3 ms·
With the fruitless/mindless attacks from the comments, I can see the crowd is still about the same. Lots of low hanging fruit with a few guys getting rich (like
by ambiate 12y ago
With the fruitless/mindless attacks from the comments, I can see the crowd is still about the same. Lots of low hanging fruit with a few guys getting rich (like most schemes).
It is funny how this business has not changed since 1998. The communication channels changed, but the ideas and market is still the same. My first introduction to this was with the Windows RPC remote exploit vulnerabilities. I setup some honeypots to determine what the botnets were up to (most were manual B/C class scans at that time, the good old days before decentralized command). I ended up following the trail of controllers up to a random efnet IRC chatroom and finally to a more private area. That's where they sold/traded data from the botnets. This was prior to the 'rent a botnet to DDoS' era.
Back then, credit cards without CVV2s (from Windows IIS Servers exploited with that long string bug leaking out plain text documents) were worth about 50 cents a piece. CVV2 brought it up to around $2-3 for US, $4-6 for UK/CA. Address information was around $15. It seems the market has deflated a lot, the credit cards are probably from targeted companies rather than scripted botnets looking for vulnerable boxes, and the data can just be bought from a website rather than having to get a third party to moderate the exchange.
Once again,the comments reminded me the most of that community. Someone mentioned about entering CC info on a CC theft site. There used to be a RTF document exploit where you could execute something or another from them, the dump sellers would infect their dump files (RTF docs) and steal the client's data. These communities are cutthroat.