Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 38

Thread: 14 Year Old BitTorrent Hacker Threatens to Sue What.cd Users

  1. #11
    BawA's Avatar FST Pioneer BT Rep: +1
    Join Date
    Jun 2003
    Location
    Some Where but not here
    Age
    41
    Posts
    4,213
    Quote Originally Posted by What.cd
    Show/Hide ∼ The guys behind the attacks ∼ posted on Nov-13-07 by What

    We highly suggest you change the password associated with the account. They are salted and encrypted, but we have no way of knowing what Richard has done with them.

    So, there's been a lot of speculation about who was behind the attacks on us. Waffles? RIAA? We've already come out and told you that it isn't the first. The waffles guys are cool, really. And the RIAA? Well, they don't redirect people to shock sites, as far as I know. So, who else would want to hack us? We've done our detective work, and located the two people. If you want to know who they are, skip to the end of the post. If you want to know who they are and why they hate us so much, read on in the ordinary up-down fashion.

    When we first opened our public beta, we were temporarily hosted on the bitient.org server, which was owned by one of our admins (Noah). Noah also lent out hosting space to a few other people, and gave them shell access. When Noah granted us access to his server and IRC network, one of the owners to a site hosted on the server saw us as intruders, and felt a great deal of animosity towards us. This user's nick was 'P3T3R'. We left him alone, because it's never good to make enemies when you're running a site like this, but he seemed very intent on intimidating us. The following is from my IRC logs:

    [Sat Nov 3 2007] [23:23:38] (P3T3R) btw, be prepared
    [Sat Nov 3 2007] [23:23:42] (P3T3R) i'd watch it if I were you
    [Sat Nov 3 2007] [23:24:02] (P3T3R) make the most of what you have while you have it
    [Sat Nov 3 2007] [23:24:14] (P3T3R) cos you just might have it taken away from you...
    [Sat Nov 3 2007] [23:24:37] (WhatMan) What the hell are you on about, P3T3R?
    [Sat Nov 3 2007] [23:24:43] (P3T3R) i'm not quite sure
    [Sat Nov 3 2007] [23:24:48] (P3T3R) or am I?

    We suspect he was working with his brother 'biscuit', who has a reputation of being quite knowledgeable about linux, and 'hacking' in general.

    Things were pretty normal for the next few days, but then we started seeing disturbing things appear in our database. Most of you guys know what these disturbing things were - redirects to shock sites, fake RIAA notices, etc. We initially thought that this was because of SQL injections - after all, TBSource comes with a load of exploits by default. So we went through the site, and patched up all the injection points (there were a lot of them). When we put the site back up, we immediately got hit by another attack. So we took it down again, and found and patched a couple more exploits. Then we put the site back up, and got hit by another attack.

    After checking our database logs, it became painfully clear what had happened. The site and the database are hosted on separate servers. The attacker was connecting to the database server from the web server, but it didn't look at all like an SQL injection - none of our ordinary database calls accompanied the malicious queries. So, we decided that the attackers must have access to the web server, and since it was time to move from that temporary server anyways, we packed our bags and left.

    This is when the SQL attacks stopped.

    As we've already stated, the attackers then turned to brute force. The DDoS attack was well done, which made us think that the attackers were more than bored kids - but then, they sent out a shitload of fake RIAA emails, which looked like the work of a 14 year old. It was these emails that allowed us to track down the attackers.

    The emails were well spoofed - the "originating IP" belonged to Dutch offices owned by the RIAA. However, they made a serious fuckup - a load of them were sent from [email protected]. This is not the case of a hacked mail script, as we never had a mail script - this was the case of someone trying poorly to hide their identity. A couple hours after these emails were sent out, every user in #what.cd received a CTCP-Version request from a user called 'biscuit'.

    This is where it gets cool.

    Sending version requests to everyone in a channel is the sort of thing script kiddies looking for someone to hack would do. As a good sysadmin, I tracked down biscuit's IP address:

    [22:17] [Whois] biscuit is [email protected] (Biscuit)
    [22:17] [379] biscuit is using modes +wrxt
    [22:17] [378] biscuit is connecting from *@*********.bb.sky.com **.***.**.**
    And searched for it on the site - I came up with this account: /userdetails.php?id=1106

    So, p3t3r and biscuit are on the same IP address. They both hate us, and p3t3r has openly threatened to take our site down. P3T3R has an account on the site, that logs into frequently, but never uses to upload or download. They both have shell access to our original server, so they could get into the database. Biscuit, the "1337 hax0r", sends a version request to everyone on IRC, a couple hours after scam emails have been sent out from a server they have access to. A little more research shows that P3T3R is 14 years old, and biscuit is his brother. It all sounds pretty conclusive to me. I go on to the bitient.org IRC channel to see what I can find. What do I find?

    [22:37] (Noah) BISCUIT!
    [22:37] (Noah) You'd better not have been the one sending those fake RIAA emails!
    [22:37] (P3T3R)
    [22:37] (Noah) And you most certainly have better not have been the one behind the hack
    [22:37] (Noah) the emails CAME FOMR MY IP!
    [22:37] (P3T3R) hack?
    [22:37] (Noah) FROM THIS FUCKING SERVER

    This pretty much convinced me that these two (especially P3T3R) were the ones behind the attacks. So, I'm sure you're all curious as to who these people are.

    We only went so far as to find out info on P3T3R. His name is Peter Cole, and he lives in Yorkshire, in the UK. His email addreses are *****@p3t3r.co.uk and *****@gmail.com (the second one is also his MSN). His AIM is *****, and his Yahoo messenger username is *****. He has a personal web site (hosted on the bitient.org server) at p3t3r.co.uk - sadly, his home address and phone number are hidden from the whois. There's a shitload of information on him, easily accessible via google.

    Neither I nor the rest of the staff is going to do anything to him - we just thought you'd like to know who the dickhead with your email address is. You can do with this information what you please.

    EDIT: I had a nice chat with Noah earlier - apparently, P3T3R isn't the asshole, his brother is. His brother's name is Richard Cole, uses the email address [email protected] and owns the domain iheist.com - and the whois information for that isn't kept a secret. This is their address and phone number:

    Administrative Contact:
    Cole, Richard @googlemail.com
    ### ****
    Halifax, Other ### ###
    UK
    +.######### Fax: +.########

    We also got a load more proof from Noah - he read their history file. It is available online here: http://pastebin.ca/770838 The cool shit starts at command 491 (a DOS attack). You can also see biscuit hacking our database, etc.

    I've removed his email from the news post for the day, at Noah's request - he wants to flame him without his email getting lost in piles of spam. I'll re-post it when Noah's done.

    EDIT again: We've decided to take the emails off for good. You can easily find them with a google search, anyways.
    i so like conspiracies

    if those IP's get to the tracker members biscuit is a goner, his simply fucked.
    Last edited by BawA; 11-13-2007 at 06:04 AM. Reason: Automerged Doublepost


    "You can be mad as a mad dog at the way things went; you can swear and curse the fates, but when it comes to the end, you have to let go"
    Benjamen button

  2. News (Archive)   -   #12
    JA's Avatar //Me<3You!? BT Rep: +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100BT Rep +100
    Join Date
    Oct 2006
    Location
    Sydney
    Posts
    3,283
    Quote Originally Posted by fstrulz View Post

    I bet that kid is J.A...

    Oh wait... J.A's 16...

    I got better stuff to do that dDos a site...

    Shouldn't you be googling for Brazilian girls now?
    eee

  3. News (Archive)   -   #13
    ye i had that mail too & i won't lie i really thought that that tracker was conspiracy tracker to catch the people who use thous sites but after i found out it was a joke its kinda funny

  4. News (Archive)   -   #14
    Ace30's Avatar Member BT Rep: +1
    Join Date
    Jul 2006
    Location
    Kentucky
    Age
    47
    Posts
    23
    I had an oink account before it got taken down for the 2nd time that is but I still have the email about my account can I join what.cd or waffles somehow? Thanks in advance because I don't have any private trackers for music now it sucks

  5. News (Archive)   -   #15
    sleepyy's Avatar Old-Fashioned BT Rep: +10BT Rep +10
    Join Date
    Oct 2007
    Posts
    969
    Don't they have nothing better to do is his life so crap he has to anoy other people. this has to do with waffles? or did i read it wrong if it is why don't these people work together and grow and share their ideas together and build one super site and not just try to take each other down? this is just plain stupidity.

    These silly little kids never learn it's allways the people useing the site that get hurt not the site owners all that happens to them is they have no member or no site for 50000 users haveing nowhere to go i would say is a far worse..


    I find it funny he is smart enough to take down and find all the person details from a torrent site but his not smart enough to hide his name face and age and home town how ironic
    Last edited by sleepyy; 11-13-2007 at 09:44 AM.

  6. News (Archive)   -   #16
    Living on the edge BT Rep: +4
    Join Date
    Aug 2007
    Location
    irc.p2p-irc.net/t**
    Posts
    499
    that kid has got some quality though may be he is a script kiddie but he is good at it though

  7. News (Archive)   -   #17
    iNSOMNiA's Avatar 1/G BT Rep: +16BT Rep +16BT Rep +16BT Rep +16
    Join Date
    Oct 2006
    Posts
    583
    i lol'd

    The trouble with the world is that the stupid are cocksure and the intelligent are full of doubt.

  8. News (Archive)   -   #18
    zallofa's Avatar Non Trader BT Rep: +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50BT Rep +50
    Join Date
    Oct 2007
    Posts
    334
    14 years...oh i received that mail

  9. News (Archive)   -   #19
    dvd4alll's Avatar BANNED BT Rep: +13BT Rep +13BT Rep +13
    Join Date
    Oct 2007
    Location
    Helioplis
    Posts
    271
    good to know!

  10. News (Archive)   -   #20
    $SnoopDo2G$'s Avatar Don Doggy BT Rep: +6BT Rep +6
    Join Date
    Dec 2006
    Location
    The Cape of Good Hope
    Posts
    792
    Im pretty sure the kid have his own tracker already,
    and he's makin' money and he's bored as hell maybe that's why he did that...
    Some people are really lame, im sure some people are scared now of torrents... LOL

Page 2 of 4 FirstFirst 1234 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •