Nasa IT expert explains how hackers allegedly hacked the IEBC server and manipulated the algorithm to ensure Uhuru Kenyatta maintained a constant lead against Raila Odinga.
this guy was paid to come pretend that he has inside info on the servers... unless he has administrative access to those servers, how did he access that info? Hopefully the 30 pieces of silver he received will be worth his soul...
guys please lets tone down. lets maintain peace in our country. my main worry about this hacking is not that the system has been hacked (it's pretty obvious the systems were hacked and the hacker is an unsophisticated one by maintaining 11% margins, and then using MSANDO's and chebukati's user names (with msando's password, it would have been better to create another user after his death), but the person at IEBC who printed out these master logs.. there can only a be a few system administrators there and i ask the government to provide security to all IEBC IT staff right away - i really pray for Kenya
5 years later we are still this same same place!! Damn.. CHANGE is not easy. Democracy is not free. And Justice has such a high price! We will overcome.
our fellow kenyans. mjinga akierevuka mwerevu yu mashakani. may peace prevails as we awaits for legal procedures. Amarillo our tears will not go like that, please fight for democracy
Kenyans will never forget you if anything bad happen to people, if you were not employed by the iebc how did you know that paricular time something has happened, just accept your defeat and let wanaanchi go to work, you were nerd once again, na you promised wanaanchi kama hiyo akuna tena, Raila wewe ni muongo, so if the system was hacked na u never were prepared to stop that until you were given results, Kanani hatuende tena, Kisumu riots 👎👎👎
Are you an IEBC staff???? Of cos NO How did u get into the system to get hold of all this information????? Of cos u hacked Who is the hacker here????? Definitely it's you You should be arrested
We are going to church yet we steal..... Tunaekewa mikono na mapastors wanaotusupport.... We kill in the name of winning an elections... Question.... 'will God forgive us as a tribal communities together with our pastor?'...... Prayers yet sycophants
why couldn't you do one for NASA my friend, it's too late, I do not want to change my career from your lecture of IT. You were the one in charge of the cloud and now we are stuck in the middle of the river Jordan
Let's the Kenyan spirit hold. Sing with me kakai's song "ewe kenya mama yangu sita kuacha bali nitakuombea. The song insist that Kenyans must maintain peace and respect each other. "
N Kama n yy ameongoza angesema nn? we are tired of you Mr ondinga... Hakuna time utaongoza ii Kenya. mungu ndo alichangua our president. his sent from heaven
a self-signed certificate generally just means that the organization that runs the server chose not to pay for a signed certificate they can be expensive, depending on the features they want or they didn't have technical expertise to configure one . So now if you connect to a web server that provides an SSL certificate, but it is not signed by a trusted third party, this could mean that you are communicating with an imposter that is pretending to be a server belonging to a different organization.
Leon kim And when you read stuff from Google, don't bring it here word for word posing as if its your own genuis thoughts. It's called plagiarism if you don't give credits. So I'll do that writer a favour and share the link to their well explained post. superuser.com/questions/161820/why-is-an-unsigned-ssl-cert-treated-worse-than-no-ssl-cert
yes and it doest compromise on your security. but you'll have problems with others trusting you because your certificate is not from the trusted third party certificate vendors. That's why users get asked by browser if they're still willing to access the site despite it not having a public certificate.
Sweety Heart Mrs Domo! Cry for your Country ... wacha kuchochea.. kama we ni mwaminifu THINK!! N ask yourself, what could be the course of all these. Raila is just responding what Uhuru have started. Mwizi wewe . NENDA CHURCH UOMBEWE. Mkorini wewe.
This is deception at its best. If the hacker could instal and run algorithms (mathematical functions or procedures) in the SQL server database, then they could also run scripts to create SSL certificates.
the biggest lie here is the use of the word "unsigned certificate" such wrongful use of a word shows you he has no idea what he is saying, it is irrelevant to hacking and is in no way a sign of intrusion.
Raila won Uhuru back off with peace✌ Uhuru won Raila should back off with peace✌ and go home. Why should you fight and hurt yourselves for leaders who will not be with you during your fights!😞Burning n fighting n killing yourselves for no reason. This all is just TRIBALISM in Kenya.He won he lost we have to accept it and move on! Students need to go to school n others need to continue with their work just announce the results! "STOP SPREDING RUMOUR IN PLACE OF #✌"
Self-signed a.k.a machine issued SSL certificates are normally used by windows server. No need to use a publicly signed certificate for internal operations as the cryptography is still strong. It is not an indication of an attack. Does anyone have a link to this full document or logs?
Thanks @Safari Pole. My take, these logs are from a 32bit MsSQL Server 2008 (Microsoft SQL Server). The current version is 2016 and servers should be 64bit, so this is likely running on a personal computer. From a design point of view it would make more sense (to me) to have one database covering all counties. The logs show a database per county, that's 47 databases in all! IEBC also confirmed they do not use Microsoft's database making this 2008 version database running from a personal computer look rather suspect (last election they were running Oracle).
I heard Raila/joshua claiming he has a plan to take his followers to canaan,now are they talking from there or where exactly because canaan is a land of milk and pure honey?And does israel know they have Joshua ad associates behind their backs?
Wow! This guy is giving IT Experts a bad name by masquerading as a computer nerd. Needless to say, he talks like he HACKED into the IEBC's system by giving some details that only an IEBC Admin has access to. He's being economical with words by not saying how he get that information.
Mapinduzi Mapinduzi you really are stupid. That is only a log of the activity on the server. Anyone, can print it if he/she has some form of access into the server. Remember, there were many users who had access to the server but only Msando had super user privileges
Raila is going crazy! Your campaign team failed miserably now they are using the opponents strength to justify their failures. Please come back in 2022, we need you to encourage people to vote for Arap Mashamba who will be your opponents.
If you have the exact times when the hackers accessed the machine, then why dont you check out the cctv footage around the machines at the exact time? We are all literate... Dont try and fools out of us.
No i don't have a problem to your allegations but how exact did you guys know about this???so you hacked in to the system and you identified the hack i think the DCI should interrogate you or maybe you guys have an insider how has access to the system and this, this is unacceptable u should name that guy. And by the way what DB[SQL] a you people talking about coz IEBC IS talking of a different DB [ORACLE]
Ni mtu ameenda shule huyo sio kama wewe muuza makaa!!! People have gone to school so they know where to check and how to check!!! That's why mlinaswa! Na kama yuko wrong, ambia washikaji wako wafungue server!!! Kazi iishe papo hapo!!!!
The Maverick! They think they are fooling Kenyans but Kenyans have known all along most of the tricks. They were just not brave enough to confront in the past for obvious reasons
The whole process makes sense sure, but it beats logic to claim the master log was not only so easily available but also not encrypted. Typically they are. You can also easily feign master logs. Another issue is IEBC uses Amazon S3 Servers whose master logs typically are encrypted and the algorithm is only gonna decrypt them upon approval by the super admin which thus means the hacker must have somehow decrypted it and it being 256 character encryptions, I doubt they could do so so fast unless they have some form of super computer. They thus must have credentials. One of them must have Musando's access codes if the logs are genuine and if not, then the logs must have been fabticated. Also, I doubt the access credentials to the system would be as plain as the names of the officials, chebukati? musando? Really? I woildnt use those even for social network usernames let alone such a sensitive case. The names must have been a bit complex, including special characters. Be sensible. Rao, even if you won, youre still guilty here. You have to explain how you decrypted the logs. Or acknowlefge you fabricated the logs prehand in case of loss. Either way youre in pretty hot soup but I guess you have nothing to lose so you dont mind watching the nation burn.
You why are you confusing Raila with your ideologies .Please young man, please don,t' bring division in Kenya. How are you log into see this who log in and out?Are you Mr Musando. you are the one hacking the IBEC computers. The security should be aware of this.
Pumbavu!!!!!!!!!!!!! Go retire Ogwambo.....The so called IT expert is reading a scripted document!!! I as an IT expert...would just have questions in my mind as to how this person come to such findings... ?????? Mhhhh``======???? Kenyans wake up
Proudly Kenyan Hahahaha ndio maana jubilee ili fail kwa kuiba kura kwa computer....eti nawe unajidai kuwa IT expert!!! IT experts like you ambaye haelewi chochote ndie wameangusha chupilee!!! Noma sana!!!
Please protect the IT Experten.. He is doing a Right job.. Hatutaki wezi kabisa.. Kisha Uhuru atiewe ndani kabisa. Mwizi yeye.
Raila the expert must b protected coz we don't want musando killers to come for him.
Ali Duba infact l thought of that he needs super protection.
Ali Duba they won't be that stupid ..killing him would clearly imply that they stole the election
super protection by who?
raila killed musondo to get the password kwani huyu jamma na hafanyi IEBC ilijuaje hizo story
this guy was paid to come pretend that he has inside info on the servers... unless he has administrative access to those servers, how did he access that info? Hopefully the 30 pieces of silver he received will be worth his soul...
If this guy is not an employee of IEBC, he should be held liable for the hacking. CID should be on his heels
we are not crying for raila but for our suffering Kenyans
Justine Eshalai exactly
Justine Eshalai Exactly
Justine Eshalai true my I see darkness in our country
Justin very true dea we r tired surely
Justine Eshalai true some see it funny
as we vote for kenya, please nawa omba wakenya mudumishe amani, wote wenye wana tumia mtandao muhubiri amani amani,
We're not crying for raila but for Kenyans suffering. Again uruhu to serve the nation? ....
Mungu wasaidie Kenya waepukane na Manyang'au ambao wapo tayari kuiba kura bila kujali damu za Wakenya
Tibim....Tialala......The truth shall set us free😂😂😂😂
This is the good time,because yesterday was busy for us voting.
guys please lets tone down. lets maintain peace in our country. my main worry about this hacking is not that the system has been hacked (it's pretty obvious the systems were hacked and the hacker is an unsophisticated one by maintaining 11% margins, and then using MSANDO's and chebukati's user names (with msando's password, it would have been better to create another user after his death), but the person at IEBC who printed out these master logs.. there can only a be a few system administrators there and i ask the government to provide security to all IEBC IT staff right away - i really pray for Kenya
5 years later we are still this same same place!! Damn.. CHANGE is not easy. Democracy is not free. And Justice has such a high price! We will overcome.
Musando was assassinated and his finger chopped and they change everything in system we all gonna know in the end
Why did you wait untill now, you should have taken action while people were still voting so this is NONSENSES.
Mary Mary Exactly!!
Mary Mary do you even know what Raila was talking about here,tinga angefanya nini voting ikiendelea ??
Duuuh they had to prove there was algorithm changed before coming out plus it would have suppressed the voting process, it pretty clear to me.
hawa watu wataongoza wapi wakitukana KIKUYU hawajui sisi hufunzwa kupiga kura tangu utotoni
Mary Mary ofcox
our fellow kenyans. mjinga akierevuka mwerevu yu mashakani.
may peace prevails as we awaits for legal procedures.
Amarillo our tears will not go like that, please fight for democracy
Waaaaaaaaaaaanainchi ndw wanaumia those guys are just telling us tha truth
aty atb loging au coz mm sioni ukweli hapo
@Samuel Githiri wat can u say to day 2020?
Kenyans will never forget you if anything bad happen to people, if you were not employed by the iebc how did you know that paricular time something has happened, just accept your defeat and let wanaanchi go to work, you were nerd once again, na you promised wanaanchi kama hiyo akuna tena, Raila wewe ni muongo, so if the system was hacked na u never were prepared to stop that until you were given results, Kanani hatuende tena, Kisumu riots 👎👎👎
Hack it yourself if it's possible
Raila stop feeding us lies and propaganda
haina haja ya mwanainchi kupiga kura....waachiwe waongoze milele
Are you an IEBC staff???? Of cos NO
How did u get into the system to get hold of all this information????? Of cos u hacked
Who is the hacker here????? Definitely it's you
You should be arrested
wewewewewe thats the storo
kabisa na kama sio yeye they should name that insider
Installing stored procedures?? What is that?? You mean creating stored procedure?? IT expert, my foot!!
We are going to church yet we steal..... Tunaekewa mikono na mapastors wanaotusupport.... We kill in the name of winning an elections... Question.... 'will God forgive us as a tribal communities together with our pastor?'...... Prayers yet sycophants
Haki wizi kenya, jameni timechoka, mungu. .......komboa kenya
peace love to all kenyans we all one
thanks for explaining how your plan flopped..Gerarahiaa
Where are your results cos you had your own tallying centre...God bless kenya
salma Hussein relax ni mbaya
Evans Mandela ,ok...then
salma Hussein Ameen ya rabbi
why couldn't you do one for NASA my friend, it's too late, I do not want to change my career from your lecture of IT. You were the one in charge of the cloud and now we are stuck in the middle of the river Jordan
Let's the Kenyan spirit hold. Sing with me kakai's song "ewe kenya mama yangu sita kuacha bali nitakuombea. The song insist that Kenyans must maintain peace and respect each other. "
Considering the time of the press conference when did u write all the 52 pages of ua document
N Kama n yy ameongoza angesema nn? we are tired of you Mr ondinga... Hakuna time utaongoza ii Kenya. mungu ndo alichangua our president. his sent from heaven
God watching be with us
uhuru must go
a self-signed certificate generally just means that the organization that runs the server chose not to pay for a signed certificate they can be expensive, depending on the features they want or they didn't have technical expertise to configure one .
So now if you connect to a web server that provides an SSL certificate, but it is not signed by a trusted third party, this could mean that you are communicating with an imposter that is pretending to be a server belonging to a different organization.
finally someone who speaks english
so now you know why chris was murdered..
Leon kim And when you read stuff from Google, don't bring it here word for word posing as if its your own genuis thoughts. It's called plagiarism if you don't give credits.
So I'll do that writer a favour and share the link to their well explained post.
superuser.com/questions/161820/why-is-an-unsigned-ssl-cert-treated-worse-than-no-ssl-cert
Yessssss...@christine
yes and it doest compromise on your security. but you'll have problems with others trusting you because your certificate is not from the trusted third party certificate vendors.
That's why users get asked by browser if they're still willing to access the site despite it not having a public certificate.
This guys makes no sense at all, If they have a case they would have to take it to the courts.
God is going to fight for us
Since iebc has not given access to NASA,is it possible that SA msando was forced to create credentials for NASA black hats?
No one can curse what God blesses.
where did this IT expert get that document from?
Why does the NASA IT expert answer the question that is thrown at the end? A reporter asks: "Where did you get the information from?"
simple go to court immediatly
Kana imeleta utata warudie kura raila asikubali safari hi haki Niko nnje ya kenya but ka homa kamenipata wapi wakenya tunaelekea
the it" expert" explains an MySQL server file, while IEBC are using Oracle. where did you get this information
LORD HAVE YOUR WAY IN US!!!
Sweety Heart Mrs Domo! Cry for your Country ... wacha kuchochea.. kama we ni mwaminifu THINK!! N ask yourself, what could be the course of all these. Raila is just responding what Uhuru have started. Mwizi wewe . NENDA CHURCH UOMBEWE. Mkorini wewe.
Ni usingizi au ni kilio Kenyans were watching and they are still watching
No comment, how did we get here?
Mary Mary nonsense ni Kula ulitowa, Wakenya wamepiga kura vizuri na matokeo ni ya kulazimisha uongozi
This is deception at its best. If the hacker could instal and run algorithms (mathematical functions or procedures) in the SQL server database, then they could also run scripts to create SSL certificates.
Mr Raila,we made up our minds!!you can't confuse us with the fact. We knew your plan and thats why uliplan kujisworn in in TZ
Wapi chiloba aelimishwe mambo ya systems
mr. prime minister acceptbda defeat peacefully nd relax umezeeka
Thiei mukamie.....translation...... Raila tosha
Jackson Wainaina hahahahaaa
Jackson Wainaina wacha utoto ffs
Jackson Wainaina
the biggest lie here is the use of the word "unsigned certificate" such wrongful use of a word shows you he has no idea what he is saying, it is irrelevant to hacking and is in no way a sign of intrusion.
I need to view that log document myself. It will be better if that document were to be posted online for anyone to review them
We are setting a bad precedents in our country
Someone have the complete video with the Q&A?
is it true that Raila is one the verge of losing the fifth time.
THE BEST WAY TO GO TWO COUNTRY ONE FOR NASA & JUBLEE
Who killed Chris Msando? did he give you guys a backdoor to tag IEBC Systems?
can IEBC confirm if Chris credentials were used to login to the system and by who?
Benson G. It is very likely that his credentials were hard coded in the IEBC app. This is normal practice when you build a database management app.
it seems Nasa decided to hack the system to see if Jubilee had hacked the system and they found jubilee inside" guys stop misusing IT terms..
Huyu jamaa anasema nn juu simwelewi mm you mean you are cooking your things mnatuletea hapa huyo jamaa nikaa ameandikiwa venye atasema
James Mbogo relax,
The IT Expert is Railas Nephew
So far jubilee has more members of Parliament and Senate , now tell me how Raila won
JohnM Vevo how much do they add or provide in your monthly bills...
That's the nonsense you are serving us today 5 yrs later.. very regrettable
Raila won Uhuru back off with peace✌ Uhuru won Raila should back off with peace✌ and go home. Why should you fight and hurt yourselves for leaders who will not be with you during your fights!😞Burning n fighting n killing yourselves for no reason. This all is just TRIBALISM in Kenya.He won he lost we have to accept it and move on! Students need to go to school n others need to continue with their work just announce the results! "STOP SPREDING RUMOUR IN PLACE OF #✌"
No more nusu mkate if that's what you are looking for. Kubali matokeo na hiyo masomo yako mingi upeleke Canaan.
Raila stop day dreaming
Ati computer literate 😂😂. .....ata muendee Bill Gates....kameiva already 🤔🤔🤔🤔
Charles Muthee kako ndani ndani ndani
Charles Muthee haha
Charles Muthee but God will curse you big... Just wait and see
Go to hell if not Canaan
.
Self-signed a.k.a machine issued SSL certificates are normally used by
windows server. No need to use a publicly signed certificate for
internal operations as the cryptography is still strong. It is not an indication of an attack. Does anyone have a link to this full document or logs?
facebook.com/media/set/?set=a.1197985420306852.1073741844.301058486666221&type=1&l=8d60cd1ba2
Thanks @Safari Pole. My take, these logs are from a 32bit MsSQL Server 2008 (Microsoft SQL Server). The current version is 2016 and servers should be 64bit, so this is likely running on a personal computer.
From a design point of view it would make more sense (to me) to have one database covering all counties. The logs show a database per county, that's 47 databases in all!
IEBC also confirmed they do not use Microsoft's database making this 2008 version database running from a personal computer look rather suspect (last election they were running Oracle).
I tried to login to the system but all the algorithms on MS SERVER was LISTENING PORTS were all busy.Its true anonymous were on job.
how did this so called IT expert access the iebc servers n quarried to know who hacked the systems? ....
This speech sounds so rehearsed.
I heard Raila/joshua claiming he has a plan to take his followers to canaan,now are they talking from there or where exactly because canaan is a land of milk and pure honey?And does israel know they have Joshua ad associates behind their backs?
Wow! This guy is giving IT Experts a bad name by masquerading as a computer nerd. Needless to say, he talks like he HACKED into the IEBC's system by giving some details that only an IEBC Admin has access to. He's being economical with words by not saying how he get that information.
Mapinduzi Mapinduzi you really are stupid. That is only a log of the activity on the server. Anyone, can print it if he/she has some form of access into the server. Remember, there were many users who had access to the server but only Msando had super user privileges
Mapinduzi Mapinduzi ethical hacking my fren...its a valid job.
you don't know what you are talking about... why have super user account if anyone can access anything they want in the system?
msando is "dead", who else has access to the server, and gave raila those logs?
Raila is going crazy! Your campaign team failed miserably now they are using the opponents strength to justify their failures. Please come back in 2022, we need you to encourage people to vote for Arap Mashamba who will be your opponents.
what we need is Peace.....
If you have the exact times when the hackers accessed the machine, then why dont you check out the cctv footage around the machines at the exact time?
We are all literate... Dont try and fools out of us.
Senseless point
I thought IEBC is using an Oracle Database?
Hakuna kitu kama hiyo. ..raila bondo straight
does any one know this so called expert's name??
No i don't have a problem to your allegations but how exact did you guys know about this???so you hacked in to the system and you identified the hack i think the DCI should interrogate you or maybe you guys have an insider how has access to the system and this, this is unacceptable u should name that guy. And by the way what DB[SQL] a you people talking about coz IEBC IS talking of a different DB [ORACLE]
Uyo ndo hacker nkt
AM I HEARING RIGHT THAT THE DEAD ALSO LOGO IN
i think if you know hacking has taken please you can find the hacker as a computer guru...
I am an IT expert and I can tell you for free this is BS.
lyt mq how is this BS? I know computers myself & what the IT expert says; makes sense.
Am using the computer myself and all I know is that Kenyans have spoken na wamesema ni Uhuru tena. When will you ever concede defeat
lyt mq i am also an IT expert and i can also tell you for free you are a bullshitter
lyt mq I'm not an IT expert but I can smell your shit from 19km away
Pawambu M..Lol Very funny
waa huyu jamaa anasema nini alitoa wapi ADMIN password ndio akajua logins zimefanywa ngapi na sangapi ???????
Nasa IT expert explains how hackers= aje
Ni mtu ameenda shule huyo sio kama wewe muuza makaa!!! People have gone to school so they know where to check and how to check!!! That's why mlinaswa! Na kama yuko wrong, ambia washikaji wako wafungue server!!! Kazi iishe papo hapo!!!!
The Maverick! They think they are fooling Kenyans but Kenyans have known all along most of the tricks. They were just not brave enough to confront in the past for obvious reasons
Listen up guys give us ur true numbers and stop wasting time its a working day.
Haki si mwachekesha eeehh
Aki complaining msando ako mortury???? Let him rest in peace
this guy is a digrace to hacking community
The whole process makes sense sure, but it beats logic to claim the master log was not only so easily available but also not encrypted. Typically they are. You can also easily feign master logs. Another issue is IEBC uses Amazon S3 Servers whose master logs typically are encrypted and the algorithm is only gonna decrypt them upon approval by the super admin which thus means the hacker must have somehow decrypted it and it being 256 character encryptions, I doubt they could do so so fast unless they have some form of super computer. They thus must have credentials. One of them must have Musando's access codes if the logs are genuine and if not, then the logs must have been fabticated. Also, I doubt the access credentials to the system would be as plain as the names of the officials, chebukati? musando? Really? I woildnt use those even for social network usernames let alone such a sensitive case. The names must have been a bit complex, including special characters. Be sensible. Rao, even if you won, youre still guilty here. You have to explain how you decrypted the logs. Or acknowlefge you fabricated the logs prehand in case of loss. Either way youre in pretty hot soup but I guess you have nothing to lose so you dont mind watching the nation burn.
iyo ni yake ameongwa to atoe diz non existing infmtn
did I hear msando logged in?
You why are you confusing Raila with your ideologies .Please young man, please don,t' bring division in Kenya. How are you log into see this who log in and out?Are you Mr Musando. you are the one hacking the IBEC computers. The security should be aware of this.
I believe in god
Dont think kenyans are foolish UhuruRuto must go home or let kenya divide periode
Hahaha Raila hatoshi kwani ujui open ur eyes 😂😂😂
Fancy Jenevive KENYA 's not your father bequest, ati divide our nation
i will tell you for sure that guying is dumping words he has no idea what they mean , nor correlate to what hacking is, nor make any sense .
Database passwords are usually hard coded in the app's source code or a protected configuration file. Just saying...
Ex Machina that's possible but I believe there must have a 2-factor authentication. The missing thumb...
Warudie kupiga kura hadi raila atakaposhinda.
You decided to have a parallel tallying centre so as to raise issues of rigging.we knew the plan before.Chukueni majembe mkalime tunahitaji unga
Pumbavu!!!!!!!!!!!!! Go retire Ogwambo.....The so called IT expert is reading a scripted document!!! I as an IT expert...would just have questions in my mind as to how this person come to such findings... ?????? Mhhhh``======???? Kenyans wake up
Proudly Kenyan Hahahaha ndio maana jubilee ili fail kwa kuiba kura kwa computer....eti nawe unajidai kuwa IT expert!!! IT experts like you ambaye haelewi chochote ndie wameangusha chupilee!!! Noma sana!!!
Your user name reflects your Character and how you think....Maverick. I would not say much...lakini ''Mavi Rick'' states it all!!!
By the way I am not a Kikuyu..neither a Luo, Kisii, Kalenjin or Kamba.