Feeds

Portrait of an (alleged) cyber bully as a young man

Accused CastleCops nemesis didn't get mad. He got bots.

The Essential Guide to IT Transformation

Late in the evening of February 13, Paul and Robin Laudanski were planning the following day's Valentine's celebration when they received word that CastleCops, the volunteer security website they run, was under assault.

Greg C. King in a photo from his Yahoo Profile.

At its peak, the five-day attack flooded CastleCops with close to 1 gigabyte of data every second. The distributed-denial-of-service deluge was so severe that the husband-and-wife team were forced to take their site offline 15 minutes after it started. It also knocked CastleCops' webhost offline for two days, causing more than $160,000 worth of damage to the company and its customers.

"We were planning on having a family Valentine's event," said Paul Laudanski, who along with Robin was forced to spend the next several days migrating to a new hosting provider. "Then, of course, the DDoS started, which ruined those plans."

The attack, according to federal prosecutors, was the handiwork of Greg C. King, a 21-year-old California resident who at one point maintained a 7,000-node botnet. On Monday, he was publicly charged with four counts of illegal hacking, charges that carry a maximum penalty of 40 years in prison and a $1m fine.

King has pleaded not guilty, and he reiterated his claims of innocence in a telephone interview with The Register. He said he was released on $25,000 bond and is under orders not to use computers outside of his job, which he declined to identify.

The indictment comes three weeks after a yearly report from Arbor Networks found for the first time that internet service providers rated botnets as the top operational threat to their infrastructure.

Revenge of the King

While more and more of today's cyber criminals are driven by financial gain, King's four-year DDoS spree was motivated by revenge for perceived slights, according to court documents and interviews. King's need to lash out ran so deep that his crippling attacks continued even after federal authorities raided his parents' Fairfield, California home in 2004, prosecutors allege. Even a conviction for attempted armed robbery, for which King served seven months jail time earlier this year, didn't weaken his resolve.

King "just continued on and on and on and on," said Tami Quiring, owner of KillaNet Technologies, a British Columbia-based website for high school students preparing for careers in online media. "He would make appearances on IRC and just taunt the kids and threaten them and post links to some really disgusting porn sites."

Quiring says one of her first brushes with King dated back to 2003, before the suspect had even turned 18. A chat server she maintained was subjected to a smurf attack, a particularly powerful type of DDoS that bounces spoofed ping requests off thousands of vulnerable routers and, in the process, significantly amplifies the amount of traffic directed at a victim. As a result, she said, she was forced to pull the plug on her site.

Over the years, Quiring says, she tried all kinds of evasive maneuvers. She repeatedly changed servers. She blacklisted his IP address. She and her employees engaged him in chat dialogs. None of it had any effect. She said the attacks continued through last year, when a site she set up to host a large video game tournament was taken offline, preventing Nvidia, ATI and other partners from accessing the site at a crucial moment.

"We withstood attacks that took Yahoo! down," Quiring said. "For a long time, our servers were locked up like Fort Knox."

The SilenZ Treatment

A key element in the vengeance allegedly meted out by King was acknowledgment from his victims that they were being punished. And as a result, he took few steps to cover his tracks. He frequently taunted his victims in chat rooms before and during his attacks, and on several of those occasions, he dropped hints about his real-life identity, according to court documents.

He went by the same handful of online monikers, including SilenZ, SilenZ420 and Gregk707, and he also used the same several email addresses - including gregk707@yahoo.com and silenz420@gmail.com - to establish accounts on the systems he attacked. He frequently used his parents' SBC DSL line to log in to the accounts and read email. He was partial to using the passwords "1fuckhead" and "1fuckhead1" on many of those accounts.

"My good friend's ISP shut him over this fucking post," a user by the name of SilenZ wrote in a CastleCops forum shortly before the February 13 attack began. "I have the right to be angry. If you edit my post once more, you will be sorry."

SilenZ was banned from the boards at 10:40 that night. About four minutes later, the DDoS started.

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.