Kevin Mitnick / Novell - War Dialing → Pretexting → The Voicemail Trap That Named the Hacker → The Watched Honeypot
Kevin Mitnick was already a fugitive - the FBI's most wanted hacker, living under a false identity in Denver - when he turned to Novell, one target on a long list he worked for proprietary source code. Novell knew early: he war-dialed the entire San Jose campus hunting for modems, phones ringing desk after desk, which told the network team someone was seriously trying to get in. His pretext calls mapped the humans rather than the systems - along the way he learned that network administrator Shawn Nunley controlled the modems, hijacked employee Gabe Nault's voicemail and planted an out-of-office greeting in his own voice to survive verification, and found Nunley's home phone number. The late-night call asking for policy-breaking inbound modem access was the tell; Nunley played along, asked him to leave a voicemail, and taped it - the first and only direct evidence naming the hacker, and the lynchpin of the federal case. Then Novell turned the tables entirely: it granted the requested access on 1-800-37-TCPIP, a number that existed for no purpose but to capture his caller ID, and routed him through a terminal server where every keystroke was watched live and every session recorded. Mitnick spotted the caller-ID trap and dialed around it - but never knew he was in a fishbowl. Novell kept him off the ATM system that held all NetWare source, and all he ever downloaded was inconsequential code.
Novell was one stop on a long target list - the federal indictment also names Motorola, Nokia, Fujitsu, Sun Microsystems, and NEC - and the tradecraft was the same everywhere. Before making a single call, Mitnick invested significant time learning everything publicly available about his target. He gathered employee names from directory listings, understood Novell's internal team structures, learned real internal project names, and immersed himself in NetWare technical documentation so he could speak fluently about the product - a prerequisite for any convincing pretext. As he wrote in The Art of Deception: "When you know the lingo and terminology, it establishes credibility - you're legit, a coworker slogging in the trenches just like your targets."
Goal: Build enough authentic detail to withstand scrutiny from a real Novell employee
Mitnick's method: "Pretext calls" - low-stakes calls to gather information for higher-stakes calls later
Already a fugitive, Mitnick opened the campaign the old-fashioned way: war dialing - sweeping Novell's San Jose campus phone ranges number by number, hunting for a modem that would answer. Desk phones rang sequentially through the building, one after another, for anyone paying attention to hear. Novell's network team was paying attention. Before Mitnick ever got anything, the defenders knew somebody was seriously trying to get in - they just didn't know who. In this chain, detection precedes access.
The giveaway: Phones ringing desk after desk in sequence - a scan you can hear
Defender state: Persistent threat confirmed, identity unknown - the hunt for the hacker starts here
Mitnick worked Novell by phone, presenting himself as a legitimate employee or developer with a plausible reason for calling - real names, correct internal terminology, manufactured urgency, a different pretext for each target. His genius was psychological: he assessed each target's willingness to cooperate in the first few seconds and adapted in real time. What the calls harvested was not credentials but intelligence. Somewhere in those conversations he learned who Shawn Nunley was - and that Nunley controlled the modems and all inbound access. Around the same time he broke into the real Gabe Nault's voicemail and recorded an out-of-office greeting in his own voice, pre-poisoning the verification channel for the pretext to come. Eventually, he found Nunley's home phone number.
Mitnick on reading targets: "I'm always on the watch for signs that give me a read on how cooperative a person is"
Intelligence gained: Who controls inbound modem access (Shawn Nunley) + his home phone number
Pre-positioned bypass: Hijacked Gabe Nault's voicemail, planted a Vail out-of-office greeting in his own voice
Armed with what the elicitation calls had taught him, Mitnick went straight for the gatekeeper. Late one night, Shawn Nunley - the network administrator responsible for all of Novell's inbound connectivity - got a call at home from "Gabe Nault", a real Novell employee. The pretext was immaculate: the caller name-dropped Snowbird, a real internal top-secret project; he was on vacation in Vail and needed to make emergency code changes that could not wait; and the vacation story checked out, because the greeting on the real Gabe Nault's voicemail - the one Mitnick had planted there himself - backed it word for word. What he wanted was direct inbound modem access. That request was the tell. Modem access at Novell ran through a secure dial-back system keyed to known phone numbers, plus manager approval - and Nunley owned that system. No genuine employee needed what this caller was asking for. Rather than confront him and burn the contact, Nunley played it cool: he could not grant the access from home anyway, so it would have to wait until morning - "but in case I forget, please leave me a voicemail."
The pre-positioned bypass: Mitnick had hijacked the real employee's voicemail and planted the out-of-office greeting in his own voice, so call-back verification would confirm the imposter
The tell: The request itself - direct inbound dial access violated the dial-back policy and its approval workflow
The counter: Don't tip off the attacker - stall politely and convert the contact into a recorded artifact
The voicemail was waiting the next morning, and Nunley immediately recorded it onto a cassette for safekeeping. Its significance is hard to overstate. Across years of intrusions at company after company, investigators had collected no physical evidence directly tying the crimes to Kevin Mitnick himself. A voice on tape, soliciting policy-breaking access to Novell's network, was the first and only direct evidence that the hacker was, in fact, Mitnick. As Nunley later put it: "You can't cross-examine a keystroke." That recording became the primary evidence in the federal case - the lynchpin that turned suspicion into a prosecutable identity. There is a fitting symmetry in it: Mitnick had weaponized a voicemail box to sell the pretext, and a voicemail box is what finally named him.
Evidence before the tape: No physical evidence tying Mitnick to a major crime
Role in the case: Primary evidence in the federal prosecution; Nunley became the primary witness
With the tape in hand, Novell did the counterintuitive thing: it gave "Gabe Nault" exactly what he had asked for. The dial-in came up on 1-800-37-TCPIP, a number provisioned for no purpose other than to see who called it - toll-free billing delivers the caller's number (ANI) to the account paying for the call, so every inbound call would unmask him. Mitnick knew the phone system too well for that. He recognized what an 800 number would give away, dug through the phone system to find the DID number the 800 line translated to, and dialed that directly instead, sidestepping the caller-ID capture. What he could not sidestep was where the line landed.
The mechanism: Toll-free ANI delivery - the callee sees the caller's number
The evasion: Mitnick located the underlying DID number and dialed it directly, bypassing the ANI capture
His side: Dialing in at night from Denver, living as "Eric Weiss", cloned cell phones his standard practice for hiding location
The DID trick bought Mitnick nothing that mattered, because the line terminated on a terminal server Novell controlled. The network team watched every keystroke of every session in real time, and an early version of NutCracker, hooked to the ethernet side of the terminal server, captured and recorded the sessions. The defenders did not just observe - they played with him: interrupting sessions when he got close to systems that mattered, or simply when they got bored. The most wanted hacker in America believed he was inside Novell. He was inside an instrumented box Novell had built for him.
Live monitoring: Real-time keystroke visibility for the network team
Session recording: An early version of NutCracker on the ethernet side, capturing full sessions
Active control: Sessions interrupted at will - especially near sensitive systems
Watching his sessions, the team could see what Mitnick was learning as he learned it. He discovered the existence of ATM, the internal system where Novell stored all of its source code - the real prize. Because the defenders could see him coming, he never reached it: sessions that headed toward ATM got cut. Over the course of the operation he did manage to download some source code, but only inconsequential material. The federal indictment would later charge him with copying proprietary Novell software, and that is true as far as it goes. What it does not say is that everything he took from Novell, he took on camera, out of the shallow end of the pool.
The block: Sessions cut whenever he closed in on it - he never reached ATM
Actual take: Inconsequential source code, downloaded under full surveillance
Legal record: The 25-count indictment includes copying proprietary Novell software
Mitnick stayed loose for some time after the tape - dialing into Novell's fishbowl while the wider pursuit continued, until Tsutomu Shimomura helped track him to Raleigh, North Carolina, a chase that is its own famous story - but when the FBI finally had him, the Novell tape anchored the case, and Nunley worked with the prosecution as its primary witness for five years. He grew increasingly troubled that Mitnick was held without a bail hearing and without access to the evidence against him; when a senior prosecutor told him on the record that the point was "sending a message to other would-be hackers", Nunley parted ways with the DOJ and contacted Mitnick's defence team. Mitnick was released on a plea deal - and the man who trapped him became one of his closest friends for the rest of his life. It's one of the most extraordinary adversary-to-friend trajectories in the history of computer crime.
Found with: Cloned cellular phones, 100+ cloned phone codes, multiple pieces of false identification
Sentence: 46 months + 22 months for supervised release violation (5 years total, including 8 months solitary)
Shawn Nunley: Set the trap → primary witness → challenged the DOJ over due process → lifelong friend of Mitnick
