Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Craig Jones

πŸ‘€ Speaker
See mentions of this person in podcasts
3537 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

And it...

Darknet Diaries
174: Pacific Rim

Sat again in Chengdu.

Darknet Diaries
174: Pacific Rim

We found this trial license and they were also recited to a 163 address and a moniker that we called GBigMau.

Darknet Diaries
174: Pacific Rim

We kind of pivoted on him.

Darknet Diaries
174: Pacific Rim

We found that he actually started to experiment with this database or SQLI injection like our mother SoCo.

Darknet Diaries
174: Pacific Rim

And we kind of found then looking at his IP address, again, we had phenomenal telemetry here.

Darknet Diaries
174: Pacific Rim

He was looking at different knowledge base articles around our kind of previous CVEs issues.

Darknet Diaries
174: Pacific Rim

He was looking through our forum system to look at maybe other potential issues or places that he could maybe pivot and work on.

Darknet Diaries
174: Pacific Rim

And we find that he was an actual firewall researcher.

Darknet Diaries
174: Pacific Rim

And he published a number of different vulnerabilities.

Darknet Diaries
174: Pacific Rim

We could see him on Linux boards everywhere.

Darknet Diaries
174: Pacific Rim

publishing various different router vulnerabilities up until about 2018, and then he went silent.

Darknet Diaries
174: Pacific Rim

He'd been really, really busy up until like 2018.

Darknet Diaries
174: Pacific Rim

Now, we kind of found out that he was working for a company called Xizhuan Silence Information Security Technology.

Darknet Diaries
174: Pacific Rim

Mostly because doing some extra OSINT, we found that his username appeared in many Chinese hacking groups and lots of CTFs, so like capture the flag type events, where he'd been registered towards this company as well.

Darknet Diaries
174: Pacific Rim

So we found corroborating evidence from a couple of different places that this was the same guy in the same company, you know?

Darknet Diaries
174: Pacific Rim

Again, located in Chengdao in China.

Darknet Diaries
174: Pacific Rim

So we found a really clear picture of who this person was.

Darknet Diaries
174: Pacific Rim

Now, his external OPSEC was pretty good.

Darknet Diaries
174: Pacific Rim

You would not have been able to find him that easily, but because we could see the internal telemetry and get the license information, kind of connect the dots, we could actually pin these devices to him and his usage.