Ochko123 - How the Feds Caught Russian Mega-Carder Roman Seleznev

  Переглядів 621,568

Black Hat

Black Hat

День тому

Best of Black Hat USA 2017 Briefings Winner
How did the Feds catch the notorious Russian computer hacker Roman Seleznev - the person responsible for over 400 point of sale hacks and at least $169 million in credit card fraud? What challenges did the government face piecing together the international trail of electronic evidence that he left? How was Seleznev located and ultimately arrested? This presentation will begin with a review of the investigation that will include a summary of the electronic evidence that was collected and the methods used to collect that evidence.
by Harold Chun & Norman Barbosa
Read More: www.blackhat.com/us-17/briefi...

КОМЕНТАРІ: 777
@patrickcameron2950
@patrickcameron2950 3 роки тому
Him surviving a terrorist attack and spending two months in a coma halfway through the story was a hell of a twist.
@grubybysior8635
@grubybysior8635 2 роки тому
Freaking spoilers >:(
@topdog5252
@topdog5252 2 роки тому
@@grubybysior8635 😞 oh no
@baruchben-david4196
@baruchben-david4196 3 роки тому
The thing is, he more ir less handed himself over to the authorities by being so sloppy. It's less credit to the Feds, and more blame to him.
@borregoayudando1481
@borregoayudando1481 Рік тому
so the lesson goes back to opsec 101
@xv0047
@xv0047 Рік тому
Even with all that, if he just never left Russia there is nothing the feds could have done about it.
@x87-64
@x87-64 8 місяців тому
​@@xv0047that's what most do. he is one guy who got caught. there are hundreds more like him
@anuragkashyap8026
@anuragkashyap8026 4 роки тому
Lesson : 1 Live in Russia & Never Leave Russia THATS ALL
@napalm3899
@napalm3899 4 роки тому
This. Vadym Iermolovych made that mistake by going to Mexico. The night he arrive in Mexico, Mexican cops approached him at his hotel and told him he was not welcome in Mexico. They said the government of Ukraine had agreed to fly him back to Ukraine. They confiscated his laptop, and put him on an airplane. They said he would have one stop in Dallas, Texas. When the plane touched down in Dallas he was in US territory. The first 4 rows of the plane stood up, announced themselves as US federal agents, and arrested him. The Mexicans cleverly handed him over to the US and got him to agree to it.
@anuragkashyap8026
@anuragkashyap8026 4 роки тому
@@napalm3899and that was his last mistake or the last bad decision.
@anuragkashyap8026
@anuragkashyap8026 4 роки тому
@EramSemperRecta oh ! 😲 Was that so ?
@ulfpe
@ulfpe 4 роки тому
Russia dosent have as nice beaches as the Maldives, human weakness
@elvinpineda1825
@elvinpineda1825 4 роки тому
word that was his mistake, plus using usa hop 1 instance.
@frostbolt4359
@frostbolt4359 3 роки тому
Learned a lot. I still find it amazing that these massive online empires tend to fall due to massive opsec failures. Silk Road, Alphabay, etc.
@electricz3045
@electricz3045 2 роки тому
Most marketplaces not even fall. Most are still alive or did a own exit scam but it's more interesting for jonalists to talk about the fallen ones.
@ilaser4064
@ilaser4064 5 років тому
Would have laughed if he was successfully sued for infringing on 2Pac's IP before being arrested for fraud.
@ThePeacePlant
@ThePeacePlant 3 роки тому
The court and judge would have found anyway to make him lose that case. Unfortunately the US courts or not fair if they want to catch you or don't like you
@keystarr
@keystarr 11 місяців тому
A legendary talk! Thank you so much for putting this out
@MrRigdensChannel
@MrRigdensChannel 6 років тому
Great video. I was really surprised when I saw the old Broadway Grill. I walk past that shuttered restaurant almost every day.
@Harmonikdiskorde
@Harmonikdiskorde 3 роки тому
Same! I briefly felt second-hand famous.
@MadameMinty
@MadameMinty 6 років тому
tl;dr he basically handed himself to them on a plate.
@RonJohn63
@RonJohn63 6 років тому
Obviously, he thought that -- being the rich son of a member of the Duma -- he was above the law and so didn't need to employ OPSEC.
@TheOxywolf
@TheOxywolf 6 років тому
RonJohn63 9
@blackneos940
@blackneos940 5 років тому
@@TheOxywolf 8
@William.Shakespeare
@William.Shakespeare 4 роки тому
yeah but a venue like this for them to speak is pretty cool.
@daveslow84
@daveslow84 4 роки тому
@@blackneos940 7
@VisualJoey
@VisualJoey 4 роки тому
The Roman empire has fallen.
@BvousBrainSystems
@BvousBrainSystems 4 роки тому
"Was there any encryption that you had to deal with?" "In this case no, there was none" *audible laughter across the room* This hacker is getting roasted by the guys who cuffed him lol
@danpowell806
@danpowell806 5 років тому
1.7M instances of theft, 38 counts of fraud. That's one count for every 45k card numbers he was caught with.
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
Dan Powell Maybe he stole an average of 45k cards at each store he hacked. Or maybe he (provably) hacked/defrauded 38 stores to get to the cards, then purchased many more stolen cards from other criminals that got them through other (unspecified) crimes. After all, he had officially graduated from thief to fence long before his arrest.
@slappy8941
@slappy8941 4 роки тому
Well if someone breaks into your house and steals all your stuff, they won't be charged for each individual item stolen, but for the act of burglary itself.
@RyanKearney0
@RyanKearney0 6 років тому
Anyone else notice the workgroup name of the machine was VAIO? This guy never reformatted the machine after he bought it? Damn...
@svampebob007
@svampebob007 6 років тому
ikr
@ronaldckrausejr7762
@ronaldckrausejr7762 6 років тому
Real hackers also purchase their computer hardware with cash, and then also have it shipped to a third party - completely untraceable
@JG-ye7ey
@JG-ye7ey 6 років тому
He had 1.7million CC numbers on his computer. He is maybe THE definition of a 'real hacker'...sloppy though.
@rev.philthyphil6839
@rev.philthyphil6839 6 років тому
Ryan Kearney lol
@moth.monster
@moth.monster 5 років тому
Sometimes they bake that stuff into the BIOS. No reason to remove the manufacturer name and logo aside from bragging rights at that point. My computer still says it's from ZT Systems even though I just bought a used motherboard. I guess it was in a compuer made by them at some point. And i'm too lazy to fully reset every little thing in the BIOS just to make it say something else.
@dreftymac9916
@dreftymac9916 4 роки тому
Dude, this is awesome and needs to be made into a screenplay.
@pqsk
@pqsk 2 роки тому
yes. I would love to see a trilogy film. Part one is when he starts off. part two is the terrorist attack and the coma and recovery and part three when they nail him. depending on how good it is there would be a prequel trilogy on how he learned not to use encryption and how to be sloppy 😆
@jamesparker6876
@jamesparker6876 4 роки тому
Excellent work gentlemen!! Keep it up.
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
go f... yourself
@jamesparker6876
@jamesparker6876 3 роки тому
To: @@aniellodellacroce9848 They will get you too Aniello. You should have kept your head down. You are Guilty of "Having a brain and attempting to use it".
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
@@jamesparker6876im not hiding at all. i welcome anyone who wants to give me a visit and get free involuntary led injection at very high velocity
@enlightendbel
@enlightendbel 5 років тому
"Would it have been harder to convict if you didn't have his password?" He wasn't protected in any way on that Vaio, no security measures, hardware or software based, as these guys explained, there was no encryption or anything even remotely security related on that laptop. There's 10000 ways to get into a windows system if you have physical access to the system. There's 100000 ways to get to the data on a system if you have physical access to the system. It was cute they guessed the password, but that wasn't even needed. His shitty password, combined with his bad security measures and all the other ways he was blazee about security, the dude was bound to get caught and bound to get convicted if caught. His security measures were to travel to and through places that didn't extradite to the US. Including the place he was arrested. Little did he know or understand that diplomacy used to be a thing and you can get any country to agree to anything if its worth their while.
@enlightendbel
@enlightendbel 5 років тому
He was an expert at obtaining credit card numbers through black market available malware. So far, there hasn't been much of any indication he did much of any actual hacking.
@kali6651
@kali6651 5 років тому
@@enlightendbel There are many cases where LEO cannot access encrypted data from a hard drive. There are definitely ways to hide your data and keep it hidden.
@enlightendbel
@enlightendbel 5 років тому
Adrian Yes? And? Did I say anything to the contrary? The subject is this guy, not general practices and problems.
@user-rc9jf8ng2k
@user-rc9jf8ng2k 5 років тому
LOL @ Blazee.. I think you mean blase.
@Lizardboythelazy
@Lizardboythelazy 4 роки тому
He's not a hacker, he's a skiddie. He found one method that worked (RDP brute + malware) and abused it heavily. The reason he was so successful I think is because he was an expert at leveraging what he obtained to profit.
@Ye4rZero
@Ye4rZero 5 років тому
24:40 you can tell he's used to waiting for applause at this point, but wrong crowd lol
@milanstevic8424
@milanstevic8424 4 роки тому
@g milne ДА
@Tridd666
@Tridd666 4 роки тому
He's a Fed
@larrywages5887
@larrywages5887 5 років тому
Fascinating from Mrs Wages
@livefastdieold180
@livefastdieold180 6 років тому
I was just at Mandalay Bay not to long ago, delivered a 350k granite saw to a counter top and tile expo.
@percyblakeney3743
@percyblakeney3743 5 років тому
As an audience member I'd say "thank you for the insight as to how your team did it." As a gov supervisor I'd ask "why the sh*t are you showing your cards!"
@kidoido
@kidoido 2 роки тому
Its all explained here why the feds started talking at defcon, black hat etc. : ukposts.info/have/v-deo/oGmojKdtpohzz30.html
@toxic_narcissist
@toxic_narcissist 2 роки тому
Which cards? This guy basically surrendered by having zero opsec
@robgigabyte580
@robgigabyte580 Рік тому
Obviously you are not involved in Computer security. He was sloppy in his hacking, left breadcrumbs leading directly to him... But nothing said here was opening up any "Tell Tales" of the investigation.... No REAL cards are being shown or disclosed if you know anything about vulnerabilities in networking or computer security
@MilesBellas
@MilesBellas 5 років тому
Nov 2017 "The prolific Russian hacker Roman Seleznev was sentenced to 14 years in prison Thursday for his role in a $50 million cyberfraud ring. This latest sentence follows a 27-year-prison sentence Seleznev received in April on charges of hacking point-of-sale computers that he then sold to the criminal underground. That scheme generated nearly $170 million in fraudulent charges, prosecutors said. Both sentences will run concurrently."
@edt11x
@edt11x 5 років тому
With all the IRS scammers, credit card scammers, spammers and other scams, its really good to hear a story where one was tracked down and arrested. Really great presentation!
@kabib0831
@kabib0831 4 роки тому
They should make a movie about this.
@ke0kie
@ke0kie 5 років тому
So the typical carelessness, ego, lavish behavior, and carelessness was Roman's demise.
@Everett-xe3eg
@Everett-xe3eg 4 роки тому
The word is hubris.
@marciomello4418
@marciomello4418 3 роки тому
Love this video
@macnutz4206
@macnutz4206 4 роки тому
He got 27 yrs. He also got 14 yrs from a bank fraud charge in Atlanta. Concurrent sentences, of course. I expect he will be back in Russia long before twenty seven years is up.
@Sugrax
@Sugrax 2 роки тому
27 years for no physical harm done? US is fucking insane
@LiEnby
@LiEnby 2 роки тому
Meanwhile 5 years for murdering someone
@silentone6411
@silentone6411 2 роки тому
because he goes straight back to Russia and continues doing it probably , only way to actually stop him is keeping him in jail here.
@N99622
@N99622 11 місяців тому
​@@LiEnby And 3 months for raping a child 🤪 Law enforcement only cares about protecting the banks here.
@MarkH10
@MarkH10 5 років тому
The major weakness in this and so many cases is Russia itself. Who wants to live IN Russia, or move TO Russia for 'the good life'. As soon as a Russian has money, he is gone. IF you ever think a Russian girl loves you, offer to marry her and move to Russia for the rest of our lives!!! See how long that relationship lasts after she thinks you are serious.
@n.k.63
@n.k.63 4 роки тому
Lived in Toronto for awhile, moved back to Russia, zero regrets. Yes, some things are annoying, but overall quality of life is better, finding good job with English and some skills is easy, most importantly - no SJWs, no speech police, no feminists to speak of.
@gophop
@gophop 4 роки тому
Nonsense. With millions of dollars you can build wtf you want, wherever you want, and import anything of interest. Tropical vacations are a status symbol in Russia.
@joshuaronquillo1673
@joshuaronquillo1673 4 роки тому
@@n.k.63 We don't want an authoritarian police state to protect our feelings from 30 college students and women who want respect from society.
@NickBailuc
@NickBailuc 3 роки тому
@@n.k.63 100% agree^^^^^^^ , also in the process of moving from toronto to moscow (originally from ukraine tho)
@qsam14
@qsam14 3 роки тому
Totally false. I had a Russian client when I drive Uber and she was very sweet, even offered me food and asked me to come over to her workplace. She was a teacher assistant.
@ericsbuds
@ericsbuds 6 років тому
excellent talk! glad to know there are some smart people on the right side of the law too!
@code4food
@code4food 4 роки тому
too? you're overestimating criminals
@VenturiLife
@VenturiLife 6 років тому
I found malware on some public hotel computers in Bali trying to intercept banking details... wonder who that could have been. Always try and use your own machine when travelling.
@ly-yx1rk
@ly-yx1rk 6 років тому
shades2 when I travel I buy prepaid debit cards. If it's not my machine it doesn't get my numbers. And it's super easy to install a keylogger on any unattended machine.
@semtex2978
@semtex2978 5 років тому
Lucas Gorski very true. 👍
@madtrade
@madtrade 6 років тому
in conclusion it's better to be a bankster than a hacker
@TheXSairam
@TheXSairam 6 років тому
or dont be lazy and stupid
@finalsolution3690
@finalsolution3690 6 років тому
The bankers are the biggest criminals giving themselves millions in bonuses "some free money"
@mcgoldsmithstein7256
@mcgoldsmithstein7256 6 років тому
Have you ever paid something with paypal? Something as common as the double currency exchange... let's say from euros to dollars to euros.
@MonMalthias
@MonMalthias 6 років тому
The most profitable crimes are the legal ones.
@DxBlack
@DxBlack 6 років тому
Time to grow up and stop equating immoral but rational activities to being illegal. If you can't pay the interest, don't take the loan. If the rates in your mortgage seem too good to be true they are. Etc etc, you have a brain...no one can force you to use it.
@legendwarrior85
@legendwarrior85 6 років тому
Great catch !!!!
@craffte
@craffte Рік тому
these are old but always entertaining.
@andbiker81
@andbiker81 6 років тому
Haha they actually thought they could bribe their way out of any trouble, very typical for a corrupt Russian official because this is exactly what they do at home. Thank you for bringing this criminal to justice, this was definitely not possible in Russia.
@theNISK
@theNISK 6 років тому
he wasn't a government official.
@RonJohn63
@RonJohn63 6 років тому
His father was (is?) a member of the Duma.
@theNISK
@theNISK 6 років тому
So then you agree - his father is a state official, not him.
@RonJohn63
@RonJohn63 6 років тому
IIRC, his father the state official was in full agreement with the idea.
@yc5117
@yc5117 6 років тому
Lol the father, a state official, was the one that was going to be bribing the prosecutor, not the guy in prison........
@thekaiser4333
@thekaiser4333 5 років тому
@Norman Barbosa Aren't the Maldives a little bit outside U.S. jurisdiction?
@jamegumb7298
@jamegumb7298 4 роки тому
Way outside. As are the Philippines, where they randomly stop and search people, and there is footage of raids they do over there on YT. As is Colombia, where the DEA does raids and wipes camps using drones and special forces. Not all are FARC encampments, maybe up to 40% are not going by if weapons are found. AS is Mexico, where the DEA operates over the border. As is Aruba, where the DEA arrested a bunch of people after their own incompetence got their car broken into and a bunch of people they were on a terrace with having cocktails refused to search with them. As is Italy, where they kidnap citizen for renditions and black site prisons. As is Kazakhstan, where they kidnap citizens for renditions. As is Pakistan, a supposed ally where find more people than just Bin Laden to kill. As is Japan, where an American criminal is taken out of Japan and will not see a Japanese court. See the Okinawa incident. The hash trafficker. Spoiler Alert: We can do it so we will. So fuck you.
@tarkanya7906
@tarkanya7906 3 роки тому
love that video
@bra24hnt52
@bra24hnt52 3 роки тому
Ok thats it - no more flowers for my wife
@marksmod
@marksmod 4 роки тому
very interesting
@sathyantinku9177
@sathyantinku9177 2 роки тому
That guy thought he would never ever be caught. How the hell a hacker uses Ochko123
@uis246
@uis246 11 місяців тому
Btw this literally means Butthole123
@jonslg240
@jonslg240 4 роки тому
He'll serve 21.6 years of that 27 year sentence, since he's in federal custody. They make you serve 80% I believe.. that is a long time. Maybe long enough where he won't do it when he comes out. If his dad's very prominent, he might be able to get a pardon after 10-15 years.
@MegaSmouke
@MegaSmouke 4 роки тому
Russian government is very corrupted. I'm pretty sure his dad knew about his son crimes and maybe even supported him in this. Looks like people in USA start to understand this, so guy will be in jail for full 21.6 years. And no way he will change his mind, I know russian people and can guarantee, that only suggenstion he and his father have that they do a poor job to protect him from a jail, that's it, no regret about crimes at all.
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
@@MegaSmouke US government is much more corrupt than Russian. you just got no idea
@MegaSmouke
@MegaSmouke 3 роки тому
@@aniellodellacroce9848 no, US people has 20 times more money for they job than russians. Russian salary is 200$-500$ per month with constant everyday inflation. When Russian government is extremely rich people, everybody are billionaires. You very naive if you think that US government is much more corrupt than Russia. Because if it was true, american people would be much poor than russian people, but in reality american people has much higher salaries for their job, that's clearly show that US government spend much more money on their people, than russian government.
@artemiddle
@artemiddle 3 роки тому
@@aniellodellacroce9848 definitely not. I think you don't realize the scale of corruption in Russia. You can pay for absolutely anything here. Nothing unusual when someone pays a police officer to not get his driver's license cancelled for DUI or something like that. Just a regular day in Russia.
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
@@artemiddle look there's more money in US that means there's a lot of corruption and i'm not talking about small police type of bribes but on higher level, in States if you have a lot of money you can pretty much legally bribe any Congressman, House representative and senators with that said i agree that the same thing applies to Russia BUT there is more money circulating in states (and more corporations-they bribe a lot) therefore there should be more corruption on higher level in US. obviously it's almost impossible to bribe the police in states, even if you have a lot of money you still can't bribe your way out of DUI or something. Police in Russia is more corrupt compared to US but oh higher level it's no contest due to the amount of money circulating. and let's not forget that US is the richest economy in the world so there must be more of corruption. if there's money there's corruption.
@SAROSRUSSIAN
@SAROSRUSSIAN 6 років тому
ОЧКО123
@machinerin151
@machinerin151 4 роки тому
I know, right?
@Akus75038
@Akus75038 3 роки тому
When did this conference take place?
@Optable
@Optable 11 місяців тому
Chief really put those bad cop pants routine on during the questions at the end there huh. Actually solid questions with important feedback to much more pressing issues gone totally dismissed, and all he seemed to attempt to prove is that verbally "it was really just all so terribly hard" to retrieve all that unencrypted, unobfuscated, out in the open, slam dunk data! When really the only hard part wasn't so hard, sitting there biding time, waiting for a blip on a spinny class globe. Then all of the sudden, let's make sure black hat knows again how hard it was to jump those hoops! Around any sort of justice process, avoidance of contacting any actual authority at all costs, refusal to explain why (which could get secops/pentesters/law enforcers killed or imprisoned in many jurisdictions) while snerking at the valid argument that those actions could undermine or blow the cover of many much more difficult ongoing undercover ops or surveillance work, and sow even further distrust into these TA's regarding what it will take to self preserve their own lives. And for these sociopaths, every more reason to push anybody in front of the way to avoid the bars. Not textbook blokes like this one "sophisticated and large scale *network*" here. This crowd is in no shortage of extremely bright individuals. Nobody expected ya to debate the modalities and procedures of undercover tactics for federal government acronym agencies. We just wanted- something, at all?
@edwardlouisbernays2469
@edwardlouisbernays2469 4 роки тому
Wow, just October 1, 2017, a month later, Mandalay Bay was a slaughter ground!
@sendlocation8476
@sendlocation8476 Рік тому
@ OPSEC NERDS If his whole system was encrypted would that mean the L.E would not be able to access or retrieve anything from that laptop? And would be useless to them?
@N99622
@N99622 11 місяців тому
It depends. They had a lot of other evidence against him without the laptop. But encryption depends on the algorithm and the strength of your password (basically more entropy in the password, the better). There are also ways to create "hidden encrypted volumes" where you can keep an operating system, files, or whatever. This allows you to have plausible deniability-- you don't know about any hidden volumes! Best thing to do is always keep your online identities isolated from one another and encrypt everything. Get rid of logs. Ideally you would have a burner computer that has no identifying information associated with your real identity, fully encrypted. If you feel like the feds are sniffing your butt, just destroy the laptop and drop your activity for a while.
@visvge4934
@visvge4934 6 місяців тому
No, they would be able to access it. It would just be a little more hands on
@visvge4934
@visvge4934 6 місяців тому
Hardware based encryption can have the keys sniffed off the wire
@CGoody564
@CGoody564 5 років тому
"we don't give attribution for that" I don't understand why not. The security vulnerability is just as attributable to the attack as the one exploring it.
@DustinRodriguez1_0
@DustinRodriguez1_0 6 років тому
It's odd to me that they rely on file modified/accessed records. Those can be set to anything by anyone. They're really not reliable...
@fss1704
@fss1704 6 років тому
yepp
@lydianlights
@lydianlights 5 років тому
The point was that the defense brought that up as proof of him being framed. Therefore the prosecution had to prove that that was not the case. It was a stupid defense, but "the defense is stupid" is not a valid legal argument.
@rastavolt
@rastavolt 5 років тому
@@lydianlights Ironically his stupid defense strategy could be a valid reason for appeal, under incompetent counsel rules. Although, I don't think it would make any difference in this case. His incompetence is what got him caught in the first place.
@lydianlights
@lydianlights 5 років тому
lol... and that's why I'm not a lawyer
@chukchee
@chukchee 3 роки тому
How were the point of sale computers hijacked? Did Seleznev install software on those computers?
@tthtlc
@tthtlc 5 років тому
you either pay money to the pentesters, or to the hacker, depending on who charge less. and not sure if pentester will turn into hacker in future? Any relationship to cybersecurity earning good income?
@craffte
@craffte Рік тому
That flowers receipt...
@domonique546
@domonique546 5 років тому
Listening as a ex laptop acer owner...
@UkrPat
@UkrPat 3 роки тому
Roman’s ochko has played Tchaikovsky’s Swan Lake after all.... if you know what I mean 😏
@nightwaves3203
@nightwaves3203 5 років тому
A hack user not hacker appears to me.
@naseweisz
@naseweisz 5 років тому
Interesting screenshot at 20:28... iirc the red and yellow card next to a posting are only visible to moderators and thus the screenshot has been taken by a staff member.
@ug0ts3rvd
@ug0ts3rvd 5 років тому
yep I noticed that too, admin perms to infract people
@nickdrozd
@nickdrozd 5 років тому
I assume the pics were taken after the arrest? for evidence show or tis power point?
@Simonoswald1
@Simonoswald1 5 років тому
@@nickdrozd May be or may not be, what he wanted to point out that theres a spy/snitch/whatever in the admin/mod staff of this carder forum^^
@danpowell806
@danpowell806 5 років тому
More like they got a copy of the database of the carder forum, possibly by search warrant on the server, and then pwned the copy as god.
@yesterdaysguy
@yesterdaysguy 4 роки тому
Could also be parallel construction for sure - nice catch.
@elliesagestar
@elliesagestar 4 роки тому
So the takeaway is, use Linux and disable logs :D
@glanoe
@glanoe 3 роки тому
and dont go on holiday with an unencrypted laptop stuffed chock full of incrimating evidence.....
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
@@glanoe nailed it. but most importantly! never leave Russia lol
@glanoe
@glanoe 3 роки тому
Aniello Dellacroce Russia is a big place, why would you need to leave it's borders.
@rhards
@rhards 3 роки тому
@@glanoe to flex exotic places on instagram.. duh.
@lonnieo4676
@lonnieo4676 3 роки тому
and don't use yahoo email address...
@PiiSmith
@PiiSmith 4 роки тому
And it is still credit card fraud, that is the running wild. Can we please get a more secure payment method, than credit cards.
@voronacloud
@voronacloud 10 місяців тому
For those who are intrested. Ochko can mean a few things: - butthole (vulg) - name of the card game. russian version of BlackJack - point (i.e. measured metric earned in sports, games, competitions) Main meaning - toilet (vulg)
@msnpassjan2004
@msnpassjan2004 4 роки тому
36:00 So there is no point to using a VPN because windows records everything in multiple ways?
@fluffigverbimmelt
@fluffigverbimmelt 4 роки тому
Those two things are hardly even linked
@msnpassjan2004
@msnpassjan2004 4 роки тому
@@fluffigverbimmelt They don't need to track you live. If there is a detailed log file, they can track you forever.
@totallynotlogic9849
@totallynotlogic9849 4 роки тому
@@msnpassjan2004 No that isnt what a VPN is, a VPN cloud your data being sent to servers from your ISP or even the servers themselves. This is local, and will not be sent to severs or your ISP
@VikisView
@VikisView 3 роки тому
Why not go with Virtual Networks ??? And Changing Mac Address Because , mac address is permanent number of your device which connecta details of u to APN , and Better to use socs For Firewall More Firewall more safety ...
@yyny0
@yyny0 3 роки тому
Install gentoo
@theteenengineer7589
@theteenengineer7589 4 роки тому
great
@info781
@info781 4 роки тому
So the Restaurant POS system was installed on a windows server that had a common login password for many servers? Why did people not patch their POS system? I wish they had commented on that more including the name of the system.
@gophop
@gophop 4 роки тому
Small businesses don't have active management in place. They don't have dedicated staff, nor do they bother to maintain a contract with an IT company. Only call for service when shit breaks.
@FinflyWeb
@FinflyWeb 6 років тому
hi black hat ,plz can i upload to youtube 2 part from your video the part1 from 17:17 to 17:46 and the part2 from 19:09 to 20:23 and produce on them something that i will upload later ?
@b3twiise853
@b3twiise853 16 днів тому
6 years later, no answer?
@FinflyWeb
@FinflyWeb 16 днів тому
@@b3twiise853 i am still waiting bro
@pilarcuarezpardo1167
@pilarcuarezpardo1167 3 роки тому
A natureza é maravilhosa
@Shiyounin
@Shiyounin 2 роки тому
49min? Isn't there a short version of the story somewhere?
@Timm2003
@Timm2003 Рік тому
"Did u track how many other russians stopped vacationing in maldives" xD
@taitjones6310
@taitjones6310 5 років тому
"Any questions?" Person asks question: " I can't answer that."
@ArkFinance1
@ArkFinance1 2 місяці тому
The art of Doublespeak 😜
@CatchTheBus
@CatchTheBus 6 років тому
Люди из Владивостока никогда ничего не доби...
@machinerin151
@machinerin151 4 роки тому
С чего ты взял, что он из владивостока? Вдруг это москвич, который купил дом во владивостоке чтобы просто на море ездить.
@miloradowicz
@miloradowicz 2 роки тому
@@machinerin151 адрес в паспорте, алё? Острякова 26, кв 113, Владивосток?
@lucah4613
@lucah4613 5 років тому
wait so he just bruteforced rdp and installed some sort of keylogger on restaurant systems? were that many of those cash things using rdp?
@AA-gl1dr
@AA-gl1dr 4 роки тому
John Smith *cries in Java*
@gophop
@gophop 4 роки тому
It's because IT vendors who setup POS remotely use just that. Shit never gets turned off. And no keylogger needed, he pulled the CC numbers from the server. POS server probably stores shit in open text in a database. Which isn't all that insecure... if the fucking server doesn't have RDP open!
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
gophop Even if not usually stored in plain text, he could install a patch that grabs each card and stores it in a plain file for later delivery to his rented server.
@Arbiter710
@Arbiter710 4 роки тому
Port scans RDP (most of them have common passwords)then searches queries...a lot of DBs are still getting breached like this
@ScoopDogg
@ScoopDogg 6 років тому
He should have done it the legal way and become a bank manager..... why didn't the government reimburse the mam n pop companys before they went under, or do they only do this for banks who do far more damage to society than this guy did... at least he put the money back in the system and had a good time instead of greedily hoarding it... hes gunna walk out in a few years and don't be fooled hes still got that money LOL.. wish they put this much effort in arresting Bush n Blair who on the grand scheme of things did far far worse than this guy...
@yc5117
@yc5117 6 років тому
Why would the government reimburse the shops exactly...? It is their responsibility, by law, to protect any personal details on their systems. They did that inadequately and I'll be damned if they're paid for bad security out of my tax dollars. It's bad enough they did it to failures of banks.
@johndoe-gt4rx
@johndoe-gt4rx 4 роки тому
The businesses didn’t lose money from the credit cards being stolen directly. They went under because customers didn’t trust the business anymore and for good reason.
@theverdantwolf5402
@theverdantwolf5402 4 роки тому
@@yc5117 - that's why the US is tearing itself apart...the top can force the bottom to keep them from falling while putting all cost on the people...I'd rather my tax money go to help a local shop than a bank..... America became a socialist country by the order of Wall Street signed by Bush but they want a one way street. Socialism for the 1%, they deserve everything because they already have it...dog eat dog capitalism for the rest of us to fight each other or do tricks for their scraps.
@gophop
@gophop 4 роки тому
They didn't go out of business because of card fraud. It's bullshit to gain sympathy and praise for FBI's heroic work. *barf*
@theverdantwolf5402
@theverdantwolf5402 4 роки тому
@@gophop have you ever had card fraud as a business? It does hit you. Especially if you are swarmed with it, because your an easy cut out for carders, and a swarm can definitely put someone out of business while they wait for investigations to get the insurance reimbursement. Depends on standing capital, inventory, and credit lines to weather it.
@domonique546
@domonique546 5 років тому
What do they do with the enterprise accnts??.all must be orderly written someplace...
@captainmaxwell5017
@captainmaxwell5017 4 роки тому
I find it curious that he was basically at the epicenter of a "terrorist attack" explosion.??? it wouldn't be too much of a stretch to assume that at some point, they may have decided to just take the guy out. Save time and money, etc. I just think that it's odd that when they were about to move on him....he got blown up. Having had run ins with law enforcement in general, as a U.S. citizen I have been set up, beaten without cause, and jailed. I can only imagine how they would likely treat this guy. The U.S. Govt. doesn't like competition when it comes to ripping off their own taxpayers.
@MegaSmouke
@MegaSmouke 4 роки тому
And why they need to blow-up whole building to kill one guy if they can just shoot him somewhere at night at dark place?
@erzazerzaz
@erzazerzaz 4 роки тому
All foreigners usually go to the same restaurants, it's a natural target for some organization of peace.
@tokyot3232
@tokyot3232 4 роки тому
he didnt switch servers once a month jesus
@gcbzzzz
@gcbzzzz 6 років тому
how difficult it would have been to simply invent a disk image with all this evidence? for example, no new information found on the laptop. only previously known aliases and known stolen cc numbers taken from the cc server.
@gophop
@gophop 4 роки тому
or simply swap a pre-prepped hard drive in. A lot of the windows shit should be inadmissible in court. All of that stuff is easily editable in log files and registry.
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
gophop That's why they have a hallway full of cops willing to swear up and down that they picked up the laptop from another cop at so and so time, didn't plant evidence or leave it unguarded, then handed it to a 3rd cop at so and so time. Even the defense knows this, so they rarely bother. Except in the OJ Simpson case where the defense knew they had proof one of those cops was an admitted racist that they could accuse of lying.
@StewartLucrative
@StewartLucrative 3 роки тому
I don't know anything about hacking, this conference, or US attorneys, but I'm surprised he's giving a talk here.
@yrebrac
@yrebrac 2 роки тому
It is a common thing for security agencies to talk at security conferences for some reason. In this case it's a win-win for them. Hacker was so stupid they don't have to reveal much, but they still get to advertise their success and capabilities to the BH community, thereby discouraging cybercrime.
@codyjewson4704
@codyjewson4704 5 років тому
Roman. Dope name 👌💪
@99Kuromaru
@99Kuromaru 4 роки тому
Actually quite common and boring Slavic name
@impaugjuldivmax
@impaugjuldivmax 4 роки тому
lol, Roman is not a slavic name. it us clearly the Latin name used in Eastern Roman Empire
@99Kuromaru
@99Kuromaru 4 роки тому
@@impaugjuldivmax let me rephrase, quite common and boring name used among Slavs
@zuiokopl2256
@zuiokopl2256 5 років тому
so it mean america can just mail paypal and get a copy of email? Like wow, fuck the privacy
@aniellodellacroce9848
@aniellodellacroce9848 3 роки тому
yes
@AleksandarGrozdanoski
@AleksandarGrozdanoski 5 років тому
Sounds exciting. I would love to have a job like theirs.
@moregirl4585
@moregirl4585 6 років тому
To avoid randomly reading/writing why not just give it a executing segment without W/R permission?
@RussianLearnsYou
@RussianLearnsYou 4 роки тому
Can confirm. Ochko means butthole but it's pronounced 'ah-CHKOH'. The second syllable is stressed so the first 'O' sounds like 'ah'
@xplinux22
@xplinux22 4 роки тому
Username checks out.
@CGoody564
@CGoody564 4 роки тому
That's phonetically incorrect. The ch is a part of the first syllable; not the second. The o sounding like ah is correct, but the ch is still a part of the first syllable.
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
RussianLearnsYou Can it also mean "asshole", as in "a really unpleasant person"?
@sauliusjance6300
@sauliusjance6300 4 роки тому
@@johnfrancisdoe1563 what about dalbayob? Ever heard that one?
@dassatisfan
@dassatisfan 4 роки тому
@@johnfrancisdoe1563 no, ochko cant be used for "really unpleasant person". dolboyob means dumbass btw
@theukadamyt
@theukadamyt 6 років тому
Harold looks and sounds like Harold from Harold and Kumar lol
@thesorrow7499
@thesorrow7499 5 років тому
This is the biggest load of bullshit I've ever heard ! SHAYE, Biboran, bratiya, Biboran
@boahkeinbockmehr
@boahkeinbockmehr 4 роки тому
Would be interesting to know what this guy's motivation was. As it sounds his father is a Russian oligarch with strong connections, so money probably wasn't the main driving force. So boredom? Wanting to prove himself? Becoming independent of his father?
@Jixejo
@Jixejo 4 роки тому
if you think the motivation is anything more than money then you are missing the trees for the forest...
@joebonsaipoland
@joebonsaipoland 4 роки тому
In Russia like most places it’s all about the money!!!!!
@miloradowicz
@miloradowicz 2 роки тому
The reason is coming back to his roots. The Russian government itself is comprised of mafiosi and former gangsters.
@thygrrr
@thygrrr 2 роки тому
I spotted the feds!
@UNOwen-ky5ib
@UNOwen-ky5ib 5 місяців тому
Easiest game of Spot The Fed ever…
@douro20
@douro20 6 років тому
Why would he want to call himself 'potato'?
@NicholasLittlejohn
@NicholasLittlejohn 5 років тому
Scholtzkys will do it every time.
@MrEndzo
@MrEndzo 11 місяців тому
Forensic 101: turn off the electronic you sized and use a faraday bag.
@AndreyAntonchik
@AndreyAntonchik 6 років тому
Around 17:37 we can see his passport number and personal information. But not only that we also see the personal information of Udatova Nina. Anyone have any clue who she is?
@rkan2
@rkan2 6 років тому
Andrey Antonchik The wife?
@nabugijin9910
@nabugijin9910 6 років тому
Andrey Antonchik his daughter
@JG-ye7ey
@JG-ye7ey 6 років тому
i just opened a credit card in her name
@intuit13
@intuit13 5 років тому
Yes, it was his daughter. She was born 33 years before he was..
@tacosplease4906
@tacosplease4906 Рік тому
What is a fsb?
@chupathingy5862
@chupathingy5862 11 місяців тому
34:27 you forgot to censor the card number.
@wouldntyouliketoknow9891
@wouldntyouliketoknow9891 5 років тому
Why in the hell would they publicly detail all this? I mean, yeah he did say that a lot of it is public record due to the trial proceedings, but even at that digging through trial proceedings is nasty time consuming work and is a high bar that would keep a lot of people out. Here they have bundled up all kinds of "how to be a better criminal" information in a nice easy video. If I was going to turn to a life of crime I would start by watching a bunch of these videos...
@Wowthatsfail
@Wowthatsfail 5 років тому
wouldnt you like to know problem is this guy is the dumbest of hackers. If you only try to do better than him you will still get arrest
@absurdengineering
@absurdengineering 4 роки тому
You should start by reading relevant court cases, and all of this is public record. Nothing they said here would be hidden for someone willing to shell out for a bit of Pacer subscription, or just walk in to the court in question and go to their file division. There you can inspect all unsealed records as you wish. There are lots of books that detail cases in the way it was done in this talk, and if the people with direct involvement with the case won’t say it, then someone else whose career it is to write about such things will do it anyway. You’re vastly overestimating the effort needed to collate all this information for someone whose job was to do it, or someone just serious about it. Sure, the first time round it will suck, but so it would if you sat for the first time in your life at a piano. You wouldn’t ask someone about how hard a piece of music is to play after their first lesson on the instrument. I wouldn’t ask anyone inexperienced with gathering such information about how hard it really is to gather it. I presume you haven’t done it much.
@uis246
@uis246 11 місяців тому
Let's make laws secret, so criminals wouldn't know what they will be charged for
@chilldudemanguy
@chilldudemanguy 4 роки тому
surprised at his sloppiness, he didnt make it very hard at all for law enforcement to find him out
@andreinekrasov2036
@andreinekrasov2036 5 років тому
How hard can it be to to find a jury that knows nothing about computers to indict a Burger? I'm sure DOJ or FBI makes sure to find a knowledgeable jury...certain.
@gophop
@gophop 4 роки тому
A competent defense would've thrown all of that shit out. Windows logs? LMAO
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
gophop This was Seattle, home to Microsoft. Hard to find 12 random people there and none knowing the inside of Windows.
@akompsupport
@akompsupport 5 років тому
Why weren't any bankers prosecuted after 2008???
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
Emanuel Fernán Because they actually knew how to efficiently bribe US authorities?
@QuaQuoHD
@QuaQuoHD 6 років тому
I am surprised this kind of info is released publicly. Carders/hackers now have a very useful manual on "how to not get caught due to own silly mistakes".
@starrychloe
@starrychloe 6 років тому
QuaQuoHD - criminals are dumb. They don't watch this stuff.
@whatfireflies
@whatfireflies 6 років тому
When you have a criminal empire you're too busy partying and whoring to give a f*** about these kind of details.
@QuaQuoHD
@QuaQuoHD 6 років тому
Ah, I see. Now I am relieved. There's just one little thing keeps bothering me... How come these dumb criminals made a multi billion dollar industry? While catching just one guy out of thousands out there is apparently such a huge deal...
@Luftbubblan
@Luftbubblan 6 років тому
@starrychloe Isn't that exactly the kind of people that watches this? :P Black hat talks... Why would a person with no black hat interest watch this?
@P1nkR
@P1nkR 6 років тому
The hackers already have this kind of info. It's called common sense.
@VigneshSKannan
@VigneshSKannan 6 років тому
Mind Blowing, The exploiter gets exploited! It's tom and jerry
@andreyche193
@andreyche193 5 років тому
So this guy's "political ties and his father's position" mentioned at 3:25 may explain a lot!
@lesthodson2802
@lesthodson2802 5 років тому
Oh, yeah. I'm *sure* they don't collect the content of the data they watch. Yeah. Definitely. Totally believable. Yup.
@mp1335
@mp1335 4 роки тому
47:46 "...didn't blow any techniques that weren't public" :)
@LiEnby
@LiEnby 4 роки тому
i mean if its HTTPS it would be impossible to get the content so.
@machinerin151
@machinerin151 4 роки тому
Yeah, most connections nowadays are encrypted, so no point in storing gigabytes of gibberish.
@Messiah38
@Messiah38 5 років тому
Why do hackfest, 2600 event and other invite police to the events?
@NimbleJack3
@NimbleJack3 5 років тому
It's meant to be an open, public exchange and showcase. If they wanted to secretly swap illegal secrets away from the eyes of the government, they wouldn't rent a function centre to do it. This is a "fun" event.
@jaketus
@jaketus 5 років тому
How dumb was he not to encrypt his drives. And why would one use Windows in that case.
@impaugjuldivmax
@impaugjuldivmax 4 роки тому
that moron is just a scapegoat in someone's big game..
@420xanatos
@420xanatos 4 роки тому
You caught an IRL firewall that got paid for 14 years to carry a stacked laptop and leave crumbs to him.
@scottleft3672
@scottleft3672 3 роки тому
The Maldives is money lauder central, that's his nest egg stash right there.
Black Hat 2013 - OPSEC Failures of Spies
25:11
HackersOnBoard
Переглядів 221 тис.
ISSEI funny story😂😂😂Strange World | Magic Lips💋
00:36
ISSEI / いっせい
Переглядів 91 млн
😱СНЯЛ СУПЕР КОТА НА КАМЕРУ⁉
00:37
OMG DEN
Переглядів 1,7 млн
LIVE - Парад Победы в Москве. 9 Мая 2024
2:27:56
AKIpress news
Переглядів 2,2 млн
Excited Dog Zooms In and Out of Sliding Door!
00:18
The Pet Collective
Переглядів 12 млн
Card-skimming scams target a new group of Americans
5:51
CBS News
Переглядів 898 тис.
How Smartcard Payment Systems Fail
58:56
Black Hat
Переглядів 155 тис.
Chip & PIN Fraud Explained - Computerphile
8:45
Computerphile
Переглядів 840 тис.
When Cybercriminals with Good OpSec Attack
49:01
RSA Conference
Переглядів 174 тис.
Doctor Mike Tries KETO for 30 DAYS
9:01
Doctor Mike
Переглядів 6 млн
I'll Let Myself In: Tactics of Physical Pen Testers
44:56
Wild West Hackin' Fest
Переглядів 2,8 млн
Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference
41:18
DEFCONConference
Переглядів 599 тис.
ISSEI funny story😂😂😂Strange World | Magic Lips💋
00:36
ISSEI / いっせい
Переглядів 91 млн