SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> No Category

Canadian teen arrested in DDOS Web attacks

Canadian teen arrested in DDOS Web attacks

By:  Elinor Abreu  On: 04 May 2000 For: IDG News Service Creator

Confirming suspicions that the attacks on CNN.com, Yahoo.com Inc. and a handful of other popular Web sites in February were the work of "script kiddies," officials have arrested a 15-year-old Canadian who allegedly bragged about perpetrating at least one of the attacks.

The teen, whose hacker name is Mafiaboy, was arrested recently in Montreal and released after pleading not guilty to charges of two counts of mischief to data and obstruction of the lawful use of data. He is accused of conducting a distributed denial of service, or DDOS, attack on CNN.com and the more than 1,200 sites it hosts worldwide. The attack disrupted access to the sites for more than four hours on Feb. 8.

The Yankee Group estimated that the attacks cost the industry about US$1.2 billion. Mafiaboy allegedly bragged about the attack in Internet Relay Chat forums, even soliciting the names of other sites that were then attacked, according to Michael Lyle, CTO at Recourse Technologies. In an interview after the attacks, Lyle said he had seen snippets of the logs containing the boasts.

"Bragging about your hacking exploits is just classic hacker behaviour," said Jennifer Granick, a San Francisco attorney who has defended several hackers. "You have a young kid who appears to be looking for attention. Both bragging on IRC and doing this kind of attack are ways of obtaining that attention."

The attack used an existing script and required no serious knowledge about computer networks to pull it off. In addition, the attacker's methods were sloppy. "There were pieces left behind on our computer," said Kevin Schmidt, campus network programmer at the University of California at Santa Barbara, where two computers were compromised but only one was used in an attack. "There was some indication that Mafiaboy may have been involved. There are indications but not proof."

Yahoo was the first site attacked in February, followed over the next two days by eBay.com, Buy.com, Amazon.com, CNN.com and E-Trade.com. The FBI said it also was looking into an attack on Excite.com, which came to light after the first attacks were announced. At the time, ZDNet.com also claimed to have been a victim, but the site was not on a list of targets being investigated by the FBI.

DDOS attacks are designed to shut down target sites by flooding them with traffic. In this case, the victimized sites were not entirely shut down, but most visitors were unable to reach them. The excessive traffic comes from "zombie" or "slave" computers, usually high-speed servers onto which someone has installed software that includes instructions for carrying out an attack.

Charges in other attacks could be filed against Mafiaboy or other suspects, according to Sgt. Gilles Michaud of the Royal Canadian Mounted Police. If convicted, Mafiaboy faces two years in a juvenile detention center. Officials seized his computer and, as a condition of bail, are prohibiting him from using a computer without supervision, connecting to the Internet or entering a computer store.


Sign up for our Newsletters
Tags: security












Print |  Views: 2053   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Elinor Abreu Elinor Abreu is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Websense advises IT managers to think like criminals
Websense advises IT managers to think like criminalsThe hacker community is becoming much better organized and often its goal is to find sensitive data without prospective targets discovering there was a security breach. How to protect yourself
Germany to make hacking a crime
Germany to make hacking a crimeNew legislation proposed by the German government aims to make computer hacking a punishable crime. The draft law, announced Wednesday, defines hacking as penetrating a computer security system and gaining access to secure data, without necessarily stealing data.
Symantec upgrades warning system
Symantec upgrades warning systemIn a sign that it is continuing to digest the technology it swallowed with three high-profile purchases last July, Symantec Corp. has announced an upgrade to the DeepSight Threat Management System, which it acquired with its purchase of SecurityFocus Inc.
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.