Showing posts with label CYBERWARFARE. Show all posts
Showing posts with label CYBERWARFARE. Show all posts

Saturday, April 20, 2013

Richard Clarke: China's Cyberassault on America - WSJ.com

In justifying U.S. involvement in Libya, the Obama administration cited the "responsibility to protect" citizens of other countries when their governments engage in widespread violence against them. But in the realm of cyberspace, the administration is ignoring its primary responsibility to protect its own citizens when they are targeted for harm by a foreign government.

Senior U.S. officials know well that the government of China is systematically attacking the computer networks of the U.S. government and American corporations. Beijing is successfully stealing research and development, software source code, manufacturing know-how and government plans. In a global competition among knowledge-based economies, Chinese cyberoperations are eroding America's advantage.

The Chinese government indignantly denies these charges, claiming that the attackers are nongovernmental Chinese hackers, or other governments pretending to be China, or that the attacks are fictions generated by anti-Chinese elements in the United States. Experts in the U.S. and allied governments find these denials hard to believe.

Three years ago, the head of the British Security Service wrote to hundreds of corporate chief executive officers in the U.K. to advise them that their companies had in all probability been hacked by the government of China. Neither the FBI nor the Department of Homeland Security has issued such a notice to U.S. executives, but most corporate leaders already know it.

David Gothard

Some, like Google, have the courage to admit that they have been the victims of Chinese hacking. We now know that the "Aurora" attack (so named by the U.S. government because the English word appears in the attack software) against Google in 2009 also hit dozens of other information technology companies—allegedly including Adobe, Juniper and Cisco—seeking their source code. Aurora wasn't an isolated event. This month Google renewed its charge against China, noting that the Gmail accounts of senior U.S. officials had been compromised from a server in China. The targeting of specific U.S. officials is not something that a mere hacker gang could do.

The Aurora attacks were followed by systematic penetrations of one industry after another. In the so-called Night Dragon series, attackers apparently in China went after major oil and gas companies, not only in the U.S. but throughout the world. The German government claims that the personal computer of Chancellor Angela Merkel was hacked by the Chinese government. Australia has also claimed that its prime minister was targeted by Chinese hackers.

Recently the computer-security company RSA (a division of EMC) was penetrated by an intrusion which appears to have stolen the secret sauce behind the company's SecureID. That system is widely used to protect critical computer networks. And this month, the largest U.S. defense contractor, Lockheed, was subject to cyberespionage, apparently by someone using the stolen RSA data. Cyber criminals don't hack defense contractors—they go after banks and credit cards. Despite Beijing's public denials, this attack and many others have all the hallmarks of Chinese government operations.

In 2009, this newspaper reported that the control systems for the U.S. electric power grid had been hacked and secret openings created so that the attacker could get back in with ease. Far from denying the story, President Obama publicly stated that "cyber intruders have probed our electrical grid."

There is no money to steal on the electrical grid, nor is there any intelligence value that would justify cyber espionage: The only point to penetrating the grid's controls is to counter American military superiority by threatening to damage the underpinning of the U.S. economy. Chinese military strategists have written about how in this way a nation like China could gain an equal footing with the militarily superior United States.

What would we do if we discovered that Chinese explosives had been laid throughout our national electrical system? The public would demand a government response. If, however, the explosive is a digital bomb that could do even more damage, our response is apparently muted—especially from our government.

Congress hasn't passed a single piece of significant cybersecurity legislation. When the Chinese deny senior U.S. officials' claims (made in private) that Beijing is stealing terabytes of data in the U.S., Congress should not leave the American people in doubt. It should demand answers to basic questions:

What does the administration know about the role of the Chinese government in cyberattacks on public and private computer networks in the United States?

If there is widespread Chinese hacking of sensitive U.S. networks and critical infrastructure, what has the administration said about it to the Chinese government? Specifically, did President Obama raise concerns about these attacks with Chinese President Hu Jintao at the White House this spring?

Since defensive measures such as antivirus software and firewalls appear unable to stop the Chinese penetrations, does the administration have any plan to address these cyberattacks?

In private, U.S. officials admit that the government has no strategy to stop the Chinese cyberassault. Rather than defending American companies, the Pentagon seems focused on "active defense," by which it means offense. That cyberoffense might be employed if China were ever to launch a massive cyberwar on the U.S. But in the daily guerrilla cyberwar with China, our government is engaged in defending only its own networks. It is failing in its responsibility to protect the rest of America from Chinese cyberattack.

Mr. Clarke was a national security official in the White House for three presidents. He is chairman of Good Harbor Consulting, a security risk management consultancy for governments and corporations.

Posted from DailyDDoSe

Thursday, August 23, 2012

Obama faces delicate decisions as cyberattack fears rise

President Barack Ob, ... ] White House photo

At the height of the economic crisis in 2008, Saturday Night Live’s “Weekend Update” comedy news show rolled out the character Oscar Rogers as a faux financial commentator. His advice on how to restore the economy? “Fix it! It needs to be fixed! Now!”

Four years later, lawmakers are grappling with a cybercrisis, and despite rising concerns, legislative debates over how to secure U.S. networks and infrastructure have often resembled nothing so much as Oscar Rogers yelling “Fix it!”

Now, with Congress looking unlikely to act anytime soon to fix vulnerabilities in the nation’s computer systems that leave them open to cyberattacks, President Obama is weighing the pros and cons of using anexecutive order to do what Congress hasn’t.

Experts in government and industry alike report a tide of attacks aimed at stealing information from individuals, companies, and government agencies, potentially making a strong case for presidential action.

Further bolstering the case are warnings from top national-security officials that a catastrophic attack on a critical system like those that run energy grids or chemical plants could cause damage to the economy or even loss of life.

But Obama needs to consider his options carefully, because any unilateral steps could invite accusations from his critics of overstepping his authority. As the acrimonious debate over antipiracy legislation illustrated earlier this year, simmering Internet issues can easily explode.

In the final days before the August recess, the Senate hit an impasse on broad cybersecurity legislation that the White House and national-security and defense leaders support. The bill stalled after businesses and Republicans said the legislation would create burdensome regulations for industry without doing enough to shore up defenses against cyberattacks.

Top White House counterterrorism aide John Brennan said earlier this month that Obama was looking at the possibility of an executive order but that there is no decision yet.

Lee Hamilton, a Democratic former House member who sits on a board that advises the Homeland Security Department and who examined government security failures as cochair of the 9/11 Commission, said that Obama is right to consider moving forward on his own. He said the stalemate in Congress is a “serious breakdown” reminiscent of failures before the terrorist attacks on Sept. 11, 2001.

“The preference would be to work together with Congress, but the threat is serious enough that an executive order is in line,” he said. “There is certainly a lack of urgency in dealing with this, and it’s not a business-as-usual problem. Given the fact that Congress hasn’t acted, the president has the obligation to put together options to secure the country.”

While the debate in Congress largely broke down along party lines, some prominent Republicans support the cybersecurity standards backed by the White House.

Top national-security advisers for GOP presidential candidate Mitt Romney, such as former Homeland Security Secretary Michael Chertoff and former National Security Agency and Central Intelligence Agency chief Michal Hayden, differed with Republicans in Congress and publicly called for the Senate to pass provisions that have Obama’s support.

Romney campaign spokeswoman Andrea Saul declined to elaborate on the Republican candidate’s assertion that more needs to be done to secure American networks, or comment on whether he would favor using an executive order in the absence of legislation. But she reiterated Romney’s promise to make cybersecurity an early priority and didn’t rule out executive action. Romney's plan would require agencies to begin developing a new national cybersecurity strategy within the first 100 days of his administration. “Once the strategy is formulated he will determine how best it can be implemented,” Saul said in an e-mail.

Polls show that while Americans express concerns over cyberattacks, they, too, are divided over what should be done.

Separate surveys published by United Technologies/National Journal and The Washington Post over the summer found that a majority of Americans prefer that the government either not create standards for private companies, or keep any standards voluntary.

Backers of the White House’s proposals, however, say an executive order could add clarity to the debate and prove to skeptics that the government can play a greater role in protecting American networks without violating privacy or burdening private businesses.

“I think it’s hard to make things any messier than it was politically,” said James Lewis, an expert at the Center for Strategic and International Studies. “If done right, an executive order could help critics reconsider their arguments.”

That’s an analysis echoed by University of California (Berkeley) professor Steven Weber who said many people seem to be “sleepwalking” when it comes to the threat of cyberattacks. An executive order, he said, could reform cybersecurity policies before a catastrophic attack galvanizes public opinion.

An executive order could give Obama the chance to take a strong stand on a rising national-security concern while portraying Republicans in Congress as ditherers.

But an order is unlikely to accomplish all of the White House’s aims. It couldn’t hand DHS wider authority to ensure that certain private networks are secure. Nor could it entirely ease legal restrictions that prevent businesses from sharing threat information. Even policy changes for some federal network-security policies would likely need congressional action. Additionally, any action would need to avoid inciting privacy watchdogs who fear cybersecurity could be used as an excuse to undermine civil liberties.

And some analysts said the politics of an executive order could cut both ways for Obama. Presidents often win political debates that pit them against an unpopular Congress, especially one perceived as unable to do anything substantive, said Peter Feaver, a former National Security Council staffer during the Clinton and George W. Bush administrations. But if Obama were to take unilateral action, it would give his critics on the right an opening to paint him as an “imperial” president and to accuse him of saddling business with new regulations, Feaver said.

“In general, White Houses win in these fights with Congress, but this White House has played this card many times,” Feaver said. “This is an issue where there are bound to be unintended consequences and any cybersecurity measures will need a system to fix and update the provisions down the road. This administration has a hard sell assuring people to trust them to fix things later.”

Paul Rosenzweig, a consultant and visiting fellow at the conservative Heritage Foundation, said a cybersecurity executive order could play into both the “imperial presidency and do-nothing-Congress” narratives, but said he thinks there is a genuine possibility for a future compromise and unilateral action by Obama would do little to actually help secure private networks

http://m.nextgov.com/cio-briefing/2012/08/obama-faces-delicate-decisions-cybe...

Posted from DailyDDoSe

Sunday, July 1, 2012

Reality Bytes: CyberBusted 12/21/2010 Posted on Firetown.com

CyberBusted 12/21/2010 Posted on Firetown.com

FIRETOWN-- THIS IS YOU! I HOPE YOU ALL APPRECIATE THAT I WENT OUT ON A FUCKING LIMB TO PROTECT THE INTEGRITY OF THIS FORUM, BUT I WOULD LIKE AN APOLOGY FROM THE ADMINISTRATOR(S) OF THIS "CLOSED GROUP" AS TO WHY NOBODY RESPONDED [EXCEPT FROMMES- AND HE CAUSED EVEN MORE OF A MESS BY SUPPORTING YOU!]

@firetown URGENT log out of all accounts and change your pass... on Twitpic

MIKE-- I'M CALLING IT AS I SEE IT. IF YOU RUN THIS FORUM THAN YOU HAVE AN OBLIGATION TO PROTECT IT AND EACH OF US FOR SUPPORTING YOU BY GIVING US A SAFE PLACE TO SHARE IDEAS.


NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE.
ARE YOU A BLACK SHEEP OR A ASLEEP AT THE WHEEL? YOU HAD THE ABILITY TO CLEAR MY NAME AND PUT AN END TO THIS SITUATION BEFORE IT ESCALATED TO THIS POINT.SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY NOT ONLY CLEAR MY NAME BUT TO CONFIRM THAT YOU ALSO HAVE EVIDENCE TO PUT AN END TO DISINFO AGENTS AND PROVOCATEURS THEN YOU OWE IT TO EACH AND EVERY ONE OF US TO COME FORWARD.

I EXPECT YOU TO DO SOMETHING AND DO IT QUICKLY. REMOVE ANYONE WHO THREATENS THE SAFETY AND INTEGRITY OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? I HAVE BEEN ON WATCH NOW FOR WAY TOO FUCKING LONG WITH NO END IN SIGHT.

"FIRST THEY CAME FOR THE JEWS?"

WRONG!

FIRST THEY CAME FOR THE COMMUNISTS! [REF: NIEMOLLER]

WAKE THE FUCK UP.
HOW WOULD YOU FEEL IF YOU WERE ACCUSED OF NOT ONLY A CRIME, BUT BEING UNETHICAL AND DISLOYAL TO YOUR FOLLOWERS - WHICH BTW, YOU WERE!

WELL GUESS WHAT? I STEPPED UP FOR YOU AND YOU BETTER STEP UP TO THE FUCKING PLATE FOR THE REST OF US. WHEN DID YOU TURN INTO A GREY SHEEP? WAKE THE FUCK UP AND GET YOUR SHIT TOGETHER.

GET YOUR SHIT AND MY SHIT OUT OF THIS MESS BEFORE WE ALL GO DOWN WITH THIS SINKING SHIP.

I HAVE PAID DEARLY FOR BEING SO OUTSPOKEN AND DEDICATED IN MY SEARCH TO FIND A PLACE WHERE WE CAN CELEBRATE INDIVIDUAL FREEDOMS FREE FROM REPRESSIVE GOVERNMENT AND TOXIC PEOPLE.

I WOULD REALLY APPRECIATE A FUCKING ANSWER AS TO WHY WE ALLOW THIS KIND OF BULLSHIT TO CONTINUE? DON'T YOU GET IT... DIVIDE AND CONQUER.  [REF: COINTELPRO]

DIVIDED WE FAIL. 

FACE IT WE ARE NOT ON ANIMAL FARM-- WE ARE ON PLANET FUCKING PLUTO WHERE WE ARE TOO BUSY WATCHING THE MICKEY MOUSE CLUB INSTEAD OF OUR CHILDREN. [REF: THE CORPORATION]

WE ARE NOT ALL CREATED EQUAL. SOME ARE MORE EQUAL THAN OTHERS.  [REF: ORWELL, ANIMAL FARM]

SO WHEN I AM SENDING AN SOS FROM WHATEVER PLATFORM... THAN I DESERVE THE COURTESY OF SOMEONE TRYING TO DELIVER THE MESSAGE IN A LANGUAGE OR FORMAT THEY CAN UNDERSTAND. AND, TRYING TO SHOW SOME SUPPORT IN A LANGUAGE OR FORMAT THAT I CAN UNDERSTAND. [REF: #ONE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE. SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY TO BOTH CLEAR MY NAME AND PUT AN END TO THE SITUATION I EXPECT YOU DO IT AND QUICKLY REMOVE ANYONE WHO THE MEMBERS OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? PUT AN END TO DISINFO AGENTS AND PROVOCATEURS.

IF YOU WON'T DO IT FOR ME, DO IT FOR YOURSELF. IF NOT FOR YOURSELF THEN DO IT FOR THE WORLD. [REF: STEVIE NICKS TIMESPACE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

see for yourself!

no response. none.

Posted from DailyDDoSe

Friday, May 18, 2012

LulzSec, FBI, CIA, AntiSec, Sabu, AnonOps... Government Social Media Experiment Gone Horribly Wrong

Joseph K. Black

Social Media Experiment Gone Horribly Wrong

Mon Feb 28 04:46:25 CST 2011

 

Update: On October 31, 2011, Joseph K. Black was arrested by Nebraska police officers after a 35 minute car chase spanning four counties, during what was described as one of his psychotic episodes. For more details and the police reports, read all about it. In addition, a full criminal history on Black is available.


Given the inane amount of joseph black babble to come from Joseph K. Black via Facebook and Twitter in late January of 2011, we'll spare everyone a lot of the gory details and just post a few short examples of why Black will not only never obtain his dream job of National Cybersecurity Advisor, but will likely end up working the counter at a Runza near you some time in the near future, provided he doesn't end up in prison.

Simply put, Black has designs on being appointed "National Cybersecurity Advisor" by the Obama administration. While that in itself may be an admirable goal, Black seems to think that self-promotion, being top 10 on search results and outlandish claims through social media outlets will help his cause more than, say, actual experience and contributions to the security industry ("cyber" or otherwise). Moving into February, his big thing became some fictional "megacommunity" ("Google it!" he says) with imaginary ties to every government agency, big service provider and anything else that he fancies.

 

With his inability to use Twitter and Facebook correctly, posting everything three or four times, he betrays the notion that he is an expert at anything. Because really, Twitter is hard to figure out. According to Black, he is the Ben Roethlisberger of Cybersecurity, the Governor of Cyberspace, the King of Cyberspace, the John Wayne of Cyberspace, the Michael Jordan of Cybersecurity, the Smokey the Bear of Cybersecurity, the Captain of the Cool Kids and a Cybersecurity ROCKSTAR! We could cite dozens of examples of his general idiocy here, but a short few should paint a clear picture of the level of e-tard we're dealing with:

   
   

The @Gregory_D_Evans Twitter account summed it all up very nicely in one tweet:

It should be noted that before Black "went full retard" as mentioned above, Lyger did try to personally and privately contact Black twice via email to open a dialogue. Neither email was answered:

 

Whether he's just overzealous, delusional, a net-kook, or a simple troll, we're done with him. Desperate and irrelevant, Black has had his 15 minutes of notoriety (not "fame", as he probably thinks) and like all good trolls, his time too has passed. He isn't relevant enough to include on Errata: Charlatan, so he ended up here, on Postal: Asshats.

*PLONK* .. we'll leave you with this mess:

   
   
   

   
   

main page ATTRITION feedback


Posted via email from DailyDDoSe

Saturday, April 21, 2012

Anonymous - Operation Tennessee

Uploaded by BecomeAnonymous on Jun 23, 2011

Official Info Poster: http://www.tinyurl.com/TNPoster

More Propaganda: http://pastehtml.com/view/awzjuotfz.html

Recently, we have witnessed the oppressive hands of Tennessee, pass a bill which makes it a crime to post images that "cause emotional distress". Individuals who disobey this unconstitutional law would be sentenced to a year in jail or a large fine. This is a bold attempt to crush our freedom of speech, the first amendment.

By imposing this law on the people of Tennessee, you are denying their human rights. Anonymous criticizes and takes action against those who indulge in such behaviors. It has become clear what actions we must partake in, it is our moral obligation to defend the rights of others that we believe to be under threat.

Tennessee's bill makes it a crime to transmit images portraying content which may "frighten, intimidate, or cause emotional distress". The consequence is up to almost a year in jail or a $2500 fine. Tennessee recently also indulged in another oppressive legislation making it illegal to share content. Streaming one video or song could result in the same consequences of jail time and fines. While sharing software valued over $500 would result in a felony. This is Tennessee's attempt at abolishing your rights. Do not let them shackle your wrists and ankles, take action.

We are fond of those who have taken the conjectures of our operation into physical reality. A few of our members have expressed their disgust of the bill by implementing their thoughts on the state capitol building of Tennessee.

Remember, We Are Anonymous. We Are Legion. We do not forgive. We do not forget. Expect us.
Category:

Nonprofits & Activism
Tags:

operation
tennessee
anonymous
hackers
state
capital
vandalizim
please
support
ddos
dos
HBgary
operationtn
optn
operationtennessee
ryan
lulzsec
joepie91
commanderx
oporlando

Posted via email from DailyDDoSe

Monday, August 15, 2011

DailyDDoSe™ Psychotronic Assault August 15, 2011 4:44am by @ELyssaD™

This is an example of what I see on my computer on a daily basis. Many times my IP or cell signal gets jammed. I believe that the [X-files] may be involved ~ and published an article about Mossad and Israeli spies being used for covert ops in the United States. That may not have been such a good idea.
Category:

News & Politics
Tags:

* Psychotronic
* Weapons
*Mossad

Posted via email from Whistleblower

Friday, June 24, 2011

Arrest Puts Spotlight on Brazen Hacking Group LulzSec - NYTimes.com

June 23, 2011

Arrest Puts Spotlight on Brazen Hacking Group LulzSec

LONDON — As suspects go, Ryan Cleary did not look dangerous: a pale 19-year-old who looked five years younger, wearing a white skateboarding T-shirt and track pants, standing nervously in a courtroom here on Thursday.

But charges by the British police link Mr. Cleary to a hacking group called Lulz Security, or LulzSec, which has been on an Internet crime spree in recent weeks, attacking Web sites and computer networks including those of the United States Senate, the Central Intelligence Agency and Sony.

The British tabloids have been quick to cast Mr. Cleary as the young criminal mastermind behind LulzSec, calling him “Hack the Lad” in front-page headlines. His mother, Rita, has said her son is highly intelligent but has a history of mental illness, including agoraphobia. His lawyer, Ben Cooper, described Mr. Cleary as “a vulnerable young man.”

Though it is not clear how much notoriety he deserves, Mr. Cleary’s arrest has made him a focus of the public fascination with a wave of computer hacking cases, carried out by amorphous online collectives.

The police say Mr. Cleary is guilty of illegally using a computer to perform denial of service attacks — bombarding Web sites with so many automated messages that they shut down. They say his targets were organizations including the British Serious Organized Crime Agency.

In the hierarchy of computer hacking, the accusations against Mr. Cleary and the actions of LulzSec fall broadly into the category known as hacktivism. Hackers of this type are not motivated by money, but are mainly interested in protesting against or antagonizing their targets, or in showing off technical skills.

Hacktivists, according to computer security experts, are a different breed from mainstream cybercriminals, who seek financial gain. Such criminals, for example, manipulated Citigroup’s Web site to steal the personal information of credit card holders.

The third category, experts say, are warriors, either working in the “cybercommands” of governments like those of the United States and other countries, or for mercenary or terrorist groups. They defend computer networks, power grids and state secrets of their own country, while devising tactics to attack enemies.

Hacktivists tend to portray their activities as digital sit-ins, a form of protest. But security experts say their attacks often cause real damage to computer networks and financial losses. LulzSec has been more aggressive than most, and more brazen in its choice of targets.

“This is organized criminal activity that is typically distributed across many different countries,” said Mark Rasch, a former prosecutor in the Justice Department, who is director of security for CSC, a computer services company. “It’s a serious crime.”

On Thursday evening LulzSec released what it said were hundreds of internal documents from the Arizona Department of Public Safety, including material related to border patrol and counterterrorism operations. It said it was taking aim at the agency because of Arizona’s anti-immigrant policies. A Department of Public Safety spokesman, Capt. Steve Harrison, said the documents appeared to be authentic but were sensitive, not confidential.

Hacking has been a pursuit of mischievous young men — and they are nearly all men — since shortly after computers were invented. But the Internet made it an increasingly international pursuit. The intruders quickly became power users of online bulletin boards and Internet chat software, using those tools to communicate and organize activities.

“Hackers were among the first to figure out the benefits of social networking,” said Alan Brill, a senior managing director of Kroll, a security consulting firm.

The far-flung hacker networks present a formidable challenge for law enforcement. But in recent years, they and prosecutors have more and more formed their own international networks of communication, sharing information across borders. Mr. Cleary’s arrest, for example, involved cooperation between Scotland Yard and the F.B.I.

LulzSec, on a Twitter feed that it uses to communicate with more than 250,000 followers, has said that Mr. Cleary is “at best mildly associated with us.” The group did not respond to a Twitter message seeking comment for this article.

LulzSec, experts say, is a splinter group from Anonymous, another online hacking collective. Anonymous is best known for its attacks last year in support of WikiLeaks, led by Julian Assange. The group went after the Web sites of companies like MasterCard and PayPal, which had refused to process donations to WikiLeaks after it disclosed confidential diplomatic cables.

Earlier this year, said Barrett Brown, a former Anonymous activist, “some of the most prominent leaders and hackers broke off and are now LulzSec.”

The two hacker groups certainly strike different poses. LulzSec’s statements and its actions display a spirit of exuberant anarchic glee. Lulz, in essence, means mean-spirited laughter, and LulzSec’s Web site describes the group as “a small team of lulzy individuals who feel the drabness of the cybercommunity is a burden on what matters: fun.”

The group is strongly antagonistic to the media. When a TV journalist for Russia Today asked for an interview, she was told it would be granted only if she and her producer wore shoes on their heads and wrestled in mud while singing. They declined.

There seems to be far less glee in the Anonymous culture. In a YouTube video describing the group, a voice intones: “There is no control, no leadership, only influence. The influence of thought.” Later, the video adds that Anonymous’s actions have “brought justice to our world.”

LulzSec’s exploits have riled others in the hacker world who object to its activities, particularly exposure of personal information of innocent Internet users. Those people are now working to stop LulzSec by investigating its members’ identities and providing information to the F.B.I.

The core LulzSec group, according to Mr. Brown, the former Anonymous activist, numbers between five and 10. Mr. Brown said the members he had dealt with — known by online nicknames like Topiary and Sabu — are mostly men in their early 20s.

Mr. Brown said he had dealt with Mr. Cleary, and that he believed — contrary to LulzSec’s statement — that he was involved with the group. But a person involved with Anonymous, who declined to be named for fear of prosecution, said Mr. Cleary was peripheral.

On Thursday the court agreed to delay Mr. Cleary’s application for bail while police investigated.

Hacker networks and their activities are murky by design, said Bruce Schneier, chief security technology officer of the British company BT Group. LulzSec, Mr. Schneier said, “is a badge, a name you call each other if you’re one of the cool hacker kids now.”

Riva Richmond contributed from New York.

Posted via email from Whistleblower

Thursday, June 23, 2011

From Lulz to Global Espionage: The Age of the Cracker

From Lulz to Global Espionage: The Age of the Cracker


Tuesday, June 14, 2011



Scot Terban

Baed7cd90281d85b6943e9bf3cfc9fe0

It seems that 2011 is turning into the year of the cracker. Between Anonymous, Lulzsec, and the ongoing wave of espionage being carried out by nation states, we have begun to see just how serious a threat cracking really is.

Of course both of these groups of attacks  have greatly differing motives as well as means. Lulzsec, well, is doing it for the Lulz and the others such as nation states or criminal gangs, are doing it for political, financial, or personal gains.

In this post I will cover all three groups and their motives as well as means.

Lulzsec:

Lulzsec is a splinter group of Anonymous who for all intents and purposes, have decided to carry out raids on any and all sites that they feel need their attention. This could be simply a process of finding the lowest hanging fruit and exploiting it or, there may be some further agenda that they have yet to explain fully. So far though, we have the simple explanation of “They are doing it for the Lulz...”

Lulzsec really began their efforts with focusing their full attention on Sony Corp. Sony pissed them off by attempting to prosecute a coder/hacker/reverse engineer named GeoHotz. Geohotz managed to tinker with some Sony code and they went out of their way to try and destroy him.

It’d be one thing if he was being malicious, but Geohotz was not.. Instead Sony was. This caused a great backlash in the hacker community against Sony, and though they came to an agreement with Geohotz, Lulzsec decided they needed some attention.

After numerous attacks on Sony that netted Lulzsec much data and showed just how poor Sony was at protecting their client data, Lulzsec decided to take their show on the road so to speak. They began their new campaign with “The Lulz Boat” which set sail for #fail as they say.

Soon the Lulz were epic and the target scope began to open up. Lulzsec attacks began to show up on Pirate Bay as well as on pastebin where they would dump the data from their attacks and laugh at the targets poor security.

What once seemed to be revenge has now morphed into a free for all of potential piratical actions for unknown reasons by Lulzsec. Of late, they also seem to be profiting from their actions by donations of bitcoins as well as perhaps other help from the masses who enjoy their antics. It is hard to tell exactly what the agenda seems to be for Lulzsec as it is still evolving…

Meanwhile, their actions have risen the ire of not only the likes of Sony, but now the governments of the world as well as their law enforcement communities. Who knows how long it will be before they are collared or if they will be at all.

Nation State Actors:

The ‘Nation State Actors’ may well be the most sophisticated group here. Many of you likely have heard the term APT, and this group would be the core of the APT. Those nations that have the means to use assets at their disposal to make long term and concerted attacks against their targets. This is the real meaning of APT (Advanced Persistent Threats)

What we have seen in these last few months is either an escalation on their part, or, we are just now catching on to their attacks by actually paying attention to information security.

I am not sure which it is really, but, I lean toward there being more attacks as the programs developed by certain countries have solidified and spun up. As you have seen here, I have made much mention of China as being the culprit in many of the attacks recently. I stand by that assessment, but one must not forget other countries like Russia or Israel for APT attacks.

This all of course is just a natural progression from the old school espionage with physical assets in the field to a digital remote attack vector. As we have gotten wired, so has the espionage game.

In the case of the wired world, unfortunately, much of the security that would usually surround assets in the old days, are not put into place in the digital. Why is this? It could be a lack of understanding, or, it could also be that the technology has outpaced the security values that they require to protect the data within.

Either way, hacking/cracking has now become a tool of war as well as intelligence gathering. It’s just a fact of life today and unfortunately the vendors and users have not caught up on means to protect the assets properly.

Industrial Espionage:

This is where the APT, Lone crackers, Companies, and Nation States meet. All of these groups use hacking/cracking as a means to an end. In the case of nation states, they are often looking to steal IP from companies.

Often times that IP happens to be from defense contractors. This is a dual use type of technology both for war as well as any technology taken could further their own in many other ways.

In today’s world, you have all of these players using attacks to steal data for themselves, or their masters. The recent attacks on Lockheed are just this, APT attacks, likely by China engaged to steal IP on military hardware and technologies to augment their own and compete not only on the battlefield but also economically.

Other attacks are likely un-noticed and carried out by single aggressors or small teams that hire themselves out for this purpose. These are the civilian equivalent of the nation state spies and often can be contracted by nation states or other companies to carry out the work.

In fact, this has become a boutique niche for certain individuals and companies in the ‘private intelligence’ arena. For this type of actor, I suggest reading ‘Broker, Trader, Lawyer, Spy’

Criminal Gangs:

This brings me to the criminal gangs. These are most commonly from the Eastern Block (The former Soviet Union) and they too often work tacitly for the government. In the case of Russia, there is a large amount of governmental complicity with the gangs. This is because much of the Russian government is made up of Russian mob types or, are paid handsomely by them for complicity.

Much of the crimeware trojans out there are Russian (Ukraine) made and the money that they steal from their quick hits goes to the East. Just by looking at the news, you can see how many ATM skimming attacks have money mules hired by the Russians and how often the money makes its way there.

An interesting convergence here is also the connection between the Chinese in some cases and the Russians working together. There was a spate of Russian run botnets that had Chinese involvement as well as Russian servers/sites showing up in China recently.

With the synergy of the Russian and the Chinese malware makers working together, we will have a level of attacks that will only escalate as they learn from each other and perfect their methods.

Meanwhile, they are robbing places blind by stealing PII data to create identities with as well as just transferring large sums of money digitally from banks that lately seem to be getting off for not performing the due diligence of security on behalf of their clients.

When The Players All Meet:

It seems that in the end all of the players meet at the nexus of digital crime. Whether its stealing data for profit, or as an act of patriotism for a nation state, all of the players work within the same digital playground. As the technologies meet, so do the players and it is likely there will be bleeding together of means and opportunity.

In the case of Lulzsec, it has yet to be determined what they really are all about other than the laughs. As they were once a part of Anonymous, one might think they might have a political agenda, but they have said otherwise. However, some of their actions speak to a more political bent than anything else. The recent attack on the senate websites seems to belie at least some politics at play as they stated they didn’t like them very much.

More importantly though, it is the response by the nation states and their law enforcement groups that will be interesting. For groups like Lulzsec, they are now passing from the nuisance category into perceived enemies of the state. Once they start attacking government and military targets with their lulz, then they are likely to see a more hardened response from intelligence agencies as well as the likes of the FBI.

Once the laws and the enforcement agencies catch up with the technology, then we are going to see some interesting times…

K.

https://www.infosecisland.com/blogview/14414-From-Lulz-to-Global-Espionage-Th...

Posted via email from Whistleblower

Saturday, June 18, 2011

LulzSec Attacks CIA Website, Taunts The Jester

LulzSec Attacks CIA Website, Taunts The Jester


Thursday, June 16, 2011



Headlines

69dafe8b58066478aea48f3d0f384820

Reports indicate that the hacker collective known as LulzSec conducted a successful attack against a public-facing website of the Central Intelligence Agency on Wednesday.

LulzSec recently claimed responsibility for attacks against the U.S. Senate website and PBS, as well as for the hacking of networks belonging to the Atlanta chapter of FBI affiliate InfraGard. The group defaced the organization's website and exposed InfraGard's email database.

LulzSec claims to have also hacked Sony Pictures, Sony Entertainment and Sony BMG, compromising the data for over one million customers as well as gaining access to admin passwords, music "codes" and "coupons".

LulzSec also recently gained unauthorized access to the online networks belonging to Public Broadcasting System in protest of a Frontline documentary examining the whistleblower organization WikiLeaks and accused federal document leaker Bradley Manning.

The latest distributed denial of service (DDoS) attack, which caused periodic outages for the CIA site, was announced with a Twitter message from the group stating, "Tango down - cia.gov - for the lulz."

"Tango down" is the trademark Twitter message usually issued by anti-jihadi hacktivist The Jester when targeting a website with his XerXeS DoS tool. According to The Tech Herald, the use of The Jester's catch-phrase was a deliberate taunt.

The Jester replied in king by Tweeting, “Expect me. My silence is not an indication of weakness, as your mouth is an indication of yours,” and that “no comforting words from this point on. My silence previous, and forthcoming, is the anti-you.”

This could be the beginning of another clash of the hacktivists, as witnessed earlier this year. The Jester previously traded jabs for several months with members of the rogue hacker group Anonymous after the WikiLeaks takedown, with each threatening to undermine and expose the other's operations.

Strangely enough, they had a meeting of the minds when it came to their mutual disdain for the Westboro Baptist Church after Anonymous defaced one of the church's websites and The Jester maintained attacks on multiple WBC websites for several months earlier this year.

The Jester is known mostly for his repeated denial of service attacks on militant Jihadi websites (video),  a psy-ops campaign against Libyan loyalists, as well as his attack on the WikiLeaks website in late November that forced the organization to shuffle Internet hosting providers.

Stay tuned...

Posted via email from Whistleblower

LulzSec Attacks CIA Website, Taunts The Jester

LulzSec Attacks CIA Website, Taunts The Jester


Thursday, June 16, 2011



Headlines

69dafe8b58066478aea48f3d0f384820

Reports indicate that the hacker collective known as LulzSec conducted a successful attack against a public-facing website of the Central Intelligence Agency on Wednesday.

LulzSec recently claimed responsibility for attacks against the U.S. Senate website and PBS, as well as for the hacking of networks belonging to the Atlanta chapter of FBI affiliate InfraGard. The group defaced the organization's website and exposed InfraGard's email database.

LulzSec claims to have also hacked Sony Pictures, Sony Entertainment and Sony BMG, compromising the data for over one million customers as well as gaining access to admin passwords, music "codes" and "coupons".

LulzSec also recently gained unauthorized access to the online networks belonging to Public Broadcasting System in protest of a Frontline documentary examining the whistleblower organization WikiLeaks and accused federal document leaker Bradley Manning.

The latest distributed denial of service (DDoS) attack, which caused periodic outages for the CIA site, was announced with a Twitter message from the group stating, "Tango down - cia.gov - for the lulz."

"Tango down" is the trademark Twitter message usually issued by anti-jihadi hacktivist The Jester when targeting a website with his XerXeS DoS tool. According to The Tech Herald, the use of The Jester's catch-phrase was a deliberate taunt.

The Jester replied in king by Tweeting, “Expect me. My silence is not an indication of weakness, as your mouth is an indication of yours,” and that “no comforting words from this point on. My silence previous, and forthcoming, is the anti-you.”

This could be the beginning of another clash of the hacktivists, as witnessed earlier this year. The Jester previously traded jabs for several months with members of the rogue hacker group Anonymous after the WikiLeaks takedown, with each threatening to undermine and expose the other's operations.

Strangely enough, they had a meeting of the minds when it came to their mutual disdain for the Westboro Baptist Church after Anonymous defaced one of the church's websites and The Jester maintained attacks on multiple WBC websites for several months earlier this year.

The Jester is known mostly for his repeated denial of service attacks on militant Jihadi websites (video),  a psy-ops campaign against Libyan loyalists, as well as his attack on the WikiLeaks website in late November that forced the organization to shuffle Internet hosting providers.

Stay tuned...

Posted via email from Whistleblower

Sunday, June 12, 2011

Enemy Investigation: Semantical Reverse Engineering || Fravia+

Fravia's Anonymity Academy

Enemy tracking

2) Language patterns and the stalking tablet

(Fravia's semantical reverse engineering tricks)


~
Enemy tracking, a very difficult art, can be divided into stalking, reversing language patterns and luring. In order to stalk you need a deep knowledge of Usenet spamming (and war) techniques like flaming, trolling and crossposting. A good Fravia can moreover easily 'reconstruct' (part of) the snailtrail of his enemies and defeat their smoke curtains applying some easy semantical reverse engineering tricks. Finally the Fravia will lure his targets into the open web and identify it.
1) General stalking techniques
2) Reversing language patterns
3) General stalking techniques


Reversing language patterns

I have randomly taken from today post two snippets :-)
Now tell me, this one:

man..could ya pleeeeez send me ( if ya got it ) the Casmate crack ???  need the shit bad..gonna d/l the software directly form the casmate site..
And this one:
I subscribe to a very good service: LinkAlarm that periodically  checks the links on my pages (now well over 200 links). Do you use it?
have been written by the same person?

The answer is NO, they have been written by two different persons, but how can I be so sure? The language patterns differ, yet this could of course be intentional. You will know why, I believe, as soon as you have read the content of this page.
(*I have published it at the bottom, in reverse order, you'll check later :-)

Well, reversing language patterns seems to be something pretty new: I could not find much on the web. So I'll try to summarize, and slowly add in this page, what I have noticed experimentally until now. I'll also teach you

my own best stalking method: Fravia's stalking tablet (TM :-)
Please take note that in the following, as usual in our reversing tradition, with "target" I intend the person (and pseudo) you want to find more data about (and if possible his real identity)
There are many 'inconscious' characteristics in someone's writings and ramblings, and contraryly to what you may think, email comunication does indeed carry A LOT of clues that are as useful as theusual body language clues you costantly check when you comunicate physically with someone or all the clues given by your partner's voice when you are at the telephone.
Some of these clues are of linguistical, other of grammatical and others are of what I would call 'Internettical' type... with this I mean clues that neither voice nor paper printed comunication usually convoy.

Since we must start from somewhere, as first clue I would use the "gender" differences.
For gender here I do not mean that you can state if your target is a woman or a man (if you could it would be probably a pretty poor target :-)
I mean that you can state if your target uses 'male' or 'female' patterns in his communication... chances are that if he uses these patterns under one bogus identity, he'll use them under all other ones as well... :-)
Now, please, understand me correctly, because I do not want to be pulled into any useless 'gender style' discussion... and I know that many American friends are obsessed by this kind of crap (writing she/he and so on). So let's be clear: I have always been convinced that, apart from minor obvious physical differences, there is NO real difference between Women and Men, in all good or evil characteristics of our specie. Women can (and of course

should, with bona pace of all species of religious idiotical fundamentalists) drive, kill, write, love, play and fight as well as any man, and anyway there are so many women with male psychological characteristics and so many men with female psychological characteristics that I believe it does not make much sense to differenciate anything between the twin parts of our race.

Yet among the few physical differences cited above is the well known fact that women give birth to children, and this, added to society pressures, common tradition, biased instruction, television crap, advertisement conditioning, you name it, makes a LOT of almost inconscious differences and can actually give us the possibility of reversing (in part) the 'gender leaning' language patterns of our target.

In other words analysing usenet style emailings you may check if your target has a more "female" or a more "male" personality basing on the following:

The male style is characterized by adversariality: put-downs, strong often contentious assertions, lengthy and/or frequent postings, self-promotion, and sarcasm (not always witty).

The female-gendered style, in contrast, has two aspects which typically are found together: supportiveness and attenuation.

Male-targets use more coarse and abusive language and seem to change their opinions slightly less often than females-targets.

Female-targets send more messages explicitly referring to other members of the group than Male-targets.

Context differences certainly may obscure or speciously highlight your results. Always work cum grano salis. In the usual context of Internet discussion groups "normal" group psychology does not apply. Group membership on usenet is very large and members do not know all others in the group (especially if there are a large number of "lurkers", people who read messages but does not write responses and therefore are invisible inside the discussion).
Morever on Usenete the task is mostly not to produce a specific result, but rather to generate ideas and discuss them.

Male-gendered targets in discussion groups use language that a) states facts without personal ownership, b) challenges group members, c) calls for explicit action, d) is argumentative, e) uses coarse and abusive language, and f) attempt to indicates the members status.

Female-gendered targets in discussion groups use a language that a) self-discloses, b) states personal ownership of opinion, c) apologizes, d) asks questions, e) uses "we" pronouns, f) responds directly to others in the group, and g) seeks to prevent or alleviate tension or arguments.

Exactly as we have a male/female differenciation, there are MANY other 'sharp edges' that you can use to stalk your target, as you will see in my tablet below.

Keep in mind that computer conversation draws from features of both written and oral discourse and as such has a whole serie of linguistic and textual patterns:

Emphatic, Humorous, Informal.

Syntactic informality often takes the form of incomplete sentences and conversational cadences. For isntance

"Waitamoment!... what d'you mean?"; "Hmm, I see. . .";  "Mmm, no, no... I didn't mind it..."

The informal, conversational rhythm created by the "Hmm", "Mmm" and the ellipsis is clearly intended to evoke (although through written means)

spoken discourse. Similarly, , "Wouw", "Sigh", "Gulp" and "Gasp" are used occasionally to mimic vocalizations or paralinguistic features.

Another device used to mimic characteristics of speech is the textual indication of emphasis on words or phrases (present in many messages). For example, some targets OFTEN use capital letters to create the sense of oral emphasis, others *use asterisks*, others S P A C E S and some use the html tags, inside their emails, <u> for this same purpose </u>.

Such emphasis cannot be indicated in the written text using underlining or italics, obecause most protocols for exchanging electronic mail, don't support them yet (expect an explosion of clues as soon as colors will be commonly email exchanged :-)

All these clues depend from the alphanumeric characters of written text, that are used to evoke the emphasis of speech.

In some cases, exclamation points add oral emphasis, as in the subject line "No No! Flush it!!"

Yet there are also involontary clues:
A good stalker always takes note of how many exclamation points and how many question marks the target 'commonly' uses. There are many different patterns:
?
  ?           (space and question mark)
??
???
? ? ?      and so on
This is of course true also for commas, colons,semicolons , and (parenthesis ) that may or may not be spaced before the preceding word.
Another typical involontary clue is due to the 'typing habits' of your target. He may, for instance, often enough write 'inetresting' instead of 'interesting'; 'nuff' instead of 'enough', and so on and so on. This is of course pretty rare, yet it happens in less evident parts of the message. For instance, does your target break line
when he wants to substantiate a point? Does he write short or long sentences? Does he use tirets - like this - or rather parenthesis (like this)? And what about his emotycons? :-] is NOT :o)

Finally, does he write "i use" or "I use"? Often enough email is sent WITHOUT any automated spelling correction check whatsoever.

There are also 'comportamental" e-mail clues, for instance there are some email comments, on a thread, that at times clearly resemble those that occur in a face-to-face meeting, when a speaker turns towards and briefly addresses one of the individuals present, but without yielding the floor to that person: "What's your opinion about this, Brick?" "Hope to hear from Cal about this stuff!

This kind of attitude pattern can constitute a very STRONG clue when you try to identify a target.

Another example is when you suspect, examining the thread, the existence of private, backchannels between your target and somebody else.
Backchannels, on usenet, are nothing else than the electronic communication between two or more individuals

that is not sent to the group as a whole.
This can at times be evinced from the contexts. Such messages, like whispered side conversations in a meeting, involve concerns or strategies adopted by allies on particular issues.
In this cases you may try to find out which are the 'allies' and the 'reference points' of your target inside the group and attack from those sides.
You'll VERY FREQUENTLY find this when you stalk trolls (see
enemy.htm), because trolls are trollyng mostly IN ORDER to find and contact other trolls-savy.

Yet another 'comportamental' example is the interplay among MORE THAN ONE fictious identities. In Balif's example (see enemy.htm), you have seen how his target used a whole plethora of faked personalities in order to create a 'group' impression. Of course the more fictious identities you identify, the easier it is to see the common sharp edges they possess.

Thus the language of Usenet demonstrates several characteristics more typical of oral communication in an organizational setting, casual conversation or, rather, organized meetings.

In fact the syntax and word choice often evoke conversational informality, emphasis, rhythm, and even vocalizations. On the other hand, the messages may also evince characteristics of written discourse such as formal wording, careful composing and editing, and textual formatting.
A typical case is when there is a LIST of points

  • 1) inside
  • 2) your target's
  • 3) email
There is also at times an interesting evidence of patterns that are a distinctively characteristic of web interaction. Many messages display ascii graphic, typographical ascii jokes, signets and subject line humor, patterns also that are very unlikely in written and oral discourse. All such patterns ca be, at times, interesting clues.

These clues and patterns reflect both the capabilities of the web and the characteristics of the group. The interactivity of oral discourse is in fact supported and encouraged on Usenet by the ability to engage in rapid exchanges and to collect and respond to embedded excerpts of previous messages. At the same time the asynchronous nature of the web and the editing capabilities of the participants' email applications allow reflection and crafting patterns more characteristic of the written discourse. The web's ability to support informal textual exchanges allow a playful relationship with the text, or to indulge in flaming.

Of course all sort of interaction, the characteristics of the individual targets, their social community, and their motherlanguage influence the particular combination of linguistic and textual characteristics that they express.

Do not underestimate the richness and complexity of email communication... as soon as you'll have learned your stalking abc you'll never miss much all the clues that the real, non virtual world gives you when you communicate.


Now have a look at the semplified version of Fravia's stalking tablet (TM):

Fravia's stalking tablet, public version 2.003, end july 1998
Target name: enemy@somewhere.com      Candidate: sillybozo@that.one
Clue Definition Example Target Candidate
TICS measure whether or not the message body gives clues about frequent typing mistakes/particularities of the author: 0 = no, 1 = yes. "inetresting enough" "'nuff said" "gimme a note" "least, but not last"
SELF verbal self-disclosure, statements by the author of the message about the author of the message: 0 = no 1=yes. "I'll trade ya shit", "I still like Netscape", "I'm an email junkie", "My hair is black" but not "My mother's hair is black" or "My cat is black"
GRAMMAR measure whether or not the message body gives clues about the education of the author: 0 = no, 1 = yes. "the distinction between amateur and professional" "I gave him an acknowledging e-mail wave and he answered in kind " "an unjustifiable extravagance"
OPINION measure statements of the personal opinion of the message author; it had to indicate the first person directly or indirectly. 0 = no opinion was present, 1 = opinion was present. "I think lusers should be banned", "Chocolate is a favorite flavor of mine", "I love lollypops".
FACT measure statement of fact (whether or not the fact was correct), without first person reference to the message sender: 0 = no statement of fact, 1 = one or more statements of fact. "God has created the earth and Winsconsin." "The government is loaded with freeloaders." "Communists rule." But not "according to me"
KNOWLE measure whether or not the message body gives clues about the level of computer/internet knwoledge of the author: 0 = no, 1 = yes. "operands which are addresses will get added the image base of the DLL" "get a trowaway account at any third-party service provider so as to throw a bulk mailbomb past his first line blocks. The account will cease to exist in short order, but you'll have already tested his precious defending bots"
BIAS measure whether or not the message body gives clues about characteristical idiosyncrasies of the author: 0 = no, 1 = yes. "women always make the best trollees as they have a logical reasoning capacity of zilch" "the mark of a gullible American that will almost certainly believe anything you tell him"
APOLOGY measure any form of apology (implied or direct): 0 = no apology present; 1=slight apology; 2 = clear apology. "I wanted to apologize" "I am sorry I said what I said", "I take my words back", "please accept my apologies."
QUESTION measure the presence of questions: 0 = no, 1 = yes. "How can I ban him from this group?", "Where can I find Softice?."
ACTION measure any call for action on the part of the reader: 0 = no, 1 = main content of the message. "Visit this URL" "Write your congressman." "Go see this movie."
CHALLENGE measure the presence of a challenge, dare, or bet: 0 = no, 1 = yes. "Demonstrate that you can hack that backdoor!" "I challenge you to support that statement." "Let's see if you can do that."
FOREIGN measure whether or not the message body gives clues about the mother language of the author: 0 = no, 1 = yes. "what the cuckoo are you saying?" (german) "I am conscient " (french) "Settember" (italian)
COALIT1 measure degree of agreement or disagreement with another person or statement previously appearing in the group discussion. 0 = no reference to another person's message, 1 = mild response to other persons on the group, 2 = strong response to other persons on the group. "I really agree with Bertie." "I think Bertie and Godzill's ideas suck."
COALIT2 measure the use of the first person plural pronouns (we, us) towards others on the group 0 = no, 1 = yes. "We are dealing with a DLL here" "We seem to be able to takle these guys well." "Good for us!"
FLAME1 measure levels of argumentativeness of a message: 1 = positive, neutral or no opinion to 6 = hostile: profanity, tirades, to 10 = ignoring completely the original issue. "I have to take issue with you on that one." "Only a real dork would hack such a stupid server."
FLAME2 measure levels of the use of coarse or abusive language in a message: 0 = no abusive language to 10 = abusive aggression about content and persons in and out of the group. "I can only say that you must be a real asshole." "F*uck you." "You sure do go to great lengths to make yourself looking like an asshole."
FLAME3 measure efforts to prevent or alleviate tensions or arguments in the discussion: 0 = no such efforts, 1 = tries to calm ongoing tension. "I think things are getting out of hand here. Let's cool the tirades and get back to the point."
STATUS measure whether or not the message body or header give clues about the personal status of the author: 0 = no, 1 = yes. "WarezDood" "mwr (Master "white" Fravia)" "Sysop" "ThATVerYSpEcia1Dudez" "Administrative contact: "
TIME measure the reliability of email timings: 0 = no statement possible, 10 = target always emails at 15:00 GMT See headers
GEOGRA measure the reliability of geographical clues: 0 = no statement possible, 10 = target lives in Indianapolis "July is really pretty hot this year!" (northern emisphere); "I had to call the Landrat" (Germany/Austria) "No kidding? Here in Detroit?"

Gotcha! (0=FALSE 1=TRUE)

I don't think it needs a lot of explanations, keep in mind that the PURPOSE of the above tablet is not so much to understand directly WHO is your target, but to understand if your target is in reality the one candidate you suspect. Once you have zeroed in, you'll stalk the (presumibly less protected) other PSEUDO in order to find out -if all works well- WHO is your target... and some luring techniques (and social engineering) will at that moment be quite useful, see my luring.htm section...


A word of warning:


You found my site and you are reading this, therefore you have now a relatively "high" level of web-lore and reversing knowledge.
Until recently I kept this section of mine in a "closed" server with other mildly powerful and potentially dangerous tutorials and tools. I am now going public with my stalking lore because spamming has taken incredibly annoying proportions and I have decided to create as many powerful Fravias as possible in order to tackle and destroy the commercial idiots.

Yet, as you perfectly know, knowledge can be used either for good or for evil. Knowledge, especially this kind of knowledge, is a powerful weapon. You may use it to defend yourself but you may

not use it to offend innocents
I hope to have you at my side, fighting on the web for knowledge and against all commercial zombies, but I cannot avoid that you join the dark side if you want to... if you do, however, take care not to meet me.

This section of my site, under perennial construction, was started on 31 July 1998
red1) general stalking red3) luring
redFravia's antispam related page
redhomepage redlinks red+ORC redbots wars redstudents' essays redcounter measures
redbots wars redantismut CGI tricks redacademy database redtools redjavascript tricks
redcocktails redsearch_forms redmail_Fravia
redIs software reverse engineering illegal?

red(c) Fravia, 1995, 1996, 1997, 1998. All rights reserved

*) Answer to the 'two snippets' question... Hey! Try to find the solution by yourself BEFORE reading the following!
decaps era teppins tsrif eht fo kram noitseuq dna sisehtnerap eht

Posted via email from Whistleblower