Former YouSendIt CEO pleads guilty to Web attack on his old company
latimesblogs.latimes.com
latimesblogs.latimes.com
He was arrested on criminal charges for running a simple benchmarking program? By the company he was formerly the CEO of?
This is patently ridiculous, and can only be a case of YouSendIt having some major grievances with him about something else, or some other kind of ulterior motive. It seems only reasonable that he was running apache benchmark for curiosity, not with any serious malicious intent, and is now being held on some trumped up charges concocted by people out to get him.
If anyone knows of an article that actually explains the relationship between YouSendIt and their former CEO, please link to it.
"Beginning in or about December 2008 and continuing through June 2009, Mr. Shaikh sent an ApacheBench computer code to YouSendIt’s servers. ApacheBench is a benchmarking program used for measuring the performance of computers known as web servers. ApacheBench was designed to determine the number of requests per second a server is capable of serving. By intentionally transmitting the ApacheBench program to YouSendIt’s servers, Mr. Shaikh was able to overwhelm the servers’ capabilities and render it unable to handle legitimate network traffic."
I have to think when they say "sent... to" they mean he directed the AB to make requests from YouSendIt's server, not that he posted it to the service. Otherwise the rest of the statement - "able to overwhelm the servers’ capabilities and render it unable to handle legitimate network traffic" - doesn't make any sense, unless someone can explain how simply transmitting the benchmark executable via the service somehow caused that.
(As someone else pointed out, he could have used AB to /post/ AB to the servers... but I don't see anything in these articles to necessarily support that... and it would seem like the payload is less interesting than the transmission method.)
In fact, the allegation doesn't really make sense, because as the former CTO, if he had really wanted to interfere with the company's ability to do business, you'd think he could have found much better ways to do so. Logging in and deleting the company's data, turning employees/investors against them, or writing negative articles about them would have had a far greater consequence on their business than running an apache benchmark program.
To be clear, I'm not claiming to know what happened; I'm just saying that this press release is a deeply one-sided view of the story, and that the situation smells funny.
He may have been taking a plea bargain out of fear of much worse?
This statement makes it clear how unfamiliar the FBI is with technology.
I reread the FBI's statement, and I'm not convinced that what you suggest is what they actually mean, however. Does yousendit actually work that way? Can I send someone an arbitrary executable referenced from an email and it actually runs?
$ ab -c 500 -n 1000000 http://example.com/some/resource/intensive/url
Amazing how many sites this kind of "attack" would take down. Most sites don't have any throttling in place to stop it.Wonder whatever happened to that ordeal
I agree with comments here that this is one of those 'these facts don't sound like the story in which they are presented' Given the timeline of his relationship with YouSendIt its possible he had a grudge against them, just speculation though.
What he did was something like this...
C:\Apache\bin\ab.exe -c 500 -n 5000000 -p ab.exe http://yousendit.com/send-it
Using ab.exe to POST the binary ab.exe over and over using the service (yousendit) which send file1 from user1 to user2.