by 

 
With his baby face and doughy body, 17-year-old Joshua Gilson does not look like your typical FBI quarry.

In fact, huddled over his Toshiba laptop, with rock music blaring from his bedroom stereo and Jerry Springer flickering on the TV, the Sheepshead Bay resident looks like any other teenager, albeit one experiencing maximum sensory overload, 1998-style.

But actually Gilson is part of a nationwide networkof teenage computer hackers who have stolen everything from Internet accounts to credit card numbers, a cybergang that has flourished despite a yearlong effort by the FBI to curb this online piracy, the Voice has learned. “I’ve stolen accounts and stuff like that. I didn’t even think it was that big of a deal,” Gilson said. “Everybody does it.”

For months, federal investigators have been serving subpoenas and search warrants at the homes of these young hackers, carting away computers, disks, modems, and other items as parents watch in horror. Agents with the FBI’s computer crimes squad have recently raided homes across the metropolitan area–from Brooklyn to the New Jersey suburbs–as part of a probe into wide-scale credit card fraud and other cybercrimes.

In several instances, agents visited the same residences more than once — first in mid 1997 and then again earlier this year — because some young hackers were undeterred by the federal probe. According to one court record, a hacker recently boasted to a friend that “nothing could be done to him because he was a minor.”

One federal investigator acknowledged that while “it’s tough to prosecute a juvenile,” the FBI is “not always sure you’re gonna find a teenager” at “the end of the string.” The source added, “And if you do, it still doesn’t mean the game is off, because if the damage is severe enough it is still a crime and it’s still a problem.”

Since the probe is ongoing–and every target appears to be underage —
investigators have tried to keep details of the case confidential, including whether any teenagers have been arrested on federal charges. But interviews with several subjects of the criminal inquiry and a confidential FBI document obtained by the Voice provide a detailed look at the current investigation.

The federal probe began last spring, when agents learned of the “massive deployment of a password-stealing program” on the Internet, according to the FBI document. The scheme targeted accounts on America Online (AOL), the nation’s largest online service. AOL is a favorite nesting place for young hackers, who congregate in chat rooms with names like Dead End and Island 55. “Fifteen seems to be the preferred age for an AOL hacker,” said one long-in-the-tooth 18-year-old hacker.


Three 17-year-olds take credit for inserting pornographic images into America Online’s widely used chat service. Users of the latest version of AOL's Instant Messenger (AIM) software started encountering an unpleasant surprise on Saturday morning: At least three crackers -- malicious hackers -- began inserting pornographic images into "AIM Today" and vandalizing content on at least four screens of the chat software. Since last August, users.....
Cow Pasture #2

FuCkeRH0sT:FuCkeRH0sT: *** You are in "Cow Pasture". ***FuCkeRH0sT:HoSSxMaN8: Hello all.ZzzZvvVVVv: Hey HoSSxMan!!Guide KJL: Zzzz...I don't know about that...FuCkeRH0sT: KiLL4SSA1 has entered the room.Guide KJL: it's not my department.ZzzZvvVVVv: Do ya'll really meet in WhoviIIi?HoSSxMaN8: Who has a gateway?Guide KJL: Pomp...cuz we like this room!WwABBawW: guide you can TOS some1 yourself right?HoSSxMaN8: What about Padde CeiiFuCkeRH0sT: BaLLa r0x has entered the room.ZzzZvvVVVv: becuase there were so.....
The AOL Protocol

The AOL Protocol

When you hear the phrase “The AOL Protocol”, I bet most of you immediately think of FDO, right?
Although FDO is a part of the AOL protocol, it in no way encompasses the big picture. When I use
the term “The AOL protocol”, I refer to how the AOL client and server interact with each other,
how data is prepared, how it is sent, and how it can be manipulated.

There currently exists no formal documentation of the AOL protocol, or at least one that is
publicly available. For this reason, I have taken it upon myself to strip the bits of
information from my feeble mind and write a document with at least basic information about
the AOL protocol. The information included in this document is what I have learned, from
exploration, help from others, and just stumbling upon it. I in no way guarantee the accuracy
of the information contained herein. That said, here is what I know.

Ryan D Johnson RJ2 3740 Granger Rd Bath, OH 44333

Bath Township man wanted ex-girlfriend to know that money has no value to him

By Gina Mace

Special to the Beacon Journal

BATH TWP. – In an effort to prove to his ex-girlfriend that money means nothing, a 20-year-old Granger Road man smashed an SUV and sent another luxury vehicle into a creek, township police said.
A 2-month-old Volkswagen Touareg blaring rock music from the sound system sat in the front yard of Ryan Johnson’s home Monday — severely damaged from smashing through the security gate, uprooting a tree, then being assaulted by golf clubs and boulders. A Mercedes SL500 was parked in Yellow Creek, under the driveway bridge leading to Johnson’s mansion.

The two vehicles were worth more than $100,000, police said.
Johnson told police he did it for his ex-girlfriend. Last week, she asked police to accompany her to the home so she could remove some belongings.

Police were called to Johnson’s home around 3 p.m. Monday by neighbors who thought they heard an explosion.

One neighbor, who asked not to be identified, said he went outside after hearing the noise.

People were running around, making sure everyone was OK,'' the man said.A kid was out there with huge boulders, breaking out windows. He was throwing stones at it. Later he came out with a set of golf clubs and was teeing off on it.”

The “kid,” identified by police as Johnson, was still smashing the SUV when police arrived.


I found this old post from O0O of the old AOL-Files.com site posting this on DigitalGangster.com   Join Date:  Apr 2007Location:  NYCPosts:  1,428   its funny how 12-14 years later people remember things so much differently than what you remember. Many of the names here I haven't seen since bouncing around the PRs in the late `90s. Many of you remember the "leet" SN jackers/suspenders.....

ACK Tunneling Trojans

– Arne Vidstrom, arne.vidstrom@ntsecurity.nu
Summary

Trojans normally use ordinary TCP or UDP communication between their client and server parts. Any firewall between the attacker and the victim that blocks incoming traffic will usually stop all trojans from working. ICMP tunneling has existed for quite some time now, but if you block ICMP in the firewall you’ll be safe from that. This paper describes another concept, that I call ACK Tunneling. ACK Tunneling works through firewalls that don’t apply their rule sets on TCP ACK segments (ordinary packet filters belong to this class of firewalls).


_________________________________________________________________________ TCP\IP: A Mammoth Description By Ankit Fadia ankit@bol.net.in_________________________________________________________________________ TCP\IP or Transmission Control Protocol \ Internet Protocol is a stack or collection of various protocols. Aprotocol is basically the commands or instructions using which two computers within a local network or theInternet can exchange data or information and resources. Transmission Control Protocol \ Internet Protocol or the TCP\IP was developed around the time of theARPAnet......
Old AOL Phishing Phrases

Hi, I'm with AOL's Online Security. We have found hackers trying to get into your MailBox. Please verify your password immediately to avoid account termination. Thank you. AOL Staff Hello. I am with AOL's billing department. Due to some invalid information, we need you to verify your log-on password to avoid account cancellation. Thank you, and continue to enjoy America Online. Good Evening. I am.....
Exploring Historical & Emerging Phishing Techniques

International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23

Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.