Texas Man Pleads Guilty To Building Botnet-For-Hire
Julie188 writes "A Mesquite, Texas, man is set to plead guilty to training his 22,000-PC botnet on a local ISP — just to show off its firepower to a potential customer. David Anthony Edwards will plead guilty to charges that he and another man, Thomas James Frederick Smith, built a custom botnet, called Nettick, which they then tried to sell to cybercriminals at the rate of US$0.15 per infected computer, according to court documents."
I hope they get charged with 1 count per infected PC - and screw concurrent sentencing.
Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
With the script-kiddie-ization of viruses, I'm surprised we aren't hearing more about these small time thugs getting caught. Perhaps it just needs more time to catch on.
At just .15 per bot, this confirms that the economic downturn has affected the bot trade as well.
No stimulus package in sight. I'm holding on to my bots till the rebound.
That's, like, US $3300 for the lot. He's not going to get much hookers and blow outta that.
If he did any programming at all to develop the exploit, then his wages are in the basement. (Probably right next to his 'office'.) Once you factor in the time it would have taken to propagate, test and market the botnet, this guy stood to earning the merest pittance.
Then again, he was stupid enough to turn the thing on his own ISP, so we shouldn't marvel too much over his lack of business acumen.
Crumb's Corollary: Never bring a knife to a bun fight.
"Now witness the power of this fully armed and operational botnet."
Don't perform cybercrime in the borders of the USA.
God spoke to me.
It seems very interesting that they were able to do this, but limited the botnet to the local ISP. In TFA they also state they "attacked" a Planet hosted server but didn't say if it was a DDOS or what. (The Planet is one of the bigger north texas hosters/data centers, I got to have a personal tour there once while working on building a data center elsewhere, they are very professional) and TFA later states they comprimised another website. What confuses me is that most botnets are installed via some sort of social engineering, be it XSS, email spam, etc. But it seems that since they were able to build it in such a short time on such a targeted demographic, that it falls closer into the spectrum of a Storm style botnet, that uses DDOS as both attack and defense. But regarding that I also don't understand the compromises of the website via a large scale like that, usually a DDOS is just that, a denial of service, if there is a vulnerability what is the use of an entire botnet? Maybe used to brute force something, or obfuscate multiple scans of vulns, but overall it seems like this was someone who stood on the shoulders of other botnet writers (would be interesting to reverse engineer the code and see) in order to make a quick buck (which is easy to do on IRC's underbellies) Anyone who pays attention at all to botnet or other malicious writers knows that if attention is directed to your code, it's fairly easy to track you down. It is also notable that this happened in 2006, and so it took this long for law enforcement to build a good enough case against them. Anyway, interesting at least to me, as I've been training up on computer forensics so its interesting to look at things like this.
"It's ok, I'm completely secure as long as my iron is off"
I live in Texas. Right outside of Houston, to be specific.
Credentials established, let me state this for the record : Mesquite is one of those towns you go "I fucking slowed down for this?" while passing through.
The pieces now fall into place.
PC moderators can suck my White pierced, tattooed dick. If you think pride == hate, s/dick/Aryan meat mallet/g.
That's the same as 0.15 cents. That's cheap!
I was one of the ircers on kidindustries.net when we were most active back in 2005. I knew both Zook and Davus and had also read the Nettick source code. It was written in Visual Basic and integrated into software which served the purpose of altering Habbo Hotel and then downloaded and spread. I remember the T35 hack, there were some cc's in there. Questions?
Obligatory free software rant: I bet he didn't even consider making his software free.... and then
I hadn't the slightest objection to his spending his time planning massacres for the bourgeoisie... (P.G. Wodehouse)
Have you grown up yet?
The attempted sales price (U$0.15/machine, would presumably be negotiated down 0.10-0.12) is ~100x less than users would pay to not be infected, and about 1000x less than it will take to remove the malware. Any person who buys and uses the botnet will generate similar economics.
This is an obvious clear loss to humanity -- the crooks gain _very_ much less than the damage they cause. A negative sum game.
The same might be said of Goldman-Sachs: even without the front-running and counter-dealing, they mispriced risk for short-term gain. They and their ilk (GS was probably one of the least-bad) caused much damage (more to come) without net gain. Their deals were at best zero-sum minus their hefty fees but with huge amounts of hidden risk (which comes home to roost).
He's from Texas, so Net-Hick would be more appropriate.
I think this is a clever bot post. I saw another posting for this Bol Apartments in another thread and the text in the body is identical to http://it.slashdot.org/comments.pl?sid=1635012&cid=32027656.
Looks like the captchas need to be updated.
That should be the punishment -- fry, fry, fry. I know what the smoker should be.
Infuriate left and right
Ukraine botnet build YOU !
Yours In Astrakhan,
Kilgore T.
http://www.youtube.com/watch?v=D2isSJKntbg
According to Verizon rep, 0.002 dollar = 0.002 cent. So your parent is right.
New Economic Perspectives
I mean, like 3 first names.
Oh,wait...
WARNING: Smartphones have side effects--most of them undocumented.