Script kiddies: The Net's cybergangs

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
They're the gangs of the Internet. Teenagers, bored with their real existence, hit the electronic byways of the Net to tag Web sites with electronic graffiti -- out for the equivalent of an electronic joy ride. They go by such names as Artech, Nemesystm, Team Holocaust and Doodoo Krew, but security experts refer to them as ankle-biters, packet monkeys and script kiddies -- denigrating them for their lack of skill. Yet, like a pirate radio station, the so-called script kids have the power to send a message to the world, if for only a few minutes, using pre-made tools just as office workers use spreadsheets and word processors. "It's a way to escape a lot of the bullshit that I get in real life," said one teenage Web vandal known on the Internet as "Artech" during a recent Internet chat with ZDNet News. "Because I don't have that much going on in my life." Last February, that boredom led Artech to deface three pages in the US department of transportation's Web site, where he labelled himself as "America's worst screw up". The defacement and its proximity to a spate of high-profile denial-of-service attacks reportedly earned Artech the ire of attorney general Janet Reno and the National Infrastructure Protection Centre, which added him to a wanted list of high-profile vandals that they've decided to actively pursue. That's a full measure of notoriety for someone who claims to be a Midwestern 16-year-old and who ended his chat with ZDNet News by typing, "My dad just said 'Now!'... that's when I gotta get leaving". Little else seems to be able to tear Artech -- who says he spends anywhere from eight to 14 hours on his computer each day -- from his keyboard. Despite such dedication -- or addiction, some might say -- the teenage Web vandal does not consider himself a hacker. Hackers, the digital elite of the Internet, are looked up to for their encyclopaedic knowledge of how the Net works. Artech, by contrast, tags high-profile sites with the equivalent of digital graffiti. "If [I] have to use a script kiddie method, oh well," he said. "I would rather be a script kiddie than use some mad skill and take down an unknown Web site." "Nemesystm", another script kid who claims to be Dutch teenager based in the Netherlands, doesn't consider himself a hacker either. "When I deface, I consider myself a script kiddie," he told ZDNet News during an IRC interview. "When I break into sites, not, because I find my own exploits." Nemesystm claims he and his group -- the Delinquent Hacking Corporation, or DHC -- have digitally tagged more than 300 Web sites. Boredom got the better of him, as well, he said. "The world we live [in]... everything is the same, so incredibly boring. I feel if I deface, at least, I'm making some kind of difference." The Dutch teenager -- who got hooked on circumventing network security when he discovered someone had placed the Back Orifice Trojan horse on his computer -- stands out from the crowd by placing poetry on Web sites that he tags. "Breathing is hard/ when the world/ has stopped [to] care," reads the opening stanza of "Choke", a poem posted on the recently defaced US Navy Patrol Squadron's Web site. Other script kids leave behind flashy graphics, explanations of how to fix the security hole in the defaced system, or messages written to others in 31337 (elite) speak, the lingua franca of the script kiddie subculture. No matter what marks are left behind, the goal is fame, said Brian Martin, a staff member with security-scene follower Attrition.org. "They see it more as a way to get their name on the Internet than learning about computers," he said. Yet, increasingly, the likes of Artech and Nemesystm are becoming a thorn in the sides of corporations, non-profit groups and schools -- in short, just about anyone else who has thrown up a Web site. Data from Attrition.org shows a general increase in Web site defacements, which peaked in November 1999 at about 650 defacements and now has levelled off to around 400 defacements per month. While businesses and the FBI are dismayed by the numbers, script kids are not serious threats, said Martin, who uses the handle "Jericho" in the online world. "They will probably remain a big annoyance," he said. "While it does create a perception that a lot of hackers are out there doing a lot of damage, most of these kids don't have the brains to turn the exploit into a serious compromise." While Martin sees no reason to fear the script kids, those kids see little reason to fear the real world of the FBI and investigations. "I live by a couple [of] simple rules," said Nemesystm. "If I can keep them, they can't do a thing till I'm an adult, but take my computer away." Those rules? Never deface any site in your own country or give information about yourself over the Internet. Don't deface a site if you are unsure of it. And, finally: "Be nice, always, so no one will hate you," he said. Nemesystm has already seen changes among other script kids, changes that he doesn't like. "A lot of kiddies use [the simplest flaw] to get into [Windows] NT sites, and just put one line -- just to brag," he said. The Doodoo Krew did just that when the group tagged the Spokane Police Department's Web site earlier this month. The group left behind a simple white Web page containing five words: "Doodoo krew in the y2k." "If [the others] want to do that, fine, but it doesn't mean anything," said Nemesystm. More than the changes in the underground community, the Dutch teenager sees changes in the public's perception of Web vandals. "I think that people will eventually learn the difference between a hacker and a defacer and leave the hackers alone," said Nemesystm. "I'll continue defacing, not as much as I used to, but I will be around." Stay tuned today for ZDNet's Summer of Hacking special. Take me to Hackers What do you think? Tell the Mailroom. And read what others have said.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

8 minutes ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

27 minutes ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

31 minutes ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

48 minutes ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

4 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

5 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

5 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

6 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

7 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

9 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

17 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

23 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

24 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

24 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

1 day ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

1 day ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

2 days ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

2 days ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

2 days ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit