IT security staff keep paedophile business afloat

Police are holding the IT security linchpin responsible for propping up an online business that specialises in networking paedophiles and trading images of children being sexually abused.

Yesterday Queensland Police announced that Operation Achilles -- which has been pursuing child sex offenders online -- has led to the successful shut-down of a major paedophile business. Queensland Police cooperated with the FBI, as well as New Zealand and European law enforcement agencies, to bring down the operation.

At the centre of the operation is an Italian Web site administrator, Sergio Marzola, who was responsible for the ongoing security of the group's communication, Queensland Police said.

Twenty paedophiles across six countries have been arrested. Investigators are now poring over 400,000 video files captured from the group.

Want to know more?

For all the latest news, analysis and opinion on security, click here

"Some networks have a security officer, for lack of a better word, who that's all that persons job is to ensure the proper encryption is utilised, change the encryption keys on a regular basis, look for violation of whatever the group's security protocols might be," said Arnold Bell, Head of FBI Innocent Images Unit, on ABC's Lateline.

Ty Miller, CTO of penetration testing firm Pure Hacking, said that the systems described by the FBI mirror "high security" organisations.

"That sounds like a typical thing that an organisation should do if they are a high security organisation, for example, a bank. They will rotate keys on a regular basis just in case someone cracks a key," Miller told ZDNet.com.au.

The gang also used legitimate Web sites to create backdoors for the group to communicate and trade -- a technique commonly used by groups distributing malware.

"Often when you find a compromised Web site, you will find things like spam servers and porn servers have been set up. They end up hosting IRC servers and peer-to-peer file sharing," said Miller.

"If they're using compromised systems to distribute content, there's no difference between the way they operate and your more generic hackers who are trying to cause mischief," he added.

While sophisticated encryption technologies protected the organisation, the level of encryption used by the group exposed it to prosecution under US law and was high enough to prompt charges of obstructing justice, according to Lateline.

The Bureau of Industry and Security, under the US Department of Commerce, regulates the export of encryption technologies in the US. Other controls on the export of encryption technologies are governed under the Wassenaar Agreement, to which Australia, along with 40 other countries, are signatories.

Queensland Police would not disclose the level of encryption being used by the group because it would compromise ongoing investigations, a spokesperson told ZDNet.com.au.

Advertisement

Talkback 2 comments

  1. IT security staff keep paedophile business afloat Anonymous -- 07/03/08

    OK, so the guy knew something about IT security, but to describe the person as IT security staff is misleading as it implicates all IT security staff. If you are after attention grabbing headlines fine, but it probably would have been better to call him an IT Security Expert or something similar. Try for accuracy Zdnet.

  2. No different are you mad Anonymous -- 07/03/08

    "If they're using compromised systems to distribute content, there's no difference between the way they operate and your more generic hackers who are trying to cause mischief," he added. (Ty Miller)

    Bloody hell of course it's different it's child porn and there are paying customers if compromised sites are hosting this stuff it's going to be easier to track them and arrest the culprits rather than a typical web site defacer.

Add your opinion


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured