{"id":17491,"date":"2020-01-20T16:17:15","date_gmt":"2020-01-21T00:17:15","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/01\/20\/news-11226\/"},"modified":"2020-01-20T16:17:15","modified_gmt":"2020-01-21T00:17:15","slug":"news-11226","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/01\/20\/news-11226\/","title":{"rendered":"DDoS Mitigation Firm Founder Admits to DDoS"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Mon, 20 Jan 2020 23:13:03 +0000<\/strong><\/p>\n<p>A Georgia man who co-founded a service designed to protect companies from crippling distributed denial-of-service (DDoS) attacks has pleaded to paying a DDoS-for-hire service to launch attacks against others.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-36825\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2016\/10\/ddosbomb.png\" alt=\"\" width=\"593\" height=\"365\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2016\/10\/ddosbomb.png 699w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2016\/10\/ddosbomb-580x357.png 580w\" sizes=\"auto, (max-width: 593px) 100vw, 593px\" \/><\/p>\n<p><strong>Tucker Preston<\/strong>, 22, of Macon, Ga., pleaded guilty last week in a New Jersey court to one count of damaging protected computers by transmission of a program, code or command. DDoS attacks involve flooding a target Web site with so much junk Internet traffic that it can no longer accommodate legitimate visitors.<\/p>\n<p>Preston was featured in the 2016 KrebsOnSecurity story <a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/ddos-mitigation-firm-has-history-of-hijacks\/\" target=\"_blank\" rel=\"noopener\">DDoS Mitigation Firm Has History of Hijacks<\/a>, which detailed how the company he co-founded &#8212; <strong>BackConnect Security LLC<\/strong> &#8212; had developed the unusual habit of hijacking Internet address space it didn&#8217;t own in a bid to protect clients from attacks.<\/p>\n<p>Preston&#8217;s guilty <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2020\/01\/preston.information.pdf\" target=\"_blank\" rel=\"noopener\">plea agreement<\/a>\u00a0(PDF) doesn&#8217;t specify who he admitted attacking, and refers to the target only as &#8220;Victim 1.&#8221; Preston declined to comment for this story.<\/p>\n<p>But that 2016 story came on the heels of <a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/israeli-online-attack-service-vdos-earned-600000-in-two-years\/\" target=\"_blank\" rel=\"noopener\">an exclusive about the hacking of <strong>vDOS<\/strong><\/a> &#8212; at the time the world&#8217;s most popular and powerful DDoS-for-hire service.<\/p>\n<p>KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2017\/08\/alleged-vdos-operators-arrested-charged\/\" target=\"_blank\" rel=\"noopener\">exposed the co-administrators of vDOS<\/a> and obtained a copy of the entire vDOS database, including its registered users and a record of the attacks those users had paid vDOS to launch on their behalf.<\/p>\n<p>Those records showed that several email addresses tied to a domain registered by then 19-year-old Preston had been used to create a vDOS account that was active in attacking a large number of targets, including multiple assaults on networks belonging to the <a href=\"http:\/\/www.fsf.org\/\" target=\"_blank\" rel=\"noopener\">Free Software Foundation<\/a>\u00a0(FSF).<\/p>\n<p>The 2016 story on BackConnect featured an interview with a former system administrator at FSF who said the nonprofit briefly considered working with BackConnect, and that the attacks started almost immediately after FSF told the company&#8217;s owners they would need to look elsewhere for DDoS protection.<\/p>\n<p>Perhaps having fun at the expense of the FSF was something of a meme that the accused and his associates seized upon, but it&#8217;s interesting to note that the name of the FSF&#8217;s founder &#8212; <strong>Richard Stallman<\/strong> &#8212; <a href=\"https:\/\/krebsonsecurity.com\/2017\/01\/who-is-anna-senpai-the-mirai-worm-author\/\" target=\"_blank\" rel=\"noopener\">was used as a nickname by the co-author of <strong>Mirai<\/strong><\/a>, a potent malware strain that was created for the purposes of enslaving Internet of Things (IoT) devices for large-scale DDoS attacks.<\/p>\n<p>Ultimately, it was the Mirai co-author&#8217;s use of this nickname that contributed to him getting caught, arrested, and <a href=\"https:\/\/krebsonsecurity.com\/2018\/10\/mirai-co-author-gets-6-months-confinement-8-6m-in-fines-for-rutgers-attacks\/\" target=\"_blank\" rel=\"noopener\">prosecuted<\/a> for <a href=\"https:\/\/krebsonsecurity.com\/2016\/10\/source-code-for-iot-botnet-mirai-released\/\" target=\"_blank\" rel=\"noopener\">releasing Mirai and its source code<\/a> (as well as for\u00a0<a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/the-democratization-of-censorship\/\" target=\"_blank\" rel=\"noopener\">facilitating a record-setting DDoS against this Web site in 2016<\/a>).<\/p>\n<p>According to a statement from the <strong>U.S. Justice Department<\/strong>, the count to which he pleaded guilty is punishable by a maximum of 10 years in prison and a fine of up to $250,000, or twice the gross gain or loss from the offense. He is slated to be sentenced on May 7.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2020\/01\/ddos-mitigation-firm-founder-admits-to-ddos\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2016\/10\/ddosbomb.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Mon, 20 Jan 2020 23:13:03 +0000<\/strong><\/p>\n<p>A Georgia man who co-founded a service designed to protect companies from crippling distributed denial-of-service (DDoS) attacks has pleaded to paying a DDoS-for-hire service to launch attacks against others.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[23975,10712,23976,10400,16696,10741,23977,17226,10747],"class_list":["post-17491","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-backconnect-security-llc","tag-ddos-for-hire","tag-free-software-foundation","tag-mirai","tag-neer-do-well-news","tag-richard-stallman","tag-tucker-preston","tag-u-s-justice-department","tag-vdos"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17491"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17491\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17491"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}