  • Wherein Seraph Gets Hacked.....

    So, last night sucked big time for me.

    Bit of Obligatory Background:

    Last month, Big Script Company (BSC) that I work with a lot, went through a minor scandal because some guy posted on Facebook that he'd gotten a rather large payment from them. According to him, he was a grey hat hacker (We'll call him GHH), and found and exposed several large vulnerabilities in BSC, and was paid handsomely for it. BSC made no comment on the matter, but dang, people freaked out.

    I didn't really think twice on it, until last night.

    Around 9:30 pm I got a weird email through one of my nonprofit websites. It was stating that he found some vulnerabilities in my sites, and that I needed to pay him so he'd tell me what they were. Wait, what? I figured maybe it was a prank, and went about my business.

    A few minutes later he emails me again, saying he is waiting for my reply, and I'd better "move quickly, and pay quick". Or else...something might happen to my websites.

    Wait now, that's extortion. WTF.

    I looked up the email address and's GHH. Who is now moving nicely into black hat territory, apparently. GHH is now emailing me like crazy, and stating that I'm taking "much too long to pay".

    Quite upset, I start backing up everything and backing up my databases as quickly as possible. While I'm doing so, I made a quick post summarizing what was going on, to a social network. One of my clients sees this, and take note this guy is practically made of money, and messages me.

    "I'm sorry...I kinda paid him for this exact thing last month. Guess he saw your connection with me and... well... Looks like you're his new victim."

    That's right. One of my super rich clients paid this guy for it, because, well, a couple thousand isn't all that much to him. So, since it's known that this guy is my client, GHH assumed that I must also be super rich, and is now targeting me.

    All of a sudden, things get worse. I got an auto-email from my hosting company, notifying me that one of my databases is going haywire, and will be shut down shortly because of the massive load it's causing. Yep, GHH lost patience with me.

    Thankfully, it's for a forum that I ran, that nobody'd used in months, so meh, I flat out disabled it. Big woop.

    Super rich client then tells me that after he paid GHH, he went and bought a super expensive piece of software that scans websites for vulns and spits out a report that tells you every single darned hole that you have, no matter how small. It also lets you know if someone is currently attempting a hack, and where it is. Problem is, it does this by attacking your website. Hard.

    Well, I have nothing else for it, and told him if he could, to go for it. I needed to know where he was.

    So, the friendly fire began.

    GHH contacts me, saying that since I'm not paying, he'll "show me just how vulnerable my sites are", and begins SQL injections. ugh. Thankfully, Rich messages me with the first hole, and spots the injection within minutes. Closed the hole, removed the injection...and continued to wait out the storm. GHH proceeds to double his attack as well, setting up more and more injections, and ALSO beginning an attack on my other databases.

    Since there's not much I can do but 'huddle under a rock' at this point, I begin tracking down GHH. I promptly find his Twitter, his Facebook, where he goes to university, and his address. He's in India, so I'm kinda screwed there with going to the police. He also is a member of a white hat forum, that is supposed to quietly help people out with vulnerabilities on their sites. Um, yeah dude, you're NOT white hat. Far from it.

    Eventually, Rich's attack slows, and he gives me the first report. Not too bad, but it found two holes that GHH was currently forcing his way through. Closed them up, and GHH's attack slowed noticeably. He even sent me an email, reminding me that I should totally pay him, and soon. Heh.

    It takes hours, but Rich's software finally finishes, and he tosses me the reports. Its about the same for my sites, just a hole or two on each, but it's enough for GHH. I thank Rich, who heads to bed, and I proceed to go and do my best to try and close up each hole. I least enough to deflect GHH. His attacks came to a halt, and he sent me a couple more emails trying to get me to pay up, no longer saying that he would exploit vulnerabilities, though.

    Finally got things wrapped up around 2 am, just....did not want that to be how I spent my night, you know? Going to have to try and have someone who is more versed in this stuff look over everything later, because I hope I did stuff right.

    And seriously, I am concocting one of my evil revenge plans for GHH. He has no idea who he tangled with, and I'm SO going to make sure he gets payback for this. First stop's going to be the FBI, going to file a report/complaint with them today/tomorrow, and see what they say. I know he's in India, but I'm fairly sure we have a treaty of sorts, and with all the Lulzsec stuff...they're taking things like this more seriously. After that, I'm getting his forum account banned at the white hat place, and then...generally wreaking as much havoc on him as I can without drawing too much ire. I am seriously upset that he ruined my entire night, and gave me way more stress than I need right now.
  • #2
    Seraph, what GHH did is illegal in a "contact the FBI Now. Faster." sort of way. It's called "unauthorized access to a computer system" and carries with it some very, very hefty penalties. And, given that he was trying to get you to pay up or he'd bring down your servers, racketeering also comes into play. In other words, federal crime. And it sounds like you have at least some contact info and some logs, and this is very fresh.

    Please, contact the FBI and report this with as much detail as you can. "Payback" can just as easily occur from a jail cell. I know he's in India, but as you mentioned, there are treaties.


    • #3
      I am going to, trust me. The buck stops here, I'm going to turn his butt in.
      • #4
        Oh, wow. That's crazy-making. I can't wait to hear what happens with this. Let us know what you do and how it goes, ok? I love a good revenge story, when the victim deserves it, as in this case.
        • #5
          Holy shit! I hope the FBI gets his ass, I hope your stuff is all right.


          • #6
            Please keep us updated and yeah, I hope he did no damage. Kudos to Rich who helped you fend this guy off! Would love to see GHH's face when his local authorities land on him with both feet ...


            • #7
              What a fucking scumbag! -sends hugs-
              • #8
                Quoth Ghel View Post
                Oh, wow. That's crazy-making. I can't wait to hear what happens with this. Let us know what you do and how it goes, ok? I love a good revenge story, when the victim deserves it, as in this case.
                This. I think I'll add this to my Safari "read this later" list just so I can keep tabs on the outcome. And hope that it includes lots of Spartans and a deep deep pit.
                (and now my overcaffinated mind is picturing Leonidas saying, "This is SERAPH!" as he's kicking the hacker into the pit, instead of "Sparta" ...)

                • #9
                  I HATE these types. Despise, loathe, wish a fate worse than death upon them. I had to rebuild a server two months ago because of douche nozzles like this. Someone, somehow figured out a way into the server (I suspect my one and only wordpress site) and managed to send out enormous amounts of spam. There was nothing in the HTTP logs, so it was coming in another way. In the end I had to lock the server down to just 10 open ports and rebuild everything from backup. I lost 5 days of my life to that crap.
                  • #10
                    There definitely are treaties - and India is signatory to them.

                    His actions are jailworthy. Your hosting companies will have logs showing both the friendly and unfriendly fire.

                    He is not nearly as untraceable as he thinks he is. I know - from my husband's experience - that the Australian Federal Police can and will trace attacks of this nature and prosecute this sort of thing as a criminal act.
                    (Note: my husband was the sysadmin, not the criminal, in these cases. Just in case anyone needed that clarified. )

                    If the Australian Feds will do it ... well, how much more active do you think the US Feds are likely to be?
                    • #11
                      That guy is a creep.

                      May Seraph rain almighty vengeance down upon him. Fiery vengeance!
                      Knowledge is knowing that a tomato is a fruit. Wisdom is not putting it in a fruit salad.


                      • #12
                        That dude needs his ass handed to him in the most painful and expensive way possible.


                        • #13
                          Looks at thread.
                          Reads thread.
                          Goes back to building his survival shelter.


                          • #14
                            Not much of a hacker, this guy... only exploiting the known stuff. Still, he needs a swift kick in the butt. Perhaps a note to the university he's at, is a good idea, too. They might take a dim view on students doing criminal things.

                            Please keep us posted.
                            • #15
                              Seraph, dear, this is when we really need to get you to weaponize your Enemy of Normalcy powers and unleash them upon Mr. Darker Shade of Gray.

                              Barring that, I'm going to start seeing if I can find the nearest pig farm for you.
