Krebs Pinpoints the Likely Author of the Mirai Botnet (engadget.com) 98
The Mirai botnet caused serious trouble last fall, first hijacking numerous IoT devices to make a historically massive Distributed Denial-Of-Service (DDoS) attack on KrebsOnSecurity's site in September before taking down a big chunk of the internet a month later. But who's responsible for making the malware? From a report on Engadget: After his site went dark, security researcher Brian Krebs went on a mission to identify its creator, and he thinks he has the answer: Several sources and corroborating evidence point to Paras Jha, a Rutgers University student and owner of DDoS protection provider Protraf Solutions. About a week after attacking the security site, the individual who supposedly launched the attack, going by the username Anna Senpai, released the source code for the Mirai botnet, which spurred other copycat assaults. But it also gave Krebs the first clue in their long road to uncover Anna Senpai's real-life identity -- an investigation so exhaustive, the Krebs made a glossary of cross-referenced names and terms along with an incomplete relational map.
How about the link directly to Krebs? (Score:5, Informative)
https://krebsonsecurity.com/20... [krebsonsecurity.com]
BK rocks BTW.
Re:How about the link directly to Krebs? (Score:5, Insightful)
Re: (Score:1)
Many of which end up here a day later, so...
Re: (Score:2)
Engadget used to a lot better site but not these days. Pick any article and if the original source is cited at all it'll be 2, 3, 4, 5 links into the article with all the other links pointing to other Engadget stories, each of which pulls the same
Re:How about the link directly to Krebs? (Score:5, Interesting)
Re: (Score:1)
Probably makes em more money from the links
Re: (Score:1)
Re: (Score:2)
How do you propose moving the ACs comment? This isn't reddit.
Re: (Score:2)
Re: (Score:2)
Moderator points don't move a comment, they just make it more visible. That is why I was asking about the terminology (in a joking manner), no comments move around on the page.
Re: (Score:2)
Usually, but this one was quite easy to find. Hint: Never look in the article for the link - look below and there's usually a "Source" link which links to the sources for the article. It's not buried, but it's not hard to find, though the coloring could be better. That's more of a CSS pr
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
BK rocks BTW.
Yep, he gets it: "The object of Minecraft is to run around and build stuff, block by large pixelated block. That may sound simplistic and boring, but an impressive number of people positively adore this game -- particularly pre-teen males."
Re: (Score:2)
https://www.reddit.com/r/AskReddit/comments/5nqq3c/serious_people_whove_written_malicious_code/dce7rh9/
Re: (Score:2)
BK rocks BTW.
He does. Let's hope he is right and that this person will have to pay for all the damage he did. If not, criminal business practices like this will become more common...
Re: (Score:2)
Re: (Score:3)
"...an investigation so exhaustive," Really? How exhaustive was it? Are we talking 2 searches on Google Exhaustive? Or what?
It's almost like you didn't read the article.
Re: (Score:1)
Re: (Score:3)
So your original question "Really? How exhaustive was it?" was answered immediately after the bit you quoted, which is why everyone else who is more fluent in English was confused by you asking the question in the first place. To them the answer was right ther
Re: (Score:2)
Lol, "The Krebs".
Re: (Score:3)
RTFA?! Why? If one casually notices the quotes, it's those two little marks placed together, it's used to 'quote' a source. The quoted source implies that the reader doesn't comprehend what is being explained.
I agree, it's clear that you don't comprehend what is being explained.
If, however, you had taken a moment to just look at the article it probably would have answered your ignorance, demonstrated by what you wrote: "Really? How exhaustive was it? Are we talking 2 searches on Google Exhaustive? Or what?"
You're free to be as ignorant as you like but don't get your panties in a twist when others point out that your ignorance is a self-inflicted wound.
Re: (Score:1)
Re: (Score:2)
I'm commenting on the post; see the quotes, they have a use. Google it?
Some people are hard of hearing but you appear to be hard of thinking.
Re: (Score:1)
Re: (Score:2)
Link to Krebs (Score:1)
This is a technical community. Why link to a pre-digested Engadget re-telling of a really great piece by Krebs?
Comment removed (Score:4, Funny)
Re: (Score:2)
Why engadget? (Score:1)
My guess was wrong (Score:1)
I had theorized a frustrated biochem student who mistakenly attributed the creator of the Krebs Cycle [umich.edu].
Re: (Score:2)
I had theorized a frustrated biochem student who mistakenly attributed the creator of the Krebs Cycle [umich.edu].
Yes, but it doesn't really work like that if you're on statins.
Indictments? (Score:1)
Indictments in 3...2...1...
The only question is will that be days, weeks, months, or years?
Re: (Score:2)
Meh, sounds more like the anger I harbor.
Which is more "Fuck you for getting there first" than just "Fuck you".
I would argue that no one on this site would be against controlling botnets of this size and capability. Half of you already site behind networks ranging in the thousands of devices.
Re: (Score:2)
Nah, some people, even here, have an actual conscience.
Re: (Score:2)
Which is more "Fuck you for getting there first" than just "Fuck you".
Nope, not me. I genuinely hate the idea that one or two fuckheads with a botnet can wreck the internet for tens of thousands or even millions of people, or destroy the livelihood of people who are just trying to do something like providing a legitimate service such as a Minecraft server.
-
I would argue that no one on this site would be against controlling botnets of this size and capability.
I disagree...I don't think that the majority of people on Slashdot are amoral fuckheads without a shred of integrity. You might fit into that category, however.
Re: (Score:2)
Yep, and it is easy to figure out who did what and when. All you need do is ask them.
Rodrigo Duterte (Score:3)
Would agree with your crime fighting methods.
I can't say that I don't like it in theory, but in practice it seems to have some side effects.
Re: (Score:2)
I can't say that I don't like it in theory, but in practice it seems to have some side effects.
I know, there always seems to be some collateral damage, but what can you do? It's not a perfect world, amirite?
If you want we could just give them a super-expedited trial and then life imprisonment but the follow-on costs of doing that concern me.
Re: (Score:2)
Get Doxed (Score:2)
Why go public instead of notifying the FBI? (Score:2)
Surely the FBI is trying to find out the identity of the criminal who created this botnet. Why would Krebs go public with it, instead of going to the authorities? At the bottom of the article, it says "The FBI officials could not be immediately reached for comment." What does that mean? "could not be immediately reached?" Why was he doing this investigation alone? And why did the author of the botnet release the source code?
Re: (Score:3)
Why was he doing this investigation alone?
Vengeance. Jha messed with Krebs, and Krebs messed back. Hard. And by going public, Jha can not attack him since he is too busy trying to burn the evidence. It is also a message to others...
Re: (Score:3)
Krebs better be right or Jha will have one hell of a defamation case against him
Re: (Score:3)
Seems like Brian connected the dots.
Re: (Score:1)
Krebs is an investigative journalist.
Why did they release the code?? To brag.
Correct Article (Score:5, Informative)
https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/
We do we link to some shitty gadget blog instead of the original author with real credibility?
Now... (Score:1)
...the point would be that this person be punished fully to the degree appropriate to the economic damage they wrought.
I like execution for any crime where the costs exceed $1 million, whether they're a hacker or Goldman Sachs.
Re: (Score:2)
It depends if you stole $1 million from a crook or from many people who didn't have much money in the first place.
If you want to make the punishment fair, at least make it proportional to that actual harm done to people. Money means nothing.
Re: (Score:2)
Like hacking into one pc and saying 'hi' causing their firm to have to spend 2 million upgrading all their pcs security.... or sharing 20 tunes.
HAHAHAHAHAHA (Score:5, Funny)
wow awesome! (Score:3)
I actually read through the whole article and its great detective work. I get the feeling people were bragging to krebby because of how famous he is and they, being anonymous hackers, can never shut up and stop bragging. I love how the reddit account mentioned has recent postings (last one 3 days ago), hasn't been scrubbed, and links together many aspects of the guys life (his love for anime, the dorm he lives in at ruttegers, discussion of botnets and networking).
A life lived online is not very anonymous it seems! especially when you re-use handles and are young and really really like to brag.
Hopefully he made enough to buy a plane ticket away from the USA before the shoe drops on him. I'd be at the airport right now if i was him. Love how Jha says at the end "I don't think there are enough facts to definitively point the finger at me," Jha said. âoeBesides this article, I was pretty much a nobody. "
Well so were all the serial killers and other sociopaths of history... obviously! Someone did the detective work and now they are notorious, like you.
My advice? Run! The FBI surely has enough resources to get IP address for skype users, and reddit gives up their users at the drop of a hat. The FBI can easily take possession of his computer equipment with this kind of evidence. I doubt he was that careful and everything is tight and anonymous at the layer 3 level.
Expecting to see him arrested within days! FBI doesn't like to be made a fool of!
ISR (Score:2)
In Soviet Russia, senpai gets noticed!
Re: (Score:1)
Win.
Russians hack everything (Score:3)
Wait, I thought it was Russians? After all, "Mirai" means "gullible" in Russian.
Re: (Score:3)
Or "Future" in Japanese. The author watched Mirai Nikki and was inspired by the anime. All in BK's article.
Nothing like a good old fashioned witch hunt. (Score:1)
Re:Nothing like a good old fashioned witch hunt. (Score:4, Insightful)
Yeah it really sucks when you find out that someone investigating all of the murders in town notices that the bloody footprints keep leading to your door.
If he didn't want to go down for this then he shouldn't have done it. I probably have more respect for Brian Krebs than any other journalist, he's obviously not infallible but his investigations and articles are great pieces of work. After reading the article, it seems pretty unlikely that there is another person in that small group of people who are connected which is actually the author but somehow didn't get noticed by Krebs. Jha admitted that the author of the botnet is a sociopath, so he's at least self-aware, but I'm not going to shed any tears for him when the FBI comes calling again. His attacks have run into the hundreds of thousands or millions of dollars, and he's directly negatively impacting the lives of many other people. If you want to try to poke holes in any of Krebs' arguments then go ahead, but if you haven't even read his article then it's probably better to save your witch hunt cliche for a time when it applies.
This article kills working time! Goog Read (Score:1)
The original article is good but a long read.
Why do it? (Score:1)
American individuals who play this game, and do not have Mafia lawyers, will eventually receive long prison sentences for multiple counts of extortion.
The upside is the rush of power, and revenues in the thousands of dollars. These are poor compensation for a decade or more in the slammer.