwords into a temporary file on the system where Castillo could have access. An analysis of the injected malware ultimately tied Castillo to the intrusions.

As a result of the intrusions and injection of the malicious software by Castillo, the University incurred a loss of over $67,000 in its efforts to protect students and faculty from the illegal or fraudulent use of private account information, including the retrieval of the captured files. To date, no known use or misuse of the captured information has been reported. The university has reportedly bolstered its VPN to safeguard the system from such access in the future.

Castillo faces a maximum of five years imprisonment and a $250,000 fine for this conviction and is scheduled to be sentenced on December 10, 2007 at 10:00 a.m. The court has entered an order permitting Castillo to be released on a $25,000 unsecured bond pending his sentencing.

Castillo’s conviction was one in a long string of anti-cybercrime victories this week. Read here.