WARNING!

Status
Not open for further replies.
Quote from shortie:

there is a distinct possibility that EMR was set up.

we probably won't know the truth. a couple of rounds of waterboarding will squeeze the confession out of him.

nobody is safe!!!

heheehe how right you are

USA government now has a law where they can pick you up and water-board you without charge or court

and they can keep you indefinitely

not kidding yankee :(
 
Quote from Max E. Pad:

Cold/C-kid on the other hand has been spamming the forum and sending out PM's about Joe for a long time and he is actually a psychopath, he has a history of actually posting violent angry stuff, and he actually started spamming the site with child porn already 1 time. Plus he has been spamming stuff about Joe to people via PM for months. He actually seems to have some sort of strange psychotic vendetta against Elite trader, where as Bearice really didnt appear to mean anyone any harm.


Quote from Baron:

Bingo. He is behind this without a doubt in my mind. So after some discussion yesterday, we realized that in the beginning, there was a point when Cold was a regular member and was talking about trading like everybody else. He eventually turned into a jackass and had to be banned for such. That was the beginning of him going ballistic and wanting to bring us down. Since then, his antics have come and gone in waves, probably depending on his medication, but the point is that he was participating normally for a while and had no reason to do something like mask his IP address through a proxie server. So we went back and looked just to see if his IP was very consistent at the beginning stage or if it shuffled all around to something different every time he posted. Sure enough, it was the same IP, day in and day out.

So we did a Geo IP lookup and this is what we found:

http://www.geoiptool.com/en/?IP=75.153.42.110

So as you can see in that link, the IP originates from Canada.

What's great about this is that Cold confirmed himself in this post that he is Canadian.

http://www.elitetrader.com/vb/showthread.php?s=&postid=1870632&highlight=canadian#post1870632

So needless to say, his big mouth in the very beginning may end up being his downfall.

Obviously, Baron, MaxiPants and others had no clue what was going on. It was too easy to blame it on Cold (even though the pieces of the puzzle did not fit) and you fell for it.

The chance that these jokers got the right guy this time is very small IMHO.
 
I think there is more to this story. I can't recall exchanging pm's with him and we never had any verbal sparring on here that I can recall yet I got the pm from the hacker that baron deleted. I don't know emrglobal but there are trojans out there that allow the hacker to do anything they want. He could have been hacked, had a keylogger installed, then they have his username and password. They could have been using his computer as a redirect site to host this crap. Perhaps elitetrader itself was hacked and this hacker stole usernames and passwords that way. If a machine is compromised an ip does not mean anything as I could be in europe making your computer in chicago do anything I want with the right knowledge.
 
There are a couple of possibilities. Anyone can VPN or surf anon with an offshore server and post those pics. The first week was devoid of actual exploits AFAIK. I am sure there were other attempts that only Baron was privy to, but we saw the PMs. You certainly wouldn't need to hijack EMRs iMac to do so. It would be counter-productive.

Let's assume that he was hacked for the javascript exploit. WHY would the perp go to the trouble of embedding the exploit under EMRs handle when he could far more simply login under a new nick and embed the script?

I can imagine that all of the early exploits were bounced off of many offshore servers... otherwise Baron would've had the perps IP from day one.

So why hijack EMRs machine to execute the javascript? It could've been done in seconds off of a new anon nick served from Russia, Bangalore, etc...

It's a fucking IQ test to assume the perp went to the trouble to remote his machine to load the exploit when for over a week the perp was content to sending the porn through PMs off a VPN, etc.

Ask yourself which is more likely? A spammer/competitor was content with sending kiddie porn to our inboxes for over a week from anon addresses and ONLY THEN decided to hijack a machine to load the exploit. Absolutely fucking ridiculous and UNNECESSARY. VPN or tor -> open new webmail -> open ET alias -> post java exploit.

EMR did it with his hands from his San Antonio apt. His password was not changed. He was posting like mad on FB and elsewhere during this time.
 
Quote from volente_00:

I think there is more to this story. I can't recall exchanging pm's with him and we never had any verbal sparring on here that I can recall yet I got the pm from the hacker that baron deleted. I don't know emrglobal but there are trojans out there that allow the hacker to do anything they want. He could have been hacked, had a keylogger installed, then they have his username and password. They could have been using his computer as a redirect site to host this crap. Perhaps elitetrader itself was hacked and this hacker stole usernames and passwords that way. If a machine is compromised an ip does not mean anything as I could be in europe making your computer in chicago do anything I want with the right knowledge.

It is absolutely possible to use a trojan rootkit to take over a PC and post using that PC and its IP
I don't know if that's the case here, but it can definitely be done.

You could even delete the trojan with overwrites once you are done, completely hiding your actions.
All of this is doable and you don't even have to be an expert, just medium expert.
 
Quote from atticus:


It's a fucking IQ test to assume the perp went to the trouble to remote his machine to load the exploit when for over a week the perp was content to sending the porn through PMs off a VPN, etc.

Ask yourself which is more likely? A spammer/competitor was content with sending kiddie porn to our inboxes for over a week from anon addresses and ONLY THEN decided to hijack a machine to load the exploit. Absolutely fucking ridiculous and UNNECESSARY. VPN or tor -> open new webmail -> open ET alias -> post java exploit.

EMR did it with his hands from his San Antonio apt. His password was not changed. He was posting like mad on FB and elsewhere during this time.

You talk big talk and with authority, are you sure you should be making statements like that

just a while ago you thought it was guy "cold" because Baron manager of ET said so.
And now you are sure it is EMR guy

Maybe the hacker took this seriously and made sure someone else get blamed.
Police should figure this out not you or me.
 
Quote from ChDong:

You talk big talk and with authority, are you sure you should be making statements like that

just a while ago you thought it was guy "cold" because Baron manager of ET said so.
And now you are sure it is EMR guy

Maybe the hacker took this seriously and made sure someone else get blamed.
Police should figure this out not you or me.

Yeah, numbnuts, that would be all nice and neatly packaged were it not for the fact that I never mentioned COLD and he was brought into this thread AFTER the javascript exploit.

Retard.
 
Quote from volente_00:

I think there is more to this story. I can't recall exchanging pm's with him and we never had any verbal sparring on here that I can recall yet I got the pm from the hacker that baron deleted. I don't know emrglobal but there are trojans out there that allow the hacker to do anything they want. He could have been hacked, had a keylogger installed, then they have his username and password. They could have been using his computer as a redirect site to host this crap. Perhaps elitetrader itself was hacked and this hacker stole usernames and passwords that way. If a machine is compromised an ip does not mean anything as I could be in europe making your computer in chicago do anything I want with the right knowledge.

He sent me a series of emails and at first he said it was "unknown forces" that had hacked into his computer, possibly a virus or something like that. Please see below:

---------- Forwarded message ----------
From: <ericross@mac.hush.com>
Date: Wed, Dec 14, 2011 at 2:16 PM
Subject: Account Hacked
To: support@elitetrader.com


Hello, My account has been hacked by unknown forces. I just got back
today and found my computer has been hit with some sort of virus.

But now he's admitting that he made the post himself including the javascript redirect. The only thing he's disputing now is that nobody was redirected to child porn, but they were redirected to non-pornographic images of adult women.

On Wed, Dec 14, 2011 at 3:38 PM, 007 emrglobalmarkets@gmail.com wrote:

... 3. I stayed away from ET for a while, afraid that I would come across
child porn pictures. When, on Sunday, I noticed that Baron had
finished his maintenance I wanted to verify if the redirect function
had been disabled. I uploaded a handful of FAKE photo-shopped pictures
of adult women whose heads I had replaced with the heads of 2 young
girls, taken from a normal, non-pornographic image. Then I posted the
redirect link in a reply to an old spam thread. I repeat: This was NOT
real child porn, unlike that which I had a received a few weeks
before. It was just obviously faked images of adult women.

That's interesting because I didn't see any of these non-porn photos of adult women that he's talking about. And judging by how you guys were describing the disgusting content that you were seeing, you didn't either.

And finally, I would like to point out that all of the disgusting child porn photos that the web site that you guys were being redirected to have been magically taken down last night by someone.

I will leave it up to you guys to make your own conclusions about what's going on here.
 
Status
Not open for further replies.
Back
Top