Big mistake. People who mess with Brian Krebs tend to end up fully doxed and arrested shortly afterwards. You'd think the blackhat world would understand this by now. Krebs is not a guy want to be investigated by.
Its up now. Tops story is about the lizard squad. This is an interesting tidbit:
>These two services, like most booters, are hidden behind CloudFlare
Wow, is cloudflare so poorly run they have no idea they're hosting/caching/accelerating Lizard Squad tools? CF plays up itself as this strong security minded service, but it looks like they're in bed with the blackhats.
I was on the fence with them, but now I think I'm just going to roll my own mod_security/mod_evasive proxy and call it a day. If they dont care about or can't detect these types of clients, then I don't want to do business with them.
Well quite frankly if you've been in the scene for a while, you'd be able to tell using other clues, speech patterns, and reused nicks.
Julius Kivimäki aka zee, aka Zeekill (https://encyclopediadramatica.se/Zeekill) has an extensive history, he actually has been dox'd and outed numerous times prior to this.
I knew lizard squad was zee by zee's idiotic behaviour. He constantly used the moniker "Ryan" or "Ryan Clearly" the name of another unrelated hacker. Well sure enough he gave an interview to someone using that moniker. Having even the tiniest bit of inside knowledge it was easy to piece together 1 + 1 = 2 and lizard squad is zee, aka julius.
There are other clues too, believe it or not, not too many entities are capable of massing as large a ddos as they were. Those that have the technical capability, normally don't advertise as such.
Zee was a "special" case, in that he had the capability, and advertised it as such, I was astounded the boy hadn't been jailed years prior. As I mentioned earlier he has an extensive history, and was involved in many of the large site take downs and ddos's that have made public news.
He probably found them because they did something stupid. Maybe not all of them have screwed up (yet). They certainly don't look very careful. Krebs figures the first two will turn over the rest as part of a plea deal, and that will be the end of it. https://krebsonsecurity.com/2014/12/lizard-kids-a-long-trail...
Krebs is really well connected to the underworld, plenty of people pass him information confidentally, just like any other journalist. He also understands this field far better than most people, so although he probably did find them "easily", it probably wasn't "on his own" and it almost certainly wouldn't have been anywhere near as easy for you or me to do it.
What is the actual law that someone that engages in DDOS'ing violates? I feel like we might need one specifically for the activity. It's effectively the internet version of criminal mischief. It's not hacking and all of that, but it's also not something that we should just let go all the time. I'm getting sick of hearing about script kiddies DDOSing random websites, I'd be happy to see some fines.
DDOS attacks are generally launched from botnets consisting of computers that are illegally accessed without their owners' permission. While the DDOS itself may not violate any laws, executing it via hijacked computers certainly does.
It is certainly unlawful: it is trying actively to disrupt someone's service (a website but also possibly its entire business). There are also specific laws for DoS[0].
Does anyone know lizard squad's motivation? Are they just out to get attention, or do they have some grudge against gaming companies? Regardless, their criminal behavior doesn't impress me or strike me as making a lasting impact.
It looks like their motivation behind the holiday attacks on Xbox LIVE and PSN was to get following on their Twitter account to advertise their DDoS-as-a-service platform.
My 13yr old brother spent all year saving his pocket money on a deal with dad where dad would put in the rest for him to get his first ever gaming console, an Xbox One. On Christmas he got it, and for 3 days straight he couldn't get it working AT ALL since the Xbone needs XBL to be online to activate, download games (they're all download tokens now), etc.
Christmas was well and truly ruined for him. It was heartbreaking to see that happen to him after all year of working his butt off and looking forward to it.
Some people decided to spend their christmas gaming with other people. That is a valid wish and an enjoyable group activity. And they were obviously "ruined".
How would you feel if you went to an amusement park with your family and found it is closed, because a group of kids spent the night destroying things?
A few days ago I saw how some children felt the Christmas ruined and was the worst of his life by not playing GTA online with their friends, I think the most disturbing should not be the attack but how people are seeing the dates which should in more family matter junction and other things.
[+] [-] mike_hearn|11 years ago|reply
[+] [-] jonursenbach|11 years ago|reply
[+] [-] trippy_biscuits|11 years ago|reply
http://i.imgur.com/vQTaCKx.png
[+] [-] pmalynin|11 years ago|reply
[+] [-] ChrisGranger|11 years ago|reply
[+] [-] Buge|11 years ago|reply
[+] [-] icanhasfay|11 years ago|reply
[+] [-] freshyill|11 years ago|reply
[+] [-] Cub3|11 years ago|reply
[+] [-] freshyill|11 years ago|reply
[+] [-] drzaiusapelord|11 years ago|reply
>These two services, like most booters, are hidden behind CloudFlare
Wow, is cloudflare so poorly run they have no idea they're hosting/caching/accelerating Lizard Squad tools? CF plays up itself as this strong security minded service, but it looks like they're in bed with the blackhats.
I was on the fence with them, but now I think I'm just going to roll my own mod_security/mod_evasive proxy and call it a day. If they dont care about or can't detect these types of clients, then I don't want to do business with them.
[+] [-] vlad003|11 years ago|reply
[+] [-] codyb|11 years ago|reply
[+] [-] hysterix|11 years ago|reply
Julius Kivimäki aka zee, aka Zeekill (https://encyclopediadramatica.se/Zeekill) has an extensive history, he actually has been dox'd and outed numerous times prior to this.
I knew lizard squad was zee by zee's idiotic behaviour. He constantly used the moniker "Ryan" or "Ryan Clearly" the name of another unrelated hacker. Well sure enough he gave an interview to someone using that moniker. Having even the tiniest bit of inside knowledge it was easy to piece together 1 + 1 = 2 and lizard squad is zee, aka julius.
There are other clues too, believe it or not, not too many entities are capable of massing as large a ddos as they were. Those that have the technical capability, normally don't advertise as such.
Zee was a "special" case, in that he had the capability, and advertised it as such, I was astounded the boy hadn't been jailed years prior. As I mentioned earlier he has an extensive history, and was involved in many of the large site take downs and ddos's that have made public news.
[+] [-] sp332|11 years ago|reply
[+] [-] mikeryan|11 years ago|reply
http://krebsonsecurity.com/2014/12/whos-in-the-lizard-squad/
http://krebsonsecurity.com/2014/12/lizard-kids-a-long-trail-...
[+] [-] neotek|11 years ago|reply
[+] [-] BillFranklin|11 years ago|reply
> the group jokes incessantly about Krebs' hairline and proudly proclaims, "You can't arrest a lizard."
[+] [-] sporkenfang|11 years ago|reply
[+] [-] krschultz|11 years ago|reply
[+] [-] greenyoda|11 years ago|reply
[+] [-] thu|11 years ago|reply
[0]: http://en.wikipedia.org/wiki/Denial-of-service_attack#Legali...
[+] [-] peteretep|11 years ago|reply
http://www.legislation.gov.uk/ukpga/2006/48/section/36
[+] [-] normloman|11 years ago|reply
[+] [-] landr0id|11 years ago|reply
[+] [-] RunningWild|11 years ago|reply
[+] [-] dsl|11 years ago|reply
[+] [-] UhUhUhUh|11 years ago|reply
[+] [-] justizin|11 years ago|reply
[deleted]
[+] [-] meowface|11 years ago|reply
[+] [-] tptacek|11 years ago|reply
[+] [-] ExpiredLink|11 years ago|reply
Come on!
[+] [-] Andrenid|11 years ago|reply
Christmas was well and truly ruined for him. It was heartbreaking to see that happen to him after all year of working his butt off and looking forward to it.
[+] [-] Argorak|11 years ago|reply
How would you feel if you went to an amusement park with your family and found it is closed, because a group of kids spent the night destroying things?
[+] [-] victormx|11 years ago|reply
[+] [-] bhouston|11 years ago|reply
[+] [-] thirsteh|11 years ago|reply
[+] [-] sroerick|11 years ago|reply