tag:blogger.com,1999:blog-35783026.comments2008-04-26T10:22:57.740-07:00CyberCrime & Doing TimeGary Warner, UAB Center for Information Assurance and Joint Forensics Researchhttp://www.blogger.com/profile/10822366940133384061noreply@blogger.comBlogger48125tag:blogger.com,1999:blog-35783026.post-13173714717221630522008-04-26T10:22:00.000-07:002008-04-26T10:22:00.000-07:00rofles here<br><br>http://rapidshare.com/files/110...rofles here<BR/><BR/>http://rapidshare.com/files/110599604/Digerati-Exposed.zip.html<BR/><BR/>:) njoy <3<BR/><BR/>also:<BR/><BR/>scriptkitty.net (etc)rofleshttp://www.blogger.com/profile/05155712900116379095noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-18689237454210847292008-04-25T21:57:00.000-07:002008-04-25T21:57:00.000-07:00I like when I get mentioned in articles when peopl...I like when I get mentioned in articles when people have zero clues as to what they are talking about, I didn't know I was Digerati! WOW! Learn new things everday!<BR/><BR/>My site is off line because I haven't had the time to manage anything, I'm back and got everything going, rlee1918@gmail.com<BR/><BR/>peace.ryanhttp://www.blogger.com/profile/12441721539302461852noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-66458395358310178822008-04-17T23:06:00.000-07:002008-04-17T23:06:00.000-07:00I’ve read that this was a recent example of what t...I’ve read that this was a recent example of what they call a whaling attack – a phishing attack targeting executives in corporate offices like CEO’s, etc.. There have been many articles and blogs suggesting that this attack was especially sophisticated and difficult for spam filters to catch.<BR/><BR/>Remember, that it is not legal to send a subpoena via email unless it has been agreed to by all parties. Also the URL for all U.S. federal courts is “courtname.uscourts.gov” and not<BR/>“uscourts.com” as listed in the email. So beware of this and other sophisticated phishing attacks. An additional FYI: The Abaca Email Protection Gateway (www.abaca.com) service was the only service I know that quarantined these emails.victor louishttp://www.blogger.com/profile/05965594516944149842noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-39240956787031665612008-04-09T11:43:00.000-07:002008-04-09T11:43:00.000-07:00Wow as priest,zero and stm pointed out you sure go...Wow as priest,zero and stm pointed out you sure got a lot of that wrong. <BR/><BR/>You should ask anyone of these people what actually happened because between SSgroup and taunet all the real facts are available and you will find that Mr Goldstein IS a pedophile - this is not speculation it is observation, facts deduced from evidence.<BR/><BR/>BTW - I think you'll find it was me doing the character assassination and much deserved it was too.<BR/><BR/><BR/>kthnxbaiGammarayshttp://www.blogger.com/profile/08010580522987462375noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-82929903063266100922008-04-08T02:02:00.000-07:002008-04-08T02:02:00.000-07:00Priest is right.<br><br>You really need to do more...Priest is right.<BR/><BR/>You really need to do more research on things before oyu publish the on the internet.zerofool2005http://www.blogger.com/profile/06353493073193535867noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-75618236945112405332008-04-07T12:42:00.000-07:002008-04-07T12:42:00.000-07:00Ugh, I forgot to mention the part where you said t...Ugh, I forgot to mention the part where you said that TAUNET was hosted at UPENN and AKILL and Digerati attacked it with the botnets causing damage to UPENN computers.<BR/><BR/>Reality:<BR/><BR/>Digerati was a student at UPENN and hosted a private IRC server there. That irc server was not public, was not used for chatting, was merely a place for the bots to join and recieve orders.<BR/><BR/>Te UPENN damage was caused by all those bots connecting to their network and flooding them off.<BR/><BR/>UPENN itself was never the target of a botnet attack, their network was merely too weak to take the strain of all those joins to one machine.<BR/><BR/>Hey! Maybe <B>I</B> should write the articles from now on? =)Priesthttp://www.blogger.com/profile/08303590107151543972noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-61556332437589348652008-04-07T12:28:00.000-07:002008-04-07T12:28:00.000-07:00Oh good grief, I was right there to see all this h...Oh good grief, I was right there to see all this happen and you got basically nothing right.<BR/><BR/>AKILL was caught only because Ryan Goldstein, A.K.A. Digerati, gave him up to the feds after he got caught. As an attempt to bargain his way into a lesser sentence.<BR/><BR/>There was no "massive collaboration between governments" or law enforcement agencies, as all these articles that have suddenly sprang up state.<BR/><BR/>Also, Digerati (Ryan Goldstein) and Ryan1918 are two different people. I can understand how you messed that one up since Ryan is such an amazingly rare name these days.<BR/><BR/>"He was behind the original DDOS against CastleCops"<BR/><BR/>This statement strikes me as fantasy filler, an author's desperate attempt to make it appear as if they've done actual reasearch.<BR/><BR/>I've not been able to find anything to support this statement, I was in a position for quite a long time where if it had happened I'd have it in my notes, and CastleCops is subjected to a DDOS attack, what? twice a day? Well at least you went with a safe choice, who the heck is going to find any reference to Digerati (Ryan1918? lol) amongst all those DDOS posts.<BR/><BR/>TeamLoosh was just a suckup crew, they hosted evidence files collected by SSGroup.Org (the group that banned DIgerati from their IRC channel on TAUNET and petitioned to have him network banned ... successfully) so that they could get some admins into the SSGroup VIP forums.<BR/><BR/>At any rate, TeamLoosh is a nothing crew, a group of unmentionable nobodies that are hardly relevant to AKILL in any way.<BR/><BR/>The attacks against TAUNET were because SSGroup had an irc server there, when ssgroup moved servers (starting thier own network) the target changed.<BR/><BR/>So taunet isn't really relevant either, ssgroup should have been mentioned at least, since they were the actual target. Try some google and you'll undoubtedly see that. (google.com is a search engine, it's used by good authors to do a thing called research. If you don't know what research is, and I doubt after reading this article that you do, you can go google it.)<BR/><BR/>Where are all the articles asking why Goldstien isn't being charges as a sex offender? I know for a fact the FBI received video and photographic evidence that should have at least gotten them to court, I was sitting right beside my wife when she gave it to them.<BR/><BR/>I'm thoroughly disgusted by all of these articles that are 90% make believe.<BR/><BR/>"Last night the BBC World Service called to ask me what I thought of the AKILL conviction."<BR/><BR/>Why? Why did they call you? Were you there? Where? I didn't see you!<BR/><BR/>BBC, call someone that actually KNOWS something. Hell call me! Go log in on one of the IRC Networks that was actually involved in these incidents and ask them!<BR/><BR/>UAB: Go find a new Director of Research in Computer Forensics. One that actually knows something.Priesthttp://www.blogger.com/profile/08303590107151543972noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-77490811172594479332008-04-07T11:45:00.000-07:002008-04-07T11:45:00.000-07:00god your dumb......<br><br>ryan1918 != Ryan Goldst...god your dumb......<BR/><BR/>ryan1918 != Ryan Goldstein AKA Digerati<BR/>Digerati was never part of TeamLoosh.<BR/>TeamLoosh is not a "hacker" website. Its a bunch of skiddies who go round raging people.......<BR/>Taunet wasnt hosted at UPENN.<BR/><BR/>Dig made some serious mistakes by posting every where that he was infact studying at UPENN. Which became his downfall. If your going to make an interview for a worldwide news corporation. You REALLY need to learn what your talking about.zerofool2005http://www.blogger.com/profile/06353493073193535867noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-32996416798036292672008-04-07T11:30:00.000-07:002008-04-07T11:30:00.000-07:00you try to link several things together out of thi...you try to link several things together out of thin air. taunet wasnt hosted at upenn and isnt a university chat room and digerati isnt ryan1918. did you even read the indictment?stmhttp://www.blogger.com/profile/08207492497333836119noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-80007634304832394722008-04-07T11:28:00.000-07:002008-04-07T11:28:00.000-07:00This comment has been removed by the author.stmhttp://www.blogger.com/profile/08207492497333836119noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-22307224923511905002008-03-03T08:58:00.000-08:002008-03-03T08:58:00.000-08:00World Of Warcraft gold for cheap<br><a href="http:...World Of Warcraft gold for cheap<BR/><A LEVELING POWER HREF="http://www.wow-powerleveling.org" REL="nofollow" TITLE="wow">wow power leveling</A>,<BR/><A GOLD HREF="http://www.wow-powerleveling.org" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.xowow.com" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A LEVELING POWER HREF="http://www.xowow.com" REL="nofollow" TITLE="wow">wow power leveling</A>,<BR/><A LEVELING POWER HREF="http://www.powerlevelingweb.com" REL="nofollow" TITLE="wow">wow power leveling</A>,<BR/><A LEVELING POWER HREF="http://www.powerlevelingweb.com" REL="nofollow" TITLE="world" WARCRAFT OF>world of warcraft power leveling</A>,<BR/>world of warcraft power leveling<BR/><A LEVELING POWER HREF="http://www.powerleveling-wow.com/siteMap.asp" REL="nofollow" TITLE="wow">wow power leveling</A>,<BR/><A GOLD HREF="http://www.srogold.com" REL="nofollow" WOW TITLE="cheap">cheap wow gold</A>,<BR/><A GOLD HREF="http://www.tbcgold.com" REL="nofollow" WOW TITLE="cheap">cheap wow gold</A>,<BR/><A GOLD HREF="http://www.gogoer.com" REL="nofollow" WOW TITLE="buy">buy wow gold</A>,<BR/><A GOLD HREF="http://www.gogoer.com" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gogoer.com" REL="nofollow" WOW TITLE="Cheap">Cheap WoW Gold</A>,<BR/><A GOLD HREF="http://www.gamelee.com" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gamelee.com" REL="nofollow" WOW TITLE="Cheap">Cheap WoW Gold</A>,<BR/><A GOLD HREF="http://www.wowgoldlive.com" REL="nofollow" TITLE="world" WARCRAFT OF>world of warcraft gold</A>,<BR/><A LEVELING POWER HREF="http://www.wowgoldlive.com" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gamelee.com" REL="nofollow" TITLE="world" WARCRAFT OF>world of warcraft gold</A>,<BR/><A GOLD HREF="http://www.gogoer.de" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gamelee.de" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.tbcgold.de" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.wowgoldeu.de" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gogoer.fr" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.gamelee.fr" REL="nofollow" TITLE="wow">wow gold</A>,<BR/><A GOLD HREF="http://www.tbcgold.fr" REL="nofollow" TITLE="wow">wow gold</A><BR/>buy cheap World Of Warcraft gold n3k6u7qlhttp://www.blogger.com/profile/15469803290087254615noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-21505645257216207422008-02-29T18:12:00.000-08:002008-02-29T18:12:00.000-08:00World Of Warcraft gold for cheap<br><a href="http:...World Of Warcraft gold for cheap<BR/><A HREF="http://www.wow-powerleveling.org" REL="nofollow">wow power leveling</A>,<BR/><A HREF="http://www.wow-powerleveling.org" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.xowow.com" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.xowow.com" REL="nofollow">wow power leveling</A>,<BR/><A HREF="http://www.powerlevelingweb.com" REL="nofollow">wow power leveling</A>,<BR/><A HREF="http://www.powerlevelingweb.com" REL="nofollow">world of warcraft power leveling</A>,<BR/>world of warcraft power leveling<BR/><A HREF="http://www.powerleveling-wow.com/siteMap.asp" REL="nofollow">wow power leveling</A>,<BR/><A HREF="http://www.srogold.com" REL="nofollow">cheap wow gold</A>,<BR/><A HREF="http://www.tbcgold.com" REL="nofollow">cheap wow gold</A>,<A HREF="http://www.gogoer.com" REL="nofollow">buy wow gold</A>,<BR/><A HREF="http://www.gogoer.com" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gogoer.com" REL="nofollow">Cheap WoW Gold</A>,<BR/><A HREF="http://www.gamelee.com" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gamelee.com" REL="nofollow">Cheap WoW Gold</A>,<BR/><A HREF="http://www.wowgoldlive.com" REL="nofollow">world of warcraft gold</A>,<BR/><A HREF="http://www.wowgoldlive.com" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gamelee.com" REL="nofollow">world of warcraft gold</A>,<BR/><A HREF="http://www.gogoer.de" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gamelee.de" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.tbcgold.de" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.wowgoldeu.de" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gogoer.fr" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.gamelee.fr" REL="nofollow">wow gold</A>,<BR/><A HREF="http://www.tbcgold.fr" REL="nofollow">wow gold</A><BR/>buy cheap World Of Warcraft gold k3f6a7pshttp://www.blogger.com/profile/15469803290087254615noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-20815112217439642342008-02-21T21:02:00.000-08:002008-02-21T21:02:00.000-08:00From claude.benoit@coned.com<br><br>Subject line ...From claude.benoit@coned.com<BR/><BR/>Subject line You’re the One<BR/><BR/>Inside letter <BR/><BR/>The Moon & Stars http://75.176.123.128/Marvhttp://www.blogger.com/profile/16922864012901013877noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-38509027828027480622008-01-23T18:15:00.000-08:002008-01-23T18:15:00.000-08:00Hi! I write from mexico city, found your blog "by ...Hi! I write from mexico city, found your blog "by Accident" searching the "powerof3x.com" file that some site tryied to download to my Mac...haha...<BR/><BR/>well I googled it and here I am...reading your blog...awsome!<BR/><BR/>keep the good job!<BR/><BR/>:)ecapdevillehttp://www.blogger.com/profile/11128325122942240859noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-89288125801306966442008-01-22T05:23:00.001-08:002008-01-22T05:23:00.001-08:00This comment has been removed by the author.Royhttp://www.blogger.com/profile/06423705453928016993noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-56652976930118934542008-01-22T05:23:00.000-08:002008-01-22T05:23:00.000-08:00I'll add that I just got this on my work email<br>...I'll add that I just got this on my work email<BR/><BR/>I Love Thee > Subject<BR/><BR/>You're My Dream http://60.1.49.231<BR/><BR/>was the message<BR/><BR/>Google is your friend ^_^<BR/><BR/>oh ya, and I don't know if the person responsible is the one who sent, or if thye are someone infected, but the email is druet@cayeaccommodations.com<BR/><BR/>i looked up caye accommodations and its for buying villas in the Caribbean or something. so idk.Royhttp://www.blogger.com/profile/06423705453928016993noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-90015182918402100272008-01-11T14:42:00.000-08:002008-01-11T14:42:00.000-08:00$24,000 giftcard?! they say most criminals are stu...$24,000 giftcard?! they say most criminals are stupid, but now i REALLY believe it! who does that?!<BR/><BR/>if you're going to commit <A HREF="http://www.onlinecheck.com/merchant_accounts/credit_card_processing.html" REL="nofollow">credit card processing</A> fraud, i would think you would want to be inconspicuous about it as not to get caught.<BR/><BR/>these folks deserve all the punishment they get!!shannonhttp://www.blogger.com/profile/01902618643180216675noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-48645035103664136672007-12-11T12:53:00.000-08:002007-12-11T12:53:00.000-08:00I found this rather intriguing.<br>From all the sp...I found this rather intriguing.<BR/>From all the spambots everywhere. Thank you for the recognition.<BR/><BR/><A HREF="http://ronpaulchat.50webs.com" REL="nofollow">http://ronpaulchat.50webs.com</A>Websterhttp://www.blogger.com/profile/12797734265495958515noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-44639541253833095902007-11-27T18:21:00.000-08:002007-11-27T18:21:00.000-08:00Hello, I have a question. Was anything siad about ...Hello, I have a question. Was anything siad about employees monitoring? I work as a system administrator and have installed PC ACME on each of the PCs in our company. All the employees know about this fact as we tell them that there will be the monitoring software installed on their PCs before they sign the contract. The software is licenced. So, is everything legal?Maxhttp://www.blogger.com/profile/03352965418669286254noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-50870110786523418302007-11-20T23:38:00.000-08:002007-11-20T23:38:00.000-08:00Thanks for the post. Got one today and was curious...Thanks for the post. Got one today and was curious but not enough to open it so I googled and found your entry.Righteoushttp://www.blogger.com/profile/00631903486695634983noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-55987656710626055242007-11-19T15:46:00.000-08:002007-11-19T15:46:00.000-08:00I have received one of thes e-mails and am glad to...I have received one of thes e-mails and am glad to know it is spam, as i found it quite threatening.<BR/><BR/>It is good that information is passed on about this kind of junk. I was able to look on google and find it to be a "trojan" . None of my anti-virus or spyware checks picked up on it.ileshahttp://www.blogger.com/profile/04012405360834744989noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-34112717387130083582007-11-17T18:08:00.000-08:002007-11-17T18:08:00.000-08:00The state agency I work for is seeing these also. ...The state agency I work for is seeing these also. We started receiving them this morning (9:19AM EST on 11/17), but they suddenly stopped coming in around 11:53AM. In that span we received approximately 100 infected attachments.<BR/><BR/>This isn't the first malicious .scr attachment I've seen not get picked up by AV. On 11/15 we rec'd an attachment named "complaint.zip". Inside that was "complain.scr", about 223K in size. The email delivering it was supposedly from the Better Business Bureau, had a partial match on our agency name in the text, so it appeared targeted at us. Fortunately the name it was addressed to was obviously phony, so the recipient knew enough to alert us to it. This complain.scr scanned cleanly, too.ejhondahttp://www.blogger.com/profile/02090599071527307930noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-76662887327754091112007-11-11T15:23:00.000-08:002007-11-11T15:23:00.000-08:00Hahaha, I ran into exactly the same phenomenon whe...Hahaha, I ran into exactly the same phenomenon when I posted some examination of a similar spam:<BR/><BR/>http://taint.org/2007/11/01/192745a.html<BR/><BR/>BTW your spam data mining sounds _very_ interesting. I'm one of the developers of SpamAssassin, and I've been messing around with an automated mechanism to extract SA rules from trapped spam corpora:<BR/><BR/>http://taint.org/2007/03/05/134447a.html<BR/><BR/>that's similar in results to the clustering method you guys are using, but I'll bet that's more sophisticated.<BR/><BR/>I'd love to get more info on ways we could share data/results...Justin Masonhttp://www.blogger.com/profile/16955170493368020909noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-27379979420098798592007-11-08T19:15:00.000-08:002007-11-08T19:15:00.000-08:00Good day Mr. Warner,<br><br>Yes, this story has in...Good day Mr. Warner,<BR/><BR/>Yes, this story has indeed taken on a life of its own. The results of your quite valid security analysis continue to be misconstrued throughout IT security media a week later. As I just posted to <BR/><BR/>http://www.networkworld.com/news/2007/110507-spam-the-vote-ron-paul.html<BR/>Spam the vote: Ron Paul spam surfs into inboxes<BR/><BR/>Missing & Inaccurate Information<BR/>Submitted by sfrahm on Thu, 11/08/2007 - 9:36pm.<BR/><BR/>Missing information. - The spam is often used to create You Tube Terms Of Service violations backlash that gets legitimate Ron Paul videos pulled off. This part of the spam is an open attack on the campaign.<BR/><BR/>The following comment is not accurate. - "That fact may suggest Paul's online supporters are stuffing the virtual ballot by voting early and often at political polling Web sites." Reputable polls use one time cell phone or one time IP Address voting to prevent repeat votes.S Frahmhttp://www.blogger.com/profile/10041415410119448175noreply@blogger.comtag:blogger.com,1999:blog-35783026.post-73417752711294049052007-11-02T22:40:00.000-07:002007-11-02T22:40:00.000-07:00"Identity Thieves Contribute To Ron Paul President..."Identity Thieves Contribute To Ron Paul Presidential Fund"<BR/>http://www.kxan.com/Global/story.asp?S=7305398&nav=0s3d<BR/><BR/>There is OBVIOUSLY something very, very messed up going on here, folks. So, banks are now going to start rejecting donations to Ron Paul as a result of this?<BR/><BR/>And they can't track these people down (because they often run off to another country??? What? What kind of stupid excuse it that?)Scott_McDonnellhttp://www.blogger.com/profile/17005030073774937344noreply@blogger.com