Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 13 September 2008

Internet Landfills: Praise for Brian Krebs

Posted on 04:32 by Unknown
Have you ever played Sim City? One of the problems a City Manager has to deal with is the disposal of waste. One of the possible solutions to that problem, is that you can create a landfill. The next problem is always where to put it, because your Sims will all complain and move away if you put it in their neighborhood. The same thing happens in real life. Google ("public meeting" and landfill) and you'll find tens of thousands of pages about meetings where Citizens get together to complain about the landfill that either is, or has been proposed to be, near their homes.

At the Birmingham InfraGard meeting on September 9th, I shared a presentation called "The Beautification of Internet Landfills". It started out with a couple definitions:

Internet Landfill
A network, hosting site, or registrar which attracts an entirely unlikely percentage of criminal activity
Beautification
Causing such landfills to reform their evil ways, or find themselves in legal trouble, or bandwidth impaired due to “public shunning


The meeting dropped a challenge to the Birmingham InfraGard members to become part of the "Neighborhood Watch" for the Internet.

When you see Badness, as a Corporate Security Professional, what do you do:

  • (A) Protect your own systems from the Badness?
  • (B) Share what you've learned with others, so they can be protected too?
  • (C) Trace the Badness to its origins and attempt to shut it down?
  • (D) Report the Badness to an appropriate Law Enforcement Agency?

The answer should be (E) - All of the above.

If you don't know HOW, I told the InfraGard members, then lets share information together to LEARN how.

One of the best ways to see an example of this in action is to follow the SecurityFix column by Brian Krebs of the Washington Post, and to examine and emulate the work of the fine researchers and security companies that he mentions frequently there.

We've all read the stories about the Russian Business Network, and how they were hosting criminal content all the way back to 2004, primarily under the guise of "Too Coin Software". RBN has been documented as the host of hundreds of child pornography websites, the notorious "iFrameMoney.biz" advertising network, and other badness such as the UrSnif Trojan and the SetSlice exploit. As recently as April 2007, they were infecting visitors with spam-based exploits being pushed by our friends Naked Britney and Paris. After making a ridiculous claim to have relocated to Panama (despite still being fed by upstream provider SBT Telecom in St. Petersburg), RBN continued to host its badness until they were outed by a journalistic campaign of exposure.

While there were some great publications shining a light on RBN, the one that seemed to me to have the greatest impact was the October 13, 2007 piece in Brian Krebs' must read column, SecurityFix.
"Shadowy Russian Firm Seen as Conduit for Cybercrime"
An Internet business based in St. Petersburg has become a world hub for Web sites devoted to child pornography, spamming, and identity theft, according to computer security experts...


Last week, Krebs declared that he was going on a campaign to unmask some other criminal organizations working openly and unafraid on the Internet.

Many people miss perhaps the best part of the first report, which was:

Report Slams US Host as Major Source of Badware

Following this report, the comments lit up like crazy, including, as we were shocked to see, Emil K., the owner of Intercage/Atrivo, who proclaimed his innocence, but also promised quick action on any criminal activity, and posted his ICQ number in case anyone had anything they wanted to report:

It was also interesting to see Konstantin Poltev rise to his defense in the comments, also proclaiming his own innocence, and providing his personal email address (kokach@estdomains.com) and promising to take quick action against any abuse on their site saying "We are going to perform a total clean-up, really total."

Another Intercage employee invited anyone who has problems for a tour of his data center, and reminded that you can email "abuse@intercage.com" with abuse complaints, or "russ@intercage.com" or "emil@intercage.com" if you have suggestions to improve their business.


Some of his columns since then have included:
Scammer-Heavy U.S. ISP Grows More Isolated which reminded us that Atrivo is Bad, and showed how Atrivo's various Internet Connectivity sources have been pulling the plug to avoid being associated with their evil.

A Superlative Scam and Spam Site Registrar which introduced the public to what security researchers have long known: Criminals like to register domains with EstDomain, because they ignore abuse complaints and let the crime continue.


EstDomains: A Sordid History and a Storied CEO which called attention to the well-known criminal career of Vladimir Tsastsin, the CEO of EstDomains, and asked the question if we should have a domain registrar who has done time for credit card fraud, document forgery, and money laundering.

Fake Antispyware Purveyor Doubles as Domain Registrar which focused on the practices of Klikdomains, aka Vivids Media GMBH, which has been behind many of the fake anti-virus and anti-spyware products. Because of Krebs work, Directi Internet Solutions, in India, has changed their business practices, and will no longer allow Klik to use its anonymizing service "PrivacyProtect" when registering domains. Directi's president, Bhavin Turakhia, shared with Krebs that nearly half of the 100,000 domains registered by Klik have eventually been suspended for abuse. After Krebs targeted their domains, Directi terminated another 21,000 sites in 48 hours!

The current series by Krebs resulted from some of the replies he received from another Must Read series, called Web Fraud 2.0, the week of August 17-23. The components of that series were:

Web Fraud 2.0: Cloaking Connections

Web Fraud 2.0: Validating Your Stolen Goods

Web Fraud 2.0: Digital Forgeries

Web Fraud 2.0: Distributing Your Malware



Interesting Sidebar found in WIRED along these same lines:
Online Posse Assembles, to Unmask Russia's Hackers
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • Minipost: IPR Center celebrates Cyber Monday
    The National Intellectual Property Rights Center (IPR Center) announced today that in celebration of Cyber Monday, they have Seized 82 Domai...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Work at Home . . . for a Criminal?
    How do you tell if a "Work at Home" invitation is a scam? Here's a clue: It comes in your email. In today's Blog, I tho...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ▼  September (10)
      • Digital Certificate Spammer Goes for Google Adwords
      • Governor Palin's Email: Security Questions in the ...
      • CareerBuilder Latest Digital Certificate Malware T...
      • Internet Landfills: Praise for Brian Krebs
      • Protecting Anonymized Religious Speech Overturns N...
      • FBI Cyber Agent Shawn Henry Earns Promotion
      • Is The Analyzer Really Back? (The return of Ehud T...
      • Work at Home . . . for a Criminal?
      • Hurricane Gustav: Fraud Watch Day Three
      • Hurricane Gustav: Fraud Watch
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile