Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Wikileaks Payback - Offensive and Defensive
#37
FBI Raids Texas Server Farm for Clues to Anonymous Group, Operation Payback


Share
By: Fahmida Y. Rashid
2010-12-30



Federal agents seized two hard drives from a server in a Texas company believed to have been used to launch the DDoS attack against PayPal as part of a pro-WikiLeaks protest.

#ArticleWidgets { font-family: Arial,Verdana,Helvetica,sans-serif; font-size: 11px; text-decoration: none; margin-bottom: 0px; }#ArticleWidgets { color: rgb(0, 51, 153); text-decoration: none; line-height: 16px; }#ArticleWidgets.a, articlewidgets.a:hover { color: rgb(0, 51, 153); text-decoration: underline; line-height: 16px; }#position { padding: 5px 0px 5px 5px; }#spacer { height: 5px; line-height: 5px; }.add2head_new { font-size: 11px; font-weight: bold; width: 200px; margin-left: 8px; margin-right: 8px; display: block; float: right; }.ArticleWidgetsHeadline { font-size: 11px; font-weight: bold; }
The FBI raided a Dallas-based server farm and seized servers used in the distributed denial-of-service attack against PayPal earlier this month, according to an affidavit obtained by the Smoking Gun Web site.
Federal agents are looking for clues as to the identity of the hackers who orchestrated the DDOS attack on PayPal, according to the affidavit. It is unclear whether the raids were successful in that regard.
The FBI began their investigation shortly after the Anonymous group of Internet activists launched DDoS attacks against PayPal and other financial and technical service companies for cutting off support to the WikiLeaks site after it published thousands of secret U.S. state department cables.
The PayPal blog was offline for a few hours as part of the DDoS campaign the Anonymous group called "Operation Payback." Volunteers were encouraged to download a point-and-click DDoS tool to attack PayPal and other targets, including Visa, MasterCard, Bank of America (earlier this week), and a Swiss bank who froze WikiLeaks founder Julian Assange's accounts.
FBI investigators believe that some volunteers used botnets of compromised machines to launch a more potent assault, according to the affidavit.
"Vigilante DDoS, a bunch of kids getting together and running a software," is not a particularly powerful attack because there is not enough volume, Jason Hoffman, of Joyent, told eWEEK. Attackers would have needed five to fifteen million people all on high broadband connections to "be effective," he said.
PayPal provided FBI agents with eight IP addresses of servers that were used to run IRC chat servers associated with planning the Operation Payback attacks, according to the affidavit. Investigators believed the same systems were used as command and control hubs for botnets used during the DDOS attacks.
According to the affidavit, "multiple, severe DDos attacks" had been launched against PayPal, which amount to felony violations of a federal law covering the "unauthorized and knowing transmission of code or commands resulting in intentional damage to a protected computer system."
One IP address was traced to Host Europe, a Germany-based Internet service provider. The server in question turned out to belong to a man from Herrlisheim, France, but that the root-level access to the machine appeared to be from a remote user with administrator access, said the affidavit. The log files indicate the commands to execute the attack came from this remote address, which led investigators to hosting firm Tailor Made Services in Dallas, Texas.
Investigators believe the command to launch the attack was made on Tailor Made Services systems and relayed to this server in Germany to hide its origin.
A pair of log entries on the compromised Host Europe machine contained the same message: "Good_night,_paypal_Sweet_dreams_from_AnonOPs." according to a sworn statement from FBI agent Allyn Lynd.
Agents raided Tailor Made Services on Dec. 16 after getting a search warrant based on the affidavit. Agents copied two hard drives from the targeted server during this raid, according to Smoking Gun. There is currently no information available about what was found on the drives.
Another IP address associated with the attacks was traced to a Canadian ISP in British Columbia, which was actually a virtual server physically hosted at California-based "co-location" firm, Hurricane Electric. There is no information as to whether the company had been raided by agents at this time.
"The philosophers have only interpreted the world, in various ways. The point, however, is to change it." Karl Marx

"He would, wouldn't he?" Mandy Rice-Davies. When asked in court whether she knew that Lord Astor had denied having sex with her.

“I think it would be a good idea” Ghandi, when asked about Western Civilisation.
Reply


Messages In This Thread
Wikileaks Payback - Offensive and Defensive - by Myra Bronstein - 08-12-2010, 03:57 AM
Wikileaks Payback - Offensive and Defensive - by Myra Bronstein - 08-12-2010, 04:23 AM
Wikileaks Payback - Offensive and Defensive - by Magda Hassan - 31-12-2010, 01:29 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  London shoot-out: Inside the CIA's secret war plans against WikiLeaks Magda Hassan 5 5,461 30-09-2021, 12:13 PM
Last Post: Magda Hassan
  US Intell planned to destroy Wikileaks Peter Presland 468 386,158 22-07-2018, 07:46 AM
Last Post: Magda Hassan
  Venezuela: WikiLeaks confirms US plans Magda Hassan 26 16,937 26-04-2014, 03:01 AM
Last Post: Magda Hassan
  Wikileaks publishes Stratfor Global Intelligence files. Magda Hassan 26 20,038 16-11-2013, 09:45 AM
Last Post: David Guyatt
  WikiLeaks publishes more than 1.7 million United States records Magda Hassan 62 30,161 26-06-2013, 06:22 PM
Last Post: Jan Klimkowski
  WikiLeaks cables: MI5 offered files on Finucane killing to inquiry Magda Hassan 6 6,986 12-12-2012, 11:47 PM
Last Post: Jan Klimkowski
  Wikileaks: Google caught in spy games on execs and ‘regime change’ Magda Hassan 2 4,477 10-08-2012, 05:57 AM
Last Post: Ed Jewett
  WikiLeaks releases mystery file (31 Aug 2011) Ed Jewett 12 14,111 03-09-2011, 03:06 PM
Last Post: Magda Hassan
  Destruction of WikiLeaks source material by Daniel Domscheit-Berg Magda Hassan 6 10,879 30-08-2011, 05:49 PM
Last Post: Keith Millea
  PBS website hacked, defaced after WikiLeaks documentary... Ed Jewett 2 4,425 31-05-2011, 02:50 AM
Last Post: Ed Jewett

Forum Jump:


Users browsing this thread: 1 Guest(s)