Slashdot Mirror


Vigilante Hackers use Old West Tactics for Justice

dismorphic writes "Angered by the growing number of Internet scams, online 'vigilantes' have started to take justice into their own hands by hacking into suspected fraud sites and defacing them. These hackers have targeted fake websites set up to resemble the sites of banks or financial institutions in recent weeks, and have inserted new pages or messages. Some say 'Warning - This was a Scam Site,' or 'This Bank Was Fraudulent and Is Now Removed.'" So maybe it's not a posse of horsemen, but it's still kinda cool that someone is taking care of those who would defraud the public.

91 of 532 comments (clear)

  1. justice by Artana+Niveus+Corvum · · Score: 5, Interesting

    I truly often wish that sort of justice were legal... When the law can't back itself up and the people can...

    --
    -----------------------------------------
    Remove the Greed which plagues mankind.
    1. Re:justice by lawpoop · · Score: 3, Insightful
      This is not justice. Who says that this site or that site is a fraudulent bank? How would you like it if a 'vigilante' defaced your site claiming you were a fraud?

      If you don't have a trial with evidence, all you are doing is creating cycles of revenge, with no resolution. With a justice system, wrongs can be righted, and then we are done with the matter.

      There is no justice system that is totally perfect, but resorting to vigilantism when justice isn't perfect would make the situation much much worse.

      --
      Computers are useless. They can only give you answers.
      -- Pablo Picasso
    2. Re:justice by peculiarmethod · · Score: 2, Insightful

      Unfortunately, this specific *type* of working around the legal route to justice will only stengthen the tactics/creativity used by "bad guys"(c). It's introducing the darwin effect, and will only kill off the stupid for s short time.. until they learn they much up the anty. In time that will only make it harder to detect the scams. While its cool in the short run, it's only helping the bad guys evolve.

      kinda cool though.

      --
      ** "It's not my job to stand between the people talking to me, and the ones listening to me." -- Pego the Jerk
    3. Re:justice by Adrilla · · Score: 4, Insightful

      and meanwhile, while all of this time is passing waiting for arrests and trials, they fraudulent websites are robbing people who don't know any better. I don't fully endorse the defacing the sites but it's something and it works quicker than waiting for the justice system to catch up. It's not a resolution, but it is a deterent, not to mention if the justice righted the wrongs and we were already "done with the matter" the vigilantes wouldn't have fake sites to deface.

      --

      "Plans are for fools! Oglethorpe, the plutonian (Aqua Teen Hunger Force)
    4. Re:justice by ear1grey · · Score: 4, Funny

      This was originally an ill-considered and underinformed comment disagreeing strongly with the attitude and social misalignement of the parent comment, however vigilantes have hacked it and altered it's purpose to throw the original comment's cunning and socially wry insight into sharp relief.

    5. Re:justice by thinkliberty · · Score: 3, Funny

      Yeah but scammers are now useing new souper P-P-P-Powerbooks!

      There is no way you are going to bring down their site.

    6. Re:justice by secolactico · · Score: 4, Insightful

      Slippery slope argument? In this case it's pretty clear that GOOD came out of this, did not make any situation much much worse.

      Actually, slippery slopes sometimes start like this. With a clear cut case of right and wrong. But tomorrow it might be used as precedents for other actions. For example, DMCA "violators" might find their site defaced with a sign that says: "This software brakes the law and the author is a criminal".

      When someone bypasses the rule of the law and proper procedures and takes justice into his own hands, and "the system" looks the other way or even condones the action, it opens the door to all other sort of vigilantism.

      --
      No sig
    7. Re:justice by shawn(at)fsu · · Score: 3, Insightful

      Aren't we the same people that worry about the goverement taking away our right of do process with the Patriot act. I'm sure the goverment probably uses some of the same reasoning. "It would take month to get this court order to tap the phone line"

      That said I really don't care about these sites getting defaced, if they accidently deface a legitimite site well then I think they should be punished.

      --
      500 dollar reward for tip(s) leading to the arrest of the person(s) who stole my sig.
    8. Re:justice by Adrilla · · Score: 4, Insightful

      Like I said I don't fully endorse what they're doing, and one of the reasons why is because it can spiral out of hand. But I can understand the intent and I can appreciate standing up for the average consumer who doesn't know that they are getting taken advantage of, there is some sort of neighborhood justice there. It's not good, but I don't think it's bad either, I'd say it falls in a favorable area of gray and as long as it stays there, I can live with that.

      --

      "Plans are for fools! Oglethorpe, the plutonian (Aqua Teen Hunger Force)
    9. Re:justice by knBIS · · Score: 2, Informative

      I got my first fraud email from some site claiming to be paypal the other day, and followed the link to see how convincing it was... The site looked pretty good (unless you check out the address bar... )

      So i figured i'd try and login with some random user name and password... Well it seemed like they actually forward the information to paypal's site to check and see if its valid...

      Maybe they just deny everyone who tries to login, but it looked like my browser was actually sending some information to paypal.com befroe the russian site told me that my info was invald... i didn't really want to try it with my real info, so i'm not really sure how it would behave if it recieved a good username/pass,,

      So depending on how much effort they put into building the fake site, flooding it with bad date might be sort of useless

    10. Re:justice by future+assassin · · Score: 2, Informative
      Yes it is when fag ass scammers can send you an email that takes you to a site like this and scam you out of your cc info.
      http://www.futureassassin.com/phish/dv_01.gif/
      http://www.futureassassin.com/phish/dv_02.gif/
      I reported this site to netcraft and they send me an email back confirming I found a phishign site. This site was shut down a few minutes later and the domain was put into REGISTRAR-HOLD

      By the way if you are the first to discover a phish site netcraft sends you a present,. still waiting for mine :)

      --
      by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
    11. Re:justice by JockAMundo · · Score: 5, Interesting

      I've often thought of writing a script to flood bogus data into scam sites

      I do this all the time. It is easy with the Firefox Web Developer extension. I just turn the post into a get, remove the field limits, and fill the fields with hundreds of characters. I usually take some text from Project Gutenberg. Then I stuff the big GET into a wget command in a looping bash script and let it run for a few hours. These sites are usually just php mailers, and so I get the satisfaction of filling a scammers mail box.

      Probably useless, but it makes me feel better.

      (arg, slashdot says I'm a script!, that is it, I done coding for the day and I'm going for a beer)

    12. Re:justice by v1 · · Score: 2, Informative

      but to say it's a bad idea to fight injustice because the criminals will just get better, that's a blanket justification that could be applied to all crime. The result of widespread adoption of that mindset would be "anarchy".

      If you don't fight back, you are perceived as weak. Criminals prefer to prey on the weak. So by not fighting back, you are making yourself an attractive target, and will be exploited.

      Vigilante justice occurs when a group is doing something that the general public can openly agree is wrong, but for which there is no formal law or rule forbidding. The populace takes action independently to protect themselves until which time the appropriate laws are passed.

      --
      I work for the Department of Redundancy Department.
    13. Re:justice by bkissi01 · · Score: 2, Informative

      There are web pages that send a "flash mob" to their sites. You disable your browsers cache and then open the web page and it repeaditly loads images from the 419 sites. If a lot of people have the page open it will consume all of the bandwidth of the 419 sites. Kind of like the Make Love Not Spam screensaver that Lycos made. Essentially by a bunch of people constandly downloading the images from the sites it creates a DDoS attack on the site. I'm not too sure about the legality of an "attack" like this, but it is a cool idea.

    14. Re:justice by irving47 · · Score: 2, Interesting

      Sorry, but I can't buy the slippery slope argument. Some issues are black and white. Just because there are OTHER sites that aren't as easy to prove are doing something illegal doesn't mean you give a pass the the ones who are *blatantly* attempting to rob someone blind.
      If I see someone getting pickpocketed and I can aid them in getting their money back,... What am I going to do? Stand idly by and not say anything?

      --
      I had a sucky sig.
  2. ahhh... by Anonymous Coward · · Score: 5, Funny

    that's why my citibank fansite was defaced!

    1. Re:ahhh... by Dumbush · · Score: 2, Funny

      Wait a minute, your site is a fansite? How come it required my citibank login to view the news item!

    2. Re:ahhh... by Patrik_AKA_RedX · · Score: 3, Funny

      Simple: if you aren't a client, you aren't a real fan, are you? You bank account reaching a large negative number after registration is pure coincidence.

  3. gov. crackdown by Awol411 · · Score: 3, Insightful

    i love how gov. agencies will probably crack down on the hackers defacing the phishing sites, but do little to nothing about the phishing sites/people themselves its all about the quick solution, not trying to go towards the deeper problem

    1. Re:gov. crackdown by masterpenguin · · Score: 2, Interesting

      did the hackers that defaced the KKK and other Raciest websites several years ago ever get caught? Sometimes I think that the govt turns a blind eye to things that relieve the pressures of trying to regulate the internet. Self regulation can work in small doses.

    2. Re:gov. crackdown by Jesus+IS+the+Devil · · Score: 2, Insightful

      Do you actually have proof to back up this statement? I doubt it.

      --

      eTrade SUCKS
  4. Western Justice, eh ... by TripMaster_Monky · · Score: 2, Funny

    "The Geeks, the Pasty and the Unbathed"

    --
    __________
    |rip/\/\aster /\/\onky
  5. Jury nullification by XanC · · Score: 5, Interesting

    If it's common sense, regardless of the law, the people (in the form of a jury) can make it legal.

    1. Re:Jury nullification by dubdays · · Score: 4, Insightful

      Unfortunately, it seems to take FOREVER for the law to make a difference in these cases, if anything is ever done at all. The simple fact is that it's difficult, at best, to try to track and arrest an international criminal. I'm generally not one for vigilantes, but when it takes 5 months to catch the bastard legally, I'm all for taking the sucker out of business by other means.

    2. Re:Jury nullification by crymeph0 · · Score: 5, Interesting

      Agreed. From the end of TFA:

      We would rather see the industry itself find solutions.

      And while your industry is sitting around doing nothing about these fake sites set up in countries where the local police care more about rounding up dissidents than stopping fraud, people are losing their life savings. I'll take my chances with the vigilantes. Even if they make mistakes, at least they're doing something

      --
      It should be illegal to say that freedom of speech should be limited.
    3. Re:Jury nullification by ScentCone · · Score: 5, Informative

      If it's common sense, regardless of the law, the people (in the form of a jury) can make it legal.

      Not really. For example, if a person doesn't have appropriate charges brought up against them (or there are no such statutes), then there will never be an option for a jury to exercise. The jury might elect not to convict on something, but they can't cause a conviction (on other counts) where there should be one. This is particularly true where the nature of an act (like some innovative new form of online fraud, for example) hasn't been really contemplated by the justice system before.

      --
      Don't disappoint your bird dog. Go to the range.
    4. Re:Jury nullification by anagama · · Score: 2, Insightful

      The jury might elect not to convict on something, but they can't cause a conviction (on other counts) where there should be one. This is particularly true where the nature of an act (like some innovative new form of online fraud, for example) hasn't been really contemplated by the justice system before.

      It sounds like you are saying that if a person comes up with a new fraud scheme, he can't be tried and convicted. I think fraud is a very flexible term. Basically, any transaction in which Fraudster deceives "Mark" in order to get Mark to do something (transfer info, money, goods, whatever), that's fraud. It doesn't matter if you do it on the street corner, out of a brick and mortar shop, or on the internet -- the key is deception as the basis of an exchange. The problem with fraud isn't so much its definition, it's finding the fraudster and getting legal jurisdiction over him or her. A brand new innovative scam? If you can get the guy into court, he'll not get off merely because it's new.

      --
      What changed under Obama? Nothing Good
    5. Re:Jury nullification by MetalliQaZ · · Score: 5, Insightful

      The problem with vigilantes is this:

      What happens when they come after YOU, and you don't have due process to protect you?

      -d

      --
      "Here Lies Philip J. Fry, named for his uncle, to carry on his spirit"
    6. Re:Jury nullification by tomhudson · · Score: 4, Insightful
      We would rather see the industry itself find solutions.
      "The industry" would rather use this as an opportunity to sell you "our latest anti-phishing software". Fuck that! That is NOT a solution. That's barely a bandaid.
    7. Re:Jury nullification by spongman · · Score: 2, Interesting

      they can't make it legal. they can, however, choose to ignore the law.

    8. Re:Jury nullification by darkonc · · Score: 2, Interesting
      Just as long as they don't take out the entire server. A lot of these sites are hosted on hijacked and otherwise innocent boxes. If it's a multi-hosted box, you could easily end up taking out a couple hundred unrelated websites.
      Even for a single-hosted box, the person running the box may not be aware of what it's doing.

      Those caveats having been stated, however, I think that it's a nice thing to see being done. I've sent emails to the sites being spoofed suggesting that they ask for this sort of change, but I've never seen it actually done. They seem to either do nothing, or shut down the website -- no inbetween.

      --
      Sometimes boldness is in fashion. Sometimes only the brave will be bold.
    9. Re:Jury nullification by Arker · · Score: 2, Funny

      I'm protected by Smith and Wesson.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    10. Re:Jury nullification by digidave · · Score: 5, Funny

      Let me know how that BOIP (Bullet Over IP) goes.

      --
      The global economy is a great thing until you feel it locally.
    11. Re:Jury nullification by norton_I · · Score: 4, Insightful

      This is, of course, the problem with vigilante justice, and the reason it is illegal. The 'outmoded' idea of due process that makes our legal system too slow do deal with phishing and other fraudlent sites are designed to make sure the only the guilty are punished, and that the punishment is comensurate with the crime. If I get my paypal 'change your password' scam-of-the-week email, go to the site it points to, hack in, and shut down their webserver, I have maybe stopped some crimes being committed. But I refuse to trust myself to do so without disrupting anyone elses business, leaving the server open for other spambots and the like, or in general causing a mess. In the world where the chances of the perpetrator being caught were high, by hacking in myself, I might even destroy evidence that could be used to legally prosecute them.

    12. Re:Jury nullification by Short+Circuit · · Score: 2, Funny

      Love to see your monitor after that one...

    13. Re:Jury nullification by crymeph0 · · Score: 5, Interesting

      Don't get me wrong, this is not how things should be, but to turn your question around: What happens when your parents/friends/@other_close_ones get hit by a phisher, and "due process" doesn't protect them, because the industry is still "searching" for a solution?

      --
      It should be illegal to say that freedom of speech should be limited.
    14. Re:Jury nullification by Xoder · · Score: 3, Informative

      The grandparent is referring to the US (and possibly elsewhere) rarely-used practice of Jury Nullifcation. The jury essentially says that, yes, the accused is guilty of the crime stated, but the activity should not be a crime, and so we will not convict. Judges and prosecutors hate that, and will often refuse a juror if he mentions knowledge of the statute.

      --
      The previous sig has been removed due to /. protecting your best interests
    15. Re:Jury nullification by darkonc · · Score: 4, Insightful

      In this case, they're marking the site so that later 'marks' recognize that the site isn't legitimate -- but otherwise leave it up and functional. Yes, it might run over some forensic info, but given the dearth of arrests for these scams, it's rather productive to save some newbie's but (and bucks) from these people.

      --
      Sometimes boldness is in fashion. Sometimes only the brave will be bold.
    16. Re:Jury nullification by sammy+baby · · Score: 3, Informative

      Actually, there was a case not too long ago where a kid who was a photography buff was arrested for posession of... film canisters. Apparently, someone found them in his locker or on his person and assumed that he was using them to transport drugs. He was arrested, and eventually tried, for possession of drug paraphenalia.

      The punchline? Possession of paraphenalia isn't a crime where he lives. (Of course, he wasn't convicted, either.)

      Full story here.

    17. Re:Jury nullification by NinjaFarmer · · Score: 2, Funny
      Zybl0re: get on up
      Zybl0re: get up
      Zybl0re: get on up
      phxl|paper: and DANCE
      * nmp3bot dances :D-{
      * nmp3bot dances :D|-{
      * nmp3bot dances :D/-{
      [SA]HatfulOfHollow: i'm going to become rich and famous after i invent a device that allows you to stab people in the face over the internet


    18. Re:Jury nullification by Mr.Zong · · Score: 4, Funny

      What happens when your parents/friends/@other_close_ones get hit by a phisher, and "due process" doesn't protect them, because the industry is still "searching" for a solution?

      Darwinism?

    19. Re:Jury nullification by miskatonic+alumnus · · Score: 2, Insightful

      Right. It is the federal government's exclusive right to shred the constitution --- they are doing a great job of it.

  6. If only they could hack the email servers as well by ravenspear · · Score: 4, Funny

    Dear Sir,

    My name is Dr. Samouismai from the royal family of Nigeria and I would like to offer you a proposal that you may find compelling.

    I have recently come into an inheritance of goatse pics and I feel that I can not hold all of it safely. I would propose that if you agree I will hold 26 million of these pics in trust for you to deposit at whatever place you wish to keep them.

    I would like to meet to arrange this as soon as possible. If this deal succeeds, I would also like to discuss the possibility of you acquiring my collection of 4.3 million woopie cushions.

    Sincerely,
    I forgot my real name but I usually go by Jack Ass

  7. The industry itself... by neo · · Score: 4, Insightful

    Larson added, "We would rather see the industry itself find solutions."

    So would we.

  8. Hackers not always bad by masterpenguin · · Score: 2

    There has been a long history of hackers doing good on the internet. I think this is just another step in that story. Hackers have been misrepresented in the media for many years, and I for one am glad to see that for once they're getting some good press.

  9. I agree by Dancin_Santa · · Score: 5, Insightful

    We just don't see enough people hanging from trees for marrying outside their race.

    Oh, your concept of right and wrong is different from mine?

    1. Re:I agree by kclittle · · Score: 4, Funny

      I have mod points, but I can't find the "Insightful Flamebait Troll" value in the list...

      --
      Generally, bash is superior to python in those environments where python is not installed.
    2. Re:I agree by MoneyT · · Score: 5, Insightful

      How do you erode the rule of law where the law does not attempt to rule?

      --
      T Money
      World Domination with a plastic spoon since 1984
  10. Comment removed by account_deleted · · Score: 2, Interesting

    Comment removed based on user account deletion

  11. Retribution by athakur999 · · Score: 4, Insightful

    I have a little PHP script that I use whenever I get a phishing email. The script generates fake credit card numbers, expiration dates, etc. and repeatedly hits the phishing site's form dumping in random info.

    Any halfway intelligent phisher would record the IP address of each submission and just dump all of mine when he saw there were bogus, but it makes me feel good that I at least wasted some of his time ;)

    --
    "People that quote themselves in their signatures bother me" - athakur999
    1. Re:Retribution by Anonymous Coward · · Score: 2, Funny

      Just think if Visa did this. Only instead of "fake", they use honeytokens: Cards which, once used, are immediately flagged. Black Helicopters swoop in and arrest the baddie. You know, like in that documentary "Enemy of the State".

    2. Re:Retribution by jarich · · Score: 3, Interesting
      I have a little PHP script that I use whenever I get a phishing email

      Come on... post the script!

    3. Re:Retribution by lukewarmfusion · · Score: 3, Interesting

      I wouldn't be surprised if law enforcement actually used this technique.

      Seriously, how hard is it to find a phishing site's servers and the owners? I forward links, emails w/headers, whois info (one guy had his real name, address, etc. in the whois for the domain!), etc. to the authorities any time I get the emails. If you can find the hosting company, server, etc. and track down the account owner, that might work.
      But if that information is false, giving them a valid account with a "honeytoken" like you describe would be a great way of continuing your search. It's more likely that the scammer has taken precautions on their hosting account than they will when they try to use the invalid account information.

    4. Re:Retribution by lheal · · Score: 4, Funny

      >You know, like in that
      >documentary "Enemy of the State".

      Yeah, I wish Time had put documentaries in their Top 100 films list. That one surely would have been right there.

      Did you notice how the mainstream media just ignored that, treating it like just another movie?

      I added another layer of foil to the bomb shelter after I saw it.

      --
      Raise your children as if you were teaching them to raise your grandchildren, because you are.
    5. Re:Retribution by Hao+Wu · · Score: 2, Insightful
      The script generates fake credit card numbers, expiration dates, etc. and repeatedly hits the phishing site's form dumping in random info.

      Another benefit- if the scammer tries using these fake credit cards, it's a major alarm bell to the banks. It could very well make them get caught and convicted.

      --
      I suggest you read Slashdot
    6. Re:Retribution by Raindance · · Score: 4, Informative

      Hah. Good idea.

      I hope you're giving the phishing sites numerically valid credit card numbers- essentially there's a checksum hidden in a card number. Phishers can screen out completely randomly generated card numbers because their checksum doesn't match.

      Here's a link to the algorithm*
      http://www.beachnet.com/~hstiles/cardtype.html

      Enjoy.

      *No, reverse-engineering the algorithm won't generate a valid card, but it'll generate a "not obviously invalid" card.

    7. Re:Retribution by athakur999 · · Score: 4, Informative

      There's not much to it. Here was the last one I used. In this case it was bank site asking for an ATM card number, PIN number, etc. Adapting it to other sites wouldn't be hard. The way I'm generating numbers would probably get rejected if you tried to use it for credit card numbers but this particular phishing script didn't seem to do any verification so I didn't bother...

      for ($i = 0; $i 100; $i++) {

      $ssn = sprintf("%03d%02d%04d", rand(100, 999), rand(0, 99), rand(0, 9999));
      $cardnumber = sprintf("%04d%04d%04d%04d", rand(0, 9999), rand(0, 9999), rand(0, 9999), rand(0, 9999));
      if (rand(0,1)) $cardnumber .= rand(0,9);

      $expmonth = sprintf("%02d", rand(1, 12));
      $expyear = rand(2005, 2011);
      $cardpin = sprintf("%04d", rand(0, 9999));

      for($len=10,$r1='';strlen($r1)$len;$r1.=chr(!mt_ ra nd(0,2)?
      mt_rand(48,57):(!mt_rand(0,1)?mt_rand(65 ,90):mt_ra nd
      (97,122))));

      for($len=10,$r2='';strlen($r2)$len;$r2.=chr(!mt_ ra nd(0,2)?
      mt_rand(48,57):(!mt_rand(0,1)?mt_rand(65 ,90):mt_ra nd
      (97,122))));

      $email = "{$r1}@{$r2}.com";

      echo "$ssn\n$cardnumber\n$expmonth\n$expyear\n$cardpin\ n$email\n";

      $ch = curl_init();
      curl_setopt($ch, CURLOPT_POST, 1);
      curl_setopt($ch, CURLOPT_POSTFIELDS, "ssn={$ssn}&cardnumber={$cardnumber}&expmonth={$ex pmonth}&expyear={$expyear}&cardpin=
      {$cardpin}&em ail={$email}&statement=&btnContinue0. x=64&btnContinue0.y=9");
      curl_setopt($ch, CURLOPT_URL, 'http://www.ewwf.ro/KeyBank/enroll.php');
      curl_se topt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.3) Gecko/20040929 Firefox/0.10
      ');
      curl_setopt($ch, CURLOPT_REFERER, 'http://www.marumitu.com/KeyBank/enroll_auth.html' );
      curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
      curl_setopt($ch, CURLOPT_HEADER, 1);
      curl_setopt($ch, CURLOPT_TIMEOUT, 300);
      $result=curl_exec($ch);
      curl_close($ch);

      }

      --
      "People that quote themselves in their signatures bother me" - athakur999
    8. Re:Retribution by serutan · · Score: 4, Informative

      I have a little PHP script that I use whenever I get a phishing email...

      Post it on Planet Source Code -- thousands of people could be using it tomorrow.

    9. Re:Retribution by Masa · · Score: 2, Interesting

      One question:

      What if you generate and submit a valid, existing, card number by accident?

    10. Re:Retribution by SteelV · · Score: 2, Interesting

      Wouldn't it be ironic if one of your randomly generated entries actually turned out to be a real person, with all the correct information, and he got it stolen because of that? Highly, highly unlikely, but interesting to think about.

    11. Re:Retribution by opec · · Score: 2, Insightful

      A bunch of places get really annoyed if you supply false CC information (or so they say).
      Just becareful that the generating false CC numbers don't get you in trouble


      Huh? Are you saying he should be careful to not annoy the scammers? That's the entire point of the exercise.

    12. Re:Retribution by straybullets · · Score: 2, Insightful

      Hmm, and if you try enough times you might even give them valid series of number/date/names ! John Smith will be soooo happy to he finds his account zeroed by your script !!

      --
      With that aggravating beauty, Lulu Walls.
  12. Be wary of... by xquark · · Score: 2, Informative

    The links these so-called vigilantes place on those de-faced sites saying:

    "link to the bank's real web site" ;)

    he he he he he he :D

    Regards

    Arash Partow

    ________________________________________________ __
    Be one who knows what they don't know,
    Instead of being one who knows not what they don't know,
    Thinking they know everything about all things.
    http://www.partow.net/

    --
    Arash Partow's Philosophy: Be a person who knows what they don't know, and not a person who doesn't know.
  13. Hacker Man! by clayasaurus · · Score: 5, Funny

    Hacker-man, Hacker-man
    Does whatever a hacker can
    pwns fake websites, any size
    Catches phishers, just like flies
    Look out! There goes the Hacker-man!

    Is he strong? Listen, Bud!
    He's got caffinated blood.
    Can he type from a chair?
    Take a look over there.
    Hey there, there sits the Hacker-man!

    In the chill of night,
    At the scene of the crime
    Like a streak of light
    He arrives just in time

    Hacker-man, Hacker-man
    Friendly neighborhood Hacker-man
    Wealth and fame, he's ignored
    Action is his reward

    To him, life is a great big bang-up
    Wherever there's a scam-up
    You'll find the Hacker-man!

  14. Reminds me of... by hoka · · Score: 2, Insightful

    a userfriendly comic where Pitr is upset at being spammed. He discovers that the mail servers are Linux and are inseucre. The next clip is of a guy behind a computer frowning at "su: user does not exist." Theres a followup comic where all of the spammers Internet Traffic are routed to Mars. "But Mars doesn't have any... oh." All this really means is that eventually phishers and scammers will get smarter and run TrustedBSD, OpenBSD, SELinux, or some other hardened variant using mainly static pages and highly developed systems. It's really a never ending battle.

    1. Re:Reminds me of... by Dachannien · · Score: 2, Informative

      All this really means is that eventually phishers and scammers will get smarter and run TrustedBSD, OpenBSD, SELinux, or some other hardened variant using mainly static pages and highly developed systems. It's really a never ending battle.

      According to a recent article, many phishing websites are run on already insecure systems that are hacked by the phishers. This is a "good" idea from their perspective, as it makes them harder to trace. However, in such cases, the only element of choice given to the phisher is whether or not to use that particular system. The only thing they can really do to counteract vigilantism is to patch the systems they hack into while leaving their own backdoors in place.

      You're definitely right, though, that if this vigilante trend picks up, the phishers will change methods in order to rip people off.

  15. Depends by Thu25245 · · Score: 2, Insightful

    Hacking into these legitimate companies doesn't do anything to hurt the scammers.

    If the vigilantes take down the scam site, then they may prevent some people from falling victim to it. It may not hurt the scammer, but it might protect the innocent.

    And, frankly, these "legitimate companies" should do more to prevent the use of their services for fraudulent purposes. Say, writing a script to search though the hosted material for the phrase "bank account" and flag any occurrences for human review.

    I can't say I approve of this behavior...but it might have a positive effect, as well.

  16. Re:Hmmmm by ergo98 · · Score: 5, Insightful

    Hacking into these legitimate companies doesn't do anything to hurt the scammers.

    ?

    You think that it doesn't hurt phishers when their "closer" is rendered inoperational? Maybe I'm wrong, but I'm going to bet that some phisher that used their botnet to send out millions of emails (losing a number of their bots in the process) is going to be pretty pissed when some whitehat knocks their server offline before all of the morons enter their username and password.

  17. Why didn't they create EFFECTIVE anti-phish system by iamcf13 · · Score: 2

    Instead of defacing websites?

    If they are smart and talented enough to break into a webserver, they could use those skills to set up some sort of clearinghouse for phish sites to avoid that could be done as some sort of proxy + RBL for phish sites. Better yet, program a web proxy program that does something simple:

    Compare the href tags in downloaded webpages with the displayed links. If the 'root' domains don't match, imbed a warning in the HTML page before it is sent to the browser for the user to see. The proxy could be programed to look out for spoofery involving internet giants like eBay PayPal and the like. Of course this could be construed as a copyright violation for modifying someone else's webpage (unless you happen to be Google with their Google Cache).

  18. Re:Report yourself to the authorites? by Adrilla · · Score: 5, Funny

    By the way, most comic book heroes are known as vigilantes

    Well most comic book heroes have great powers, or amazing tools and weapons and um...oh yeah...They Don't Exist!

    --

    "Plans are for fools! Oglethorpe, the plutonian (Aqua Teen Hunger Force)
  19. Vigilante activism by Anonymous Coward · · Score: 5, Interesting
    Speaking of vigilante activism

    #!/usr/bin/perl
    # This is a perl script I wrote to piss off the phishers. What this
    # script does is generate fake credit card numbers that look like real
    # credit card numbers. This way, I can add bogus information to
    # phishing sites that looks legitimate
    # License: Public domain
    sub verify {
    my($cardnum) = @_;
    my($a,$b,@cc);
    for($a = 0;$a < 16; $a++) {
    $cc[$a] = substr($cardnum,$a,1); }
    for($a = 0; $a < 16; $a+= 2) {
    $b = $cc[$a] * 2;
    if($b > 9) {
    $b -= 9;
    }
    $cc[$a] = $b;
    }
    $b = 0;
    for($a = 0 ; $a < 16; $a++) {
    $b += 0 + $cc[$a];
    }
    return $b % 10 == 0;
    }
    for(;;) {
    $d = "54"; # Some phishing sites only accept cards where the
    # first numbers look like they come from a bank
    # This looks like a generic US MasterCard number
    # (MasterCard is actually 5[1-5], but I'm too
    # lazy to make the second digit a random number
    # from 1 to 5)
    for($c = 2 ; $c < 16; $c++) {
    $d = $d . int(rand(10));
    }
    #print $d . "\n";
    if(verify($d) == 1) {
    print $d . "\n";
    sleep(1);
    }
    }

    1. Re:Vigilante activism by tfoudray · · Score: 2, Insightful

      Although this is a "neat trick to pull on phishers", what you don't realize is that if you do this, especially in an automated fashion like this, there is a chance (however small) that you'll hit someone's actual credit card numbers. It actually happens from time to time. call your bank for frequency on that. not too often, but it does happen.

      Moreover, most phishers have already obtained a company's credit card verification numbers, and can and will verify the numbers they get anyway. and I'm fairly certain that can be automated as well, anyway. Sure, you can take a couple of clock cycles. big deal.

  20. 2nd Amendment by lheal · · Score: 3, Funny

    I believe our Founding Fathers, well-versed in the technology of the day, said it best:

    A well regulated Militia, being necessary to the security of a free State, the right of the people to keep and bear Sploits, shall not be infringed.
    --
    Raise your children as if you were teaching them to raise your grandchildren, because you are.
  21. Easy way to get phishing sites closed down by tyagiUK · · Score: 4, Funny

    Hack the phishing server, fire up a torrent tracker and post a link to some US chart music or movie downloads. ref: http://yro.slashdot.org/article.pl?sid=05/05/25/22 6228&tid=95&tid=17

    That way, the FBI, RIAA, MPAA will all be round there in about 10 minutes flat.

    --
    Contribute to the online videogame encyclopedia: GamerWiki
  22. someone is biased against horses by MichaelGospatrick · · Score: 2, Funny
    So maybe it's not a posse of horsemen

    I take issue with this statement. Yes horses are not as popular as they once were, but that doesn't mean they are completely out of the picture. Why you automatically assume that everyone else subscribes to your horseless worldview, I have no idea.

    --
    My genetic programming website: http://www.helpmefigurethisout.com/
  23. The Real Truth by Le_Papet · · Score: 2, Funny

    'Warning - This was a Scam Site...If you would like to aid us in our future attacks on scam sites please enter your credit card number and expiration date in the fields provided below.'

  24. Re:Where are the authorities? by fnj · · Score: 3, Funny

    So where is the FBI and the DHS when you need them?

    Having a doughnut.

  25. Mod parent down by Anonymous Coward · · Score: 5, Funny

    Parent post is clearly a fake, it claims the code is Perl, but I could read and understand all of it.

  26. Hackers should know better. by Lally+Singh · · Score: 2, Insightful

    Problems like these should be solved by technology. The time and energy of talented hackers is wasted on vigilanteism. The digital world has new rules and new capabilities.

    Sorry, I know good engineering work is harder, much less exciting, and much less satisfying than hacking the enemy directly, but why play whack-a-mole when you can make them obsolete? Ok, enough ranting. I hope y'all had fun.

    --
    Care about electronic freedom? Consider donating to the EFF!
  27. Self policing society by mollog · · Score: 5, Interesting

    I see this as another example of the self-policing that goes on here on the internet. Slashdot is another example on several levels. For example, this forum provides a means for people to express their feelings about a variety of subjects. And this forum is not mob rule, we moderate each other, and we moderate the moderations. Inflammatory and extremist talk is not tolerated silently.

    On another level, Slashdot is the pulpit where the topic of freedom gets a lively and ongoing discussion. Freedom to use and create software, freedom to exchange ideas, data, tools, freedom of expression, etc., etc.

    The 'net is not quite the free-for-all that some believe. And this self-regulation, self-policing, self-examination that is already the norm, is proof of the responsibility and maturity of so many here who make the net what it is; a cool place now, and a thing of hope for the future. So the idea of people going out and disrupting bad behavior on the 'net is a virtual tradition. To me this is a very good sign.

    Let's continue working to keep the gummint's clumsy hands off the 'net. I know they made the net, but it has grown in size and importance because of public involvement.

    --
    Best regards.
    1. Re:Self policing society by DerekLyons · · Score: 5, Insightful
      I see this as another example of the self-policing that goes on here on the internet. Slashdot is another example on several levels. For example, this forum provides a means for people to express their feelings about a variety of subjects. And this forum is not mob rule, we moderate each other, and we moderate the moderations. Inflammatory and extremist talk is not tolerated silently.
      Only so long as the inflammatory and extremist talk isn't something disliked by the Slashdot Hivemind... If it is, inflammatory and extremist talk is *encouraged* where it's not outright rewarded.
      • For instance, in the recent article about 911 and Vonage, virtually every post supporting Vonage and calling the victim 'stupid' was modded *up*, whereas virtually every one criticizing Vonage for it's misleading marketing material was modded *down*.
      • In a recent article about militarizing space, virtually every article criticizing the Administration and misreading the various treaties was modded *up*, while pointers to correct interpretations of the treary was modded *down*.
      • In virtually every article about the Shuttle, posts praising Soyuz are modded *up*, and posts pointing out that it's not as safe as propoganda would have you believe is modded *down*.
      The same can be seen in any article about MicroSoft, SCO, and a vast variety of other topics.

      Slashdot is indeed ruled by a mob - a mob extremely intolerant of dissident views and facts that fail to meet it's fore-ordained conclusions.

      On another level, Slashdot is the pulpit where the topic of freedom gets a lively and ongoing discussion. Freedom to use and create software, freedom to exchange ideas, data, tools, freedom of expression, etc., etc.
      Certainly - If you define 'freedom' as 'I can do whatever the hell the I want without any restrictions or respect for other peoples rights, except maybe the people I agree with'. The same Slashdot that gets annoyed about GPL violations is the same Slashdot who openly espouses theft of *other peoples* IP.

      And that's the ultimate tragedy of vigilante justice - it's almost always represents the views of the 'men on white horses', not those of society.

      The 'net is not quite the free-for-all that some believe. And this self-regulation, self-policing, self-examination that is already the norm, is proof of the responsibility and maturity of so many here who make the net what it is; a cool place now, and a thing of hope for the future.
      It's almost utterly unregulated and unpoliced - except for very small corners. And virtually all of those small corners are intolerant of anything 'not them'. They aren't about freedom - they are about bigotry and isolationism.
    2. Re:Self policing society by FidelCatsro · · Score: 2, Insightful

      Yep, but like all things , there are alot of bent Coppers (as in corupt) .
      Mob rule follows the loudest idiot and it can be rather dangerous if unatended . Not that i disgree in principle with swift vigilante justice against phishers , its just it can get out of hand .

      --
      The only things certain in war are Propaganda and Death. You can never be sure which is which though
  28. "Old West Tactics" by Wyatt+Earp · · Score: 5, Informative

    I'm a Middle East (1917-1995) Historian by day and an Old West Historian by night.

    This really isn't an "Old West" tactic, but a tactic used in the United States, UK and other nations with a tradition of Common Law or the inclusion of extensive non-statutory law reflecting a consensus of centuries of judgements by working jurists.

    As times changed laws became codified and the power of the People to enforce the law were erodded in the United States and other countries.

    A Judge had to own 500 acres of land without debt on the land and they had the power to cherry pick what they wanted in terms of the law for the circumstances. Law then was terrible complicated, looking at a History of American Law by Lawrence M. Friedman shows that it's terrible complex and not nearly codified enough to just throw out a list of laws and punishments. Since the law on the frontier was often a copy/paste affair and made up by the Judges and not codified, a Judge had the power to make up laws. Like Evesdroping in 1808 or Droping a Dead Body into a River in 1821. Federal Judges started to go wild with common law crimes after U.S. V. Hudson and Goodwin in 1812.

    This case allowed a Federal Judge or define a crime and issue a punishment for it. Codification would stop this by defining what was a crime, and stop a Judge from making up a crime.

    A Posse wasn't normally a group of people acting as vigilanties, but a Posse is a group deputized by a Law Enforcment agent (Town Marshal, Sheriff, Federal Agent, etc) for a fixed duration or event since communities didn't have large standing forces.

    Some examples from an essay I found on the web a while back while researching the law in the 1860s

    Citizen's Arrest

    Students of the law should note that both a statutory and common law basis for a certain degree of "vigilante behavior" is well founded. Indeed, in an era of lawlessness it is important that readers be advised as to their lawful right to protect their communities, loved ones and themselves by making lawful citizens' arrests.

    First, what is an arrest?

    We can thank Black's Law Dictionary for a good definition: "The apprehending or detaining of a person in order to be forthcoming to answer an alleged or suspected crime." See Ex parte Sherwood, (29 Tex. App. 334, 15 S.W. 812).

    Historically, in Anglo Saxon law in medieval England citizen's arrests were an important part of community law enforcement. Sheriffs encouraged and relied upon active participation by able bodied persons in the towns and villages of their jurisdiction. From this legacy originated the concept of the posse comitatus which is a part of the United States legal tradition as well as the English. In medieval England, the right of private persons to make arrests was virtually identical to the right of a sheriff and constable to do so.

    A strong argument can be made that the right to make a citizen's arrest is a constitutionally protected right under the Ninth Amendment as its impact includes the individual's natural right to self preservation and the defense of the others. Indeed, the laws of citizens arrest appear to be predicated upon the effectiveness of the Second Amendment. Simply put, without firepower, people are less likely going to be able to make a citizen's arrest. A random sampling of the various states as well as the District of Columbia indicates that a citizen's arrest is valid when a public offense was committed in the presence of the arresting private citizen or when the arresting private citizen has a reasonable belief that the suspect has committed a felony, whether or not in the presence of the arresting citizen.

    District of Columbia Law 23- 582(b) reads as follows:
    (b) A private person may arrest another -
    (1) who he has probable cause to believe is committing in his presence -
    (A) a felony, or
    (B) an offense enumerated in section 23-581 (a)(2); or
    (2) in aid of a law enforcement officer or special policeman, or other person authorized by law to make a

    1. Re:"Old West Tactics" by videha · · Score: 3, Informative

      I think the term vigilante is not correct in this instance. From Encarta dictionary;

      law-enforcing citizen: somebody who punishes lawbreakers personally and illegally rather than relying on the legal authorities
      Microsoft® Encarta® Reference Library 2005. © 1993-2004 Microsoft Corporation. All rights reserved.

      This seems more like crime prevention. One would hope that the prevention of a crime, especially without causing harm, would be considered a duty.

      I would like to say "good work" to the whitehats.

  29. Well, that explains it all by pg110404 · · Score: 2, Funny

    Here I am, minding my own business, trying to protect people by setting up a very similar web site to their bank so I can "store" their credit card numbers for them, and some jackass goes and defaces my web site.

    I never felt so insulted in all my life. Well, then. If that's people's gratitude, I'll just stop that and if they lose their credit cards, they're on their own.

  30. I have an idea by iawix · · Score: 2, Insightful

    Could someone tell these guys to bring down all those Al Qaeda (and assorted copycats) websites with beheadings and terrorist messages on them?

    --
    FAA Certified Flight Instructor
  31. It was fake; here's the real one by rkuris · · Score: 3, Interesting

    #!/usr/bin/perl
    do {
    my ($cc, $sum) = '54' . (join '', (map { $_ = int rand 10 } (1..13))) . '0';
    foreach $digit (split //, $cc) { $sum += $digit; }
    foreach $digit (split /.(.)/, $cc) { $sum += $digit; }
    $cc =~ s/.$//;
    print $cc, 9 - ($sum % 10), "\n"
    } while (sleep 1);

    --
    Get rid of everything Micro and Soft: Buy Viagra and/or Linux
  32. Slippery slope not a valid argument? by TapeCutter · · Score: 2, Insightful

    From the second link in your google links...

    "This type of argument is by no means invariably fallacious, but the strength of the argument is inversely proportional to the number of steps between A and Z, and directly proportional to the causal strength of the connections between adjacent steps. If there are many intervening steps, and the causal connections between them are weak, or even unknown, then the resulting argument will be very weak, if not downright fallacious."

    ie: The strength of the slippery slope argument can be measured by calculating probability of (A leading to B) and (B leading to C) and (C Leading to...) Unless one of those probabilities is zero, it is a valid chain of logical reasoning.

    --
    And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
  33. Re:Old west? by Soybean47 · · Score: 2, Insightful

    "vigilance"

    You keep using that word. I do not think it means what you think it means.

  34. Yeah... by kikta · · Score: 4, Funny
    Inflammatory and extremist talk is not tolerated silently.
    ...it is duly modded up. ;-)
  35. Re:Phishing and organized crime by Tongo · · Score: 2, Funny

    Oh. My. God. We must stop that evil hydrogen NOW! Think of the children!!