The teens behind the Mirai botnet
spectrum.ieee.org
spectrum.ieee.org
This did not happen [1] as was documented here[2], here and here[3]. It spices up the story but in truth, one of local telcos was affected but they accounted for less than a third of Liberia's Internet traffic. The weekend-like Internet traffic seen on that day was because of a national holiday.
Additional source: I lived in Liberia during that time managing the local IXP.
[1] https://krebsonsecurity.com/2016/11/did-the-mirai-botnet-rea... [2] https://thehackernews.com/2016/11/ddos-attack-mirai-liberia.... [3] https://twitter.com/DougMadory/status/794592487159529472
Good to read a story where teen hackers get rehabilitated rather than heavily punished and pushed further into crime. That said, they don't really strike me as genius hackers. More just opportunistic and perpetually online.
Other teens convince themselves that some shoplifting, or car stealing, or drug dealing is "acceptable".
Why does the first group get a pass?
Rehabilitation is an excellent path, but removing consequences makes rehabilitation significantly less effective. It does not need to be either - or.
It also furthers an apparent divide of justice system, irrelevant if it does or does not exists.
This reminded me of a Wired article[1] from a few weeks back that argued that many of the kids using these services to DDoS their friends/rivals don't realize they're illegal—so federal agencies are taking out keyword ads to warn potential users:
> In fact, he and other members of [cybercrime-busting group] Big Pipes argue that most booter customers seem to believe—or convince themselves—that merely paying to use one of the services to knock out an adversary’s internet connection isn’t against the law, or at least isn’t an enforceable crime. When the UK’s National Crime Agency (NCA) ran a six-month Google advertising campaign in 2018 to intercept people seeking booter services and warn them about their illegality, Clayton’s research group found that attack traffic in the UK remained flat for those six months, while it increased at its usual pace in other countries.
> In the years since, law enforcement agencies seem to have learned from that experiment: The FBI now also buys similar Google advertisements to warn potential booter customers that paying for the services is a crime. The UK’s NCA, meanwhile, has not only launched new advertising campaigns but even run its own fake booter services to identify would-be customers and then send them warnings—sometimes even with in-person visits—about the consequences of paying for criminal DDOS attacks.
[1] https://www.wired.com/story/big-pipes-ddos-for-hire-fbi/ (For the relevant bits, scroll to the "Honeypots, Google Ads, Knock-and-Talks" section)
The FBI would be indicting them, not just warning them -- go to all that trouble of setting up a fake site, and then you just give up actually indicting them for their crime? What's even the point of that? That they didn't know it was a fake site is no defense, the FBI routinely, say, sells people fake bombs and then indicts them.
> Big Pipes’ Allison Nixon says she hopes that softer tactics like those can intercept would-be booter service operators early, before they start committing felonies: She’s found that most booter operators start as customers before launching their own service. But for people who aren’t dissuaded by those interventions, she says, Big Pipes and its partners at the FBI will still be watching them.
> “The hope is that this whole show of force will convince some of them to quit and get a real job,” Nixon says. “We want to send a message that there are people tracking you. There are people paying attention to you. We have our eyes on you, we might get you next. And it might not even be on Christmas.”
So the honeypots sound like a sort of catch-and-release strategy to scare kids before they start their own DDoS enterprises.
Besides, if something is illegal and there's a significant portion of offenders who are truly ignorant of its illegality, perhaps a new approach to education is needed, which this tactic also covers.
Maybe other organizations will take notes...
Education
The Mirai botnet had a very negative impact on game play for several servers, and I would argue it was the key factor in the demise of at least one of the servers simply because it rendered certain games unplayable.
I remember you had to use NukeNabber to block attacks to TCP port 139 IIRC.
It's not clear what you're talking about when you say "several servers" or "one of the servers". What servers are you referring to?
Granted, I'm also a little surprised that the FBI didn't just twist Google's arm about it, but who knows. Maybe Google did them a solid and doesn't actually charge for the ad space, or maybe the FBI is just trying to play nice since Google has plenty of federal contracts.
Just twist their arm? What does it mean for the FBI to twist Google's arm?
What I was trying to convey was that the FBI could have exerted some kind of pressure to get Google to run the anti-booter ads of their own volition instead of the FBI (presumably) buying the ads like anyone else would buy ads. I have no idea what that kind of pressure would entail cuz I don't work for the feds and couldn't say what their "do this or else" strategies are like, lol.
I think that you are making an assumption about how the FBI operates.
Surely it's obvious that by "pressure" I'm referring to the threat of some sort of nebulous legal-y action if Google didn't comply with [xyz request]. Is that not how law enforcement functions? (I'd be shocked if they were asking very nicely and offering to take Google out to dinner.)
Don't these botnet services run on compromised computer systems?
For L7 request floods - they spin up a few dozen machines and use open & private proxies to funnel http requests thru. Sometimes those proxies are misconfigured squid, sometimes it's private proxy services, sometimes it's compromised machines converted into proxies (which may be open or require auth / has been sold).
For L3/L4 amplification/reflection they're buying machines where they can spoof and using UDP amplification lists (other people's machines) to reflect off of (and obviously not getting permission to, etc.).
The fact that people think this is impressive is mind boggling to me
If anybody from ieee is reading this, I'd appreciate more of this type of content, maybe even longer format like you'd find on LRB.
DDoSing your own university and then disclosing publicly it is like going 140 mph in a 55 mph zone though.
https://twitter.com/scottjshapiro/status/1661465332832239618
When the news broke about the perpetrators behind Mirai and specifically the Dyn attack, I was shocked that such a high-impact attack originated from one of my classmates in the CS department.
Isn't that just a protection racket? I.e. extortion?
What makes a protocol outdated? I would argue that outdated protocols "bake in" outdated assumptions. The telnet protocol has a builtin assumption that the network is secure, while newer protocols for remote administration lack this assumption and assume an actively malicious network.
At this point anyone sane should question why he would add TLS and SASL to Telnet (and expect to find clients which would support those too) instead of slapping SSH.
It's like asking why anyone would consider a hand-operated drill outdated, since you can slap an electric motor on it.
The protocols and networks the internet runs on are ancient and inherently insecure and flaky, but nobody wants to invest in solutions. These attacks have gotten easier, not harder. So I hope these kind of attacks ramp up in intensity and severity to the point that the nation is crippled by some 15 year old anime nerd. Nothing else will get the government or private industry to take security seriously.
Edit: Forgot about American Kingpin. That's a more worthy successor.