{"id":36957,"date":"2013-08-05T13:19:58","date_gmt":"2013-08-05T17:19:58","guid":{"rendered":"http:\/\/valorguardians.com\/blog\/?p=36957"},"modified":"2013-08-05T13:19:58","modified_gmt":"2013-08-05T17:19:58","slug":"fbis-troll-bait","status":"publish","type":"post","link":"https:\/\/www.azuse.cloud\/?p=36957","title":{"rendered":"FBI&#8217;s troll bait"},"content":{"rendered":"<p>Our buddy Laughing Wolf alerted us to the story and I found it at <a href=\"http:\/\/www.wired.com\/threatlevel\/2013\/08\/freedom-hosting\/\">Wired<\/a>. It looks like the FBI or some Federal Law Enforcement agency is trolling folks who use Tor, the system for hiding an internet user&#8217;s identity. Apparently they&#8217;ve developed malware that transmits a user&#8217;s actual identity to an IP address in Reston, Virginia.<\/p>\n<blockquote><p>\u201cIt just sends identifying information to some IP in Reston, Virginia,\u201d says reverse-engineer Vlad Tsrklevich. \u201cIt\u2019s pretty clear that it\u2019s FBI or it\u2019s some other law enforcement agency that\u2019s U.S.-based.\u201d<\/p>\n<p>If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI\u2019s \u201ccomputer and internet protocol address verifier,\u201d or CIPAV, the law enforcement spyware first reported by WIRED in 2007.<\/p>\n<p>Court documents and FBI files released under the FOIA have described the CIPAV as software the FBI can deliver through a browser exploit to gathers information from the target\u2019s machine and send it to an FBI server in Virginia. The FBI has been using the CIPAV since 2002 against hackers, online sexual predator, extortionists and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.<\/p>\n<p>The code has been used sparingly in the past, which kept it from leaking out and being analyzed or added to anti-virus databases.<\/p><\/blockquote>\n<p>I&#8217;m only interested in the story because some of our trolls have resorted to using Tor in order to avoid being blocked here and it would put a smile on my face to see some of them frog-marching on the evening news. Maybe this news will make them a little less willing to expose themselves to prosecution for the other things they do on the internet with their little toys, because we all know that military phonies are guilty of other things besides their uniform discrepancies.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our buddy Laughing Wolf alerted us to the story and I found it at Wired. It &hellip; <a title=\"FBI&#8217;s troll bait\" class=\"hm-read-more\" href=\"https:\/\/www.azuse.cloud\/?p=36957\"><span class=\"screen-reader-text\">FBI&#8217;s troll bait<\/span>Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185],"tags":[],"class_list":["post-36957","post","type-post","status-publish","format-standard","hentry","category-crime"],"_links":{"self":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/36957","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36957"}],"version-history":[{"count":0,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/36957\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36957"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36957"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}