Posts Tagged ‘domestic spying’

Final Post

October 2, 2009

No – I’m not dead yet!!

This is a final post at Tigerstail.wordpress.com because I am tired of seeking knowledge and bitching about that which is. It is time to use my skills to develope the solutions to all of the problems I have discovered.

Join Me at jimmicap.wordpress.com

Advertisements

The FBI and Akamai

July 19, 2009

My friendly sales rep from my ISP reminded me that the FBI is on Akami and showed me a tracert from his office which described a perfectly normal Akamai connection. For those who don’t know, I have discussed this technology before and am very uncomfortable connecting to a services which delivers content to/from? multiple ports and from multiple different IP’s and servers.

I tried to explain to him how this intrastate connection was dramatically different from any I had ever seen or discussed.

I mean the following is a tracert to Whitehouse.gov which you would expect to be well protected and I really don’t want to believe the FBI protects themselves better than they protect our President.

C:\Documents and Settings\Compaq_Owner>tracert whitehouse.gov

Tracing route to whitehouse.gov [96.16.226.135]
over a maximum of 30 hops:

1 <1 ms <1 ms <1 ms 192.168.0.1
2 27 ms 36 ms 36 ms nn-gw.viaccess.net [66.185.42.1]
3 30 ms 28 ms 21 ms auto-66.185.32.49.choice.vi [66.185.32.49]
4 164 ms 50 ms 35 ms 12.124.80.161
5 90 ms 86 ms 326 ms gbr2.ormfl.ip.att.net [12.123.32.78]
6 84 ms 86 ms 86 ms cr2.ormfl.ip.att.net [12.122.1.62]
7 101 ms 137 ms 137 ms cr1.attga.ip.att.net [12.122.5.142]
8 94 ms 94 ms 122 ms cr2.wswdc.ip.att.net [12.122.1.174]
9 109 ms 86 ms 101 ms 12.122.134.97
10 * * 87 ms 192.205.35.114
11 168 ms 86 ms 87 ms po-3.r04.asbnva01.us.bb.gin.ntt.net [129.250.6.4
5]
12 94 ms 93 ms 94 ms 168.143.97.2
13 106 ms 152 ms 93 ms a96-16-226-135.deploy.akamaitechnologies.com [96
.16.226.135]

In fact, the tracert he presented to me was extremely similar but then he was a supervisor on the system with the FBI server and perhaps not yet a target.

Now my tracert for http://www.fbi.gov was simplicity itself.

C:\Documents and Settings\Compaq_Owner>tracert http://www.fbi.gov

Tracing route to a33.g.akamai.net [66.185.33.88]
over a maximum of 30 hops:

1 <1 ms <1 ms <1 ms 192.168.0.1
2 32 ms 36 ms 57 ms nn-gw.viaccess.net [66.185.42.1]
3 24 ms 28 ms 43 ms auto-66.185.33.88.wirelessworld.vi [66.185.33.88
]

Akamai technology is supposed to maximize the utilization of Internet recourses by having cache memory for popular sites at many locations with many different routes to minimize delivery time. Putting the FBI on every ISP in America as independent system server is a logistic nightmare and with less than 6000 customers for very small ISP’s like mine, this becomes a horribly inept way to accomplish the goal of maximizing resource utilization.
.
As noted by others in the literature back to 2001, many commercial product updates come from exactly the same IP number as the FBI, including many antivirus products, Java, Macromedia, Adobe and Microsoft. It’s also bothersome to me that while my computer is being updated on parallel paths, some of the connections are from the IP which is owned by the software company, and some are the same IP as used by the FBI. Linux users should not be smug as the same FBI IP’s can be found continuously connected to my Linux machines. It’s also bothersome that when I switch antivirus and antispyware systems the infections discovered which are incompatible with the new product will have the same names as minor files used by Adaware, Trend Micro, Nortan, Micrrosoft, Sun Java and Adobe.

In a dark sort of way, I have come to accept being spied upon because, it seems to keep me free from outside infections. Now when I bother to check, my spyware, adware or antivirus shows that my machine is perfectly clean although a change of products will always bring new discoveries of infected minor files from major vendors.

Searching for the FBI

July 17, 2009

During the course of the trial I lost three computers to shut down Trojans while researching the source of the shutdown Trojan for the contraband computer held in evidence. I also lost another computer when challenged by the prosecution to visit a particular page at Cert. Prior to this, the prosecution had me identified for the record even though my position was a researcher and not a witness. To say the Department of Justice was interacting with my computers during the course of the trial is an understatement.

Over the past two years ago, I discovered my computer constantly interacting with IP numbers which were owned by my ISP. Since Carnivore was known to be stationed at a local ISP, I made the incorrect assumption that I was being monitored by that program. As time passed, I noticed extremely aggressive behavior and if I went to a suspected Federal Honeypot, as many as 60-100 ports would be opened with connections to my ISP. This reproducible behavior occurred with Linux and both current versions of Windows. (XP and Vista). When using a live Linux cd , there were no connections on start-up and the connections occurred only after I went to a suspicious site.

While I assumed that these connections were the FBI, I had no way to prove it until I stumbled on it last week. Since, I assume I am already a person of interest, I run a periodic search for the location of internet spy rooms to find out who is being watched. It should be obvious that if they can monitor my internet traffic, they can also monitor web sites offering seditious material using the same splitter technology. The perfect tool to track my signal is of course Neotrace which unfortunately has security issues so I install a new copy daily and repeat my work and use different ISP connections to verify the results.

One thing I never checked was the path to http://www.FBI.gov until last week when I ran Neotrace. I was shocked to find I was only 3 jumps from The FBI which had the same ISP as the constant connections to my machine. I double checked it with the DOS traceroute command and find that this is part of akamai technology, but the loop never leaves the United States Virgin Islands unlike any other akamai served connections I’ve traced.

Moreover, the constant connections are through parallel iexplore.exe connections which are usually spyware and the same block of IP’s have been in use for two years. (The iexplore.exe connection exists even when using Firefox) The supporting experiment of using the DOS command, “netstat –ano” allows you to observe that a browser call for http://www.fbi.gov increases the number of connections to my machine but no other new IP numbers connect to deliver content or probe my machine (aside from possibly Google.)

Interestingly enough, since this connection is being made intrastate, it may not be clearly illegal. First, most people would not dwell on the connection or try to block it as it is part of their ISP service so most would never notice or complain. Next, the site is clearly an FBI location and delivers the FBI homepage locally which is not exactly a clandestine operation. Next, Federal laws governing wiretaps, Keystroke loggers, and Trojans regulate interstate traffic and Neotrace finds no link to anything beyond the United States Virgin Islands.

As an aside, I asked a friend to do a tracert to the FBI in New York City and consistent with my suspicions, the IP she got was 204.2.199.25 which Neotrace places in New York City. I would expect that most connections to the FBI are intrastate connections.

If this is the so called Magic Lantern or the euphemism beyond that, it has a lot more power than previously described and is not simply a key stroke logger. It has the power to shut down by altering video settings, by altering the window’s registry settings so windows appear counterfeit, or by destroying the motherboard. It can also interfere with posting on a blog, and sending emails and temporarily freezing the system at an inopportune time.

Check it out yourself.

In DOS use “tracert http://www.fbi.gov&#8221; or in Linux Counsol use “traceroute http://www.fbi.gov&#8221; to find the IP of the FBI server which would deliver content to you. (It’s the last IP listed.) Give me the IP you got for http://www.fbi.gov in the comment section and I’ll let you know where it is located.

Resistance is Futile!

July 21, 2008

Once you realize that Resistance is Futile, knowledge truly is soporific. The problem is, life without knowledge acquisition becomes somewhat boring. After all how much, sex, booze,beach time and loud music can a sing person handle. So for various reasons such as the potential for my liver falling out and fear of going brain dead, I decided to sober up and read the content of all my emails from Sans to see what I’ve been missing since April. The following is extracted from various Sans newsletters and attracted my attention because of the “unique” content.

WINDOWS SECURITY
Researchers at the Internet Storm Center estimate that it takes about
four minutes for an unpatched Windows PC to be compromised once it
connects to the Internet. The survival time has consistently dropped
over the past years due to the increasing number of worms and viruses
and hackers using more and more automated attacking tools. However, a
researcher with the German Honeypot Project claims the survival time is
much higher than 4 minutes and in fact is nearer 16 hours. Either way its less than one day on line.

Google can’t stand the competition
A controversial law was narrowly voted
in last month and allows Swedish security services to eavesdrop on all
international calls into and out of Sweden. In response to the new law
TeliaSonera, the Finnish-Swedish telecoms operator, has moved its
servers from Sweden to Finland and Google is also considering a similar
course of action. After all, why should Google allow anyone other than Google to snoop on your surfing
habits and keep a history of your actions

Google Caches Retain Stolen Data
Stolen sensitive personal data, including financial account information,
have been found to linger in Google caches for months even after the
server holding the stolen information has been disabled. Cyber
criminals collect information through keystroke loggers and store the
data on servers. When the servers are discovered, they are taken down,
but the Google pages are not unless specific requests are made. A
Google spokesperson said that in general, the company does not remove
cached information, but that it eventually disappears on its own after
the original source is no longer accessible.

Coming to America!

Phorm’s technology can be
used by Internet Service Providers to track end user activity on the
Internet and place advertisements based on their online activity. Phorm
already has agreements in place with some of the U.K.’s top ISPs such
as the BT Group PLC (BT), Carphone Warehouse’s (CPW.LN) Talk Talk and
Virgin Media.

Expanding the Patriot Act
The Foreign Intelligence Surveillance
Act (FISA) allows for warrantless surveillance of
telecommunications and immunity from subsequent lawsuits served against
the telecommunications companies facilitating the surveillance. A
lawsuit claims that FISA breaches the Fourth Amendment of the U.S.
Constitution, which prevents the government from unreasonable searches
and seizures. Supporters of the law claim it is a vital weapon in the
fight against terrorism.

Don’t Xerox any $3 Bills
A feature built into many modern laser printers is raising concerns
among civil liberties groups that individuals’ privacy may be eroded.
The feature uses technology to print hidden yellow dots that are unique
to the printer onto each page. These dots are invisible to the eye, but
when viewed under a blue LED light they can identify the printer and the time of use. The
technology is used to track those who attempt to use color laser
printers to create counterfeit money. However, privacy advocates are
concerned that the technology could be misused to track and identify
whistleblowers or dissidents in totalitarian regimes.

Read it and Weep!

Google Proof Sites – Part 2 Links

December 22, 2007

One of the safer ways to check on dangerous sites is to use cache pages from Google. Unfortunately, as previously discussed, not all sites can be Googled and unbelievable as it may seem not all porn sites want more patrons.

Two of the first measures of popularity that nascent webmasters learn about are links and traffic count. Sites like Alexa and Quantcast give a measure of popularity based on traffic and Technorati uses the number of incoming links as a measure of authority. Now with the emergence of Google Stats and tools, you can use Google for a lot more than finding information on a search term.

One of the first tools that webmasters learn about is the links directive. As an example:

link:fatsavage.wordpress.com

This search can be done from any Google search bar whether on their home page or in your browser. If you follow the link above, you find 73 pages linked to my blog. Try it with your own site or blog. Only problem is, I’m not sure about the accuracy.

When you go to any of the following sites which have all been exposed at fatsavage.wordpress.com you find that all of them have no incoming links. This is pretty strange for porn sites which use traffic building link exchanges and shared databases.

link:femalesex.com
link:youngsex.com
link:youngerbabes.com
link:young-models.org
link:cnomy.com
link:shockmeshocker.com

Cut and past and put them in the Google search bar or just type them in. Using Google and viewing cache pages is fairly anonymous except for all those nasty index.dat records retained on your own machine.

The only two things that these sites have in common is they all make the Fatsavage Shitlist of Law Enforcement Honeypots, and they are all engaged in the porn industry. Still, when you check thehun.net you find 291 incoming links.

Go Figure!