Hacking Neighbor Pleads Guilty On Death Threats and Porn
wiredmikey writes "Another good reason to make sure your wireless is secured! 'Barry Vincent Ardolf of Blaine, Minnesota pleaded guilty to hacking into his neighbor's wireless Internet system and posing as the neighbor to make threats to kill the Vice President of the United States. Just two days into his federal trial in St. Paul, Ardolf stopped the trial to plead guilty. According to the US Department of Justice, in his plea agreement, Ardolf, 45 years-old, was indicted on June 23, 2010, admitted that in February of 2009, he hacked into his neighbor's wireless Internet connection and created multiple Yahoo.com email accounts in his neighbor's name." Ardolf's guilty plea included child porn possession, as well as the death threats.
First post! ...(from my neighbor's IP address; so mod him down, not me)
Some were yelling one thing, some another. Most of them had no idea what was going on or why they were there. Acts19:32
Death threats against the vice president, breaking into his neighbor's wireless... But no, he didn't stop there. Child porn.
I wonder if some company that has a wireless security technology hired this guy to make their product look necessary.
My blog: http://www.seebs.net/log/ --- My iPhone/iPad app: http://www.seebs.net/seebsfrac/
Addendum: How much legal headache did his neighbor go through before Ardolf was suspected? The article doesn't say
In all fairness, I live in Minnesota. I can vouch that there's just not much else to do around here in the winter.
There's a spot in User Info for World of Warcraft account names? Really?
The only thing I can think of is that the neighbor starts finding this suspicious stuff about them online. Calls the cops (or the cops call him) and then start pulling records off the wireless router.. Like you said the MAC address should be recorded. They may have been able to subpoena (or not, thanks patriot act) the local ISP's and start pulling mac addresses from the neighborhood.
lesson learned heh.
Connecting to a wireless router usually means obtaining IP settings via DHCP. In the process, the MAC address of your network adapter (which is supposed to unique) will be recorded on the router, at least for some period of time. Therefore, if you want to connect without leaving an obvious fingerprint pointing back to your computer, first modify the MAC address that your network card is putting out. On Windows machines, drivers often provide a way to specify your MAC address under the "advanced properties" of the adapter. On my Intel network adapter, for example, the setting is listed as "Locally Administered Address", and is undefined by default.
You might even spoof a specific make of network adapter by choosing an "Organizationally Unique Identifier" from the OUI Public Listing.
The neighbors suspected the guy right away. Fortunately, the investigators listened to the [innocent] neighbors and started looking at the real bad guy.
http://www.startribune.com/local/north/112080854.html?elr=KArks:DCiUHc3E7_V_nDaycUiD3aPc:_Yyc:aUoD3aPc:_2yc:a_ncyD_MDCiU
What I don't get is why so many folks let themselves uniquely be turned into raving lunatics about politics - especially given how important the issues are to them.
Because the law is fucking insane. For instance, we live in a country where it's considered an appropriate and measured response to throw someone in prison, and confiscate their home, for growing a plant that's some people disapprove of. How do you deal with that rationally?
If you have a mission, and that mission is important - you need to focus. Turning explosive (figuratively, or literally when you mix in religion) might seem a good way to get attention on something that is overlooked - but if you pay any attention to how political events turn out, it rarely has a positive net effect.
The problem is, nothing really has a positive effect. It's been a steady slide down towards authoritarian corporatism for all of my 30 years in this country. Every last tiny shred of hope has been crushed out of me. There is no chance for change besides another American Revolution. Unfortunately, I don't see it coming in my lifetime. All I can do is keep my head down and try not to get caught up in the machine. If anything, I'm surprised we haven't seen more people flip out. The situation definitely calls for it.
Give me Classic Slashdot or give me death!
Likely all his computer equipment confiscated for evidence, some good ol' police questioning (think how bad you would be treated if the police know you were downloading child porn) and of course his local reputation tainted by association with the case.
Of course once forensics failed to find corroborating evidence on his PC that he did the crimes, they would have immediately gone into 'this is a frame up' mode, and he would have been questioned further in regards to who would have a motive to having him arrested.
Until all the paper work is done, the 'I's dotted and the 'T's crossed, he will be without his computer gear, since it would be evidence in the case still.
WPA security is not rocket surgery! ;)
...
His threats against Biden had nothing to do with politics. Had it been McCain in office Palin would have gotten the death threat instead. It seems that he wanted revenge against his neighbors and was sane enough to understand that the local cops were worthless in matters of cyber crime and wanted to insure that semi-competent agents of the law got involved.
Dedicated Cthulhu Cultist since 4523 BC.
Find me a judge who'd consider this content secure and you might have a case. Sucks to be ignorant, doesn't it?
Dedicated Cthulhu Cultist since 4523 BC.
Don't be so quick. Many innocent people plead guilty because they've been poorly advised by a public defender. A plea of guilty doesn't mean the person was guilty. It means that a deal was offered and the suspect had no faith in his defense at trial.
Where does it say he had a public defender?
He'd refused a more favorable plea deal last summer, insisting on fighting the government's case against him. But after two days of trial -- including Thursday's testimony from expert witnesses who showed the elaborate means Ardolf used to harass and smear neighbors who'd once called the police on him -- he stopped denying what he had done.
"The reality of it became apparent to him that this was going to happen and he didn't want to perpetuate his own distress or the pain for the victims," Ardolf's lawyer, Seamus Mahoney, said Friday. Vengeful neighbor in Blaine pleads to Biden threat, hacking
Seamus Mahoney is a criminal defense attorney with a state-wide practice in Minnnesota.
Ardolf faces a potential maximum penalty of 20 years in prison on the distribution of child pornography charge, ten years on the possession of child pornography charge, five years on both the unauthorized access to a computer and the threats to the Vice President charges, and a mandatory two-year minimum prison sentence on each count of aggravated identity theft.
Ardolf, they told police, had picked up their 4-year-old son and kissed him.
So let me see if I get this straight. The max penalty for child porn possession is 10 years, and picking up a 4 year old and kissing him (presumably without the parent's consent) isn't even in the charges? Given that child porn has been extended to include images of adults who are portrayed as children and that he had inappropriate contact with a real child, that seems out of whack to me. Distribution of child porn is easier for me to understand being in the same ball park as inappropriate contact, but possession? And not even including inappropriate contact in the charges?
Maybe there is a good reason in this specific case that the articles don't cover, but this seems like a solid red flag to analyze the laws and make sure they are coded properly. This sounds like a pretty serious bug to me.
Stop-Prism.org: Opt Out of Surveillance
Unless you have the foresight to use a spoofer or - even better - use a throw-away USB wi-fi dongle, your MAC address will show up in the router's DHCP client log until the lease expires. Boom, headshot.
I just got forwarded this link by an associate of mine. I was surprised to find out this made slashdot... I was the "private investigator" that was hired to originally absolve the neighbor from sending the original emails which included the child porn to the lawfirm's partners. After seeing the pattern I thought I had a good chance to catch the hacker and the firm retained my services to go after him. The reasoning was that if we were to lock things down (remove the wireless and hardwire) that the person trying to get at the neighbor would find other avenues to get at him. We had a very reasonable honey pot that could produce honey sitting in front of us. I'm independent not working for any one other than my own company/myself or subcontracted for numerous firms around. I used a combination of wireshark and a few self custom written utilities to go after this guy. And no, these utilities are mine and are not for sale; sorry. I'm an engineer/analyst, security specialist, and developer with about 24 years of paid professional experience which really helps when you need to understand something then write a utility to provide it. His wireless was installed by qwest and used WEP as the base configuration (GASP). Whether or not this encryption should have been used or not, the sheer nature that there was some form of encryption did matter in the end. It is easy to hack WEP (and not too hard for WPA/WPA2 either...) but it is illegal to do so. This is one of the six charges he was charged with. From what I understand, if there was no encryption then it would have been a completely different case... It took months of watching the traffic, sifting through gigabytes of PCAP logs, to find what I was looking for. Once I found the smoking gun it was provided back to the FBI that validated what I found then issued a search warrant to go after the guy. The fact was that a MAC address was impossible to use so the firewall log only showed that rogue connections were being made. A single IP address was also impossible to use since that IP address was being assigned by the neighbor's DHCP server (dsl router). The FBI and Secret Service was not involved with the initial technical search nor could they be due to federal laws. Barry was a "certified ethical hacker" (CEH) which means that he knew the process and has been trained to run the proper utilities to hack. Not that this is mandatory, any kiddie can search on youtube to find out how to do this and just how easy it is. But he at least understood the concept of IP addressing. It turns out that he understood MAC addresses as well since he was changing his computer's NIC's MAC address on a regular basis. I don't know exactly what was found on Barry's computers once the FBI took over or how much (if any) additional child porn was pulled. I do know he found the previous neighbors (from another city) SSNs, their tax returns, and also copies of the current threatening letters on his computers. The other neighbor's around Barry's house were also broken into which made the argument of using a YAGI antennae an almost impossible feat due to the physical locations of the houses. All I know is that this guy had some serious issues and became "bitter" at the world that seemed to have started when his wife suddenly died about 10 years ago. There was a LOT to this case and it wasn't a simple slam dunk. We had a mountain of evidence that was racked up over a period of time. Each piece was necessary to prove/disprove methods and ownership. The worst part was getting the information in a form that the jury would understand. I firmly believe that our federal prosecutor had a good understanding (and took the time to understand) the technology behind it and created a very easily understood case without losing the intrigrity of the technology. Point is, no matter how good you think you are; there is always someone better (and the same goes for me as well). Stay white; its just not worth it.... This guy is looking at a possible 44 years in fed. Barry was offered a plea of 2 y