5 ms·
Former YouSendIt CEO pleads guilty to Web attack on his old company
- jonknee 15y agotl;dr "web attack" = ApacheBench
- desigooner 15y agoIsn't he the same guy who was barred from the iOS store for creating crappy apps that were essentially just webpages packaged as applications? Wonder whatever happened to that ordeal
- deleted 15y ago[deleted]
- staunch 15y ago$ ab -c 500 -n 1000000 http://example.com/some/resource/intensive/url Amazing how many sites this kind of "attack" would take down. Most sites don't have any throttling in place to stop it.
- phpnode 15y agoAlthough there was obviously malicious intent here I think it's amazing that typing one line into a terminal can result in (potentially) 5 years in prison.
- epochwolf 15y agoJust because something is simple or easy doesn't make it any more or less ethical to do.
- GigabyteCoin 15y agoPulling a trigger is pretty easy too.
- kristofferR 15y agoYeah, but the difference between killing someone and making a website go down is pretty huge. 5 years for a DOS is insane
- OstiaAntica 15y agoI don't know, it is a pretty vicious act to knock someone's business offline. Worse than car theft. DOS could be disrupting thousands of lives and commerce or research, depending on the site. Five years seems about right if the intent is malicious.
- duck 15y agoYou could also say not setting up the right infrastructure to stop such an attack is malicious of the owners of the site.
- Aetius 15y agoHow many queries per second could you do that with just a personal machine (i.e. not a cloud machine with huge bandwidth limits), before your ISP shut you off?
- snowmaker 15y agoWhoa .. there is a big story in here somewhere, which appears to have gone way over the head of the LA Times hack who wrote this regurgitated press release. He was arrested on criminal charges for running a simple benchmarking program? By the company he was formerly the CEO of? This is patently ridiculous, and can only be a case of YouSendIt having some major grievances with him about something else, or some other kind of ulterior motive. It seems only reasonable that he was running apache benchmark for curiosity, not with any serious malicious intent, and is now being held on some trumped up charges concocted by people out to get him. If anyone knows of an article that actually explains the relationship between YouSendIt and their former CEO, please link to it.
- Aetius 15y agoUmm, did you actually read the article? The former chief executive of the YouSendIt, a website where users can post files too large to send over email, has admitted to launching an online attack against the company he once ran. According to FBI investigators, from about December 2008 to June 2009, Shaikh sent an ApacheBench program to YouSendIt's servers, which measured the number of requests per second the site was capable of handling. Sending the program multiple times in essence amounted to a distributed denial of service attack, or DDoS attack. No "curious" person would run apache bench on a website they formerly cofounded for 7 months.
- powertower 15y agoNo. He POSTed the binary ab.exe to the website/service over and over ... using ab itself to do the POST.
- tomkarlo 15y agoThe article and the FBI statement are a little unclear, but I don't think that's what they mean. "Beginning in or about December 2008 and continuing through June 2009, Mr. Shaikh sent an ApacheBench computer code to YouSendIt’s servers. ApacheBench is a benchmarking program used for measuring the performance of computers known as web servers. ApacheBench was designed to determine the number of requests per second a server is capable of serving. By intentionally transmitting the ApacheBench program to YouSendIt’s servers, Mr. Shaikh was able to overwhelm the servers’ capabilities and render it unable to handle legitimate network traffic." I have to think when they say "sent... to" they mean he directed the AB to make requests from YouSendIt's server, not that he posted it to the service. Otherwise the rest of the statement - "able to overwhelm the servers’ capabilities and render it unable to handle legitimate network traffic" - doesn't make any sense, unless someone can explain how simply transmitting the benchmark executable via the service somehow caused that. (As someone else pointed out, he could have used AB to /post/ AB to the servers... but I don't see anything in these articles to necessarily support that... and it would seem like the payload is less interesting than the transmission method.)
- seats 15y ago>> "By intentionally transmitting the ApacheBench program to YouSendIt's server..." the FBI said in a statement. This statement makes it clear how unfamiliar the FBI is with technology.
- powertower 15y agoNo. The payload was the binary ab.exe (ApacheBench), sent over and over again using the YouSendIt service, which sends files from person A to person B instead of using email.
- seats 15y agoWell that is certainly an interpretation that would make sense, so thanks. I reread the FBI's statement, and I'm not convinced that what you suggest is what they actually mean, however. Does yousendit actually work that way? Can I send someone an arbitrary executable referenced from an email and it actually runs?
- brown9-2 15y agoWhat would be the point of this? Why send ab?
- ceejayoz 15y agoIt would certainly send a statement. "You really should be using ab for load testing. Here, have a million copies of it."
- Terretta 15y agoIs there another story you're getting this from?
- tommeelee 15y agoSo the FBI runs YouSendIt. Don't upload your warez there folks.
- powertower 15y agoMaybe they swindled him out of his vested options too.
- powertower 15y agoFor those that are getting confused. What he did was something like this... C:\Apache\bin\ab.exe -c 500 -n 5000000 -p ab.exe http://yousendit.com/send-it Using ab.exe to POST the binary ab.exe over and over using the service (yousendit) which send file1 from user1 to user2.
- tomkarlo 15y agoAre you getting this from somewhere other than the OP and linked FBI statement? Just wondering if someone else has written about this case...
- ChuckMcM 15y agoMore about Khalid : http://blekko.com/ws/Khalid+Shaikh+/techblogs http://blekko.com/ws/Khalid+Shaikh+/techblogs I agree with comments here that this is one of those 'these facts don't sound like the story in which they are presented' Given the timeline of his relationship with YouSendIt its possible he had a grudge against them, just speculation though.
- jonknee 15y agoIt's pretty pathetic that a file transfer site can be harmed by a single user running ab. I really hope there is more to this. I run ab all the time on my own stuff, I didn't know I could go to prison for something as simple as testing the performance of a site I used to run.
- mmaunder 15y agoThe fact that he got caught suggests he didn't bother to cover his tracks which is fairly easy to do. So how do you not realize that throwing a brick through your old employers front window isn't a crime?