
By 2016, vDos had become the most popular service in the world for ordering DDoS attacks.
If conspiracy theories are to be believed, antivirus companies themselves spread viruses, and DDoS protection services instigate these attacks. Of course, these are just fabrications... or are they?
On January 16, 2020, the Federal District Court of New Jersey 22-year-old Tucker Preston, a resident of Macon, Georgia, on one count of charges, specifically 'damage to protected computers through the transmission of a program, code, or command.' Tucker is a co-founder of BackConnect Security LLC, which offered DDoS protection. The young businessman could not resist the temptation to take revenge on uncooperative clients.
The sad story of Tucker Preston began in 2014, when the teenage hacker, along with his friend Marshal Webb, founded BackConnect Security LLC, which later split into BackConnect, Inc. In September 2016, this firm during the shutdown operation of the vDos service, which at that time was considered the most popular service in the world for ordering DDoS attacks. BackConnect reportedly suffered an attack through vDos — and conducted an unusual 'counter-attack,' seizing 255 enemy IP addresses via (BGP hijacking). Conducting such an attack to protect one's interests sparked controversial opinions in the information security community. Many believed BackConnect had crossed the line.
Simple BGP hijacking is carried out by announcing someone else's prefix as your own. Uplinks/peers accept it, and it starts spreading across the network. For example, in 2017, allegedly due to a software failure, Rostelecom (AS12389) for Mastercard (AS26380), Visa, and several other financial organizations. BackConnect acted in a similar manner when they appropriated IP addresses from the Bulgarian host Verdina.net.
BackConnect's CEO, Bryant Townsend, later in the NANOG mailing list for network operators. He stated that the decision to attack the enemy's address space was not easy, but they are ready to take responsibility for their actions: "Although we had the opportunity to hide our actions, we felt it would be wrong. I spent a lot of time reflecting on this decision and how it might negatively impact the company and myself in the eyes of some people, but in the end, I support it."
As it turns out, BackConnect has previously employed BGP hijacking, and the company has quite a dark history. However, it should be noted that BGP hijacking is not always used for malicious purposes. Brian Krebs , stated that he himself uses the services of Prolexic Communications (now part of Akamai Technologies) for DDoS protection. They were the ones who figured out how to use BGP hijacking for DDoS attack mitigation.
If a DDoS attack victim seeks assistance from Prolexic, the latter redirects the client's IP addresses to themselves, allowing them to analyze and filter incoming traffic.
Since BackConnect provided DDoS protection services, an analysis was conducted to determine which BGP hijacks could be considered legitimate in the interests of their clients and which appeared suspicious. This takes into account the duration of foreign address hijacking, how widely the foreign prefix was announced as their own, whether there is confirmed agreement with the client, etc. The table shows that some actions by BackConnect look very suspicious.
Apparently, someone among the victims has filed a lawsuit against BackConnect. In the name of the company that the court recognized as the victim is not mentioned. The victim is referred to in the document as Victim 1.
As mentioned earlier, the investigation into BackConnect's activities began after the vDos service was hacked. At that time the service administrators became known, as well as the vDos database, including its registered users and records of clients who paid vDos for launching DDoS attacks.
These records showed that one of the accounts on the vDos site was opened with email addresses linked to a domain registered in the name of Tucker Preston. This account initiated attacks on a large number of targets, including multiple attacks on networks owned by (FSF).
In 2016, a former sysadmin of the FSF said that the non-profit organization had considered collaborating with BackConnect at one point, and attacks began almost immediately after the FSF announced it would seek another firm for DDoS protection.
According to The U.S. Department of Justice states that for this charge, Takeru Preston faces up to 10 years in prison and a fine of up to $250,000, which is twice the total profit or loss from the crime. Sentencing is scheduled for May 7, 2020.
GlobalSign offers scalable PKI solutions for organizations of all sizes.
For more information: +7 (499) 678 2210, sales-ru@globalsign.com.
Source: habr.com
