kai axford mba, cpp, cissp, ace manager, it security services accretive solutions...

53
Trends in Cybercrime 2010 Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolution s.com SESSION CODE: SIA339 Allyn Lynd Special Agent, Cybercrime Division Federal Bureau of Investigation [email protected]

Upload: katerina-hold

Post on 16-Dec-2015

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Trends in Cybercrime 2010Kai Axford MBA, CPP, CISSP, ACEManager, IT Security ServicesAccretive [email protected]

SESSION CODE: SIA339

Allyn LyndSpecial Agent, Cybercrime DivisionFederal Bureau of [email protected]

Page 2: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Our Agenda

IntroductionsThe Case of Little HackerThe Case of Ghost ExodusWhat else is out there?Questions

Page 3: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

“Swatting”It’s not what you think…

In my former job, this was “swatting”….

Page 4: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

“Swatting”It’s not what you think…

In my former job, this was “swatting”….….but now we add a new weapon.

Page 5: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

“Swatting”It’s not what you think…

In my former job, this was “swatting”….….but now we add a new weapon.

Wiki defines it as “an attempt to trick an emergency service (such as a 911 operator) to dispatch an emergency response team.”

Page 6: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

“Swatting”In Summary…

Page 7: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

START: The Case of Little Hacker

CASE STUDY

Page 8: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: BackgroundTook place: 2002 – PresentStates involved:

Colorado, Florida, Louisiana, Maryland, New York, Nevada, Ohio, Texas, and Washington

Page 9: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case StudyThe Telephone Party Line

Page 10: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: The PlayersMatthew Weigman (“Little Hacker” & “Silence”)

Was a MinorTechnical Support ReconnaissanceHacks/Phreaks/Social EngineersMakes Swatting Calls & Wire TapsTurns Phone Service On And Off

Page 11: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Group LeaderDirects & Conducts Swatting Technical Support & TrainingExtorts VictimsWiretaps Turns Phone Service Off & On

Case Study: The Players Stuart Rosoff (“Michael Knight”)

Page 12: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Conducts SwattingExtorts Victims

Case Study: The Players Guadalupe Martinez (“Wicked Wizard” & “Mexican Warrior”)

Page 13: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Commits I.D. TheftMakes Swatting CallsThreatens Victims

Case Study: The Players Jason Trowbridge (“JohnfromCA” & “JasonfromCA” & “MrStoner”)

Page 14: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Threatens VictimsPurchases Spoof CardsRuns Party Line Web SiteOperates A Party Line

Case Study: The Players Chad Ward (“Dark Angel”)

Page 15: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Makes Swatting Calls

Case Study: The Players Charles Nalley (“Madison”)

Page 16: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Targets VictimsObtains Target I.D. Information

Case Study: The Players Angela Roberson (“Amber” & “Lil Miss Angela”)

Page 17: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: The “Jackie Donut”

Page 18: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: Let’s Make It RealLet’s listen to some of the actual calls made by these guys…Here’s some of the party line discussions….

AudioHere is an actual call made to a 911 dispatcher….

AudioThe Address

Page 19: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

TexasJohnson County SheriffFort Worth PoliceHouston Police

ColoradoEl Paso County Sherriff Security Police

LouisianaNew Orleans Police

FloridaPort Richie Police

New YorkSyracuse Sheriff

MarylandBaltimore Police

OhioCleveland Police

WashingtonKent Police Snohomish County Sheriff

NevadaLas Vegas Police

Case Study: The VictimsFirst Responders (100+)

…and many more!

Page 20: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

VerizonAT&TQwestComcastSprintFrontierOnetelcoAmeritechSouthwestern Bell

MCITime WarnerRoadrunnerEmbarqRippleBeVocalSkypeVonageSBC Global

Case Study: The VictimsTelecommunication Providers

…and many more!

Page 21: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: The PlayersMatthew Weigman (“Little Hacker” & “Silence”)

Obstruction of Justice11 years

Page 22: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Guilty Plea 5 year sentence

Case Study: The Players Stuart Rosoff (“Michael Knight”)

Page 23: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Pled Guilty2.5 year sentence

Case Study: The Players Guadalupe Martinez (“Wicked Wizard” & “Mexican Warrior”)

Page 24: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Guilty Plea 5 year sentence

Case Study: The Players Jason Trowbridge (“JohnfromCA” & “JasonfromCA” & “MrStoner”)

Page 25: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Guilty Plea 5 year sentence

Case Study: The Players Chad Ward (“Dark Angel”)

Page 26: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Obstruction of Justice9 years

Case Study: The Players Charles Nalley (“Madison”)

Page 27: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Guilty Plea 2.5 year sentence

Case Study: The Players Angela Roberson (“Amber” & “Lil Miss Angela”)

Page 28: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: Why Prosecute in North Texas?Texas residents are charged for 911 services on their monthly phone bill. 911 calls made by spoofed CallerID is a violation of 18 U.S.C. 1029(a)(9).

6/12/2006: Martinez made 911 swatting call to Cleburn, TX 911 emergency services.

10/1/2006: Martinez made 911 swatting call to Fort Worth, TX 911 emergency services.

10/6/2006: Weigman made unauthorized access to Verizon NOC in Irving, TX

10/8/2006: Weigman made unauthorized access to CTS Telecom in Grand Prairie, TX to facilitate swatting 911 call in violation of 18 U.S.C. 1030(a)(5)(A)(ii)

Page 29: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: How Did They Do It?Use of TechnologyExtensive knowledge of telephone systemsSocial Engineering

Internal employees trying to be helpfulHackingCollaborating

Sharing pass wordsDiscussing law enforcement avoidance

Page 30: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

END: The Case of Little Hacker

CASE STUDY

Page 31: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Conspiracy 18 U.S.C. 371 to commit:Fraud in connection w/ access devices 18 U.S.C. 1029(a)(9)Fraud in connection w/ computers 18 U.S.C. 1030(a)(5)(A)(ii)Conspiracy maximum sentence is 5 yearsUnderlying offense maximum penalty is 20 years

NEW 1030 CONSPIRACY CAN NOW BE USED

“Swatting”So what can I be charged with if I “swat”?

Page 32: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

START: The Case of Ghost Exodus

CASE STUDY

Page 33: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: BackgroundTook place in 2009States involved:

TexasThe fallout is still ongoing. Apparently his crew isn’t real happy with his incarceration.

Page 34: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special
Page 35: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special
Page 36: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Conducted breach of healthcare facilityUploaded video to YouTubePled Guilty to two counts of “transmitting malicious code”

He installed a “bot” onto the machine.

Sentencing in September 2010

Case Study: The Players Jesse McGraw (“Ghost Exodus” & “PhantomExoDizzmo)

Page 37: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: Let’s Make It RealLet’s watch some of Ghost Exodus’ fine work…

Page 38: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special
Page 39: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Renamed to Evolution of ETA (EoETA) after McGraw’s arrest.<yawn> “Free Ghost Exodus…blah blah”

Here’s their website…

Case Study: The Players Elektronic Tribulation Army (“ETA” and “EoETA”)

Page 40: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special
Page 41: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

END: The Case of Ghost Exodus

CASE STUDY

Page 42: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Case Study: How Did He Do It?Use of TechnologyExtensive knowledge of employer’s computer systemsPhysical Access

Page 43: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special
Page 44: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Lessons Learned“Old Skool” still works.

It’s not all about “cutting edge technology”Phreaking is alive and well.Social engineering is a major threat. Are you training your employees?

Are you monitoring?The threats? What is put on the Internet about your business?This includes background and credit checks on key roles.Do your homework! The bad guys are certainly doing theirs.

It’s time to get physical!If you lose physical control, then the battle may be already lost.Who has access? When? Why? For how long?Shameless Plug:

SIA 340: Gates, Guards, and Gadgets - Physical Security for ITTuesday, 8:00AM – 9:15AM(Yes, I realize that’s early and your 15 blocks from Bourbon Street.)

Page 45: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

So what else is on the radar?Identity Theft

PersonalBusiness (aka “Brandjacking”)

Theft of Trade SecretsCyber terrorism…and so much more!

Page 46: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Questions?Kai Axford MBA, CPP, CISSP, ACEManager, IT Security ServicesAccretive [email protected]

SESSION CODE: SIA339

Allyn LyndSpecial Agent, Cybercrime DivisionFederal Bureau of [email protected]

Page 47: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Track Resources

Poulson, Kevin. Blind Hacker Sentenced to 11 Years in Prison. June 2009. http://www.wired.com/threatlevel/2009/06/blind_hacker/McGrew, Wesley. Mcgrew Security Blog. May 2010. http://www.mcgrewsecurity.com/YouTube

“Response to Cashis Clay”“Post July 4th Infiltration”“Hospital Hacker CBS News”

Page 48: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Related Content

SIA 340 – Gate, Guards, and Gadgets” Physical Security for ITTuesday, 8:00AM – 9:15AMSessions (session codes and titles)Where else can you touch razor wire or bulletproof glass? Ever seen an IP surveillance system in action? Join us tomorrow!

Page 49: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Resources

www.microsoft.com/teched

Sessions On-Demand & Community Microsoft Certification & Training Resources

Resources for IT Professionals Resources for Developers

www.microsoft.com/learning

http://microsoft.com/technet http://microsoft.com/msdn

Learning

Page 50: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Complete an evaluation on CommNet and enter to win!

Page 51: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

Sign up for Tech·Ed 2011 and save $500 starting June 8 – June 31st

http://northamerica.msteched.com/registration

You can also register at the

North America 2011 kiosk located at registrationJoin us in Atlanta next year

Page 52: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to

be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Page 53: Kai Axford MBA, CPP, CISSP, ACE Manager, IT Security Services Accretive Solutions kaxford@accretivesolutions.com SESSION CODE: SIA339 Allyn Lynd Special

JUNE 7-10, 2010 | NEW ORLEANS, LA