Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Owen Miller

๐Ÿ‘ค Speaker
24 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
175: Bayrob

I worked on AOL's CERT team from 2011 to 2016.

Darknet Diaries
175: Bayrob

I received a report of abuse on my network from a specific IP at a specific time and was told it was related to potential Bayrob activity.

Darknet Diaries
175: Bayrob

I went ahead and started taking a look at that and started pivoting around.

Darknet Diaries
175: Bayrob

We were able to connect specific domains that they were using and accessing with various accounts, various AOL accounts that were being used in order to tunnel traffic through us.

Darknet Diaries
175: Bayrob

AOL allowed anyone to sign up for a free account and then tunnel network traffic through our dial-up IP allocation space.

Darknet Diaries
175: Bayrob

So we were basically like,

Darknet Diaries
175: Bayrob

a very large free open proxy service.

Darknet Diaries
175: Bayrob

And we're also a free email provider.

Darknet Diaries
175: Bayrob

And basically we built a full packet capture indexing system.

Darknet Diaries
175: Bayrob

At the time it was called Moloch and is now called Archemy.

Darknet Diaries
175: Bayrob

We had deployed at ISP level.

Darknet Diaries
175: Bayrob

And so us and others as well that offer those same types of services were heavily being leveraged by this group.

Darknet Diaries
175: Bayrob

in order to, you know, create new accounts, chat with people, all that good stuff.

Darknet Diaries
175: Bayrob

And so we just started digging around and seeing when they would connect in, where they would connect from, start going through all of the network traffic that they had presented to us.

Darknet Diaries
175: Bayrob

So one of the members of the group was typing in his email address to log in on like gmx.de or one-on-one internet.

Darknet Diaries
175: Bayrob

They did not use SSL at the time for the login form.

Darknet Diaries
175: Bayrob

So when he typed in his email address, he typed in his personal email address and then went, oops, and then logged in with his, you know, quote unquote work email address.

Darknet Diaries
175: Bayrob

And so we have the same IP address at the same, within like, you know, 10 seconds, like typing in someone's email address and then this actor's email address.

โ† Previous Page 1 of 2 Next โ†’