Live data from Hacker News

German police raid DDoS-friendly host FlyHosting

krebsonsecurity.com

31–40 of 48 posts

Re: German police raid DDoS-friendly host FlyHosting

#31

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Isn't almost any online payment method trivially trackable? Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...

>XMR does things that supposedly make that not really work at all

Any source? Can't find anything.

Re: German police raid DDoS-friendly host FlyHosting

#32

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

I cannot find the reference but I remember reading, not too long ago, that even the professional ransomware gangs can be extremely lazy with their own security. Apparently even some well-known players (not script kiddies) could be identified because they used their personal email address or something similar.

Re: German police raid DDoS-friendly host FlyHosting

#33

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

When I was a kid you could buy these monthly warez CDs full of games and professional software.

The gang producing them got so overwhelmed with burning CDs in their basement, that they went to a factory in Germany.

Police looked at the serial number on the CD, went to the factory and asked who the customer was and that's how they got busted.

Re: German police raid DDoS-friendly host FlyHosting

#35
post #31

Earlier quoted context omitted.

Isn't almost any online payment method trivially trackable? Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...

>XMR does things that supposedly make that not really work at all Any source? Can't find anything.

https://www.getmonero.org/resources/moneropedia/ringsignatur...

I'm not qualified to say whether that actually achieves that goal though

Re: German police raid DDoS-friendly host FlyHosting

#36
post #29

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Most criminals who are caught are not criminal masterminds. The opposite, actually, otherwise they'd probably not be caught, since their opponents aren't of the Sherlock Holmes kind either. Especially in the cyber crime field, where barrier to entry is pretty low. Source: been acting on both sides, for research.

[dead]

Re: German police raid DDoS-friendly host FlyHosting

#37

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

For over 10 years they did nothing to people who bought these kind of things with Paypal, police going after booter users is a fairly recent thing that started in the UK.

Re: German police raid DDoS-friendly host FlyHosting

#38
post #29

I wonder what sort of person is aware enough of DDoS attacks to want to buy one, savvy enough to find where to buy one, yet dumb enough to pay with PayPal. Or accept PayPal if you ran such a service. Given, it says the people running it were 16-24 and adolescent hubris knows no bounds... Maybe the customers were the same general age as the owners?

Most criminals who are caught are not criminal masterminds. The opposite, actually, otherwise they'd probably not be caught, since their opponents aren't of the Sherlock Holmes kind either. Especially in the cyber crime field, where barrier to entry is pretty low. Source: been acting on both sides, for research.

It's literally the WW2 airplane hit patterns image. Criminals who get caught are the ones making the kinds of mistakes that make it easier to catch them.

Organized crime also does a lot of "dumb" stuff but they do it at scale and make it harder to trace back the individual incident to the organization's core. They also heavily rely on disposable accomplices, which is why you still see these "make money doing nothing from home, just let us use your bank account" scams.

Re: German police raid DDoS-friendly host FlyHosting

#39

Off-topic, but why do these seizure notices always look like shitposts? They always give off "graphic design is my passion" vibes.

Design by committee (did you see how many organizational logos are on there?) plus "but make it look more cyber" plus literally done by an office worker who has no formal design training.

Re: German police raid DDoS-friendly host FlyHosting

#40
post #38
post #29

Earlier quoted context omitted.

Most criminals who are caught are not criminal masterminds. The opposite, actually, otherwise they'd probably not be caught, since their opponents aren't of the Sherlock Holmes kind either. Especially in the cyber crime field, where barrier to entry is pretty low. Source: been acting on both sides, for research.

It's literally the WW2 airplane hit patterns image. Criminals who get caught are the ones making the kinds of mistakes that make it easier to catch them. Organized crime also does a lot of "dumb" stuff but they do it at scale and make it harder to trace back the individual incident to the organization's core. They also heavily rely on disposable accomplices, which is why you still see these "make money doing nothing…

Exactly. Also, opsec does not need to be bulletproof if your operation is goverment sponsored or at least government tolerated. There's whole companies, doing downright illegal stuff in the open, enjoying sweetheart treatment by officials. OTOH, a Russian hacker, for example, would know better than to steal from their own countrymen. So they operate in other jurisdictions.

You would be mistaken btw to think this only applies to non-western parts of the world. The spectrum is a wide one, from completely covert operations, over organized crime, to companies and even the government itself. The ones who are caught are usually not the smart ones. Of course, the Dunning Kruger effect is also strong here, so most of them think they're too smart to be caught.

Post reply on HN