• On Metacritic: Bayonetta -- The Best Game of 2010?
July 18, 2007 1:00 AM PDT

FBI remotely installs spyware to trace bomb threat

by Declan McCullagh
  • Font size
  • Print
  • 20 comments

The FBI used a novel type of remotely installed spyware last month to investigate who was e-mailing bomb threats to a high school near Olympia, Wash.

Federal agents obtained a court order on June 12 to send spyware called CIPAV to a MySpace account suspected of being used by the bomb threat hoaxster. Once implanted, the software was designed to report back to the FBI with the Internet Protocol address of the suspect's computer, other information found on the PC and, notably, an ongoing log of the user's outbound connections.

Screen snapshot of 'timberlinebombinfo' MySpace account

The suspect, former Timberline High School student Josh Glazebrook, was sentenced this week to 90 days in juvenile detention after pleading guilty to making bomb threats and other charges.

While there's been plenty of speculation about how the FBI might deliver spyware electronically, this case appears to be the first to reveal how the technique is used in practice. The FBI did confirm in 2001 that it was working on a virus called Magic Lantern but hasn't said much about it since. The two other cases in which federal investigators were known to have used spyware--the Scarfo and Forrester cases--involved agents actually sneaking into offices to implant key loggers.

An 18-page affidavit filed in federal court by FBI Agent Norm Sanders last month and obtained by CNET News.com claims details about the governmental spyware are confidential. The FBI calls its spyware a Computer and Internet Protocol Address Verifier, or CIPAV.

"The exact nature of these commands, processes, capabilities, and their configuration is classified as a law enforcement sensitive investigative technique, the disclosure of which would likely jeopardize other ongoing investigations and/or future use of the technique," Sanders wrote. A reference to the operating system's registry indicates that CIPAV can target, as you might expect given its market share, Microsoft Windows. Other data sent back to the FBI include the operating system type and serial number, the logged-in user name, and the Web URL that the computer was "previously connected to."

News.com has posted Sanders' affidavit and a summary of the CIPAV results that the FBI submitted to U.S. Magistrate Judge James Donohue.

There have been hints in the past that the FBI has employed this technique. In 2004, an article in the Minneapolis Star Tribune reported that the bureau had used an "Internet Protocol Address Verifier" that was sent to a suspect via e-mail.

But bloggers at the time dismissed it--in hindsight, perhaps erroneously--as the FBI merely using an embedded image in an HTML-formatted e-mail message, also known as a Web bug.

Finding out who's behind a MySpace account

An interesting twist in the current case is that the county sheriff's office learned about the MySpace profile -- timberlinebombinfo -- when the creator tried to persuade other students to link to it and at least one of their parents called the police. The sheriff's office reported that 33 students received a request to post the link to "timberlinebombinfo" on their own MySpace pages.

In addition, the bomb hoaxster was sending a series of taunting messages from Google Gmail accounts (including dougbrigs@gmail.com) the week of June 4. A representative excerpt: "There are 4 bombs planted throughout Timberline High School. One in the math hall, library hall, and one portable. The bombs will go off in 5 minute intervals at 9:15 am."

The FBI replied by obtaining account logs from Google and MySpace. Both pointed to the Internet Protocol address of 80.76.80.103, which turned out to be a compromised computer in Italy.

That's when the FBI decided to roll out the heavy artillery: CIPAV. "I have concluded that using a CIPAV on the target MySpace 'Timberlinebombinfo' account may assist the FBI to determine the identities of the individual(s) using the activating computer," Sanders' affidavit says.

CIPAV was going to be installed "through an electronic messaging program from an account controlled by the FBI," which probably means e-mail. (Either e-mail or instant messaging could be used to deliver an infected file with CIPAV hidden in it, but the wording of that portion of the affidavit makes e-mail more likely.)

After CIPAV is installed, the FBI said, it will immediately report back to the government the computer's Internet Protocol address, Ethernet MAC address, "other variables, and certain registry-type information." And then, for the next 60 days, it will record Internet Protocol addresses visited but not the contents of the communications.

Putting the legal issues aside for the moment, one key question remains a mystery: Assuming the FBI delivered the CIPAV spyware via e-mail, how did the the program bypass antispyware defenses and install itself as malicious software? (There's no mention of antivirus defenses in the court documents, true, but the bomb-hoaxster also performed a denial of service attack against the school district computers -- which, coupled with compromising the server in Italy, points to some modicum of technical knowledge.)

One possibility is that the FBI has persuaded security software makers to overlook CIPAV and not alert their users to its presence.

Another is that the FBI has found (or paid someone to uncover) unknown vulnerabilities in Windows or Windows-based security software that would permit CIPAV to be installed. From the FBI's perspective, this would be the most desirable: for one thing, it would also obviate the need to strong-arm dozens of different security vendors, some with headquarters in other countries, into whitelisting CIPAV.

Earlier this week, News.com surveyed 13 security vendors and all said it was their general policy to detect police spyware. Some, however, indicated they would obey a court order to ignore policeware, and neither McAfee nor Microsoft would say whether they had received such a court order.

The verbatim results of our survey are here.

Declan McCullagh, CNET News' chief political correspondent, chronicles the intersection of politics and technology. He has covered politics, technology, and Washington, D.C., for more than a decade, which has turned him into an iconoclast and a skeptic of anyone who says, "We oughta have a new federal law against this." E-mail Declan.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (20 Comments)
  • prev
  • 1
  • next
Maybe just image request tracking instead
by hammc July 18, 2007 6:05 AM PDT
Is it possible that the FBI used an image to be implanted as a 1x1 pixel with a clear background. Just waited for the person to open it and once it reported back a request for said gif they had there person's computer identified. Maybe sending multiple emails or messages possibly sending from friends or family to a known address...
Pretty clever but easily discovered.

It is going to get harder and harder to really use a traditional EXE virus program like once known. Not to mention a person can track all there programs and checksum their drive if they are clever enough. This is in addition to their virus protection. This guy was using a proxy of some type possibly so this isn't your average criminal. He had done other crimes(according to the story) and just got too brazen.

I wonder what liability Myspace or other providers have if whatever method is used causes issues???
Reply to this comment
Exactly what I was thinking...
by SeizeCTRL July 18, 2007 6:47 AM PDT
I had a so-so friend who had fled the area while on probation, and knew he was going to go back to jail for lack of payment on child support. I was got along pretty good with his wife, so she asked me if there was any way to find out where he might be... so all I did was upload a specific image to my FTP, then send him a myspace email with that image link in it and when he opened the email, his IP popped up in my access logs. After that it was simple to narrow down where he was hiding.

You would think the FBI with all their resources could do this same thing without the need for spyware. How hard can it be?
not image tracking
by declan00 July 18, 2007 9:50 AM PDT
You might want to actually RTFA before posting.

A 1x1 pixel GIF isn't going to be able to report back to the FBI the IP address, MAC address, open communications ports, list of running programs, OS type and serial number, Internet browser and version, language encoding, registered computer name, registered company name, current logged-in user name, URL connected to, and a list of IP addresses subsequently visited.

It's on page 6 of the first PDF as well.
View all 2 replies
Image Requests would point to the proxy
by real_bgiel July 18, 2007 10:33 AM PDT
This guy was going thru a compromised computer. The actual IP of the requesting agent would still be hidden... no? Maybe it would show up on the compromised machine. But that would probably be inaccessible to local law enforcement.
View reply
Bet it doesnt work on Windows Vista
by richto July 18, 2007 7:52 AM PDT
I bet the FEDS have a real headache now that Windows Vista is rolling out. Users no longer run with the Administrator rights necessary to install software without a very clear warning message being displayed. Must make it much harder for the FEDS to compromise such systems.
Reply to this comment
I bet it does
by qwerty75 July 18, 2007 10:26 AM PDT
If you think Vista is secure then I guess you will believe anything.

The "are you sure you want to do this" message(they need to have this popup during install) is quite often shut off because people get sick of it.

It is still possible to install software with a user account.

If you think you are any safer in Vista then in XP, well there isn't much to say about such stupidity.
What if he was using a Mac? Or Linux?
by NCNSolutions July 18, 2007 8:35 AM PDT
Wouldn't that block CIPAV as well? If they were able to track down the compromised comuter, then I'm sure the FBI could load CIPAV onto that machine, and then track track all the IP Addresses accessing that box. Then it's just a matter of weeding through the logs. Once they have the IP's they'll know the regions, and it sounds like this kid was in the same town as the school, so zero in on the region, zero in on the ISP, and use that court order to force the ISP to turn over his account info.
Reply to this comment
Was the computer running MS-WIndows?
by The_Nirvana July 18, 2007 11:29 AM PDT
or could CIPAV be something written in assembly level code, thus
making it OS independent. Just a thought....
Reply to this comment
Assembly would not make it OS independent.
by ralfthedog July 18, 2007 12:16 PM PDT
Linux uses different handles to access hardware. It allocates memory differently. If you wanted to make it OS independent you would have better luck with Java (I don't know if Java would work, but it would be closer).

My guess is that you would use an image to get the IP address of the target, then have an application running server side punch a hole through the router. If I had my guess, Magic Lantern is a server side application. Think of something on the lines of Steve Gibson's "Shields up".

Before anyone asks, yes, you could do this if the person was running a proxy server, but it would be a bit harder. The tricky part would be getting past the firewalls that the ISP uses.
Re: Was the computer running MS-Windows?
by imacpwr July 18, 2007 12:17 PM PDT
Quote from article:
"Another is that the FBI has found (or paid someone to uncover)
unknown vulnerabilities in Windows or Windows-based security
software that would permit CIPAV to be installed."

I've never heard of an OS called Linux-Windows, Unix-Windows
or Mac-Windows so I'm going to go out on a limb and say I
believe YES.. the article refers to MS-Windows..

(next time READ the article)
View all 2 replies
If I were a security tech...
by mattumanu July 18, 2007 4:33 PM PDT
I'd demand to know how they did it. There's a possibility that the CIPAV uses some unknown vulnerabilities in current operating systems, and if so these vulnerabilities need to be addressed and patched immediately. If the FBI refused to so so, I would attempt to get a court order to force them to reveal the process.

If, to solve one case, the security of millions of internet users is put at risk, then this is unconscienable. There is no difference between this and the actions of a hacker breaking into any given computer system, and in fact, should a hacker gain access to the information deemed "classified" by the FBI, they could exploit it to do any amount of damage they wanted to. A reverse engineered CIPAV in the hand of hackers or terrorists could be lethal.
Reply to this comment
If I were a security tech...
by The_Nirvana July 18, 2007 4:50 PM PDT
I wouldn't care how they did it. They have just exploited another (unknown) windows vulnerability. There are at least half dozen of them discovered every week.
View reply
How about the face recognition program?
by nielling July 21, 2007 7:50 AM PDT
Multiply.com has recently announced that a new upgrade to their sites will be a face recognition program...in case you see photos of people and think you might know them and want to have information on them. Fear! Now why would I put an alias and codes and all kinds of security on logging into a site and then want someone to know who I am or my child is and where we live and so on? Once the persons identity is released, one can go google and there it is. What if I did not want aunt soso to know that I had been at her divorced husbands party? Do I paranoid the FBI in this type of activity? What if, I thought I saw one of the suspects online at an unusual angle...I report it and force an investigation of someone who was just enjoying a web site?
The predators have one advantage, avatar icons...
Another question...if someone ads that a site is for families...should they be required to make it safe for children...or are children no longer a part of family?
Reply to this comment
(20 Comments)
  • prev
  • 1
  • next
advertisement

E-readers' next chapter--no happy ending?

There were plenty of e-book readers on display at CES 2010, but many question whether the market for such dedicated devices can support all the new entrants.
• Photos: E-readers at CES

Inside the world's long-lost first microcomputer

Vintage computer historians have long revered the Altair 8800. As it turns out, an unknown computer project at Sacramento State beat the Altair by three years.
• Images: The first microcomputers

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right