Showing posts with label alex eckelberry. Show all posts
Showing posts with label alex eckelberry. Show all posts

Sunday, November 23, 2008

Outrageous Porn Pop-Up Case in Norwich is Over

If there were ever a modern case that could be compared to the Salem witch trials, it would be the effort to prosecute Julie Amero, a Norwich, Connecticut school teacher for (allegedly) exposing her students to pornography.

Julie was convicted on four counts of exposing kids to pornography after she turned on a spyware-infested (school-owned) machine and a flurry of porn pop-ups began appearing on the screen. Julie, who was merely a substitute teacher, didn't know what to do and the teenagers in her class witnessed the event.

Even worse, the school district had let their content filtering software expire. Computer experts later discovered the spyware infestation was caused by someone accessing a hairdressing site. Presumably, this site was accessed by a student, who wasn't aware of the spyware and didn't know the school district had let their content filtering expire.

On Friday, Alex Eckelberry, CEO of Sunbelt Software, announced that the Amero nightmare is over in his popular Sunbelt Blog. Sadly though, she still had to plead to a misdemeanor charge of disorderly conduct. The result was a $100 fine and she has had her teaching credentials revoked in Connecticut.

Considering in the initial trial she was facing a conviction on four felony counts — which could have netted her 40 years in the slammer — I suppose this is a win?

"She acquiesced to the lesser misdemeanor charge, and while it may have been a bitter pill to swallow, she can at least can move on now without this sick cloud hanging over her head. It was less than two years ago that Julie was facing felony charges with a maximum of 40 years in prison," according to Alex Eckelberry,

Alex and a host of people from the computer security industry, along with a pro bono attorney, William Dow, led the effort to expose this injustice and get Julie a new trial. The number of people who got involved in this is amazing and many of them are mentioned in Alex's blog post.

I found this case amazing since malicious and even so-called commercial sites infest unprotected machines with all kinds of "ware" on a daily basis. In this case, it was the industry that protects computers from unwanted "ware" that had to step in and educate the authorities that there was a problem with the intent in the case. Perhaps the authorities should have hired someone a little more knowledgeable in computers in the first place before attempting to prosecute Julie.

Sadly, Julie's health has been failing as a result of the stress induced by this prosecution. Even sadder, with all the real crime on the Internet, which rarely ever results in a prosecution, a lot of taxpayer money was wasted going after someone who most believe was completely innocent!

I've written a few posts about the Julie Amero story. It's ironic that Internet porn, which is allegedly controlled by organized crime, translated into a teacher being charged for turning on a computer for the first time. Even more ironic is that in those four years, very few, if any, of the people behind the actual problem have been brought to justice. Also, ironic was a WebMD survey that found that Internet porn reaches most children, including the age of the teenagers present in Julie's class that day. The truth is that most of the teenagers in the class have probably seen worse, unless they've never surfed the sometimes murky waters of the Internet.

The ironies in this case are many and in the end, history will write it that way.

Sunday, October 07, 2007

The somewhat slow response to the hacking of California.gov

With all the technology that California is famous for, you would think their government websites were state of the art, when it comes to security.

Apparently, this is NOT the case. The result has been a lot of misdirection to sites of a pornographic nature.

Alex Eckelberry, CEO of Sunbelt Software, has been blogging on this subject:

Yesterday, we reported on a federal shutdown of “ca.gov” sites to fix a hack.

Well, we have a little more information on this. It was the Marin County government website that started all of this — something we reported back in September 12th.
Does anyone besides me wonder if there wasn't much of a sense of urgency on this issue?

Bezhou Feng at Neowin.net reported that:


The shutdown, initiated by the General Services Administration (GSA), a US agency in charge of all top-level ".gov" domains, began at roughly 4:00PM (PST), quickly turning into such a problem that Gov. Arnold Schwarzenegger even considered calling the President himself.

While the porn aspect is either amusing, or disgusting (depending on your viewpoint) -- this clearly shows that .gov sites should wake up and listen when experts are trying to tell them something is wrong.

After all, this type of activity could have been something far more serious than something that is disgusting, or amusing!

Of note, as of this writing, I ran a search on Google and the Marin site (TAM) is still misdirecting users to a number of pretty nasty porn sites.

As I've written before -- exercise extreme caution when clicking on porn sites, they often make your computer come down with a virus (or worse)-- especially if "safe surfing practices" aren't being used.

Sunbelt blog post, here.

Neowin.net story, here.

Update 10/09/07: Alex Eckelberry (Sunbelt), who has covered this problem for over a month did (what I consider) an amusing post to follow-up on this one, here.

Alex and his team at Sunbelt are my favorite place to learn about computer security issues. They routinely help a lot of people free-of-charge and are experts in what they do.

Sunday, September 02, 2007

Blogger fights back against the storm worm

Since Blogger has been kind enough to host this blog for about two years now, I thought I should do a post about the recent reports concerning malware and Blogger.

Blogger itself, wasn't compromised, but a lot of bloggers individual blogs were. Most people are compromised by malware after clicking on a link they shouldn't have.

This was posted on Blogger Buzz:

You may have seen stories in the news recently about malware on Blogger, such has this one from the BBC or this one from Committee to Protect Bloggers. Blogger was not compromised. Instead, the blog posts are from bloggers whose machines were compromised by a Trojan horse.

These bloggers had their mail2blogger email addresses in their computers' address books (a perfectly legitimate use case), so when the malicious software spammed every address in their address book with its content, a copy of that email was posted to their blog.

We are in the process of notifying impacted bloggers and recommending that they scan their computers and run current anti-virus software, available in the GooglePack. This is also good advice for all computer users, especially those who may have clicked the links in the emails sent by the virus. For more information about computer security, check out upenn.edu and us-cert.gov.

The BBC article mentions that Alex Eckelberry, who blogs at the Sunbelt blog was the first to discover the problem on Blogger. Please note, Alex himself is a Blogger user and the CEO of Sunbelt Software, a computer security company.

Alex has even been kind enough to help me, when I ran into a problem, or two doing this blog.

Alex has a pretty visual post (lot's of screenshots), which show exactly how the worm would be encountered in the wild.

Of interest, Alex also discovered that Blogger wasn't the only place, where people are being lured into downloading the storm worm.

From what I understand the intent of the storm worm is to turn a computer into a zombie, which becomes part of a botnet. Botnets are networks of zombie computers.

Botnets are used to send out spam e-mail and sometimes attack other systems in what are known as DOS (denial of service) attacks. They are also used to commit click fraud.

Of note, most Internet fraud can be traced to a spam e-mail.

Besides running a scan with good anti-virus software (to see if you've been compromised) -- the best defense is to learn how to spot the lures that are designed to trick people into clicking on them. In most instances, this will stop the problem before it happens!

Monday, August 06, 2007

Bizzare site asks viewers for money to keep a bunny from being butchered!

I was reading the Sunbelt blog, written by Alex Eckelberry and came across a post he did on a bizzare and pretty sick website.

In Alex's own words:

save-me-please(dot)com is a site dedicated to saving a bunny.

We have no idea what this is odd thing is: A joke, a hoax. Or a scam.



The whole intent of the site is to get a person to pay to save the bunny.



You can view the Sunbelt blog's entire presentation, here.

Paying to save the bunny isn't recommended and as Alex aptly states, one of the videos depicting a rabbit being skinned is "enough to make you a vegetarian."

This blog, according to a study Jonathan Edwards at Yankee Group has "mojo."

I can see why it does, besides providing a lot of great information, it tends to keep the interest of the people, who read it!

The Sunbelt blog is also an excellent place to keep up on, or learn about computer (information) security issues.

Sunday, June 10, 2007

We all could be at risk of losing our freedom and becoming the next Julie Amero

Julie Amero, a substitute teacher previously convicted of showing porn to students, is getting a new trial.

Given the evidence brought forward after the trial, I'm pretty shocked they didn't just drop the whole matter.

Stephanie Reitz of the AP is reporting (courtesy of the Washington Post):

The computer was sent to a state laboratory after the trial, and the judge said Wednesday that those findings may contradict evidence presented by the state computer expert.

"The jury may have relied, at least in part, on that faulty information," said Judge Hillary B. Strackbein, who granted the request for a new trial.

Amero has adamantly denied clicking on pornographic Web sites that appeared on her classroom's computer screen in October 2004 while she was teaching seventh-graders at Kelly Middle School in Norwich.

Not very long after her conviction, I did a post on this quoting a lot of computer security experts, such as Alex Eckelberry from Sunbelt Software. Alex and other experts in the field contend the computer in question was old, lacked firewall protection, and that spyware and adware caused the porn infestation.

Their contentions made sense to me, or should to anyone -- who has accidentially clicked on one of these sites and gone into "pop up" hell.

Illegal porn is a big problem on the Internet - very few people get caught - and it's rumored to be controlled by organized crime. The Gambino crime family has allegedly made millions of it.

Recently, I blogged about British citizens, who were wrongfully accused of viewing child pornography after their credit cards numbers were stolen. This was part of an International case, involving people, worldwide.

Those responsible for investigating crimes involving computers, and the Internet are going to have to exercise a little more "due diligence" in their investigations. Spyware, adware and identity theft (to cite a few things) are making the waters a little more murky than they used to be.

Spyware and adware are used by a lot of businesses to market products. As a matter of fact, it sometimes amazes me, just WHO is using it; considering some of the privacy concerns associated with it.

The sad thing is that if you really think about it, a lot of us could be in danger of being accused of something we didn't do. Recently, we've seen a lot of stories about identity theft victims, who like Julie, went through a lot of pain and suffering for a crime they didn't commit.

This is the very reason, we need to take a hard look at what enables this activity, or makes it too easy to accomplish.

The other thing I'll add, as a closing note -- is that we live in a society --where OJ Simpson beat a murder rap because of reasonable doubt. It's pretty sad that with all the reasonable doubt revealed in this case, Julie Amero has to face another trial to prove her innocence.

AP story (courtesy of the Washington Post), here.

Previous post from Fraud, Phishing and Financial Misdeeds, here.

Thursday, February 15, 2007

Is Julie Amero (in reality) another victim of Internet crime?

Internet crime is a growing problem. Every week, we seem to read of large scale data breaches, and spam is filling up our inboxes, despite the spam filters designed to stop it.

The spam getting past these filters is often riddled with deceptive lures (links) to all sorts of porn sites. In turn, these sites often infect machines that aren't properly protected with adware, spyware, malware and even crimeware.

So far as properly protecting our machines, this can be a chore, also. It requires frequent updates, and new exploits are discovered all the time.

Sometimes even legitimate sites are hacked and people get infected just by surfing, or visiting (what they think) is a trusted site.

Criminals of all sorts, including those of an organized nature are getting involved in Internet crime. In fact, many believe the problem is growing because very few get caught, and even if they do, very little happens to them.

I was amazed when I got an e-mail from Alex Eckelberry (CEO Sunbelt Software) that a substitute teacher (Julie Amero) had been convicted for some porn that had shown up on a classroom computer.

A jury has already found her guilty and she could face up to 40 years in prison. Even worse, it appears the stress of the trial may have caused her to have a miscarriage.

Is her conviction a miscarriage of justice? Many computer experts (including Alex) seem to think so.

Alex writes a very convincing argument, where he states:
When I first read of the case, my reaction was how illogical it all sounded: A middle-aged, substitute female teacher accessing porn on a classroom computer, in front of her students on one particular day? It made no sense.
He's right, it doesn't make sense.

An article from the Norwich Bulletin stated that:

Computer expert W. Herbert Horner, testifying in Amero's defense, said he found spyware on the computer and an innocent hair styling Web site "that led to this pornographic loop that was out of control."
"If you try to get out of it, you're trapped, according to Horner."

Anyone, who has surfed the Internet knows there are a lot of malicious sites designed to lure people to click on them, using seemingly innocent lures.

She was also convicted on testimony that she must have had to physically click on the sites in question. According to Alex and other computer security experts, the pop-ups from these sites leave the same imprint as if they had been physically clicked on.

Alex wrote in the Norwich Bulletin:

The computer was also found to be riddled with spyware -- programs that generate popups and degrade system stability.

Spyware may or may not have played a direct part in this incident, but the fact it was on the system creates additional damning evidence of the state of this computer system. What is extraordinary is the prosecution admitted there was no search made for spyware -- an incredible blunder akin to not checking for fingerprints at a crime scene.

Alex also states that this was an old system, without adequate protection, despite the fact that federal law mandates that it should have been in place.

Julie, herself claims the website in question was accessed by students when she went to the restroom. When she noticed it, no matter what she did, more pop-ups would surface.

More on Herb Horner's analysis (courtesy of the Sunbelt blog), here.

In a criminal case, the standard is that a person should be found innocent if there is reasonable doubt. After reading about this case, it makes sense to me, that we have a lot of reasonable doubt that Julie is guilty.

At best, the investigation used to convict her seems to have been poorly researched, and therefore, flawed.

Porn is a big component of Internet crime, which according to a WebMD survey reaches a lot of children. This research was conducted by interviewing children, themselves.

Some of the children interviewed were the same age as the ones in Julie's class that day.

Survey, here.

So far as a connection to real (organized) crime, porn was allegedly one of the Gambino crime families biggest earners ($350 million).

Besides being unjust, going after Julie Amero, is a big waste of resources (taxpayer dollars) that could be put to better use.