Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Net extortionists in child porn threat

Subject: [ISN] Net extortionists in child porn threat
Date: Fri, 29 Oct 2004 03:31:51 -0500 (CDT)
http://www.theregister.co.uk/2004/10/28/blue_sq_blackmail/

By John Leyden
28th October 2004 

Extortionists have threaten to send out images of child abuse in
emails in the name of Blue Square unless the online gambling site
hands over 7,000 Euros ($8,900).

The sick telephone threat followed a five-hour distributed denial of
service attack against the popular site earlier this week, the BBC
reports. This DDoS attack was accompanied by an email from Serbia on
Monday threatening that the assault would be intensified unless Blue
Square paid 7,000 Euros into an account. This DDoS attack was
successfully thwarted only to be followed by a phone call to the
firm's IT director from a man with an "East European accent"
threatening to damage Blue Square's brand by distributing child porn
material in its name unless money was handed over within 48 hours.

"This is a new twist on the standard 'distributed denial of service'
attack," Ed Pownall, communications officer at Blue Square, told BBC
News. "Because we can now repel their online attacks so quickly this
is obviously an attempt to ramp up the intimidation. It is just
revolting."

The firm has decided to speak publicly about the issue so that
recipients of any depraved emails will know it is not from Blue
Square. The attack against Blue Square, launched from compromised PCs
in South America, is the latest in a long series of DDoS attacks
against online gambling sites, which have intensified this year.

In July three men suspected of masterminding a cyber-extortion racket
targeting online bookies were arrested in a joint operation between
the UK's National Hi-Tech Crime Unit and its counterparts in the
Russian Federation. The trio, who investigators reckon netted hundreds
of thousands of pounds from the shakedowns, were picked up in a series
of raids both in St Petersburg, and in the Saratov and Stavropol
regions in southwest Russia.

Extortion is not the only motive behind DDoS attacks. In August six
men were charged by the Californian courts over the first-ever case
involving the use of sophisticated denial of service attacks directed
against business rivals. Jay Echouafni, chief exec of Orbit
Communication Corporation in Massachusetts, along with a business
partner allegedly hired computer hackers in Arizona, Louisiana, Ohio,
and the UK to launch computer attacks against Orbit online
competitors. "These sustained attacks allegedly began in October 2003
and caused the victims to lose over $2m in revenue and costs
associated with responding to the attacks," according to
investigators. Echouafni, who faces a five-count federal indictment,
is on the run.

The modus operandi of DDoS attacks, whatever their motives, remains
broadly consistent. Worms such as MyDoom and Bagle (and Trojans such
as Phatbot) surrender the control of infected PCs to hackers. These
expanding networks of zombie PCs (dubbed 'botnets' by the computer
underground) are most often used for spam distribution but they also
serve as effective platforms for DDoS attacks. Attacks typically start
with crude SYN Flood attacks. If that doesn't scare targets into
paying then attackers resort to more sophisticated attacks (SYN
Floods, UDP Floods, NB-Gets, ICMP Ping Floods and UDP Fragment
Attacks). The effect on unprotected sites can be devastating.



_________________________________________
Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - 
http://www.osvdb.org/

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Net extortionists in child porn threat, InfoSec News <=