Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

An Admin's Foolish Errors Helped the FBI Unmask Child Porn Site 'Playpen'



Sites hosted on the so-called dark web are forcing law enforcement to use novel and powerful techniques to unmask them. But sometimes suspected criminals make it easier for the feds.
Recently unsealed court documents reveal that “Playpen,” one of the largest and most infamous dark web child pornography sites, was shut down partly owing to its administrator's own mistakes.
“Due to a misconfiguration of the server hosting the TARGET WEBSITE [Playpen], the TARGET WEBSITE was available for access on the regular Internet to users who knew the true IP address of the server,” a search warrant application for intercepting communications on Playpen from February 2015 reads. The search warrant and other documents were unsealed in the case of Richard Stamper, who was arrested on suspicion of child pornography charges.
“Basically, Playpen must have set their [child pornography] site to [a] default [web server setting], meaning if you typed in the IP address you could see the Playpen site,” Thomas White, a UK-based activist and technologist, explained in an encrypted chat. “Whereas if they set another default like ‘server not found,’ then you could only access Playpen by typing the correct .onion address.” This means that law enforcement could verify that an IP address belonged to a specific site.
“An FBI Agent, acting in an undercover capacity, accessed IP address 192.198.81.106 on the regular Internet and resolved to TARGET WEBSITE,” the document continues. That address pointed to a server in North Carolina, hosted by a company called CentriLogic.
The FBI was tipped off about Playpen’s IP address by a foreign law enforcement agency, as noted in other, redacted versions of the warrant. This recently unsealed version includes detail on how that IP address was left exposed.
It is not clear how the foreign law enforcement agency discovered Playpen's real IP address in the first place. But the main administrator of the site, who the FBI suspects is Steven Chase from Florida, was clearly aware of the problem and actively trying to fix it, according to the search warrant application.
“FBI agents know this by reading his private messages from the copy of the TARGET WEBSITE that was seized pursuant to the aforementioned search warrant,” the document continues.
Playpen’s suspected administrator apparently also leaked identifying information about himself.
Chase allegedly connected to the server, as well as to the PayPal account used to pay for the hosting provider, from an IP address assigned to his home in September and November 2014, instead of through the Tor network. This meant that a subpoena to Paypal revealed where the person paying for the server was likely located.
On top of this, Chase allegedly connected to a Playpen administrator account from his mother's house a number of times between December 2014 January 2015.
Mistakes are often what leads to the capture of suspected dark web criminals. In the case of drug marketplace Silk Road, creator Ross Ulbricht posted his personal email address in an advert asking for help with the site, and the FBI claimed the location of the site's server was identified because of a leaky CAPTCHA system.
Meanwhile Blake Benthall, a suspected administrator of the second iteration of Silk Road, registered a server with an identifying email address. One alleged dark web drug dealer even went so far as to trademark his brand in his own name.
The suspected owner of one of the largest dark web child pornography sites was evidently no different, and perhaps the most foolish of them all.

How the FBI Used Hacker Tricks to Track Down a Would-Be Bomber

How the FBI Used Hacker Tricks to Track Down a Would-Be BomberFbi-malware

Malicious hackers commonly use phishing emails to lure would-be victims into clicking a seemingly harmless link that will actually install malware on their computers, allowing the perpetrators to siphon data, or even spy on their victims.
But the FBI is increasingly using the same techniques in its investigations; that's how it tried to track down a suspect who was making a series of bomb threats last year, according to The Washington Post, which confirms that the feds are relying on hacker's tricks to fight crime.

The FBI's elite hacker team created a customized piece of malicious software, or malware, that would install on a suspect's computer when he signs into his Yahoo email account. A judge in Colorado authorized the bureau to use the malware, according to court documents obtained by The Post.
The malware was designed specifically to siphon certain information from the suspect's computer to the FBI, including location data and websites visited. What's more, it allows the FBI to spy on a suspect through his webcam even without its indicator light turning on.
This is not the first time that the FBI has reportedly used malware, spyware and other hacking tricks to track down suspected criminals.
In August, it was revealed that the FBI uses sophisticated hacking tools. Chris Soghoian, principal technologist at the American Civil Liberties Union, discovered this after researching LinkedIn, where FBI contractors openly advertised their hacking services for the bureau.
The FBI's use of these techniques has critics concerned they could be too intrusive and perhaps illegal.
"There hasn't been a debate in Congress about the FBI getting into the hacking business; there hasn't been any legislation giving this power; this just sort of happened out of nowhere," Soghoian said at the Def Con hacking conference this summer.
This shaky legal ground was evident in a similar case earlier this year in which a Texas judge refused to sign off on an FBI warrant request to install malware that would covertly extract files from a suspect's laptop, and take pictures using its camera, according to The Wall Street Journal.
"It's time for a real discussion about what the rules should be," Kevin Bankston, a privacy and free speech lawyer and the policy director of the New America Foundation's Open Technology Institute, said on Twitter.
In the case of the would-be bomber, identified only as "Mo," the malware didn't work as intended, but revealed that Mo actually loves in Tehran, where he is safe from arrest by the FBI — although not from its hacking tools.