Powered by Blogger.
Showing posts with label INTERNET. Show all posts
Showing posts with label INTERNET. Show all posts

An Admin's Foolish Errors Helped the FBI Unmask Child Porn Site 'Playpen'



Sites hosted on the so-called dark web are forcing law enforcement to use novel and powerful techniques to unmask them. But sometimes suspected criminals make it easier for the feds.
Recently unsealed court documents reveal that “Playpen,” one of the largest and most infamous dark web child pornography sites, was shut down partly owing to its administrator's own mistakes.
“Due to a misconfiguration of the server hosting the TARGET WEBSITE [Playpen], the TARGET WEBSITE was available for access on the regular Internet to users who knew the true IP address of the server,” a search warrant application for intercepting communications on Playpen from February 2015 reads. The search warrant and other documents were unsealed in the case of Richard Stamper, who was arrested on suspicion of child pornography charges.
“Basically, Playpen must have set their [child pornography] site to [a] default [web server setting], meaning if you typed in the IP address you could see the Playpen site,” Thomas White, a UK-based activist and technologist, explained in an encrypted chat. “Whereas if they set another default like ‘server not found,’ then you could only access Playpen by typing the correct .onion address.” This means that law enforcement could verify that an IP address belonged to a specific site.
“An FBI Agent, acting in an undercover capacity, accessed IP address 192.198.81.106 on the regular Internet and resolved to TARGET WEBSITE,” the document continues. That address pointed to a server in North Carolina, hosted by a company called CentriLogic.
The FBI was tipped off about Playpen’s IP address by a foreign law enforcement agency, as noted in other, redacted versions of the warrant. This recently unsealed version includes detail on how that IP address was left exposed.
It is not clear how the foreign law enforcement agency discovered Playpen's real IP address in the first place. But the main administrator of the site, who the FBI suspects is Steven Chase from Florida, was clearly aware of the problem and actively trying to fix it, according to the search warrant application.
“FBI agents know this by reading his private messages from the copy of the TARGET WEBSITE that was seized pursuant to the aforementioned search warrant,” the document continues.
Playpen’s suspected administrator apparently also leaked identifying information about himself.
Chase allegedly connected to the server, as well as to the PayPal account used to pay for the hosting provider, from an IP address assigned to his home in September and November 2014, instead of through the Tor network. This meant that a subpoena to Paypal revealed where the person paying for the server was likely located.
On top of this, Chase allegedly connected to a Playpen administrator account from his mother's house a number of times between December 2014 January 2015.
Mistakes are often what leads to the capture of suspected dark web criminals. In the case of drug marketplace Silk Road, creator Ross Ulbricht posted his personal email address in an advert asking for help with the site, and the FBI claimed the location of the site's server was identified because of a leaky CAPTCHA system.
Meanwhile Blake Benthall, a suspected administrator of the second iteration of Silk Road, registered a server with an identifying email address. One alleged dark web drug dealer even went so far as to trademark his brand in his own name.
The suspected owner of one of the largest dark web child pornography sites was evidently no different, and perhaps the most foolish of them all.

The One Page Project Manager for IT Projects Communicate and Manage Any Project With A Single Sheet of Paper

image 
Clark A. Campbell, author of a best-selling book on project management, has written a project management guide specifically for IT professionals who want to save time and work more efficiently. The One Page Project Manager for IT Projects:Communicate and Manage Any Project With A Single Sheet of Paper presents you with a winning formula for managing your complex IT projects using minimal resources. Coverage of vital topics like working with outside consultants, ERP project management, and ISO 9000 will be of special interest to IT managers and CIOs.

 

8 Most Famous Creepypastas That Will Scare You to Death

8 Most Famous Creepypastas That Will Scare You to DeathCreepypasta is an Internet horror story that is meant to frighten the reader and is represented as a real-life event. These stories are usually published on different forums and horror websites. The term creepypasta is based on another slang word “copypasta” that means a small block of text that can be copied and posted on different websites. The best creepypasta stories can be even better than horror movies. Here is the list of the most popular creepypastas and their characters.

15 people made famous by the internet in 2015

Internet_famous_people

You don't need a red carpet to be a celebrity anymore. All you need is an Internet connection.
Throughout 2015, our news feeds were dominated with plenty of inspiring, hilarious or even heartbreaking stories that we couldn't get enough of. More often than not, these stories weren't about some Hollywood A-lister or a reality star, they were about regular people like us.
These people found their 15 minutes of fame using the power of the Internet.





Your Wireless Router Could Be Murdering Your Houseplants

PlantAre you slowly killing your houseplants? Probably. But there might be a reason other than neglect that they’re all yellow and wilting: your Wi-Fi router.
An experiment by a handful of high school students in Denmark has sparked some serious international interest in the scientific community.
Five ninth-grade girls at Hjallerup School in North Jutland, Denmark, noticed they had trouble concentrating after sleeping with their mobile phones at their bedsides. They tried to figure out why. The school obviously doesn’t have the equipment to test human brain waves, so the girls decided to do a more rudimentary experiment.
They placed six trays of garden cress seeds next to Wi-Fi routers that emitted roughly the same microwave radiation as a mobile phone. Then they placed six more trays of seeds in a separate room without routers. The girls controlled both environments for room temperature, sunlight and water.
After 12 days, they found the garden cress seeds in the router-less room had exploded into bushy greenery, while the seeds next to the Wi-Fi routers were brown, shriveled and even mutated. See for yourself:
Plant experiment

Teacher Kim Horsevad told the Daily Dot that her students did the test twice with the same results. She was quick to point out that while the students did the experiment to test only one variable to the best of their ability, it is a high school experiment and this isn’t a professional study.
“Some of the local debate has been whether the effects were due the cress seeds drying up because of heat from the computers or Access Points used in the experiment, which is a suggestion I can thoroughly refute,” Horsevad said. “The pupils were painstakingly careful in keeping the conditions for both groups similar. The cress seeds in both groups were kept sufficiently moist during the whole experiment, and the temperature were controlled thermostatically. The computers were placed so that the heat would not affect the seeds, which was verified by temperature measurements. Still, there may be confounders which neither the pupils or I have been aware of, but I cannot imagine what they would be.”
She said the results are clearly dramatic and could trigger additional research. Two scientists, neuroscience professor Olle Johanssen at the Karolinska Institutet in Sweden and Dr. Andrew Goldsworthy at the Imperial College in London, have both expressed an interest in the experiment and may repeat it in a professional lab environment.
Perhaps coolest of all, the students were awarded for their work at the Danish national science fair.

Energy Department Forewarned About Major Data Hack

TypeBefore computer attackers breached Energy Department personnel systems in July, federal inspectors had been warning officials for years about unencrypted sensitive data and urging them to fix application vulnerabilities — failings that ultimately would lead to the hack of sensitive information on 104,179 individuals, according to a Nextgov review of annual cybersecurity evaluations.
An inspector general special report issued Friday determined that the inability to fix known entry points for hackers made possible a July intrusion into the DOE Employee Data Repository, or DOEInfo, the main Rolodex of records on employees, relatives and contractors. The outsiders stole names, Social Security numbers, banking information, and password questions and answers, among other personal data.
"Critical security vulnerabilities in certain software supporting the [management information system] application had not been patched or otherwise hardened for a number of years," the report stated, referring to the system that connects to DOEInfo. "No efforts had been undertaken to eliminate the unnecessary use of Social Security numbers in the existing DOEInfo database tables even though the requirement to do so was over 5 years old."
Among the potential doorways for hackers cited in an August 2009 IG report is that sensitive information on laptops and handhelds, as well as data sent by email, was not always encrypted. Energy officials also permit unencrypted files to be transmitted to offsite storage facilities.
A similar IG evaluation from October 2011 revealed network weaknesses had spiked 60% between fiscal 2010 and fiscal 2011. The security gaps documented included lax access controls and software defects.
Inspectors examining this summer's assault said they could not identify a single fatal flaw, but found several weaknesses that assisted the hackers, many of which, old IG reports show, were flagged previously.
Ultimately, the attackers crept in by using “exploits commonly available on the Internet to gain unfettered access to the relevant systems and exfiltrate large amounts of data — information that could be used to damage the financial and personal interests of many individuals," Friday's report states.
Exploits are hacking tools that take advantage of vulnerabilities — like those found in the earlier IG reports — to break into systems.
Among the factors that aided and abetted the hackers this year: the systems struck were directly accessible through the Web without adequate safeguards and contained vulnerabilities that weren't patched. In addition, the systems stored Social Security numbers in plain text.
Officials had been "permitting systems to operate even though they were known to have critical and/or high risk security vulnerabilities," Friday's report states. “The department had not taken appropriate action to remediate known vulnerabilities on its systems either through patching, system enhancements or upgrades."
According to the 2011 evaluation, tests at 25 facilities, including headquarters, turned up 32 new vulnerabilities plus an additional 24 left unresolved from the prior year.
One year later, a November 2012 inspector general audit found 29 Web applications, including human resource software, did not undergo “validation” to regularly check that program changes were authorized.
On Friday, Energy officials said work is underway to address the inspector general's latest discoveries. The department is examining all online systems and applications, as well as instituting new protections to restrict unauthorized disclosure. All superfluous personal information and Social Security numbers will be expunged from systems by the end of January 2014, officials said. And encryption tools will be installed to protect remaining sensitive information.