domingo, 1 de noviembre de 2015

Ashley Madison y... ya que estamos... (2/2)

Ya hemos visto que Ashley Madison debe producir (o lo hacía) pingües beneficios.
AM presumía de prestar su servicio a personas comprometidas lo cual, por supuesto, no será tema de debate en este blog. Allá cada cual con sus principios.

En cualquier caso, infieles aparte, mucha gente entró en Ashley Madison por curiosidad o por transgredir las convenciones pero sin intención real de llegar hasta el final. Sin embargo sí parece que hubo gente que llegó hasta el final y ahora están -no sé si por aquello del karma- en situación comprometida.

La base de datos de Ashley Madison fue robada y vendida a quién quisiera comprar una copia.

En julio de 2015, un equipo de hackers denominado Impact Team robó datos de más de 37 millones de usuarios a la compañía amenazando hacerlos públicos si esta no cerraba inmediatamente su web. En agosto de 2015 estos datos fueron publicados en BitTorrent conteniendo datos como nombre, apellidos, teléfono, correo elecrónico y transacciones financieras realizadas por los usuarios. Como consecuencia de este escándalo, el 28 de agosto dimite Noel Biderman, su fundador.

(Tomado de la Wikipedia)

Cuesta creer que hubiera gente que introdujese sus datos auténticos, aún confiando en el principio de confidencialidad que asumía (con poca eficacía, por cierto) Ashley Madison ¿Qué puede pasarles?

De momento unos "señores" piden un dinerillo a cambio de su discrección. Y muy en la línea del cryptolocker, la extorsión aumenta si no se les paga con rápidez.


Hey there!

If you want to keep your cheating and lies secret from your significant other, your family, your friends and work contacts then pay very close attention to this email. As what we demand is non-negotiable and you might ruin your life if you decide to ignore this email.

You must send exactly 2 Bitcoins (BTC) if you pay within 48 hours (approx. value $470USD) TO THE FOLLOWING BTC ADDRESS: 1CNrUCKbuHc1RS9XtWxCVbLHMuvhqwkedH (copy and paste address!!)

If you fail to meet the 48 hour deadline, you must send exactly 5 Bitcoin if you pay after 2 days but less then 6 days 23 hours from send time of this email; to the following BTC address: 1CNrUCKbuHc1RS9XtWxCVbLHMuvhqwkedH (copy and paste address!!)

On the 7th day if you do not pay the non-negotiable amount your significant other, family and friends along with your employer will receive copies of all the hacked data screenshots, credit card transaction logs which include ip address, billing name and address and messages and profile from the cheating site you used to be unfaithful.

If you do not pay within the time frames we have set fourth this data will be in the hands of the people you wanted to keep your cheating secret from.

We are aware that you probably don't have (bitcoin) BTC at the moment, so we are giving you this time to get BTC and pay us.

**If you need help locating a place to purchase (BTC), use the website called localbitcoins, google it, if you dont know about it. This site makes bitcoin very easy and quick to purchase using multiple methods. On localbitcoins sign up and choose to buy the bitcoin (BTC) with western union or money gram wire , find a seller of your choice (localbitcoins is a "ebay" like site with sellers with many sales and a high rating being trustworthy) pay with cash at western union or money gram when you send the wire to the seller as sellers don't accept payments made by credit card. After you send wire to seller provide the seller with a copy of the receipt and when they verify they with send the bitcoins (have the seller send the bitcoin directly to the bitcoin address we provided you with OR if they send the bitcoins to your localbitcoins wallet on site instead you will have to log into your localbitcoin wallet and send to the bitcoin address we provided you with). It will take less then and hour and a half for us to receive the bitcoins once you wire the money to a seller on localbitcoins, the seller will give you a confirmation of payment through site and we will let you know we received. You will get the information needed to send a western union or money gram wire from sellers page after you choose a seller and it will give you the exact amount to wire to seller.

Current price of 1 BTC is about 235 USD, so we are fairly cheap, at the moment. But if you ignore us, we will ruin your life and move on to other targets.

IMPORTANT: You don't even have to reply. Just pay the 2 BTC (or 5 if its after 48 hours) to [above mentioned bitcoin address] we will know it's you and you will never hear from us again.

If you need to contact us feel free but you do not have to you only need to pay and we will disappear.

But if you ignore us, and don't pay within the time frames specified we will make good on are word.

If you think about reporting us to authorities, feel free to try. But it will not help. We are not amateurs. The best thing that can happen, they will go publicly about it. We will, again, get some free publicity. But for you, you will be ruined the damage will be done.

It's a one-time payment. Pay and you will not hear from us ever again!


Pero, aquí los hackers de vía estrecha, ya directamente tiran por elevación.

To introduce ourselves first:

http://www.coindesk.com/bitcoin-extortion-dd4bc-new-zealand-ddos-attacks
http://bitcoinbountyhunter.com/bitalo.html
http://cointelegraph.com/news/113499/notorious-hacker-group-involved-in-excoin-theft-owner-accuses-ccedk-of-withholding-info

Or just google ?DD4BC? and you will find more info.

So, it?s your turn!

All your servers and websites will be going under attack unless you pay 10 Bitcoin.

Pay to 1EqwTAMgw8RtdGpWSFnsW5AdeM7RGVaKrZ

Please note that it will not be easy to mitigate our attack, because our current UDP flood power is 400-500 Gbps.

We are aware that you probably don?t have 40 BTC at the moment, so we are giving you 24 hours to get BTC and pay us.

Find the best exchanger for you on http://howtobuybitcoins.info or http://localbitcoins.com You can pay directly through exchanger to our BTC address, you don?t even need to have BTC wallet.

Current price of 1 BTC is about 230 USD, so we are cheap, at the moment. But if you ignore us, price will increase.

IMPORTANT: You don?t even have to reply. Just pay 10 BTC to the above BTC address we will know it?s you and you will never hear from us again.

But if you ignore us, and don?t pay within 24 hours, long term attack will start, price to stop will go to 100 BTC and will keep increasing for every hour of attack.

If you think about reporting us to authorities, feel free to try. But it will not help. We are not amateurs. The best thing that can happen, they will go publicly about it. We will, again, get some free publicity. But for you, price will go up.

IMPORTANT: It?s a one-time payment. Pay and you will not hear from us ever again!

In many cases, our ?customers? fear that if they pay us once, we will be back and ask for more. That?s not how we work. We never attack the same target twice.

We do bad things, but we keep our word.
Thank you?


Aprovechando una dirección de e-mail, vamos a tocar todos los palos a ver si alguno pica.

No contentos con amenazar sus servidores (¿cualos?) van más allá y prometen al extorsionado destruir para siempre su bien más preciado ¡su cuenta de Facebook!

Hey asshole,

That night you fucked me like a pig, and now I am fucking pregnant, thanks to you asshole!!!

I searched your profile on the Facebook, and found your family members, and every one of your god damn friends.

I am going tell all of your friends about this, so unless you fucking pay me $1250, I am going to ruin your life. You need to send me payment via BTC. I dont want to fucking reveal my identity to you. But I am sure, you still remember me huh.

My BTC address is 1NwpFnkQdHZsTv1ZNLRuzuauPZgDWcdk8E

Use an online bitcoin exchanger like Coinbase to send me BTC. I should receive the BTC within 48 hours.

Oh FUCK! Honey, did I tell you, that I have the video made of us! So you better send me money, or this video is going to all of your friends, and I will see you in the court!

Dont reply to this email, just send the BTC, and I will leave your life.

XOXO


Y sí. También está el vídeo porno. Que tiemble Nacho Vidal. Su reinado se ha terminado.

 I have your sex tape, and unless you send me $999 via BTC (i.e 4 BTC), I will go ahead and post your sex tape to the xxx websites.

Pay to 18qksLPj6KP3GDGPSHvNQMQDxpCyMNr63s
(Copy and paste the address! The above is a BTC address to which you need to send money. You need to use an online exchanger, like CoinBase or use LocalBitCoins.com to find a local exchanger in your area. You can pay directly through exchanger to our BTC address, you don?t even need to have BTC wallet.)

If you think about reporting us to authorities, feel free to try. But it will not help. We are not amateurs. The best thing that can happen, they will go publicly about it. We will, again, get some free publicity. But for you, price will go up.

IMPORTANT: It?s a one-time payment. Pay and you will not hear from us ever again!

In many cases, our ?customers? fear that if they pay us once, we will be back and ask for more. That?s not how we work. We never attack the same target twice.

We do bad things, but we keep our word.
Thank you


En fin. Estos blackmail provocan, más que miedo, una sonrisa complaciente preguntándose si el autor o autores de semejante campaña superan los 14 años.

Puede que algún internauta con la conciencia no muy tranquila decida aflojar ese dinerillo por si acaso aunque intuyo que los chantajistas no terminarán demasiado bien.

Ashley Madison y... ya que estamos... (1/2)

No juzgaré a los usuarios de Ashley Madison. Este no es un blog sobre moral y buenas costumbres.
Pero, desde el punto de vista informático, la brecha de seguridad de AM junto con el Dieselgate han entrado ya en la historia de los patinazos empresariales cuyas consecuencias aún están por ver.

¡Ah! Ashley Madison. Compruebo en el momento mismo en que escribo estas líneas que el dominio y la web siguen activos.

Ashley Madison. La vida es corta, ten una aventura.

¡Ojito! Que también hay falsificaciones como http://www.ashleyrnadison.com/

La portada de dicha web es muy parecida. Pero mientras la web legítima usa https, el clon ni siquiera lo hace. Para el que aún no lo haya visto, en el nombre de dominio se cambia la m de Madison por una r y una n que, visualmente, tienen un aspecto parecido.


Haciendo un Whois

Domain Name: ASHLEYRNADISON.COM
Registrar WHOIS Server: whois.safenames.net
Registrar URL: http://www.safenames.net
Updated Date: 2015-07-22T20:00:19Z
Created Date: 2009-06-09T15:17:35Z
Registrar Registration Expiration Date: 2016-06-09T15:17:35Z
Registrar: Safenames Ltd
Registrar IANA ID: 447
Registrar Abuse Contact Email: 
Registrar Abuse Contact Phone: +44.1908200022
Registrant Name: Host Master
Registrant Organisation: Avid Dating Life Inc.
Registrant Address Line 1: 20 Eglinton Ave. West
Registrant Address Line 2: Suite 1200
Registrant City: Toronto
Registrant State/Province: ONT
Registrant Postal Code: M4R1K8
Registrant Country: CA
Registrant Phone: +1.4164802334
Registrant Fax:
Registrant Email: 

Parece que el negocio de Ashley Madison funciona (ba) muy bien desde el momento en que otras empresas deciden subirse al carro y falsificar de forma descarada la web original lo cual, normalmente, generaría una serie de demandas, etcétera.

Aunque, después de lo sucedido, la reputación de la marca Ashley Madison ha caído tan bajo que no sé yo si merece la pena copiarla. Pero, como decíamos al principio, no somos quién para juzgar a nadie...