Lizard Squad attacks Brian Krebs
money.cnn.com
money.cnn.com
I agree with the OP, this is creepier and more personal (being his home) than getting drugs mailed to him. Or continually DDOS'd..
Looks like the Finnish kid Julius aka Ryan/zee was arrested in Lizard Squad roundup http://ow.ly/GFeeM>These two services, like most booters, are hidden behind CloudFlare
Wow, is cloudflare so poorly run they have no idea they're hosting/caching/accelerating Lizard Squad tools? CF plays up itself as this strong security minded service, but it looks like they're in bed with the blackhats.
I was on the fence with them, but now I think I'm just going to roll my own mod_security/mod_evasive proxy and call it a day. If they dont care about or can't detect these types of clients, then I don't want to do business with them.
It's unfortunate there's any limit on hosting. LE can still go subpoena CF and use judicial channels like always. CF should stay in the anti DDoS business and just annoy everyone with their captchas instead of implementing law and morality.
Child porn seems to be the exception, as it's easier to look at "stopping" such things getting near our visibility, instead of worrying about the actual incidence of the problem. (See Craigslist where AGs preferred to shut down a system they had access to, since that's visible, preferring to force "adult" users to buy and sell in uncontrolled markets.)
Julius Kivimäki aka zee, aka Zeekill (https://encyclopediadramatica.se/Zeekill) has an extensive history, he actually has been dox'd and outed numerous times prior to this.
I knew lizard squad was zee by zee's idiotic behaviour. He constantly used the moniker "Ryan" or "Ryan Clearly" the name of another unrelated hacker. Well sure enough he gave an interview to someone using that moniker. Having even the tiniest bit of inside knowledge it was easy to piece together 1 + 1 = 2 and lizard squad is zee, aka julius.
There are other clues too, believe it or not, not too many entities are capable of massing as large a ddos as they were. Those that have the technical capability, normally don't advertise as such.
Zee was a "special" case, in that he had the capability, and advertised it as such, I was astounded the boy hadn't been jailed years prior. As I mentioned earlier he has an extensive history, and was involved in many of the large site take downs and ddos's that have made public news.
I'm also very surprised it's taken this long for him to be arrested. He's completely brazen and has committed countless crimes despite knowing full well the general public and law enforcement know exactly who he is.
And if he truly was/is involved in carding, he probably won't get out for a while. I can hold some respect for blackhat groups, and hell, even a tiny, miniscule bit of respect for script kiddies like Lizard Squad, but once they get into financial fraud and theft my sympathy is gone.
>he probably won't get out for a while
If only I'd get sentenced in the first place.
I hope you have lots of money to guarantee a fair trial, but anyway, I'd strongly suggest you to never ever travel anywhere near the US for the rest of your life.
Zee got his net taken away from him numerous times hitting the wrong people.
But yes in a nutshell, the digital world is mostly unprotected open and unlocked houses, with little pockets of protected castles here and there, and some locked houses too.
So for example remote command injection vulns:
http://en.1337day.com/exploit/description/20598
http://en.1337day.com/exploit/description/20602
http://en.1337day.com/exploit/description/20671
Then it is just a matter of figuring out where these routers are, and then writing a few scripts to exploit and command them in mass. I don't think CSRF/XSS would net him the vast numbers he'd need to make a significant ddos.
And to more specifically answer your question, by "incoming connections", I mean like monitoring the ddos via netstat on a box zee was actively attacking.
For cases where they're remotely exposed, just about anyone can scan the Internet and try to exploit these routers. I'm sure he was doing that, but I'm sure hundreds or thousands of other people were as well.
When combined with something like a CSRF, you can use those exploits against a victim even if their router is locked down (only listening on LAN, strong admin password). All they need to do is visit a site you control, without something like NoScript. If the admin password is not guessable, then they'd need to have an active login session. That can be circumvented if the router has an auth bypass vuln, which has been found in at least a few models.
Also, I believe a lot of routers can be used for DDoSing without exploiting or compromising them at all if they're exposing SSDP (UPnP). SSDP reflection, possibly combined with NTP reflection, is likely how Lizard Squad launched their DDoS attacks.
P.S. I know you and have talked to you (and Zee and some others), briefly, on some IRC networks long ago.
If that's not the case, mind giving any hints?
We are using actual 0days to compromise the (about 100k-150k) servers we have.
I'm actually rather excited for the eventual technical analysis of our net by someone with actual technical competence. It might end up causing quite a bit of noise.
I seem to recall you guys (I think it was you guys, may be mixing up with another group; I also know you were supposedly kicked out of HTP at some point, which adds to my confusion) using one of the Rails YAML handling 0-days to acquire bots a while ago. I think someone was logging the IRC channel where they were being joined to.
Would it be fair to say the other bots are mostly a result of other web app vulns, or are you guys actually finding 0-days in native applications as well?
Do you actually have a full vulnerability research team, or is it just like 1-2 guys finding vulns? HTP's stuff like Coldfusion and MoinMoin was definitely pretty impressive.
A large chunk of the boxes we control do not have any sort of web apps running on them.
I understand you may not want to reveal much for opsec purposes, but just one question: the Lizard Squad guys seem like very run of the mill script kiddies. Why would you help them, if you are? Kind of seems like a skill and motive mismatch. Forgive my ignorance if the situation is more complicated than that; I'm just going off of what Krebs wrote.
Krebs seems to be pretty lost, especially considering that he thinks we've been attacking his site for past 40 days or so. That's just not true (and anyway, if Prolexic couldn't keep PSN up why would they be able to keep his site up?), only thing linking us to attacks against him was a joke in the topic of our fake recruitment channel telling people to take his site down for an hour or so.
Anyway, as for my motives (besides money, of course)? You don't get access to this many boxes without stumbling on at least something interesting.
I'm guessing part of the plan is to continue gaining infamy and notoriety to sell services, starting with the stresser. I also wouldn't be too surprised if perhaps the stresser is a sting op or honeytrap on your part, with the money as just an added bonus.
Now, on the other hand we have our corporate clients. These corporate clients usually contact us via email or over forums and either make us a fixed offer or request a quote for a given target and time-frame. Now, these types of clients are usually willing to pay tens, if not hundreds of thousands of dollars to disrupt their competition for a couple of days.
The second type of customer is obviously our main source of income, and what better way to find those clients than worldwide media publicity?
It'd be funny if this ended up being a sting op, wouldn't it?
It also makes me wonder if optimized command and control networks have been developed. Most of the code I see floating around public drops goes to very little effort to conceal data exfil, if it even makes an effort to identify data to exfil at all. This seems like a real waste given that some large percentage of machines you steal are likely worth more than just their cpu time and bandwidth. Obviously the more code you run, the higher your chances of detection, but it seems like a huge creative space. How do I find interesting files without tripping all the alarms? How do I efficiently take over someone else's LSM hooks?
http://krebsonsecurity.com/2014/12/whos-in-the-lizard-squad/
http://krebsonsecurity.com/2014/12/lizard-kids-a-long-trail-...
> the group jokes incessantly about Krebs' hairline and proudly proclaims, "You can't arrest a lizard."
Spend $200K on an investigation to find a kid to fine him $10K? Maybe not worth the time and money unless it provably worked as a deterrent.
1. Making your staff work overtime.
2. Leaving other work undone.
3. Hiring new staff to make up for this.
4. Keeping redundant personnel on board in case something like this happens again.
5. Hiring temporary contractors and services to help you with this specific task.
All of these cost money.
All of the following need to be paid:
Police agency in country where DDoS target resides, police agency in country where criminal resides, police agency in countries where dummy computers reside, etc?
200k was a random number but i doubt it's necessarily cheap to find any random DDoS-starter
[0]: http://en.wikipedia.org/wiki/Denial-of-service_attack#Legali...
Come on!
How would you feel if you went to an amusement park with your family and found it is closed, because a group of kids spent the night destroying things?
Oh, because they use centralized servers. Well, don't do that. Live by the cloud, die by the cloud.
Because first, we build those things and then we shame them for using them and having expectations.
Previous outages have shown that a number of Xbox Live services like matchmaking and chat have been moved onto their Azure cloud.
Christmas was well and truly ruined for him. It was heartbreaking to see that happen to him after all year of working his butt off and looking forward to it.
Seriously, you might not like MS, proprietary software, their business models, or lots of other things about them, but don't go blaming them for some cretins attacking their systems in a failed ploy to make a buck.
The Lizard script kiddies had a pretty horrible business model too, FWIW, break into a bunch of systems across the internet to DDoS Xbox/PSN servers, ruin a bunch of people's Christmas, and use the media coverage to sell their DDoS as a service scheme.
It's not that MS was being lax about properly hardening their boxes, though. You could DDoS the most hardened server out there, or a rack of them, it's really an inherent design issue with TCP/IP that you can DDoS systems. It's completely ignorant to blame MS, they didn't have a single point of failure, they had blocks of auth servers nailed.
Seriously, why do you think I am motivated by jealousy? I am not in his space, have no interactions with him or his foes. I think it is not a newswirthy story. I stand by that.