Stokes allegedly hid his device behind a virtual private network (VPN) server which he then used to open an account on the ngrok secure tunnelling service.
But doing so did not mask the unique GDID of the Windows installation he used.
Microsoft identified that GDID for investigators after a court order, based on ngrok's time-stamped access records.
10 Comments
NM_Gringo@lemmy.world · 38 pts · 37d
What kind of eleet haxor dude uses Windows?
PushButton@lemmy.world · 35 pts · 37d
Back then, we used to call those "script kiddies".
MonkderVierte@lemmy.zip · 6 pts · 36d
Most of them are still. I've read a analysis of the log of a purposedly exposed system a while ago. Don't know the exact numbers anymore but : ca. 9 of 10 are bots placing a backdoor. Of the human visitors, most are just looking around, poking things, getting bored, bye. And 2 of all of them were (cybercriminal) professionals who knew what they're doing.
0x0@infosec.pub · 10 pts · 36d
https://arman-bd.hashnode.dev/i-left-port-22-open-on-the-internet-for-54-days-here-s-who-showed-up
MonkderVierte@lemmy.zip · 1 pts · 36d
Right, that one, thanks!
Triumph@fedia.io · 19 pts · 37d
Ffs you don't do that shit from your own computer. You use a zombie.
SeductiveTortoise@piefed.social · 6 pts · 37d
They won't use their computer for a while, if that helps.
11111one11111@lemmy.world · 19 pts · 37d
Goddamn this isnt a testament to anything microsoft did this kid is just a fuckin idiot.
IamBlank@lemmy.zip · 4 pts · 35d
Windows…
JoeKrogan@lemmy.world · 2 pts · 37d
Skill issue