Feeds

Wiseguy ticket scalpers used botnets to outwit Captchas

Badfellas bust a captcha in your (super)dome

Top three mobile application threats

A gang of ticket touts have admitted that they hired networks of compromised PCs to defeat CAPTCHAs that would normally have thwarted their plan to automatically purchase tickets for high interest events.

The trio - who operated a firm called Wiseguy Tickets (now there's a name you can trust - Ed) snapped up tickets for gigs from the likes of Bruce Springsteen concerts as well as Broadway productions and baseball playoffs before selling them on to legitimate ticket brokers at a hefty markup. The tech-savvy crooks hired Bulgarian programmers – paid between $1,000 and $1,500 a month – to set up a network of PCs programmed to purchase tickets from the likes of Ticketmaster, MLB.com and LiveNation.

Using the technique, the scoundrels were able to complete ticket applications far faster than legitimate purchasers. For example they scored 440 tickets for a Springsteen gig in July 2008. The miscreants signed up to thousands of cut-out email address and registered hundreds of fake corporations to disguise their fraud.

The "Wiseguys" successfully ran the scam for seven years between 2002 and 2009 before they came unstuck last year. An indictment filed back in March in the US blames the men for "fraud, deceit and computer hacking to make more than $25 million by acquiring and reselling more than 1.5 million of the most coveted tickets to concerts, sporting events and live entertainment throughout the US".

LA residents Kenneth Lowson, 41, and Kristofer Kirsch, 37, both pleaded guilty to a variety of hacking and wire-fraud charges over the scam at a court appearance in New Jersey on Thursday, Bloomber (via The New York Times) reports. Joel Stevenson, 36, admitted lesser hacking charges over the same scam.

Sentencing is due to take place on 15 March next year. A fourth suspect in the case, chief financial officer Faisal Nadhi, remains at large. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
Oracle working on at least 13 Heartbleed fixes
Big Red's cloud is safe and Oracle Linux 6 has been patched, but Java has some issues
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.