Notorious major spammer indicted

Alan Ralsky, at one time believed to be the top spammer in the world, has finally been indicted today by a federal grand jury. His home was raided back in 2005, and he’s now been charged along with ten other people in “a wide ranging international fraud scheme involving the illegal use of bulk commercial e-mailing.” Those indicted include James E. Bragg, 39, of Queen Creek, Arizona. The indictment alleges that Ralsky’s spam gang “tried to send spam” through botnets and engaged in a “pump and dump” stock scam for Chinese companies. The Detroit Free Press’s coverage reports: “Prosecutors described Ralsky, 52, of West Bloomfield, as one of the most prolific spammers in the nation. Until 2005, when federal agents raided his home and seized his computers, his operation sent tens of millions of unsolicited email messages daily to Internet subscribers, hawking everything from sexual enhancement drugs, weight loss products and worthless stock, the government said. In the summer of 2005 alone, prosecutors said, his operation generated $3 million." The DOJ press release is here. ...

January 4, 2008 · 2 min

"Untraceable" looks unwatchable

In January 2008 the film “Untraceable," starring Diane Lane, will be released. It looks awful. The premise is that a serial killer is killing people live on the Internet, via an “untraceable website” that is connected to contraptions that kill his victims as more people visit the site. The whole concept of an “untraceable website” or the idea that such a thing would be unstoppable by ISPs and law enforcement is absurd–the immediate upstream provider of the site would merely need to null route the IP address(es) where the website is hosted, and traffic stops. They’d also be able to quickly identify the customer who owns the server in question. Even if that server was compromised and being used to reverse proxy or redirect traffic to other servers, it would still be a relatively simple matter to track that backwards, though it would be somewhat more difficult than stopping the traffic. Even if the domain name pointed to a new server on a compromised host every second, it would still be possible to contact the domain name registrar and get the domain name shut down. If users can get to it, it can be seen how and what they’re getting to, even if that’s only the front end in a chain of successive proxies. If it has a domain name, that provides another path to shutting off access. UPDATE (January 2, 2008): I came across the script online while searching for information about the writers. Let’s just say that my opinion above is not nearly negative enough. In the first 16 pages are at least six or seven scenes that really bring on the stupid. For example, FBI Agent Jennifer Marsh, who works in the FBI’s cyber division, is monitoring machines that are being compromised by hackers (honeypots, essentially, though the script doesn’t use the word). One of her machines gets compromised and she sees that it copies her files including fake financial information. It then accesses eBay to use a stolen credit card to purchase a watch. In reality, the stolen financial information wouldn’t be likely to be used from the same machine, it would be sold to another player in the underground economy. Marsh then types commands to look for the IP address of the connecting host–but if they’ve already got honeypots or honeynets in operation, that should already be logged. She then does the usual CSI-style conversion of an IP address into a name and address without issuing a subpoena to an ISP, and discovers that it’s a home belonging to a 56-year-old woman. She immediately concludes that the actual criminal must be a neighbor using her wireless connection, despite the fact that she has no evidence that the woman has a wireless access point and isn’t just another victim with a compromised machine being used as a proxy. Without doing any more verification, she arranges to get a warrant to knock the door of the neighbor down, and it turns out to be a teenage kid. On p. 16 appears this nice quote: “She types several commands into a unix shell. Trace routing algorithms begin to run. A different screen shows possible IP addresses. The list begins growing, from ten to hundreds to thousands…. Marsh shakes her head at the futility.” There are multiple methods of performing traceroutes and even of adding fake hops to a traceroute, but traceroute is unnecessary to find out the IP address of a website–it’s only useful for finding the path traffic takes to get to that website, e.g., for finding the upstream provider. But getting a list of upstream providers is better done by looking at routing tables rather than doing traceroutes, anyway. The real investigative steps would be to look at the DNS information for the domain, get the IP address or addresses from the authoritative name server (and check to see if those are changing with a short TTL), then find the upstream providers. Funniest exchange I’ve seen so far in the script (p. 26) is this marvel of self-contradiction: [FBI agent] GRIFFIN: I traced it to a Georgetown sophomore named Andrew Kinross. But then I looked closer and saw the post didn’t actually originate from his computer. MARSH: Our guy got into his computer and posted it from there. GRIFFIN: That would be my guess. MARSH: So let’s go after the originating computer’s IP. And so far, I’ve not mentioned how the hacker mastermind hacks into the FBI agent’s car (which features the fictional “NorthStar” instead “OnStar”)–in the preview, the hacker apparently is able to control the steering of her car. I suspect drive-by-wire steering will come soon in the future of the automobile, but I don’t believe it exists today. (Turns out the preview gives a misleading impression of what the script says is happening–the hacker doesn’t actually control the steering, but remotely shuts off the car’s electrical systems and power steering.) ...

December 19, 2007 · 35 min

Signs in my neighborhood

Gives you some idea of the local demographic and economic conditions (or at least what the people behind these signs believe it to be).

December 9, 2007 · 1 min

Fake weeping Virgin Mary painting

I wish I had seen this before my Channel 3 News interview about a similar painting coming to Phoenix. From Associated Press, September 19, 2007: BLANCO, Texas – Samuel A. Greene Jr., the founder of a monastery that closed amid scandal over the alleged sexual abuse of novice monks and a fraudulent weeping Virgin Mary painting, has died. He was 63. Greene’s death was being investigated as a suicide, but officials were waiting for autopsy results before ruling on the cause of death. Greene’s body was found Monday morning in his home on the grounds of Christ of the Hills Monastery. ...

November 24, 2007 · 2 min

Fox News Anchor calls for U.S. to support terrorism in Iran

If you advocate torture and car bombs, how can you have any moral justification for saying that those who use such tactics against us are wrong or evil?

November 10, 2007 · 1 min

More on waterboarding as torture

Ed Brayton at Dispatches from the Culture Wars observes that “the US has not only always considered waterboarding to be torture, but has aggressively prosecuted other nation’s for war crimes for using that technique on American POWs,” quoting Judge Evan Wallach: After World War II, we convicted several Japanese soldiers for waterboarding American and Allied prisoners of war. At the trial of his captors, then-Lt. Chase J. Nielsen, one of the 1942 Army Air Forces officers who flew in the Doolittle Raid and was captured by the Japanese, testified: “I was given several types of torture. . . . I was given what they call the water cure.” He was asked what he felt when the Japanese soldiers poured the water. “Well, I felt more or less like I was drowning,” he replied, “just gasping between life and death." ...

November 8, 2007 · 4 min

Spammers and criminals for Ron Paul

From metafilter: When Ron Paul email spam started hitting inboxes in late October, UAB Computer Forensics Director Gary Warner published findings on the spam’s textual patterns and the illicit botnet used to spread it – findings which were picked up by media outlets and tech websites like Salon, Ars Technica, and Wired Magazine’s “Threat Level” blog, the latter in a set of followup posts by writer Sarah Stirland: 1, 2, 3. The Ron Paul fan response was swift and decisive: clearly the botnet was the work of anti-Ron Paul hackers trying to discredit his campaign, and Rudy Giuliani had paid Stirland (and not UAB Computer Forensics) to do a smear piece – as claimed by a YouTube video pointing to posts on RudyGiulianiForum.com. Thus proving, once again, that the Ron Paul campaign’s greatest liability is not so much his far-right conspiracy-driven antifederal libertarianism, but rather the spittle-flecked anger of his own noisiest supporters.There are definitely a lot of nuts among Ron Paul’s supporters. Meanwhile, he raised $3.8 million yesterday (apparently a number revised downward from $4.3 million) in the largest one-day online political fundraiser ever. Intrade currently shows Paul as the third most likely GOP nominee, after Giuliani and Romney. A few other Ron Paul-related blog posts that I realize I’ve neglected to mention here, from Dispatches from the Culture Wars: “Is Ron Paul a Dominionist?" Argues that Paul appears to have much in common with some theocrats. “Sandefur on Ron Paul” Doubts that Paul is a dominionist, but suggests he might be a Thomas DiLorenzo-style neo-confederate who thinks we don’t even need a federal government (in which case he wouldn’t really be the supporter of the Constitution that he seems to be) and that the U.S. Civil War wasn’t about slavery (which is pernicious nonsense). I also just came across this story, which says that Paul would like to see the U.S. Constitution amended to remove the subject of abortion from the purview of the courts, which is yet more anti-constitutional insanity. ...

November 6, 2007 · 17 min

Break-in at CI Host colo facility

The Register (UK) reports that C I Host, a webhosting provider, has now had a fourth break-in at its Chicago colocation facility. Someone cut through a wall with a saw and stole customer equipment (and the DVRs or tape recording devices for the CCTV system). C I Host apparently took days to inform its customers of the break-in, and some have voiced suspicions that it was an inside job. UPDATE (February 4, 2007): There was some followup discussion.

November 5, 2007 · 1 min

Nacchio says government punished Qwest for noncooperation on eavesdropping

Former Qwest CEO Joseph Nacchio, found guilty of insider trading in April, is claiming in his appeal that part of the reason Qwest stock dropped in value is that the NSA cancelled some lucrative contracts with the company as punishment for its failure to cooperate in illegal warrantless wiretapping (unlike AT&T and Verizon). The Bush administration is pushing for retroactive immunity to be granted to AT&T and Verizon for its participation in these unconstitutional programs by threatening to veto any surveillance bill that doesn’t include such immunity. If the Democrats were smart, they’d go ahead and send him a surveillance bill without the immunity, and then criticize him when he vetoes it for taking action that is going to kill Americans. ...

October 13, 2007 · 1 min

CIA head investigates CIA Inspector General

CIA Director (and former head of the NSA) Gen. Michael Hayden is unhappy with CIA Inspector General John Helgerson’s work uncovering abuses at the CIA, so he’s ordered his own investigation of the IG, including an examination of the office’s confidential files. That’s sure to put a chill on employee cooperation with or reporting of abuses to the IG’s office.

October 13, 2007 · 1 min
Mastodon Verification