2600 Asks: Is Mafiaboy Real?
A couple of people sent the 2600 story that's currently running about mafiaboy, the alleged brains behind the spate of recent large-scale DoS [?] attacks. 2600 has an interesting claim - that they went on IRC as mafiaboy, and that the security expert who claims to have found mafiaboy was snowed by what they told him over IRC - snowed by lies.
Several years back, I had the pleasure of working for the ISP mafiaboy used to use as a provider. Then he managed to steal our RADIUS password file ( mind you security was very lax at the time ). He had shown us that he was cluefull to a certain degree however he was mostly blinded by his ego. I am not surprised that he could be the one who was responsible for the DDoS a couple of months back. Nor would I be surprised if he tried to take credit for it. He was liked that. During the incident, we had taken it up with his parents, who seemed not to care too much about it. His father said that he had discpined the boy but we found out that Mafiaboy was still up to no good. So in light of all this, I do believe that the RCMP did get their man and that Mafiaboy was stupid enough to get caught. On a side note, I did not read 2600's post to the world. "Keeping anonymous to protect the ... innocent ?"
His homepage is http://www.ender.com/~icee/.
He dated a girl who later committed suicide, partly due to his idiocy.
He used to hang out on EFNet #depression.
logan
Legend has it that the really good crackers never say anything and are never known to the world. I don't know if thats really true or not (how could you verify it, really?), but everyone else brags a lot.
Someone one asked Alfred Hitchcock what the ultimate crime was. His response: "The one we haven't heard about yet."
Seems apropos.
Someone on IRC lying about their identity? It defies belief. I'd write more, but this 19yr old 36DD nympho I met online wants to meet me "alone and unarmed". I'm so excited!
--Shoeboy
I fail to see how they can trace this type of DDoS back to a single individual. With all the firewalls, DHCP's and other addressing schemes, good luck finding him. I think that it's all made up for the media, and to put businesses and people at ease, thinking that "if you screw the Internet you can get caught."
The nickname being used was mafiaboy, not [mafiaboy]. The brackets are convention used to notate private messages sent from the client user to someone else. Similarly, enclosing the nick in asterisks is used to notate private messages received from another user. And enclosing the nick in equal signs is used to notate DCC chat messages received from another user.
From the log:
>>> icee [icee@dragon.ender.com] requested DCC CHAT from mafiaboy
If the nick were [mafiaboy] this line would read:
>>> icee [icee@dragon.ender.com] requested DCC CHAT from [mafiaboy]
Got it? Good.
as you can see from the IRC logs below, we dropped a few clues that the person was in a country with snow and at one point "accidentally" spoke French to imply the province of Quebec. We were amazed when the blame actually landed on someone from Montreal.
The snow reference referrs to the following block of text:
=icee= but WHY do it?
[mafiaboy] snowday
[mafiaboy] haha
And the French referred to a single use of the word "Oui", late in the chat log. Now, the first use of the word "Canada", appears way at the top and comes not from 2600 (mafiaboy), but from *icee*.. again, before 2600 mentions snow or french:
*icee* oh, did you listen to our radio stuff up there in Canada, too?
That's it. The rest of the conversation is harmless, and this portion would be harmless except for the statement that 2600 made implying that these comments helped lead researchers to Canada. Give me a break.
I've got no idea who *icee* is, and 2600's claims that mafiaboy is fake or at least not the right guy are fine with me, but this conversation makes 2600 look less like they have a clue than the FBI who at least are talking about routing logs and web logs and real data. At least I got a laugh out of this:
=icee= okay, we need to solve this trust problem, and prove you are who you say you are..
[mafiaboy] 3090
[mafiaboy] good enough?
Yeah. Good enough. :-P
When Michael Lyle, chief technical officer of Internet-security firm Recourse Technologies Inc., first accused Mafiaboy of the attacks,(just a couple weeks after they happened) he based it on chat-room talk. People were very skeptical then, and I recall someone making similiar claims - that they had impersonated the DoS perpetrator in chat rooms.
It appears the RCMP don't have much more. Maybe the arrest was just so they could search his computer for evidence, because from what's been reported in the press, there isn't any real hard evidence against him.
Don't forget that Friday is Hawaiian shirt day.
Well, if 2600's mafiaboy isn't the real mafiaboy, then how do we know that they were talking to the real icee?
And the men who hold high places must be the ones who start
To mold a new reality... closer to the heart
Other posters have commented that this seems a bit paranoid, what with the evidence and all. 2600 is claiming that the FBI doesn't have the real Mafiaboy.
Well, I claim that they're not the real 2600! We've been paying attention to a fake! Through subtle manipulation over an extended period of time, "2600" has usurped the rightful entity behind the name!
The true 2600 is, and always has been, here
-Denor
And his dad's too. I turns out that while they were after this canadian teenager, they discovered while wiretapping his house, that his 45-years-old dad was planning with a hitman to assault or scare the hell out of one of his business associates.
So, be careful, you never know when the police is coming to get your son =)
What a strange (and offtopic, I admit) coincidence.
"All the things one has forgotten scream for help in dreams". Elias Canetti
According th Reuters there are all sorts of ICQ, Usenet and IRC logs that connect Mafiaboy with the crime.
PS: Read the articles linked to the above article and judge for yourself if Mafiaboy is the real culprit or not.
...he lives in the heart of you and me, in anyone who's every sat bleary-eyed in front of a CRT at 3-am, anyone who has subsisted on Pop-tarts, Zingers, and Mountain Dew, anyone who has been shunned by society only to find acceptance in the warmth of a x86 processor! Yes, he even lives in you, Scarecrow! Every time you lick the neon Cheet-o residue off your fingers so you won't get it lodged in your keyboard...MafiaBoy is with you...each time the BSOD causes you to flop on the ground like a Pokemon-induced seizure...MafiaBoy is there flinching too!...every time you've told a newbie to try 'this really cool command, rm -r *'...MafiaBoy was laughing right along! Don't you see, Timmy? You can't touch or see MafiaBoy, he surrounds us, invisible yet guiding us. So, when those kids tell you there ain't such thing as MafiaBoy, you tell em' what ol' MorboNixon told ya! And that, ya see, is the real meaning of MafiaBoy. Now let me tell ye how I invented the question mark...
Danny: Hosts a boring local radio program
Emmanuel: Hosts a boring local radio program
Danny: Quasi celebrity status among '70's freaks
Emmanuel: Quasi celebrity status among telephone phreaks
Danny: Periods of heavy drug usage
Emmanuel: Periods of heavy drug usage
Danny: Involved in sex scandal with another man
Emmanuel: Involved in sex scandal with another man
Danny: Last name is "Bonaduce"
Emmanuel: Friends with Phiber Optik whose first handle was "Il Duce"
Danny: Supplements income by doing desperate local talk shows whenever he can
Emmanuel: Supplements income by doing desperate talk shows whenever he can
In all the mainstream Mafiaboy stories, they point to IRC logs. Where are these logs? Why aren't they linked to, if they exist? If they aren't allowed to, then why not? Shouldn't that be evidence to show the press? Or is the FBI worried that anyone viewing the logs might see holes in their case? Or do the logs not exist? Is some FBI lacky makeing fake logs now to show later?
What about Twinkies? When can I DoS a Twinkie? Will it work with fat free Twinkies? The people want to know!!!
Not a typewriter
...that basically this whole deal is going to turn into a huge media circus to make some opportunist, -somewhere-, some beaucoup cash. It might just be me, but everytime I see some 'expert' on computer security talking to the media at large, that we're probably dealing with some half-wit who can string the words together to get he sound bite.
Looks a bit like 'resume enhancement' for some has-been/never-was at some company who'd look really good with some press attention, not investigation, n'est ce pas? Too bad that some 15 year old kid in Canada is probably going to take the fall so they can fatten their bottom line.
But I'm an old fogey who checks my electronic fences, writes my letters to congress, opts out of as much as I can, and keeps my nose clean.
In space, no one can hear you moo.
A quick quote:" Montreal police hauled the father in last week after investigators, who were monitoring his 15-year-old son via tapped telephones, overheard the father and another man make plans for the assault, police officials said"
There are a number of http proxies listed on this page. Filtering can be bypassed by using SSL encryption on URLs requested through these servers.