Hacker infects 18,000 "script kiddies" with fake malware builder
bleepingcomputer.com
bleepingcomputer.com
When I was much younger I looked up to a game cheats writer on an old forum since he taught me about how they worked, which I found extremely cool (still do!). It actually formed my initial interest in security.
I asked if I could help somehow, as all young, eager noobs at the time did, and to my surprise he said yes. He wanted to track the licenses he sold to which accounts via IRC. The game would boot, hacks get injected, hacks connected to IRC and would interact with an mIRC bot to check them on his own machine. That was my first foray into socket programming and protocols, too.
A while after that, I learned my code had been shared with another cheats maker (not itself a problem for me) when I was contacted to add DCC SEND support, which allowed sending files via IRC. I don't remember if I came to the conclusion myself or if it was explicitly stated, but either way, the objective was clear, and I refused. I felt bad, had learned my lesson, and never contributed to that scene again.
That was in ca. 2006 or so. This has been going on for a long, long time.
This thread is such a solid shot of nostalgia, and why I love HN.
Then when the guys who were taking a break started watching him, they saw that he was tracking players as they went across the other side of the map, and his gun was firing as soon as they were in view. Headshots every time.
It blew my mind for two reasons.
1. It was possible.
2. This was a party with zero point of winning. There was no prize. Why cheat?
I modified it to run the "solve answer" method without reporting back to the server at a random interval that was just human enough, and played Minecraft in the meantime.
In my defense, I knew the material just fine. The program was very anal about whitespace, parenthesis, order of terms (even if it was inconsequential), so most of the homework time was spent fighting with it instead of testing my math skill. The grade for it was also pass fail, whereas the tests were what mattered (and I dared not cheat on those).
Ended up learning a valuable skill at the same time, so I still consider it a win.
I had my own stint doing this type of stuff on my different schools networks growing up and it too spawned an interest that’s led me to an entire career.
You shouldn’t feel bad - you learned, you got your kicks, and developed a conscious once you knew better. If dealing with some hacks in some of the games I played meant some curious kid got their start with programming it was well worth it.
What does piss me off are the people who turn it into a living to the extent where it becomes a plague - Warzone is a perfect example. Sure, the game still makes money, but the actual “scene” is fed up with it. I get that these same type of people/hacks are what you may have briefly been a part of, but it’s still not the same thing.
A kid contributing for fun is different than orchestrating the entire thing.
My take on it at least.
I don't know how any software houses made money with the floppy copy scene in the 80s.
Like back when all you had to do to get banned software to run on your school’s computer was rename the executable to notepad.exe - I’ll be damned if I didn’t feel like neo in the matrix at the time
They never discovered the rats we actually had installed on all their computers. They were still there years after I left, until they upgraded the computers.
We (a few friends and I) were basically the Novell Netware admins because our school didn't have a full-time computer tech and none of the teachers knew anything about it. We convinced them to let us help them in exchange for letting us read the manuals and tinker around, and we actually did help with problems and troubleshooting, mostly printing if I remember.
They never figured out it meant we also had access to the teacher-only folders though.
Back when I was a highschool freshman (2004-05) I wrote a batch script that would fire off net sends to everyone in the computer lab in rapid succession in an infinite loop, then just sort of left it on a shared drive with a conspicuous name. Sure enough, a few days later, someone ran it out of curiosity and got in trouble, but of course the file had my username in the metadata, and my computer teacher was like “Chris, you knew what you were doing, don’t do this again.”
It was the kind of “good clean fun” sort of prank that doesn’t get you in hot water or suspended, but was hilarious to watch play out.
Edit: Just re-read and saw that your friend got expelled for doing basically the same thing I did. That sucks. I’ll note that I went to an IT-focused votech school, so I think a lot of folks had a better sense of perspective as to how serious net send pranks actually were in the grand scheme of things.
We just used it for a place to run scorched earth from on the whole network without having to download it to our home folders where it'd get noticed and punished
My fixed version also had the handy feature of having a 50% chance of wiping the user's entire drive if they actually used it as part of a DDoS.
It was pleasingly brutal. First it would zero out and delete all files in the user's home directory, and then if it had access to the hard disk device it would overwrite the sectors directly from the start onwards. If not, it would iterate through all other files and corrupt whatever it had access to.
I'm satisfied to report that hundreds of script kiddies had their data irreversibly destroyed before my handiwork was noticed. I hope it was a valuable lesson to them.
If so, I might have been one of the people you taught a lesson to. :D
Of course, that was never considered nor was collateral damage because the ethical justification is just a pretense to excuse harming others.
This is not certain.
More to the point, I don't understand why you want to spank them for this now. Kids do stupid stuff and this is far less stupid and dangerous than a lot. Indeed a lot of no-effort hackers get burnt on this stuff and stop. I know people who tried and failed. Adding peril to the process scares off a lot of would-be bad behaviour.
Your argument totally falls apart here, because you’re just outright wrong. There are a ton of kids who are curious would-be hackers that turn away from the dark side forever after getting pwned while trying to do something sketchy.
... How do you know?
It taught them a valuable life lesson about trust and humility, and maybe even ethics and the risks of criminal activity in very mild fashion. Recovering from being hacked might stir feelings of empathy for their victims and lead them to learn valuable forensics skills.
Stories like this are part of the personal evolution of a lot of white hats. I think aaza did a real service to the world.
One wonders how many parents-of-script-kiddies were affected, having their data or work destroyed by blind retribution for having naive children.
This story concerns 18,000 script kiddies. Imagine the scale of impact we're talking about when magnified to their victims.
Back then: We got the 2nd computer in the household in 97, exactly so I would not have to use the family (actually business) computer anymore.
Now: I mean ok, maybe it's already swung past a certain point that there is actually only one non-mobile device in the home, but the chance that it is the targeted script kiddie's machine (and not the important family computer) is so much higher.
someone does something bad -- by all means that gives whoever carte blanche to do whatever is just as bad or equally so to the victimizers.
This doesn't make sense -- even less sense when you realize that 'script kiddies' is anyone who ran an executable from an image board; you couldn't ask for a lower bar.
Half the people who downloaded the thing probably didn't even know what the fuck an IP address is, they probably shouldn't be the ones saddled with taking on the entirety of repercussion that was meant for the person(s) who wrote the tool.
tl;dr : I bet half of the '18,000' people were 11 year olds who typed 'google.com' or their least favorite AIM screen-name into the target criteria of this already half-assed 'tool', yet people act righteous for wiping their hard-drives as if they were the real culprit.
read : wiping the not-culprits parents hard-drives in many cases, I would bet.
Second, we assign blame to the person that pulls the trigger, not the maker of the gun.
Third, these people are likely to never face any other form of punishment.
Personally, I think these facts justify this level of retribution. That doesn’t make it “legal” or “right”, but I definitely do not think it is “wrong”.
The analogy here is more akin to a booby trap than a gun, in which case we do assign the blame to the person that made the contraption intended to harm the unwitting user.
That aside, considering once it was discovered how the drive wiper that OP (aaza) claims to have made works, it basically just became a drive wiper that any bad actor could drop into a target system and run, “I intentionally distributed malware that I think, but have no way of verifying, only hurt The Wrong Sort Of People” isn’t just illegal and wrong, it’s stupid.
Imagine copying an entire binary onto a system just so you don't have to run `cat /dev/zero > /dev/sda`
Imagining script kiddies using stupid software in stupid ways very clearly and easily, also imagining a script kiddie pasting `cat /dev/zero > /dev/sda` into the windows command prompt of the computer he’s controlling with sub7 and getting very frustrated
Wow. Just wow.
I looked at keygens and whacked an entire site of 900+. Not a single one did not have a virus, and some more than one. I kept it as a zoo to test scannets.
Astalavesta baby.
In that sense, file deletion is destructive but honest. The poster owned the systems at this point and could have exfiltrated data or used the control of the systems for further attacks. This was decidedly mild.
The person who called this a cybercrime is more correct than people disagreeing
Let's be very specific: "if they actually used it as part of a DDoS.". This wasn't embedded in warez or cracking tools, it was in botnet controllers, and ran when someone had pulled the trigger to execute an attack.
A "botnet controller" requires a botnet. The OP made malware. A program, when run, that would delete your files without permission.
merely having the thought of doing something illegal isn't illegal and afaik the catholics have the only guidelines on how to deal with illegal thoughts, and "delete all the files on their hard disk or otherwise corrupt their system" wasn't in the canon that i saw.
"Years ago when DDoS tools were being distributed on 4chan I fixed a bug in one of them and redistributed it there"
"if they actually used it as part of a DDoS"
You are incorrect, they said it was a DDoS tool. You are incorrect about "merely having the thought", it required executing an attack. FAFO. Again, this is part of the personal evolution of tons of security professionals who longer do juvenile stupid shit. Or at least learned how to do so in a hardened sandbox vm.
Thats a more relevent analogy here, as probably most of those script kiddies were using the family PC which had other other innocent peoples important stuff on.
Shall I goggle ddos attacks that have cost people their lives?
>Fucking up the family computer is a formative experience for many techies.
It's true, I did it myself!
As a prank, my friends and I would do the following:
* Hide all the icons on the desktop
* Trigger an error message
* Take a screenshot of the whole screen
* Open the screenshot in MS Paint
* Carefully paint over the error message to say “You’ve been hacked.”
* Change the desktop background to be the screenshot above
* Restore all the icons.
You’d end up with a convincing looking error message that wouldn’t close, obviously.
The next class, the teacher lectured us for 45 minutes on the definition of “script kiddy” vs. “real hacker” and how we should be embarrassed.
This made the whole thing even funnier.
It’s true though, I was a script kiddie.
But it seems that's most of what Software Engineers do lately, spending most of our coding time figuring out the arbitrary bureaucracy (not fundamentals, nor insightful inventions) dumped on us, by the massive piles of stuff churned out by other people. Such that we understand very little of what we do, and consequently create very little.
Do people still say "script kiddie", or does it resonate a lot differently than it used to, maybe a little too close to home?
Which meant all a potential victim had to do was accept the file, not run it (renaming the extension was a good first step), and note the IP address of the skiddy who sent it to them. Inspect the file to see the port and password configured therein, run the control program, connect back to the origin IP with the given port and password, et voila.
I wonder how many of them thought their tool was backdoored, not realizing it was they who had compromised themselves.
Many (if not all) malwares do this now. Does this mean you don't need an antivirus when you run windows on a vm because any malware that happen to infect it would kill themselves when they noticed they're running inside a vm?
I got 100s of accounts, but never really did anything with them.
That caught my eye ^^^ Is there any virtualization software that makes VM environments indistinguishable from a "bare metal" environment?
For me I wanted an autoclicker for a few things. All sorts of sketchy sites and YouTubers recommending downloading some crap others would say is a virus and others would say are a false positive. I ended up finding a tutorial on how to write a python program and made my own autoclicker.
This will be a lesson these script kiddies probably needed. They are lucky as it does not seem nearly as bad as it could be in terms of malware.