Yahoo Hacker 'Mafiaboy' Eight Years On 183
An anonymous reader writes "Eight years ago Mafiaboy (Michael Calce) knocked Yahoo offline. Today he he works as a legitimate security consultant and has just published a book documenting his criminal career and offering advice on how people can protect themselves from people like him on the Internet."
But i thought... (Score:2, Interesting)
Re:But i thought... (Score:5, Insightful)
Re:But i thought... (Score:4, Informative)
It might be flamebait, but it is true. This guy is Canadian, living in Canada. US Federal law ? What about it?
As to whether he has such a gap in judgement, he was 15 at the time of the hack. Who does not have gaps of judgement at that age?
Re:But i thought... (Score:5, Funny)
Hell, I'm 93 and I still have gaps of judgement.
Oh wait, those are gaps of memory.
Get off my lawn!
Re:But i thought... (Score:5, Informative)
Re: (Score:1, Funny)
Probably because Canada is not part of the US yet?
Got to love how Canadians write a statement... that ends with a question mark.
Re:But i thought... (Score:4, Funny)
Probably because Canada is not part of the US yet?
Got to love how Canadians write a statement... that ends with a question mark.
Probably because Canada is not part of the US yet, eh?
There fixed it for ya.
Re: (Score:2)
Probably because Canada is not part of the US yet, eh?
I'm British, and as such, can't really hear a difference between Canada and the US. However, I am trying to learn, so I can continue to mock those North Americans who can't tell the difference between Australian and Scouse [iana.org]. So, whenever I hear a Canadian speaking, I try to look for things that distinguish. And I can't hear any. 'Specially not any 'eh' at the end of the sentence. Please advise.
Re: (Score:2)
Re: (Score:2)
If they say Rrrrr they are a pirate, else they are Canadian.
Re: (Score:2)
Well, if you catch anybody saying "Rrroll up the rrrim to win" [wikipedia.org], there's a good chance they're Canadian.
Actually, I'm Canadian, and I can't hear a difference between Canadian and US accents, but people from the US tell me otherwise. I was in a diner in New Jersey and the waitress said "Wow, you have a really thick Canadian accent." Even worse, I knew a girl from Texas and she laughed whenever she heard me say "about" [wikipedia.org].
Re: (Score:3, Funny)
Don't worry. Once Phase One is complete and your economy has crashed, we'll start Phase Two. Once we've bought up your economy and banks, your chance to be Canada's fourth territory will commence.
Re: (Score:3, Insightful)
Today he he works as a legitimate security consultant
I believe the problem word here is "legitimate"... If one has that large of a gap in judgement, most "legitimate" employers won't hire you. And that's the way it should be.
Re: (Score:1, Insightful)
If one has that large of a gap in judgement.. ...When he was 15. Everyone does crazy stuff when they are 15. I know I did. Didn't you?
Re: (Score:2, Informative)
If one has that large of a gap in judgement.. ...When he was 15. Everyone does crazy stuff when they are 15. I know I did. Didn't you?
No.
Re:But i thought... (Score:5, Interesting)
Even as a teenager, I had a strong self-preservation instinct. I knew the difference between a felony and a misdemeanor.
Re:But i thought... (Score:4, Informative)
There are two types of people: people who did crazy shit when they were 15 and
FUCKING LIARS!!
Re: (Score:3, Insightful)
Re: (Score:2, Informative)
Re: (Score:2)
I get mod points 6 days out of 7, and today by some rift in the time-space /. continuum, I have none.
+99 Truthiness
Re: (Score:2)
no no no no NO, never regret, personally I've screwed up more than I care to count, but those screw ups let to the person I am today; wouldn't have it any other ways.
(oh on a side note, any one else done stupid stuff as 15 years old that would get you caught up in the anti terror laws today?)
Re: (Score:2, Funny)
Re: (Score:2)
I'm given to wonder how I got modded +3 informative for typing 'no'.
Mind you, it seemed the simplest way to say that some of us manage to get through our teens without committing crimes.
Re: (Score:3, Insightful)
It's natural to excuse your own behavior by claiming everyone else does it too. Doesn't make it true.
No, not everyone does "crazy stuff" when they are 15. Many know better.
Re: (Score:1)
Re:But i thought... (Score:4, Insightful)
Felony or Marketing? (Score:2)
Re: (Score:2)
Well it's certainly better than DeVry!
Re: (Score:2)
There's a world of difference between staying out after curfew or getting drunk enough to throw up on your dad when he confronts you as you try to sneak in through the patio door, and knocking a major Web portal offline. Any 15 year old should understand the difference between those two, let alone a 30 year old pining for when he was 15.
Re: (Score:2, Informative)
Common misconception.
1. Most laws regarding this are state laws.
2. Reading from wikipedia, most of these laws don't hold up.
http://en.wikipedia.org/wiki/Son_of_sam_laws [wikipedia.org]
Why did I go to college? (Score:5, Interesting)
While the rest of us were going to college, this guy had the formula to quick success.
Hack into large company web sites
Get a slap on the wrist
Become a reformed hacker/security expert
Write book on exploits
$PROFIT!
Re: (Score:2)
Actually...it was probably more because the personal computer didn't really come on the scene until after I was an adult and the internet as it's known today much later. I may not have had the '1337 skills' (and most people who say they are '1337' in anything usually aren't.) But I would have had the interest and the time to see what I could get into. I'm still interested in security issues although from a different viewpoint. I find computer forensics fascinating.
Re: (Score:2)
Alabama.
WARNING! (Score:5, Funny)
I bought this book, but it intentionally contained too many pages and overflowed my bookcase. It fell off the end, and gave my cat a fatal error. While I was in the back garden burying Muffins, he sneaked into my house and stole all my stuff!
Re:WARNING! (Score:5, Funny)
I bought this book, but it intentionally contained too many pages and overflowed my bookcase. It fell off the end, and gave my cat a fatal error. While I was in the back garden burying Muffins, he sneaked into my house and stole all my stuff!
It took me three readings of that to parse that "Muffins" was the name of your cat. My first impression of your post was a lot more surreal.
Re:WARNING! (Score:4, Funny)
"Are you awake dear? I feel the need to bury my muffins".
Re:WARNING! (Score:4, Funny)
Fix typo please (Score:1)
"Yahooo"? Spellcheck, Taco. (Score:2)
Re: (Score:1, Offtopic)
What a joke. (Score:2, Funny)
Sounds like he paid for his crime...
Oh wait. He is being paid for his crime?
WTF
Words of Wisdom from a Script Kiddie (Score:5, Interesting)
Chapter two, "I installed the win32 exe called 'zombie', next I clicked on the Dee DOS button and took out CNN"
Re: (Score:1)
Re: (Score:2)
He was on the news the other day. Apparently he can't remain quiet about computer security anymore. He mentioned that online banking seemed "crazy" to him.
Once again (Score:1)
Re: (Score:2, Insightful)
Actually, crime does pay... until you get caught. And according to the US justice and political system, if you have made the right friends and spent some of your money in the right places (campaigns) then even if you do get caught, crime continues to pay. Just remember to forget how many houses you have.
Yeah, go ahead, mark this troll, but it's true.
Books by crooks (Score:1)
Re: (Score:2, Funny)
Re: (Score:3, Funny)
Aware the author is a crook?
I would not buy this cracker's sham,
I do not like it, Sam I Am!
(apologies to the great Dr Seuss :P)
Re: (Score:1, Funny)
No. People here will torrent it.
Re: (Score:2)
I'm more interested in how comfortable people are hiring crooks as security consultants.
Re: (Score:1)
Re: (Score:2)
Even that's illegal. [usatoday.com]
Re: (Score:2)
I do feel comfortable(but I won't buy it... saving on dead trees at the moment), but on the other hand, just because I buy the book, doesn't mean I feel obligated to believe what's in it...
Well... (Score:2)
Do people here feel comfortable buying books by crooks?
It does seem less risky than electing them.
Why? (Score:2)
I don't see what makes him any more insightful in this area, aside from some ancient history. Looking at the domain mafiaboy.com I wouldn't expect much of anything from this book.
As for advising the masses in how to stay safe, the rules are so basic for everyday users that I doubt a security consultant could offer anything considerably insightful:
1) Don't run files whose source you don't trust
2) Read prompts before clicking yes, default answer should be no unless you specifically understand what it's talk
Re:Why? (Score:5, Interesting)
Err... no. Assuming you're running Linux (or OSX, BSD, whatever) 1, 4 and 5 still apply just as much as they do on Windows.
1) Don't run files whose source you don't trust
Binaries can be dangerous on Linux, especially if you're a newbie user who runs things as root (and we are talking about newbies here remember). Even compiling your own apps can be dangerous if the source of the source isn't trustworthy.
4) Avoid going to domains you aren't familiar with, as they could contain exploits which can bot your machine without any interaction - stick to reputable sources of information
You're not going to be running into self-installing ActiveX malware, but you're in just as much danger from phishing, XSS or browser exploit hacks.
5) Keep your AV and Firewall up to date
The firewall issue is obvious. You need one even on a Linux PC. Maybe moreso even because Linux often comes with a raft of server and daemon stuff that Windows doesn't. AV is more contentious - but if you're using the computer for anything important, eg work related, and you don't want to pass viruses on to clients then AV is still a useful tool. I'm certain that me passing on a virus to a client would do more damage to my business than actually having my computer affected by one itself.
Your operating system is never enough for you to take a liaise faire attitude to security regardless of what you're running.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
4) Avoid going to domains you aren't familiar with, as they could contain exploits which can bot your machine without any interaction - stick to reputable sources of information
How would one realistically do that? Since I wouldn't dare claim I knew every place on the net that I'll ever need, how can you go to only trusted domains when searching for information?
Re: (Score:2)
The same way you would do so at the library?
Find a reputable primary source, then follow sources that they cite. For example, if your doing research start with a reputable journal such as the Harvard Business Review, then refer to sources they cite for further detail. More generically, start at CNN.com or wikipedia or some other "large brand" of website, and use it for direction before clicking on any link that comes off google.
By no means a full proof or robust approach, but its a good start. This assum
Re: (Score:1)
Re: (Score:2)
Not worth the time (Score:5, Insightful)
The excerpt [mafiaboybook.com] reads like a pre-teen love story.
I downloaded and then I pressed enter
I installed and then I was online
And thats chapter 5, what the hell does he write about (being all of 9 years old) for the first 4 chapters?
This won't qualify as proper fish wrapping.
Re: (Score:2)
I guess, not surprisingly, he was just a script kiddie - he downloaded hacks and ran them and thought he was a cool 133t h4x0r.
Doesn't say much for Yahoo if they hadn't protected themselves from known exploits, although I assume they learnt from the lesson.
What I always wanted to ask... (Score:4, Interesting)
Re:What I always wanted to ask... (Score:5, Interesting)
Well, assuming you posed the question to me (I was convicted of telephone fraud (phreaking) once, and discharged without conviction on charges of breaches of the telecommunications act (unlawful entry to a computer system that wasn't my own (a bank))), I would have to answer as follows:
There is almost nothing you could have done to deter me from those actions. I felt as if I was a part of a "wild frontier", and had control and abilities that very few others possessed (and, I was probably right). The feeling was that of real power - something that most people in their very early teens (when I was arrested for the crimes mentioned) don't often get a lot of... especially as the "geeky kid" at school who got picked on all the time (this was the early 90s in small town New Zealand - not the best place for a geek). Trying to convince anyone to willingly give up that sense of "worth" without getting something equal in return is pretty much impossible.
It's also worth noting that I was caught twice, for what was hundreds, if not thousands, of criminal activities. I still felt pretty bulletproof (especially after the "discharge without conviction" for the bank crack)
I made my mistakes, but honestly, I don't regret it even to this day - my current work has nothing to do with security, although I still keep up in those circles and like to hone my skills against my own systems. But, I've also never had any negative consequences other than the court imposed penalty for the phreaking (which was surprisingly minor - especially in relation to the police recommendation). If a kid were to come to me today and ask if he/she should do it, my answer would be that they should do what they feel is right and accept the consequences if they do something illegal and get caught at it. I'm not 100% sure that even means I would try to discourage them...
Of course, I was a cracker and a phreaker... not a script kiddie. "Mafiaboy" may be a little different.
Deterence... (Score:1, Flamebait)
There is almost nothing you could have done to deter me from those actions.
What if the month before a vigilante group of Yahoo fanpunks had made Michael Calce swallow his own testicles and released the video on You Tube?
would you still have been as willing to phreak then?
Re: (Score:2)
Besides - YouTube didn't exist in the early 90s when I was doing that sort of thing.
Re: (Score:2, Insightful)
No, actually you were wrong. There are many, many bright people who have the ability to do what you did - far more than you realize. The difference was that they had something that you lacked - the moral judgment not to go breaking into other people's systems, and instead to do something productive with their abilities.
It's like a bunch of teenaged burglars thinking the
Re: (Score:3, Interesting)
There are many, many bright people who have the ability to do what you did - far more than you realize.
Hmmm... as I mentioned, I lived in small town New Zealand, and it was the early 90s. I really don't think there were too many other people around with the same skills that I had. Now, you then said:
But the truth is that almost anyone can become a burglar, provided they choose to do so (emphasis mine)
I never said others couldn't BECOME able to do what I did, simply that very few others actually possessed the required skills. In the early 90s, computer crime wasn't the "cool" thing that it had become after the web explosion in the mid to late 90s. It wasn't unheard of, and was gaining popularity (see movie
Re:What I always wanted to ask... (Score:4, Interesting)
There is almost nothing you could have done to deter me from those actions. I felt as if I was a part of a "wild frontier", and had control and abilities that very few others possessed (and, I was probably right). The feeling was that of real power - something that most people in their very early teens (when I was arrested for the crimes mentioned) don't often get a lot of... especially as the "geeky kid" at school who got picked on all the time (this was the early 90s in small town New Zealand - not the best place for a geek). Trying to convince anyone to willingly give up that sense of "worth" without getting something equal in return is pretty much impossible.
To distill down your stated motivations, you were seeking power and a form of acceptance. Not much different from most young criminals, really. And the same thing could've motivated you not to do it as does motivate them: friends who value you without requiring that you break laws.
This is why it's so important to get young kids involved in after school activities and clubs. Sure, you might not have been interested in joining a youth soccer league, but what about a chess club? Or a gaming group? Basically, anywhere where you can make friends (in real life) and get positive feedback and acceptance. If you had had those, would you still have felt the need to break into banks?
Re:What I always wanted to ask... (Score:4, Interesting)
To distill down your stated motivations, you were seeking power and a form of acceptance.
Primarily the former rather than the latter... you can't really have "power" (over people) without at least some kind of acceptance, but the acceptance was definitely a secondary thing to the power. It's a pretty natural human desire to have power over others, and the school bullies would assert theirs physically, while the "general geeks" would sit back and know that they'd be asserting theirs later in life. For me, it wasn't really enough. It's not that I wanted/needed/deserved more power than anyone else, it's just that one day I found a means that gave me a more ultimate kind of power - power over the "almighty" adults. At that age, I had the typical rebellious streak of the younger teenage years, and I had found an outlet for it.
Sure, you might not have been interested in joining a youth soccer league, but what about a chess club? Or a gaming group? Basically, anywhere where you can make friends (in real life) and get positive feedback and acceptance. If you had had those, would you still have felt the need to break into banks?
I was in the chess club, maths competition team, and on the school newspaper (I became editor of it eventually)... none really did anything to stop me wanting to break in to banks. If you compare them, "broke in to bank" is a hell of a lot "cooler" at that age than "first prize in maths competition", "wrote well appreciated article" or "considered by peers to be really good at chess".
The school staff (teachers, guidance counsellor, principal etc) worshipped the ground I walked on - I could do no wrong in their eyes. My peers (geeks) respected me and looked up to me (head of that 'clique' basically), but that wasn't enough. I viewed the school staff as incompetent and unaware (how could they write reports saying "studies hard", when I didn't study a day in my life?) and my peers as slimy and greasing ("they just want to be me" (I almost certainly misconstrued their intentions - I was a cynical little bastard really)). I didn't just want to be respected - I wanted to be ADMIRED, FEARED and LOVED.
(again, PLEASE remember this is how I thought at that age - I've grown up now, and I do realise how petty and crappy those attitudes are... but I also think they're pretty common amongst people at that age)
Honestly, another factor in how I viewed the activity (rather than the reasons for it) may have been my upbringing. I was raised to question authority when that authority was not backed up with reason. So, the idea of "breaking a law" didn't have a huge negative stigma attached to it for me. I knew it was wrong in the eyes of the law, but I considered (and still consider to be quite honest) those who uphold the law with no regard for the reasons behind it to be very foolish indeed - nothing more than sheep to the system. Whenever my parents told me to do something, they'd ALWAYS give me a reason why. Teachers at school were happy to do the same as long as I was polite about it, which I always was ("Go take this to Mr Smith", "Why?", "Because he needs it, and you can miss a few minutes of class without falling behind", "Okay").
Breaking in to a bank just didn't feel wrong to me. I didn't steal money, I didn't harm anyone, I just looked around. Remember, from the eyes of a young teen, this is a pretty straightforward kind of argument - you don't really appreciate the many facets of things like that until you're much older. It's a matter of maturity, and while I certainly may have been a very smart kid, I was definitely NOT mature enough to really handle my knowledge.
Just as a side note - it eventually led me to a rather difficult point in my life in my late teenage years, where I was arrested, hired an extremely good lawyer, got off with only a fine, paid that, found out the lawyer was charging me more than three times what the fine was, cracked in to her system to ma
Re: (Score:2)
*cough* 'almost'?! :)
Re: (Score:2)
But hey, to be completely honest, maybe I was RIGHT when I was a "cynical little bastard" and I've just become wrong in my old age... one can never really KNOW, can one?
Re: (Score:2)
I like to think I know. Even if it was long enough ago that my memory is sorta hazy :)
Re: (Score:2)
So really your problem was more about a lack of morals and (possibly) empathy than anything else. It sounds like you've learned some over the years, so that's good. But this is an example of why it's a bad idea to teach young kids to always question authority: they don't have enough experience yet to know when to question things, and what questions to ask in the first place.
Questioning authority is something you should learn after high school, when you're old enough to also understand the consequences of yo
Re: (Score:2)
This is why it's so important to get young kids involved in after school activities and clubs.
Careful though. My parents forced me to join every club and sport possible, so I had 0 freetime. By the time I hit senior year I was so burned out from all that garbage I didn't go to college. And still haven't. And life now sucks.
Re: (Score:2)
Sorry to hear that life sucks, but if I were you, I wouldn't attribute it entirely to "not going to college". As a result of the way my life went after the activities that I described in this thread, I also never went to any kind of "higher education" (actually, a started a Polytechnic course, but got expelled for fixing a bug in a tutor's program that was in a folder I shouldn't have had access to), and my life has turned out pretty well.
My advice, if you're finding it hard to get work based on your lack
Re: (Score:2)
My advice, if you're finding it hard to get work based on your lack of education is to work for yourself for awhile.
That, and volunteer with non-profits. They're usually not as picky about background and education as paying employers/clients. And once you've proved yourself to the board of that non-profit, they should be able to refer to paying gigs and a real job.
Re: (Score:2)
"You never get caught the first time"
If people got caught the first time, we'd live in an almost crime free world. The risk of getting caught would be 100% and only crimes of desperation would be undertaken.
So, not wanting to get too deep, and just wanted to answer your question,
excerpts.... (Score:5, Insightful)
"I had heard you could download versions of even the most popular games for free. This was a type of "warez"--pirated software."
"I realized it was a common occurrence and that it was called punting. Someone knocked me offline by hitting me with so much data that my connection was severed. These punters seemed to have a huge amount of power over others on AOL."
"I wanted to punt someone. Badly. That's when my real hunt for AOL hacking tools started."
"I slowly learned how things worked. I eventually began to modify the applications to meet my needs. This is how kiddies become hackers."
Jesus H Christ! People buy this crap?
/., though I predict we will all get a good laugh off it.
One thing is for certain, the target audience is not to be found on
Script kiddie (Score:5, Interesting)
Re: (Score:2, Informative)
Start of the script kiddy revolution (Score:5, Informative)
It should be noted by those of us who still vividly remember, that Mafiaboy and YTcracker were relatively skill-less script kiddies, not hackers. Back then, at least.
8 years later... (Score:2)
Re: (Score:2)
Does this now make him, Mafiaman?
No.. he has been, and always will be "MafiaBitch" a whiny little brat who downloaded someone else's work to DoS some other whiny little brats.. and then he simply found bigger targets.. and now he's a fscking celebrity. I suppose that if I had been busted for shoplifting that Snickers (tm) bar when I was 15 years old, I could have turned that into a lucrative career in physical retail security and written a book... perhaps I could have titled it "Snatching Snacks" (followed by the pr0n version: "Snackin
Re: (Score:2)
From script kiddie to security expert? (Score:2)
How exactly does the transformation from a script kiddie to a security EXPERT happen?
A book on that, I'd pay to read. I'm a sucker for case sturies on business mistakes.
NOT a hacker (Score:2)
The standard security career path (Score:2)
It seems like that is the way to have a good career in IT security - either get arrested for "cyber crime" or carry out famous (or infamous) exploits in your younger years and then reform or be released and get paid to do exactly the same thing on behalf of corporations.
It makes sense. You can't learn this stuff by reading books, you need real world situations to hone your skills.
It is interesting that illegal acts committed in your teens can lead to a good "legitimate" job in the same area. If it worked th
I'd love to give a commencement address... (Score:2, Offtopic)
I was always a nice guy, and used my intellectual superpowers for the greater good.
What a sucker I was. I should have turned to crime, taken my lumps, and then profited from tales of my crimes.
Remember, boys and girls, everything your parents and teachers tell you about good behavior is wrong.
The good guys watch their retirement investments get raped bloody.
The bullies and bad guys get pardoned and bailed out with golden parachutes.
Welcome to the steaming mountain of rat shit we call civilization, kiddo.
and he was on The Hour recently, too.... (Score:2)
here's an interview of mafiaboy on a Canadian tv programme called The Hour [youtube.com].
cheers
Get caught, grow up, write - been done before. (Score:2)
Who else here remembers Bill Landreth's book?
Not that I don't believe this should be written about... quite the opposite, actually, as the technology and surrounding social and technological environment had changed quite a bit in the intervening decades.
Re: (Score:3, Insightful)
When you put it in perspective, Mafiaboy's exploits are pretty minor compared to the damage wrought by the reaction to the terrorism of 9/11.
Is there a something similar to Godwin's law for 9/11? I don't really see the connection to this article here.
Re: (Score:1, Offtopic)
What's "Osama" hiding underneath that beard, anyway?
Re:7 years ago two planes flew into the Twin Tower (Score:5, Funny)
I belive its called Giuliani's rule
Re: (Score:2)
I belive its called Giuliani's rule
Wow. I can say I was there when a new major meme was minted.
Seriously, let's get this one spread.
Re:7 years ago two planes flew into the Twin Tower (Score:5, Insightful)
Every time I fly, I am reminded just how much we lost in the years following that day.
Re: (Score:2)