• The Gulf Information Security Expo and Conference (Gisec) kicks off in Dubai. Photos by Chris Whiteoak / The National
    The Gulf Information Security Expo and Conference (Gisec) kicks off in Dubai. Photos by Chris Whiteoak / The National
  • People visit the STM stand at GISEC at the Dubai World Trade Centre.
    People visit the STM stand at GISEC at the Dubai World Trade Centre.
  • In the past year, the UAE has seen a 300 per cent increase in cyberattacks.
    In the past year, the UAE has seen a 300 per cent increase in cyberattacks.
  • The average resident in the Emirates spent seven hours and 24 minutes online per day in 2020. according to data from the World Digital Report 2021.
    The average resident in the Emirates spent seven hours and 24 minutes online per day in 2020. according to data from the World Digital Report 2021.
  • People visit Gisec at the Dubai World Trade Centre on Monday.
    People visit Gisec at the Dubai World Trade Centre on Monday.
  • The Covid-19 outbreak exposed a barrage of cyber security vulnerabilities as hackers took advantage of the uptake in digital adoption.
    The Covid-19 outbreak exposed a barrage of cyber security vulnerabilities as hackers took advantage of the uptake in digital adoption.
  • Experts said while hackers will always find ways to breach systems, international knowledge sharing will help keep abreast of new attacks.
    Experts said while hackers will always find ways to breach systems, international knowledge sharing will help keep abreast of new attacks.
  • Ahmed Saleh, sales engineer at Recorded Future, speaks on the sidelines of Gisec.
    Ahmed Saleh, sales engineer at Recorded Future, speaks on the sidelines of Gisec.

Meet the hacker given permission to breach Dubai Police's website


Georgia Tolley
  • English
  • Arabic

It only took two leisurely minutes for Marshal Webb to hack into Dubai Police's website and take it offline – a move that would normally be a criminal act.

Fortunately for him, he had permission from senior officers.

The exercise was performed live on stage at the Gulf Information Security Expo and Conference (Gisec) as an example of how hackers can breach even the most secure of institutions.

Mr Webb, from the US, runs his own security consultancy called Path Network, which advises public and private entities on how to defend themselves against hackers, a problem he predicts will grow dramatically over the next few years.

A decade ago, he was a world-famous teenage hacker and a member of Lulz Security – a group of hackers who looked to breach business and government systems.

The group claimed responsibility for several high-profile attacks, including a hack in 2011 when the personal details of about 100 million PlayStation users were stolen from Sony's servers.

Former hacker Marshal Webb has helped the US military identify vulnerabilities in its cybersecurity. Marshal Webb
Former hacker Marshal Webb has helped the US military identify vulnerabilities in its cybersecurity. Marshal Webb

Where did the interest come from?

Mr Webb said he was 12 when he turned to hacking. He did so mostly out of boredom as he grew up in an isolated, rural community in south-west Ohio, he said.

"Computers were interesting, and it was a way to explore the outside world and get out a little bit – a chance to get access to things, to learn how things worked," said Mr Webb, 28.

Mr Webb was much brighter than most kids his age and he went to university aged 12.

He quickly advanced from hacking simple websites to more complicated projects, few of which he is willing to speak about, presumably because of fears of prosecution.

"My first publicised hack that was documented was Eidos-Montreal, for a game that had been released called Deus Ex," he said describing an incident uncovered in 2011.

Eidos-Montreal's parent company, Japanese videogame maker Square Enix, said 25,000 email addresses could have been stolen in the attack, along with the CVs of 350 potential employees.

Within a few months, Lulz Security fell apart in highly acrimonious fashion, and some members outed Mr Webb for his role in the Deus Ex hack.

"Hacking is a very highly competitive field," he said.

"When hackers work in groups, there's always a lot of false flag attacks and shenanigans and highly competitive actions against each other."

Mr Webb found himself on the radars of global law enforcement agencies and he realised he had to go straight – or to undertake what hackers call "white hat" activities.

The changing face of hacking

Experts say a lack of security is creating a 'hacker's paradise'. Getty
Experts say a lack of security is creating a 'hacker's paradise'. Getty

Since then, he has been awarded a network security medal for uncovering vulnerabilities for the US Air Force, the military and the defence and control department.

He also hacked the Pentagon, which he said was easy.

"With the Pentagon and with any other organisation, the larger they are the easier they are to hack," he said.

"Hacking is really about finding mistakes, and the more assets an organisation has, the higher the chance that they've made some kind of mistake somewhere."

Many hackers are criminals who commit deeply intrusive acts, often for nefarious purposes.

Research group Cybersecurity Ventures predicted that cybercrime would inflict damage worth about $6 trillion in 2021.

It said the costs could grow by 15 per cent every year over the next five years, reaching $10.5tn by 2025.

State-sponsored hackers and organised crime gangs now dominate the market, with the introduction of digital currencies making it easier to extort money without getting caught.

"Hacking has really matured over the years," said Mr Webb.

"A lot of what we did a long time ago was not very destructive – it was very much exploratory by nature."

The growth of the industry is evident in the proliferation of news stories about hacking in the past few months.

In May, a group of hackers called DarkSide shut down the Colonial Pipeline, a critical US artery for the transport of fuel. The company paid a ransom of nearly $5 million in cryptocurrency to regain control of its systems.

DarkSide has since said it would disband, but it received more than $90m in Bitcoin from 47 victims, despite only being in operation since August, blockchain analytics company Elliptic said.

In 2019, another group of hackers hit technology company SolarWinds and gained access to the networks of several US government agencies and about 18,000 other clients. Its malicious software went undetected for nearly nine months.

Why your refrigerator could help a hacker

Cybersecurity Ventures predicted there would be a ransomware attack on businesses every 11 seconds by 2021, up from every 40 seconds in 2016.

Mr Webb said he agreed with that assessment because people had more web-enabled devices in their homes.

"In terms of sophistication on the attacking side, I think it'll get a lot worse before it gets better," he said

"We haven't seen the security position harden from the manufacturing side, so a lot of these commodity devices are just as insecure as they were 10 years ago."

Cybercrime has certainly increased over the past 12 months, in part because millions of people have been working from home because of the pandemic.

Dubai Police registered 25,000 e-crimes last year, up from 14,000 in 2019.

As habits change, many people may choose not to return to offices full-time, leaving businesses playing catch-up on their remote cybersecurity efforts.

Some companies may need to restrict their online activity in the future to stay safe, Mr Webb said.

"Businesses, governments and individuals can really help protect themselves by reducing the attack surface that they have," he said.

"The less material that they have online, the smaller their websites, the less computers they have hooked up to the internet, the less the chances that there's going to be way to get in."

Emergency

Director: Kangana Ranaut

Stars: Kangana Ranaut, Anupam Kher, Shreyas Talpade, Milind Soman, Mahima Chaudhry 

Rating: 2/5

Profile of MoneyFellows

Founder: Ahmed Wadi

Launched: 2016

Employees: 76

Financing stage: Series A ($4 million)

Investors: Partech, Sawari Ventures, 500 Startups, Dubai Angel Investors, Phoenician Fund

'Texas Chainsaw Massacre'

Rating: 1 out of 4

Running time: 81 minutes

Director: David Blue Garcia

Starring: Sarah Yarkin, Elsie Fisher, Mark Burnham

High profile Al Shabab attacks
  • 2010: A restaurant attack in Kampala Uganda kills 74 people watching a Fifa World Cup final football match.
  • 2013: The Westgate shopping mall attack, 62 civilians, five Kenyan soldiers and four gunmen are killed.
  • 2014: A series of bombings and shootings across Kenya sees scores of civilians killed.
  • 2015: Four gunmen attack Garissa University College in northeastern Kenya and take over 700 students hostage, killing those who identified as Christian; 148 die and 79 more are injured.
  • 2016: An attack on a Kenyan military base in El Adde Somalia kills 180 soldiers.
  • 2017: A suicide truck bombing outside the Safari Hotel in Mogadishu kills 587 people and destroys several city blocks, making it the deadliest attack by the group and the worst in Somalia’s history.
AI traffic lights to ease congestion at seven points to Sheikh Zayed bin Sultan Street

The seven points are:

Shakhbout bin Sultan Street

Dhafeer Street

Hadbat Al Ghubainah Street (outbound)

Salama bint Butti Street

Al Dhafra Street

Rabdan Street

Umm Yifina Street exit (inbound)

The%20specs
%3Cp%3E%3Cstrong%3EEngine%3A%3C%2Fstrong%3E%201.8-litre%204-cyl%20turbo%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E190hp%20at%205%2C200rpm%0D%3Cbr%3E%3Cstrong%3ETorque%3A%3C%2Fstrong%3E%20320Nm%20from%201%2C800-5%2C000rpm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESeven-speed%20dual-clutch%20auto%0D%3Cbr%3E%3Cstrong%3EFuel%20consumption%3A%3C%2Fstrong%3E%206.7L%2F100km%0D%3Cbr%3E%3Cstrong%3EPrice%3A%3C%2Fstrong%3E%20From%20Dh111%2C195%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3ENow%3C%2Fp%3E%0A
How to wear a kandura

Dos

  • Wear the right fabric for the right season and occasion 
  • Always ask for the dress code if you don’t know
  • Wear a white kandura, white ghutra / shemagh (headwear) and black shoes for work 
  • Wear 100 per cent cotton under the kandura as most fabrics are polyester

Don’ts 

  • Wear hamdania for work, always wear a ghutra and agal 
  • Buy a kandura only based on how it feels; ask questions about the fabric and understand what you are buying
The%20specs
%3Cp%3E%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3E3.5-litre%20twin-turbo%20V6%20%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E456hp%20at%205%2C000rpm%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E691Nm%20at%203%2C500rpm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3E10-speed%20auto%20%0D%3Cbr%3E%3Cstrong%3EFuel%20consumption%3A%20%3C%2Fstrong%3E14.6L%2F100km%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3Efrom%20Dh349%2C545%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3Enow%3C%2Fp%3E%0A
Kill%20Bill%20Volume%201
%3Cp%3E%3Cstrong%3EDirector%3C%2Fstrong%3E%3A%20Quentin%20Tarantino%3Cbr%3E%3Cstrong%3EStars%3C%2Fstrong%3E%3A%20Uma%20Thurman%2C%20David%20Carradine%20and%20Michael%20Madsen%3Cbr%3E%3Cstrong%3ERating%3C%2Fstrong%3E%3A%204.5%2F5%3C%2Fp%3E%0A