Feds Thwart Extortion Plot Against Best Buy
hiero writes "From an article
in the Star Tribune: 'Federal authorities said Tuesday they thwarted an extortion plot against Best Buy Co. Inc. by a man who sent the company an e-mail threatening to expose what he claimed were weaknesses in the retailer's computer system unless he was paid $2.5 million.' What's really interesting to me, though, is this paragraph further on in the article: 'The federal search warrant was obtained the morning of Oct. 24 and allowed the FBI, with Best Buy's cooperation, to use an Internet device known as an Internet Protocol Address Verifier. It contained a program that automatically sent back a response to Best Buy after the company sent a message to the e-mail address. The response allowed investigators to identify Ray as the sender of the e-mail threats, according to the government.' Internet Protocol Address Verifier? Is this Carnivore in action?"
I think it's called a return receipt :-D Probably was using Outlook which automagicly sends one when requested.
Blogzine
That's what happens when you try to extort a big company using Outlook.
"0101100101? It's just jibberish. *looks in mirror, gasps* 1010011010@!? AHHHHHH!!"
sounds so much better than "ping"
Best Buy and the Feds are working together! So that's why I have to return 90% of the hardware I buy from Best Buy!
Make sure you turn off Message Disposition Notification in your e-mail client.
Sheesh, evil *and* a jerk. -- Jade
the Internet Protocol Address verifier get into the hands of the RIAA.. we would not want more 12 yr olds and college students being fined ridiculous amounts, would we? :D
|/________
|\A|ALYS|
A top tip (tm) is to embed a web bug in a job aplication e-mail. Its interseting to watch your aplication being pushed around various departments and see who actually reads it.
h eck.ins.govr rorism.dhs.org. com
Yes, it's very interesting. For example, here's the log of all the machines who accessed my web bug when applied for a job at the DHS:
frontdesk.dhs.gov
hr.dhs.gov
check.dhs.gov
c
check.irs.org
it.dhs.org
counterte
legal.dhs.org
submitsubpoena.aol
bust.usmarshals.gov
brb 2 secs, someone's at the door...
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
You can send HTML letters? COOL! Are you beta-testing electronic paper or something? I'd love to get my hands on some of that.
hate to bite but 7. ??? 8. Profit!
Imagine his surprise when he received a $2.5 million Best Buy Gift Card in the mail. Doh!
Huh. It reminded me of Stalin and Beria and the NKVD, but you're right, better we should take our lessons from space opera than from history.
In Imperial Coruscant, history takes lessons from YOU!
Methinks that would be marketing speak for an HTML mail with a web bug (1x1 transparent pixel image loaded from remote server). If the 'villain' is using a mail program that displays HTML, his IP address is logged.
The villain didn't of course use any mail program but some generic webmail address (most likely outside the US). The lesson? Use Lynx to read your webmail when extorting Best Buy.
hey! just like my computer!
</obligatory karma whoring>
Sacred cows make the best burgers.
As opposed to a big company who tries to extort us to use Outlook?
My beliefs do not require that you agree with them.
Here are three ways to get on America's Dumbest:
1. Rob Taco Bell right after filling out job appication and interview. Be arrested when cops show up at your address on the application.
2. Send extortion/blackmail emails using MS-Outlook from your normal ISP account. Be busted when FBI sends email using marketing tool like Neighborhood Email or eZine Manager. FBI is too embarassed to admit they used an e-newsletter tool and come up with the "ip address verifier" device.
3. Shoplift naked. Be arrested when cop identifies the incredibly stupid butcher's meat chart tatoo when streaking through campus on a dare.
4. Keep crack pipe, crack and lighter in glove box. Be arrested when you see a billboard advising "Drug checkpoint next exit" and begin throwing crack, lighter and pipe out the window while police are video taping looking for people throwing drugs and paraphanellia out the window.
-- $G
1... Post the website and sample URLs on favorite tech site ala' slashdot
2... wait
3... PROFFIT
The More Knowledge you have the Luckier you Get- J.R. Ewing
We need as big and powerful of a government as possible. Higher taxes, more police, more spyware, more surveillance. Thats the whole goal the republican party isnt it? Well Mission Accomplished. Next time I'm voting Libertarian (Ex-Republican)
People don't exist to serve systems, systems exist to serve people.
Can we use it to trace and arrest those bastards that send out 'pay us $699 for Linux' extortion letters?
Oh no! The FBI doesn't want to investigate little Jimmy being extorted for his lunch money on the playground at school? What is this world coming to?
This example of the counter-"point" is brought to you by the citizens for people thinking first before typing. Thank you.
for a new keyboard - i was happily drinking my milk and reading /. when as I made my way across yours post, inexplicably it all came out gushing through my nose -
Also, it wasn't everywhere, just certain idiot stores, apparantly. Imagine the disappointment of all the hackers out in the parkinglot who couldn't get any credit card information at the one here in Saginaw.
I agree. In fact, I routinely turn off html in my web browser. I prefer to read the unrendered markup language.
He should have, too. :p
The World's Worst Webcomic!
Come on man, this is /. We all know everything better than anybody else. So we all know what happened.
I bet he was just trying to get his rebate money from them.
-------- This space intentionally left blank --------
I for one, welcome our new FBI overlords!
ping -l 666 -n 666 special.host.at.bestbuy.com
fsckin' DUH!
Canivore for the feds? I'm starting an open source project to hold my valuable IPAV app's intellectual property and I'm going to call it Moronivore
It *is* a troll, but its clever - please mod up
I am very easy to get along with, but I don't have time to waste being nice to people who are being stupid. -Theo
I managed to get a hold of the source code for the internet address verifier. Here goes:
."
#!/bin/bash
usage()
{
[ "$1" ] && echo "$0: $*" >&2
echo "Usage: $0 " >&2
exit 1
}
[ "$1" ] || usage "You must supply the criminal's email address"
email=$1
domain=${email##*@}
mxname=$(host -t mx "$domain" | sed -ne 's/.* \(.*\)/\1/p')
mxaddr=$(host -t a "$mxname" | sed -ne 's/.* \(.*\)/\1/p')
netblock=$(whois "$mxaddr"|sed -ne 's/[^(]*(\([^)]*\).*/\1/p|tail -1)
netowner=$(whois "$netblock")
echo "Your next step is to issue a subpoena against the following party - probably an ISP."
echo "They need to give you the current user of the IP address $mxaddr."
echo "(This may very well point back to the same ISP)."
echo "This party, in turn, must turn over the identity of the email account
echo "$netowner"