FBI Raids Texas ISP For Anonymous DDoS Info
jcombel writes with this link to The Smoking Gun, which says "As part of an international criminal probe into computer attacks launched this month against perceived corporate enemies of WikiLeaks, the FBI has raided a Texas business and seized a computer server that investigators believe was used to launch a massive electronic attack on PayPal."
Computerworld has a story, as well.
What could possibly go wrong?
http://www.newsweek.com/2010/12/21/interview-with-cyber-security-czar-howard-schmidt.html
White House cyber-security coordinator Howard Schmidt:
"We've seen over time street protests in cities that shut down traffic, and this is not dissimilar in the online world. There may be a disruption for a short period of time, but the bottom line is we continue to work to make sure that the impact is minimal."
It was a bloody IRC server that's all. It was used by LOIC to get targets, etc...
I'm sure they were scraping and recording all of the chat logs from each IRC channel that was used, and THOSE logs are the ones with the money info, like who was participating, or at least their IP at the time. Snatching the IRC servers themselves is relatively useless.
The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants.
I get the feeling we're about to see Weather Underground 2.0. FBI and friends rounding up subversives, cooking up various stories/evidence/results and both sides getting more and more serious until things go bad.
Anonymous will, I suggest, become the 21st century hippies once more and more tangential interests come aboard, and before you know it a few radical offshoot groups will take on the government in a serious way. Cyberthreats the like of government talk are bullshit, but people with technical knowhow and a bit of time can scuttle bureacracy gone bad, ala various leakings. I don't properly (beyond some scrapings of the history) know the who or what of 1969 onward and how right each side of the government-hippy fence was.. but I'm around for this fight, I'm a witnessing some disturbing trends that displease me greatly and can't say I side with the government being right.
In the cosmic irony department, the captcha for this post is "unfair".
So what?
So the donut swilling swine may've found a handful of Anonymous.
It still doesn't mean they can find their ass with both hands and a road map in a lit room.
Well that leaves only about a Legion and some left to round up. Good luck with that!
I predict heavy work for the admin nursing the FBI site. Anonymous seem to be grumpy about details like that.
use the fbi to do your dirty work
http://en.wikipedia.org/wiki/Joe_job
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
From the article:
"On December 9, PayPal investigators provided FBI agents with eight IP addresses that were hosting an “Anonymous” Internet Relay Chat (IRC) site that was being used to organize denial of service attacks."
How did paypal manage to figure this out when the FBI couldn't? It's not like the IRC servers were attacking paypal directly
In the process of lying about the REAL source of of these 8 addresses (probably an illegal wire tap), the FBI managed to make themselves look incompetent, instead of just untrustworthy
... the server did not actually send those TCP requests, but was hosting an IRC server. The flooding software allows the user to turn his computer in a voluntary "botnet member". The software then connects to a specific IRC server (can be changed easily in case the server goes out of commission), connects to a specific channel and then a bot in this channel responds to commands by the software and passes the IP address of the target.
This allows the masterminds behind the attacks to coordinate the computers effectively and paralyze sites with an instant flood of requests, instead of having each user configuring the software with a new target I.P. and having the load on the target increase gradually, making it easier to react.
DOS attacks can damage the economy and cost a people jobs and/or limit new job growth, these actions only hurt people. They belong behind bars.
So I'm assuming that we are going to see a probe by authorities into the "patriots" behind the wikileaks DDOS attacks next?
Shucks, paw, I goit meself one of dem Compooter Server wassits
"Computer Server". Sheesh - who writes this stuff?....
First mistake: They list the IP in the affadavit OUTSIDE of the logs twice as 72.9.153.42 instead of 72.9.153.142 as it should be. One could assume that they could have now raided the wrong server in Tailor Made's farm.
Second mistake: "root" is just an IRC nickname on AnonOPs, and this person does NOT have root access on the IRC server that was raid as falsely assumed in the affadavit. They have oper with override privileges, and that was what was logged. The raid on the server at Tailor Made Servers was made under false pretenses.
Third mistake: Those logs show... [Thu Dec 9 11:14:27 2010] - OVERRIDE: root(root@72.9.153.142) TOPIC #loic '!lazor default targethost=api.paypal.comsubsite=/ speed=3 threads=15 method=tcp wait=false random=true checked=false message=Good_night_paypal_Sweet_dreams_from_AnonOPs port=443 stop' ... if anyone here has looked at LOIC's topic parsing, there's two mistakes the FBI made there. The first is that there's no space between targethost=api.paypal.com and subsite=/. The second is that this person "root" is STOPPING the attacks by adding "stop" at the end of the topic. Unless they can show logs of this "root" person throwing "start" in the topic instead of stop, this person is doing exactly the opposite of "willingly and knowingly" executing commands to start a DDoS attack.
...PayPal isn't a bank.
Isn't it amazing that the FBI can get their arses into gear over Anonymous, while allowing thousands of other criminal operations to use US based servers without disturbance. I am constantly horrified by the number of malicious sites operating out of the mainland US that are clearly operating in plain sight.
Never email donotemail@WeAreSpammers.com
Anonymous guys should google an implementation of slowloris-over-Tor "XerXeS" like Th3j35t3r uses... (Yeah implementations are out there, do you think th3j35t3r wrote his tool by himself??? LOL)
Going over Tor hides the IP and doing this attack via multiple machines would make them a really nasty bunch of fuckers.
On the other hand maybe they should not do that. You see, one can easily prevent the "XerXeS" tool by just tarpitting multiple connections from a single IP. Or, better yet, tarpit all Tor exit node IPs. Then to hide oneself, the attacker would need multiple machines, essentially a botnet.
As for the former alternative. If you don't have TARPIT support, run: module-assistant auto-install xtables-addons-source
Then run: iptables -I INPUT -p tcp --syn --dport 80 -m connlimit --connlimit-above 5 -j TARPIT
Latter option left as an exercise for the reader. Tweaking connlimit-above left as an exercise to the reader :)
While a court-martial is taking place in America about those US Army thrill killers of innocents, an Australian Special Forces unit is undergoing a court-martial in Sydney -- having killed innocents, instead of the Taliban, due to "faulty intel" -- a commonly occurring event.
Polish soldiers in Afghanistan get hit with an IED, so they attack the nearest village, on the assumption the innocents there are the guilty party.
Meanwhile, we've noted that the USAF has obliterated how many Afghanistani wedding parties now (each one consisting of 70 to 90 plus people)?
War Criminal Obama, as with War Criminal Bush, hasn't pursued any of these war crimes and atrocities (excepting the one obvious one now involved in a court-martial at Ft. Lewis, Washington, USA.
Likewise, we observe the outrageious and humongous efforts (if only such efforts were ever expended to hunt down this Osama bin Laden fellow??????) to extradite Julian Assange of Wikileaks back to Gothenburg, Sweden, which just happens to be the location of Jeppesen Systems AB, a subsidiary of Boeing, and affiliated with Jeppesen Dataplan, better known as Boeing's Extreme Rendition Airlines --- how very convenient.
Also pertinent to this blog post, is that Narus, those pesky Narus boxes having been installed at switching centers and IXPs throughout North America as part of that "warrantless wiretapping"/T.I.A. criminal eavesdropping activities, is also owned by Boeing.
HACK THE PLANET
Atrocity Atrocity Atrocity Atrocity
Atrocity Atrocity Atrocity Atrocity
Come on!!! Who's With Me?
It's not just a meme, it's the description of how media control works.
Helpful Link to Tune for Singalong
http://www.youtube.com/watch?v=KMU0tzLwhbE
Unfortunately I have no mix skillz.
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
Blackboxing is what is used. Do you remember Echelon? Then changed the code name to Magic Lantern? After the FBI got rumbled?
I have the source code for the lot and might just modify it to pull an rm/rf*.* of /var/logs GUTMAN overwrite. So good luck with that.
Pray tell what version of Windows the box was running.
Or tell what software service was hacked by someone to a
bad end.
Does it get more interesting if the system involved
was a virtual machine running in such a way
that a backup picked up all the services and
law enforcement was unable to deny any further
services.
Truth is stranger than fiction, but it is because Fiction is obliged to stick to possibilities; Truth isn't. Mark Twain.