top | item 8828250

Lizard Squad attacks Brian Krebs

155 points| MarcScott | 11 years ago |money.cnn.com | reply

109 comments

order
[+] mike_hearn|11 years ago|reply
Big mistake. People who mess with Brian Krebs tend to end up fully doxed and arrested shortly afterwards. You'd think the blackhat world would understand this by now. Krebs is not a guy want to be investigated by.
[+] jonursenbach|11 years ago|reply
You really think people like Lizard Squad, who called their DDOS attack on Sony and Microsoft "security work", understand how the world works?
[+] ChrisGranger|11 years ago|reply
Some people have to learn everything the hard way.
[+] Buge|11 years ago|reply
In the past he's also been swatted and had drugs mailed to him, and a flower cross saying RIP Brian Krebs.
[+] freshyill|11 years ago|reply
The local PD is well aware of his work after the heroin incident. Trying to get him arrested isn't going to work.
[+] Cub3|11 years ago|reply
His latest tweet

  Looks like the Finnish kid Julius aka Ryan/zee was arrested in Lizard Squad roundup http://ow.ly/GFeeM
[+] freshyill|11 years ago|reply
The article says they knocked him offline only briefly, but I'm actually having trouble loading krebsonsecurity.com right now.
[+] drzaiusapelord|11 years ago|reply
Its up now. Tops story is about the lizard squad. This is an interesting tidbit:

>These two services, like most booters, are hidden behind CloudFlare

Wow, is cloudflare so poorly run they have no idea they're hosting/caching/accelerating Lizard Squad tools? CF plays up itself as this strong security minded service, but it looks like they're in bed with the blackhats.

I was on the fence with them, but now I think I'm just going to roll my own mod_security/mod_evasive proxy and call it a day. If they dont care about or can't detect these types of clients, then I don't want to do business with them.

[+] vlad003|11 years ago|reply
It looks like it's unstable. I can connect to it occasionally but most of the time Firefox is saying the connection was reset.
[+] codyb|11 years ago|reply
I wonder how he tracks them down? And if he can find two so easily (on his own?) how had they not be outed already?
[+] hysterix|11 years ago|reply
Well quite frankly if you've been in the scene for a while, you'd be able to tell using other clues, speech patterns, and reused nicks.

Julius Kivimäki aka zee, aka Zeekill (https://encyclopediadramatica.se/Zeekill) has an extensive history, he actually has been dox'd and outed numerous times prior to this.

I knew lizard squad was zee by zee's idiotic behaviour. He constantly used the moniker "Ryan" or "Ryan Clearly" the name of another unrelated hacker. Well sure enough he gave an interview to someone using that moniker. Having even the tiniest bit of inside knowledge it was easy to piece together 1 + 1 = 2 and lizard squad is zee, aka julius.

There are other clues too, believe it or not, not too many entities are capable of massing as large a ddos as they were. Those that have the technical capability, normally don't advertise as such.

Zee was a "special" case, in that he had the capability, and advertised it as such, I was astounded the boy hadn't been jailed years prior. As I mentioned earlier he has an extensive history, and was involved in many of the large site take downs and ddos's that have made public news.

[+] neotek|11 years ago|reply
Krebs is really well connected to the underworld, plenty of people pass him information confidentally, just like any other journalist. He also understands this field far better than most people, so although he probably did find them "easily", it probably wasn't "on his own" and it almost certainly wouldn't have been anywhere near as easy for you or me to do it.
[+] BillFranklin|11 years ago|reply
Attacks consisted of a briefly successful DDoS and this:

> the group jokes incessantly about Krebs' hairline and proudly proclaims, "You can't arrest a lizard."

[+] sporkenfang|11 years ago|reply
Because clearly his hairline is the deciding factor in whether he can punt their stupidity back where it belongs.
[+] krschultz|11 years ago|reply
What is the actual law that someone that engages in DDOS'ing violates? I feel like we might need one specifically for the activity. It's effectively the internet version of criminal mischief. It's not hacking and all of that, but it's also not something that we should just let go all the time. I'm getting sick of hearing about script kiddies DDOSing random websites, I'd be happy to see some fines.
[+] greenyoda|11 years ago|reply
DDOS attacks are generally launched from botnets consisting of computers that are illegally accessed without their owners' permission. While the DDOS itself may not violate any laws, executing it via hijacked computers certainly does.
[+] normloman|11 years ago|reply
Does anyone know lizard squad's motivation? Are they just out to get attention, or do they have some grudge against gaming companies? Regardless, their criminal behavior doesn't impress me or strike me as making a lasting impact.
[+] landr0id|11 years ago|reply
It looks like their motivation behind the holiday attacks on Xbox LIVE and PSN was to get following on their Twitter account to advertise their DDoS-as-a-service platform.
[+] UhUhUhUh|11 years ago|reply
Those attacks have the elegance of a sledgehammer and the content of a plastic bottle washed off on a beach. I am utterly uninterested.
[+] justizin|11 years ago|reply

[deleted]

[+] meowface|11 years ago|reply
He can be a little bombastic at times, but his reporting is solid and he's one of very few journalists left who does real investigative work.
[+] tptacek|11 years ago|reply
What does that even mean?
[+] ExpiredLink|11 years ago|reply
> Lizard Squad ruined Christmas for people around the world

Come on!

[+] Andrenid|11 years ago|reply
My 13yr old brother spent all year saving his pocket money on a deal with dad where dad would put in the rest for him to get his first ever gaming console, an Xbox One. On Christmas he got it, and for 3 days straight he couldn't get it working AT ALL since the Xbone needs XBL to be online to activate, download games (they're all download tokens now), etc.

Christmas was well and truly ruined for him. It was heartbreaking to see that happen to him after all year of working his butt off and looking forward to it.

[+] Argorak|11 years ago|reply
Some people decided to spend their christmas gaming with other people. That is a valid wish and an enjoyable group activity. And they were obviously "ruined".

How would you feel if you went to an amusement park with your family and found it is closed, because a group of kids spent the night destroying things?

[+] victormx|11 years ago|reply
A few days ago I saw how some children felt the Christmas ruined and was the worst of his life by not playing GTA online with their friends, I think the most disturbing should not be the attack but how people are seeing the dates which should in more family matter junction and other things.
[+] bhouston|11 years ago|reply
Brian Krebs is a master of publicity, often a little predictable though.
[+] thirsteh|11 years ago|reply
Is that supposed to be derogatory? Don't be peanut butter and jealous.
[+] sroerick|11 years ago|reply
Hah, why does CNN have a "Happy Birthday Playstation" message on this page?