CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

fighting back for the right reasons

 
Post new topic   Reply to topic       All -> FavForums -> DDoS [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Sep 11, 2007 3:57 am    Post subject: fighting back for the right reasons
Reply with quote

Hi folks, no matter how good intentioned it is to fight crime sites with attacks, its something castlecops does not encourage. From a post I made in another thread I explain why:

Quote:
I want to make it clear that CastleCops completely discourages any attack on any computer system. In fact, such actions are against US Law.

http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00001030----000-.html

Title 18 Section 1030(a)(5)(A)(1)
Quote:
knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;


Title 18 Section 1030(e)(2)(B)
Quote:
which is used in interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States;


Title 18 Section 1030(e)(Cool
Quote:
the term “damage” means any impairment to the integrity or availability of data, a program, a system, or information;


There is an article from the DOJ that describes the above:

http://www.cybercrime.gov/ccmanual/01ccma.html

See sections:

http://www.cybercrime.gov/ccmanual/01ccma.html#tocF.

http://www.cybercrime.gov/ccmanual/01ccma.html#tocF.1.

http://www.cybercrime.gov/ccmanual/01ccma.html#tocI.

CastleCops does not tolerate such behavior, no matter who the target is. Anyone participating in such a behavior is not harming the bad guys, but rather innocent victims, and putting yourselves into illegal activity as proclaimed in the above statute.


Tembow wrote it best for me:

Quote:
Here is one basic principle:
Never do evil that good may come of it.

Here is another:
The principle of non contradiction: an action cannot be and not be at the same time. So if you decide to break the law in order to stop criminals, you can not claim to be not breaking the law at the same time.

Ethics 101. Stand those two principals up against "the end justifies the means" or "it's a war out there so different rules apply" - sorry, I don't buy that.


From my personal experience, establishing relationships and working with them goes further during the long term than attacking back does.



Last edited by Paul on Thu Dec 13, 2007 9:59 pm, edited 1 time in total
Back to top
View users profile Send private message Send email Visit posters website
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Tue Sep 11, 2007 4:34 am    Post subject:
Reply with quote

Acknowledged!


_________________
I wish you all the best and nothing less.
Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Tue Sep 11, 2007 6:45 am    Post subject: Re: fighting back for the right reasons
Reply with quote

Paul wrote:
establishing relationships and working with them goes further during the long term than attacking back does.
Establishing relationships with law enforcement, or with criminals?
I'm a bit confused here.

Back to top
View users profile Send private message
Lord_Vader

Corporal
Corporal


Joined: Sep 08, 2007
Posts: 58
Location: Germany

PostPosted: Tue Sep 11, 2007 7:01 am    Post subject:
Reply with quote

In the case of AA419.ORG it means establishing relationships with hosters/ISPs and law enforcement, as well as regulatory bodies. In fact, our database has become a regular ressource for them.
The criminals get nothing but an UPYRS from us. Wink
I think Paul is saying something similar.

Back to top
View users profile Send private message
PAN_IRISH
Currently banned

Major
Major
Premium Member

Joined: Feb 01, 2007
Posts: 1005

Premium

PostPosted: Tue Sep 11, 2007 8:11 am    Post subject:
Reply with quote

yes,
i think so too,
because we end up engaging in the same debilitating tactics if we retaliate and waste someone else's bandwidth and cash assets.
the innocent ones are caught in the middle.
..
...


_________________
I wish you all the best and nothing less.
Back to top
View users profile Send private message
spamislame

SIRT Handler


Joined: Apr 19, 2006
Posts: 203


PostPosted: Tue Sep 11, 2007 7:17 pm    Post subject:
Reply with quote

When I first started getting involved in all of this, my only motive at the time was wasting a spammer's time and leeching their profits.

I started by creating nonsense postings for mortgage forms in 2002 or so. This definitely made some of them mad enough that they chose to DDOS my home pc.

After that died down, I began work on a more smoothly automated targeted mortgage retaliator which became the basis for the Refi Retaliator II, which SpamSlayer ultimately refined. This created believable fake identities and most definitely ate up a large amount of the spammers' profits. Each contact entry had to be verified, which also ate up a lot of time.

Later I focused on retaliating against pharmacy sites and the retaliators got more and more robust with each iteration.

By the same token, I also joined in the domain reporting which Terry got to the lean / clean state that it's in now.

My point: I will still retaliate via time-wasting means against a spammer's website. I'm not sure I would use a tool like Lipo much if at all simply because (yes) that is really stooping to their level. It also definitely does result in swift retaliation from the spammers. The same is true if you attempt to play around with any of their Storm Worm infection ip addresses. I prefer something stealthier that takes the spammers a bit more time to figure out what's going on, meantime we're also reporting their DNS.

If I discover that a site is hosted on botnet servers, my first tactic is to report the infection, plus report the domans and DNS. Then I'll place several fake orders for whatever it is they're attempting to promote. Smile I would never attack any of these servers, and I do enough research overall that you can likely believe that statement.

Also: following up on cancelled orders can eat up a huge amount of their profits. Any of these sites that feature a live chat feature or an 866 number: I complain to them repeatedly. (Not like I have all the time in the world.) Seveal sites have since gotten rid of the live chat feature, probably because I cost them enough not to warrant using it anymore.

There is attacking, and there is retaliation. I side with retaliation personally, and I do think it's distinct from just shotgun-blasting traffic.

SiL

Back to top
View users profile Send private message
Dogteams1

Cadet
Cadet
Premium Member

Joined: May 10, 2006
Posts: 6
Location: USA
Premium

PostPosted: Thu Sep 13, 2007 3:45 am    Post subject:
Reply with quote

Hi Paul

I agree very much with your Rules and Theory.
Sorry to see this crap coming down the pipe.
I guess i missed my Addy you send out once a month.
It dos sometimes makes you want to put the harm on these Bad guys.But like you say that would make us all bad guys or a Bunch of Vigilantes.
I did't know anything about all of these dos crap until tonite.This is a Bummer.............
Mark T Sunbelter
P:s I talked to Alex in email Exchange once a week.
But i hav'nt seen anything on his blog about it i think it is better to have a closed mouth on whats going on.


_________________
Dogteams1 Beta Tester for sunbelts Counterspy,2008 Member of the Professional Security Testers.Beta Tester for "Vipre"Mozlla"Plus Developers"for Firefox 3
Also been Testing Firefox Betas...........
Still Studying for my (CEH)
Guitar Teacher for Private Advanced Lessons.........
Play in my band on Week-ends.
Also belong to Rapid Resonse Team SunBelt 2005-2008
Now working for the Sunbelt Co.
Back to top
View users profile Send private message Visit posters website Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> DDoS All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer