Monday 29 December 2014

Andrew Jacob Stephens gets a roasting ............

...........from Brian Krebs.

From <http://krebsonsecurity.com/2014/12/spamhaus-cloudflare-attacker-pleads-guilty-to-computer-abuse-child-porn-charges/>

Dec 14

SpamHaus, CloudFlare Attacker Pleads Guilty

facebooktwittergoogle_plusredditpinterestlinkedinmailA 17-year-old male from London, England pleaded guilty this week to carrying out a massive denial-of-service attack last year against anti-spam outfit SpamHaus and content delivery network CloudFlare, KrebsOnSecurity has learned.

In late March 2013, a massive distributed denial-of-service (DDoS) attack hit the web site of SpamHaus, an organization that distributes a blacklist of spammers to email and network providers. When SpamHaus moved its servers behind CloudFlare, which specializes in blocking such attacks — the attackers pelted CloudFlare’s network. The New York Times called the combined assault the largest known DDoS attack ever on the Internet at the time; for its part, CloudFlare dubbed it “the attack that almost broke the Internet.”
In April 2013, an unnamed then-16-year-old male from London identified only by his hacker alias “Narko,” was arrested and charged with computer misuse and money laundering in connection with the attack.
Sources close to the investigation now tell KrebsOnSecurity that Narko has pleaded guilty to those charges, and that Narko’s real name is Sean Nolan McDonough. A spokesman for the U.K. National Crime Agency confirmed that a 17-year-old male from London had pleaded guilty to those charges on Dec. 10, but noted that “court reporting restrictions are in place in respect to a juvenile offender, [and] as a consequence the NCA will not be releasing further detail.”
During the assault on SpamHaus, Narko was listed as one of several moderators of the forum Stophaus[dot]com, a motley crew of hacktivists, spammers and bulletproof hosting providers who took credit for organizing the attack on SpamHaus and CloudFlare.
WHO RUNS STOPHAUS?
It is likely that McDonough/Narko was hired by someone else to conduct the attack. So, this seems as good a time as any to look deeper into who’s likely the founder and driving force behind the Stophaus movement itself. All signs point to an angry, failed spammer living in Florida who runs an organization that calls itself the Church of Common Good.

Not long after McDonough’s arrest, a new Facebook page went online called “Freenarko,” which listed itself as “a solidarity support group to help in the legal defense and media stability for ‘Narko,’ a 16-yr old brother in London who faces charges concerning the Spamhaus DDoS attack in March.”
Multiple posts on that page link to Stophaus propaganda, to the Facebook page for the Church of the Common Good, and to a now-defunct Web site called “WeAreHomogeneous.org” (an eye-opening and archived copy of the site as it existed in early 2013 is available at archive.org; for better or worse, the group’s Facebook page lives on).
The Church of Common Good lists as its leader a Gulfport, Fla. man named Andrew J. Stephens, whose LinkedIn page says he is a “media mercenary” at the same organization (hours after this story was posted, large chunks of text were deleted from Stephens’ profile; a PDF of the original profile is here).
Stephens’ CV lists a stint in 2012 as owner of an email marketing firm variously called Digital Dollars and IBT Inc, moneymaking schemes which Stephens describes as a “beginner to intermediate level guide to successful list marketing in today’s email environment. It incorporates the use of both white hat and some sketchy techniques you would find on black hat forums, but has avoided anything illegal or unethical…which you would also find on black hat forums.”
More recent entries in Andrew’s LinkedIn profile show that he now sees his current job as a “social engineer.” From his page:
“I am a what you may call a “Social Engineer” and have done work for several information security teams. My most recent operation was with a research team doing propaganda analysis for a media firm. I have a unique ability to access data that is typically inaccessible through social engineering and use this ability to gather data for research purposes. I have a knack for data mining and analysis, but was not formally trained so am able to think outside the box and accomplish goals traditional infosec students could not. I am proficient at strategic planning and vulnerability analysis and am often busy dissecting malware and tracking the criminals behind such software. There’s no real title for what I do, but I do it well I am told.”
Turns out, Andrew J. Stephens used to have his own Web site — andrewstephens.org. Here, the indispensable archive.org helps out again with a cache of his site from back when it launched in 2011 (oddly enough, the same year that Stophaus claims to have been born). On his page, Mr. Stephens lists himself as an “internet entrepreneur” and his business as “IBT.” Under his “Featured Work” heading, he lists “The Stophaus Project,” “Blackhat Learning Center,” and a link to an spamming software tool called “Quick Send v.1.0.”
Stephens did not return requests for comment sent to his various contact addresses, although a combative individual who uses the Twitter handle @Stophaus and has been promoting the group’s campaign refused to answer direct questions about whether he was in fact Andrew J. Stephens.

Helpfully, the cached version of Andrewstephens.org lists a contact email address at the top of the page: stephensboy@gmail.com (“Stephensboy” is the short/informal name of the Andrew J. Stephens LinkedIn profile). A historic domain registration record lookup purchased from Domaintools.com shows that same email address was used to register more than two dozen domains, including stophaus.org and stopthehaus.org. Other domains and businesses registered by that email include (hyperlinked domains below link to archive.org versions of the site):
-“blackhatwebhost.com“;
-“bphostingservers.com” (“BP” is a common abbreviation for “bulletproof hosting” services sold to -spammers and malware purveyors);
-“conveyemail.com”;
-“datapacketz.com” (another spam software product produced and marketed by Stephens);
-“emailbulksend.com”;
-“emailbulk.info”;
-“escrubber.info” (tools to scrub spam email lists of dummy or decoy addresses used by anti-spam companies);
-“esender.biz”;
-“ensender.us”;
-“quicksendemail.com“;
-“transmitemail.com”.
The physical address on many of the original registration records for the site names listed above show an address for one Michelle Kellison. The incorporation records for the Church of Common Good filed with the Florida Secretary of State list a Michelle Kellison as the registered agent for that organization.

Andrew's Skype profile, where he uses another of his favorite nicknames, "eDataKing"

Andrew’s Skype profile, where he uses another of his favorite nicknames, “eDataKing”

Putting spammers and other bottom feeders in jail for DDoS attacks may be cathartic, but it certainly doesn’t solve the underlying problem: That the raw materials needed to launch attacks the size of the ones that hit SpamHaus and CloudFlare last year are plentiful and freely available online. As I noted in the penultimate chapter of my new book — Spam Nation (now a New York Times bestseller, thank you dear readers!), the bad news is that little has changed since these ultra-powerful attacks first surfaced more than a decade ago.
Rodney Joffe, senior vice president and senior technologist at Neustar –a security company that also helps clients weather huge online attacks — estimates that there are approximately 25 million misconfigured or antiquated home and business routers that can be abused in these digital sieges. From the book:
Most of these are home routers supplied by ISPs or misconfigured business routers, but a great many of the devices are at ISPs in developing countries or at Internet providers that see no economic upside to spending money for the greater good of the Internet.
“In almost all cases, it’s an option that’s configurable by the ISP, but you have to get the ISP to do it,” Joffe said. “Many of these ISPs are on very thin margins and have no interest in going through the process of protecting their end users— or the rest of the Internet’s users, for that matter.”
And therein lies the problem. Not long ago, if a spammer or hacker wanted to launch a massive Internet attack, he had to assemble a huge botnet that included legions of hacked PCs. These days, such an attacker need not build such a huge bot army. Armed with just a few hundred bot- infected PCs, Joffe said, attackers today can take down nearly any target on the Internet, thanks to the millions of misconfigured Internet routers that are ready to be conscripted into the attack at a moment’s notice.
“If the bad guys launch an attack, they might start off by abusing 20,000 of these misconfigured servers, and if the target is still up and online, they’ll increase it to 50,000,” Joffe said. “In most cases, they only need to go to 100,000 to take the bigger sites offline, but there are 25 million of these available.”
If you run a network of any appreciable size, have a look for your Internet addresses in the Open Resolver Project, which includes a searchable index of some 32 million poorly configured or outdated device addresses that can be abused to launch these very damaging large-scale attacks.


Sunday 28 December 2014

Andrew J Stephens meets ,,,,,,,,,,

-----------Andrew J. Stevens.
 (Very long )
=========================
<http://www.meetup.com/West-Coast-Photo-Group-of-Florida/member/105355362/>
<http://www.meetup.com/Tampa-Bay-Photo-Club/members/105355362/>


AJ Stevens
Member

Location:
Saint Petersburg, FL

Member since:
August 5, 2013

Introduction

Hi, names AJ and looking forward to meeting others at this event

Introduce Yourself

My name is AJ and I own a small studio and production company in St
Petersburg, FLA

What are you looking to get out of the group?

I am seeking to network with people in the local community who share
similar interests in photo, audio, and video media production.

What's your favorite type of photography?

digital photography
================================


It appears that Mr. Stevens is a very versatile man.

He is the proud owner of at least three domains.

Domain Name: WHITEBREADSTUDIOS.COM
   Registrar: EVOPLUS LTD
   Whois Server: whois.evonames.com
   Referral URL: http://www.evonames.com
   Name Server: NS1.2FREEHOSTING.COM
   Name Server: NS2.2FREEHOSTING.COM
   Name Server: NS3.2FREEHOSTING.COM
   Name Server: NS4.2FREEHOSTING.COM
   Status: ok
   Updated Date: 25-jul-2013
   Creation Date: 14-jul-2013
   Expiration Date: 14-jul-2014

>>> Last update of whois database: Wed, 14 Aug 2013 13:58:51 UTC <<<

Domain Name: WHITEBREADSTUDIOS.COM

Abuse email: abuse@ahnames.com

Registrant:
    AJ Stevens         whitebreadmedia@gmail.com
    White Bread Media
    5100 15th Ave. S.
    St Petersburg, FL 33707
    United States
    +7.274977442
(Truncated whois)

Domain Name: WHITEBREADMEDIA.COM

Abuse email: abuse@ahnames.com

Registrant:
    AJ Stevens         whitebreadmedia@gmail.com
    White Bread Media
    5100 15th Ave. S.
    St Petersburg, FL 33707
    United States
    +7.274977442

Registered Through:
    AHnames.com  http://www.AHnames.com/

Administrative Contact:
    AJ Stevens         whitebreadmedia@gmail.com
    White Bread Media
    5100 15th Ave. S.
    St Petersburg, FL 33707
    United States
    +7.274977442

Technical Contact:
    AJ Stevens         whitebreadmedia@gmail.com
    White Bread Media
    5100 15th Ave. S.
    St Petersburg, FL 33707
    United States
    +7.274977442

Billing Contact:
    AJ Stevens         whitebreadmedia@gmail.com
    White Bread Media
    5100 15th Ave. S.
    St Petersburg, FL 33707
    United States
    +7.274977442

Name Server: NS01.000WEBHOST.COM
Name Server: NS02.000WEBHOST.COM
(Truncated Whois)

Created On:12-Jun-2013 03:06:45 UTC
Last Updated On:11-Aug-2013 03:46:32 UTC
Expiration Date:12-Jun-2014 03:06:45 UTC
Sponsoring Registrar:EvoPlus Ltd. (R1823-LROR)
Status:OK
Registrant ID:MR_3736460
Registrant Name:AJ Stevens
Registrant Organization:White Bread Media
Registrant Street1:5100 15th Ave. S.
Registrant Street2:
Registrant Street3:
Registrant City:St Petersburg
Registrant State/Province:FL
Registrant Postal Code:33707
Registrant Country:US
Registrant Phone:+7.274977442
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:whitebreadmedia@gmail.com
Admin ID:MR_3736460
Admin Name:AJ Stevens
Admin Organization:White Bread Media
Admin Street1:5100 15th Ave. S.
Admin Street2:
Admin Street3:
Admin City:St Petersburg
Admin State/Province:FL
Admin Postal Code:33707
Admin Country:US
Admin Phone:+7.274977442
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin Email:whitebreadmedia@gmail.com
Tech ID:MR_3736460
Tech Name:AJ Stevens
Tech Organization:White Bread Media
Tech Street1:5100 15th Ave. S.
Tech Street2:
Tech Street3:
Tech City:St Petersburg
Tech State/Province:FL
Tech Postal Code:33707
Tech Country:US
Tech Phone:+7.274977442  <====== 727.497.7442
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech Email:whitebreadmedia@gmail.com
Name Server:NS1.WEAREHOMOGENEOUS.ORG
Name Server:NS2.WEAREHOMOGENEOUS.ORG

(Truncated Whois)
=======================================

http://tampa.craigslist.org/pnl/tlg/3968695801.html
 fmkft-3968695801@gigs.craigslist.org

 Building the WBM Street Team (St Pete)
We are a new recording label and media production company and we are
seeking (10) charismatic people to be brand ambassadors and our initial
Street Team. This is a commission-only position and we are experiencing
a major growth time as we are seeding a new label and these positions
are both exciting and profitable.

The duties of a Street Team Ambassador is to spread the word, pass out
flyers for parties and events, and basically be the presence for the
label on the street. This requires a lot of club-hopping, interaction
with others, and an energetic personality. You must be 21 and must have
a valid FL State ID to be part of the Street Team.

Street Team Ambassadors have the potential to become A&R Reps, who
locate talent for demo deals and potential recording deals. This is a
much more desired position and is only obtained from the Street Team
Ambassadors. Let's see what you have and expect to make a few hundred to
a grand a week in this position if you work it and don't be lazy.

Location: St Pete
it's NOT ok to contact this poster with services or other commercial interests
Compensation: Commission (Expect a few hundred a week up to $1000)

Posting ID: 3968695801

===========================

ATTENTION ALL HIP HOP & R&B TALENT (Gulfport)

We are a new studio and recording label known as WBL Studios, located
in Child's Park area of St. Petersburg, and we are seeking talented
singers and rappers to come in for auditions to be on our upcoming
album. We are seeking background singers and new lyricist talent.

If you really have the goods to drop fire on St. Pete and are looking
for a place to shine, this is it. Reply to setup an audition.

Seeking;

1. Hip Hop Lyricists
2. R&B Artists
3. Hick Hop Artists
4. Trip Hop Artists

Location: Gulfport
it's NOT ok to contact this poster with services or other commercial interests
Compensation: Negotiable Contract

Posting ID: 3943153624

Posted: 2013-07-18, 1:04AM EDT

Updated: 2013-07-29, 6:32PM EDT
====================================


Some sample tracks have been posted on Reverbnation.
<http://www.reverbnation.com/whitebreadmedia>
Not my taste in music, but IMO they are not very good.
He's the Florence Foster Jenkins of Muzak.
<http://en.wikipedia.org/wiki/Florence_Foster_Jenkins>



===================================

Facebook page at <https://www.facebook.com/whitebreadmedia>

Fan Club website at <http://bgp.he.net/dns/whitebreadmedia.com#_website>

Where have I heard about this address before? 4928, 15th Ave S.?

5100 15th Ave. S is about 2 blocks away.
The **previous** tenants have
a somewhat varied history, a Google search shows at least 4 people
have given that address on their arrest mugshots, the oldest being
from 2010.