What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Instant Messaging > Yahoo! Messenger Support

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 07-24-2003, 09:21 PM
BLACK HAT BLACK HAT is offline
Junior Member
 
Join Date: Jul 2003
Location: Houston, Texas, USA.
Posts: 22
BLACK HAT is on a distinguished road (10)
Preventing Malicious Activity

I am moving this post into its own folder as it seems to have been buried. I believe this information has merit and will be of use to everyone that uses Instant Messaging programs whether it be AIM, Yahoo!, ICQ, MSN Messenger etc.

In reading through these forums it is apparent that a great many users are having difficulty with persons who boot them offline, steal their passwords and IDs etc.

This is harassment and laws exist in many US states and foreign countries that strictly forbid this kind of activity.

I live in Texas and this is the law in my state. Your state, county, city, parish, province or country probably has similar laws.

This is an excerpt from Texas State Law

77(R) SB 139 Enrolled version - Bill Text 1-1
AN ACT relating to the prosecution of and punishment for the offenses of
harassment and stalking.

BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
SECTION 1. Section 42.07, Penal Code, is amended to read as follows:
Sec. 42.07. HARASSMENT. (a) A person commits an offense if, with intent to harass, annoy, alarm, abuse, torment, or embarrass another, he:

(7) sends repeated electronic communications in a manner reasonably likely to harass, annoy, alarm, abuse, torment,embarrass, or offend another.

(1) "Electronic communication" means a transfer of signs, signals, writing, images, sounds, data, or intelligence of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photoelectronic, or photo-optical system. The term includes:

(A) a communication initiated by electronic mail, instant message, network call, or facsimile machine; and (B) a communication made to a pager.

Seeing as this is against the law, it empowers us to take action. You pay to be online and chat with friends or family and you have a right to do so without being harassed.

Track down as many booter web sites as you can and look up the web host through traceroute. If you need further instruction on how to do this just post here and I will instruct you. I know that there are many designers, webmasters, techs etc that post on these forums that are well aware that this sort of activity is not acceptable on their systems and I am surprised that no one has moved to stop this at the source.

A good tool for locating the host of offending web sites is located here, www.network-tools.com

E-mail the web host and complain that the boot programs, password stealers, account lockers etc. made available on these web sites are denying you access to the Internet service that you pay for. This is in flagrant violation of any reputable web hosts acceptable use policy against harrassment or attempting to penetrate the security of another user's account.

If someone were outside your home tampering with your phonelines so that you could not place a call, what would you do? Would you just hope that it goes away or would you take action? You would probably call the phone company or the police wouldn't you? This is no different.

This will not stop people from trading boot codes in e-mail or on P2P programs but it sure does make it hard for people to just type "booters" into a search box and start downloading.

As they say, an ounce of prevention is worth a pound of cure.

Reply With Quote
  #2 (permalink)  
Old 07-24-2003, 10:10 PM
Someguy03's Avatar
Someguy03 Someguy03 is offline
Senior Member
 
Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,337
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
There are way too many websites to be able to shut them all down. You might be able to slow down booting but not by much. Companies already work on patches that shutdown booting programs, Aol is a good example. We are on our way but theres a long road ahead of us.
Reply With Quote
  #3 (permalink)  
Old 07-24-2003, 10:40 PM
BLACK HAT BLACK HAT is offline
Junior Member
 
Join Date: Jul 2003
Location: Houston, Texas, USA.
Posts: 22
BLACK HAT is on a distinguished road (10)
I have shut down 46 web sites in 8 days. I am ONE person. How many people are registered on this forum, 6,000 or more?

If only one percent of them pitched in, that knocks down web sites at quite a clip.

This activity has been going on for years. Your suggestion to wait until AOL, Yahoo etc. resolve issues on their own is a fruitless one.


BLACK HAT

You can't convince a believer of anything; for their belief is not based on evidence, it's based on a deep seated need to believe.
Reply With Quote
  #4 (permalink)  
Old 07-24-2003, 11:03 PM
shifter's Avatar
shifter shifter is offline
Senior Member
 
Join Date: May 2003
Location: Canada.
Posts: 3,518
shifter is almost a celebrity (200)shifter is almost a celebrity (200)shifter is almost a celebrity (200)
BLACK HAT - A great and noble plan. I endorse it completely. In fact I have just finished locating an offending site containing these boot programs and have reported it to the host. It took me about 2 minutes at most, and if we all do at least one, think of the good being done. Lets keep the booters underground. To make this even easier for users I have written this blurb for you using Black Hat's initial post as a guideline so you can simply copy and paste into your email complaints. Feel free to elaborate and build the complaint so that it is most effective.

Dear Web Host,
I have just discovered http://www.offendingsite.com and am outraged at its offending content. This site contains numerous Booting programs, password stealers and/or account lockers used to maliciously attack internet users. These programs made available on this web site are denying me access to an Internet service that I pay for. This is in flagrant violation of any reputable web hosts acceptable use policy against harrassment or attempting to penetrate the security of another user's account. Please remove this site ASAP. Thank you for your immediate attention.

[color="DarkOrange"]ShiftThis.net
Reply With Quote
  #5 (permalink)  
Old 07-24-2003, 11:17 PM
BLACK HAT BLACK HAT is offline
Junior Member
 
Join Date: Jul 2003
Location: Houston, Texas, USA.
Posts: 22
BLACK HAT is on a distinguished road (10)
Way to go Shifter!

I knew I could count on a fellow designer!


BLACK HAT

You can't convince a believer of anything; for their belief is not based on evidence, it's based on a deep seated need to believe.
Reply With Quote
  #6 (permalink)  
Old 07-25-2003, 12:24 AM
Johnson Johnson is offline
Senior Member
 
Join Date: Jun 2003
Location: Lafayette, In, USA.
Posts: 258
Johnson is on a distinguished road (10)
Send a message via AIM to Johnson Send a message via Yahoo to Johnson
Cracking and booting sites put disclaimers on them, saying the programs are only there for educational purposes blah blah blah, to cover their rears. Yahoo knows about the most popular booting, cracking sites, and they do nothing about it, so i doubt their hosts would care, it all comes down to money, and if the don't host these sites, they won't be making any money.
Now if a website had trojans on it, or trojaned programs, im sure the host would take some kind of action. Theres a lot worse things then booting people or stealing their ids.
Reply With Quote
  #7 (permalink)  
Old 07-25-2003, 12:51 AM
BLACK HAT BLACK HAT is offline
Junior Member
 
Join Date: Jul 2003
Location: Houston, Texas, USA.
Posts: 22
BLACK HAT is on a distinguished road (10)
Johnson:

The disclaimers placed on booter and cracker sites is a bunch of hogwash. It is a bluff. It looks very cryptic but it is worthless. See below.

Claim: Citing "code 431.322.12 of the Internet Privacy Act" protects web site operators from prosecution.
Status: False.


http://www.snopes.com/legal/privacy.htm

Breaking into another user's account would also give you access to their e-mail. Sometimes other passwords can be found in e-mail that may allow crackers to access more information on other accounts. Additionally, IDs can be tied to Yahoo! or Microsoft Passports or Wallets.

I am not really sure where you fail to see the serious nature of this issue.

You say that it all comes down to money. Certainly, it does. But, are you content to stand by and watch others make money illegally while you work hard and abide by the law?

My research has shown that most of these sites are owned by teenage kids that may not be aware that what they are doing is against the law. They are excited by the prospect of kicking another user offline. It becomes a game to them and they form gangs or cliques that trade these various tools. They seek out the creators of these programs and in many cases the creators of these programs have leased a server so they can host this type of material. They strike up a "friendship" with the creators of these programs who then offer them web hosting at 5-10 dollars a month. It doesn't take a genius to figure out that if you supplicate the kids and endow them with some sort of cryptic status that they will become a loyal follower and host a web site with you. Get 100 kids lined up at 10 bucks a month and you can pocket 12 grand a year. Not bad. Would you like an extra 12 grand a year? I bet you would. Nice little racket, huh?

If only it were legal.



BLACK HAT

You can't convince a believer of anything; for their belief is not based on evidence, it's based on a deep seated need to believe.
Reply With Quote
  #8 (permalink)  
Old 07-25-2003, 12:58 AM
Someguy03's Avatar
Someguy03 Someguy03 is offline
Senior Member
 
Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,337
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
I never said that reporting sites didnt work. I had never tried to report sites, assuming it wouldnt work. But if you can nail 46 sites in 8 days then im off to do some reporting. Thanks for the heads up, lets hope this goes well.

How do you find the host of the site?
Reply With Quote
  #9 (permalink)  
Old 07-25-2003, 02:04 AM
David's Avatar
David David is offline
Senior Member
 
Join Date: Apr 2003
Location: Portland, OR
Posts: 5,283
David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)
Send a message via AIM to David
Quote:
quote:Originally posted by someguy03

I never said that reporting sites didnt work. I had never tried to report sites, assuming it wouldnt work. But if you can nail 46 sites in 8 days then im off to do some reporting. Thanks for the heads up, lets hope this goes well.

How do you find the host of the site?
You run a WHOIS? lookup.

www.register.com does WHOIS? lookup's.

David Amenta
Person Meets Profession - Dave Amenta .com
Reply With Quote
  #10 (permalink)  
Old 07-25-2003, 02:20 AM
Someguy03's Avatar
Someguy03 Someguy03 is offline
Senior Member
 
Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,337
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
It says that it timed out. Is this a error or do only some sites work on the WHOIS?
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
Preventing AIM on network mikemart5959 AIM Support 8 09-17-2004 01:02 AM
Any 6.1 build & Abnormal Cursor Activity gahbmwM5 MSN / WLM Archive 4 01-13-2004 07:09 AM
Preventing us from bot spam detn8r Suggestion Box 1 04-24-2003 02:40 AM
YTunnelpro activity log Banshee Yahoo! Messenger Support 2 03-23-2003 03:26 AM

All times are GMT -5. The time now is 10:52 AM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.