#54 MafiaBoy Michael Calce

Michael Calce, aka "Mafiaboy" talks about security in front of an audience at a HP seminar in Sweden in 2019.

Episode: #54 MafiaBoy Michael Calce
Published: 2019-12-01.
Participants: Mattias Jadesköld, Erik Zalitis och Michael Calce
The text was written by and summarized by Erik Zalitis.

While you listen – MafiaBoy Michael Calce

When the curious boy Michael Calce, who later got known as ”Mafiaboy” on the Internet, got his first computer as a six year old, he probably didn’t know that in a few years he would have created the first BotNet taking down some of the most vital web sites at the time. They were Yahoo, CNN, eBay, Amazon and Dell.

– ”They are here”, said his father one day over the phone. Michael´s childhood home in  Quebec, Canada was soon filled with FBI agents.

We talk with MafiaBoy about his early years, his change from black hat to white hat and the global threats of today. He also shares a ”Matrix secret” never told at any other place.

Transcript

Mattias Jadesköld (00:08.033)
So today another international IT-security podcast, an English episode because we have Michael Calce here with us, or probably more known as Mafia Boy, a former computer hacker who’s launched several DDOS attacks in two thousand against internet’s biggest sites at that time. Welcome.

Michael Calce (00:30.562)
Thank you for having me.

Mattias Jadesköld (00:32.334)
So, okay you have hacked CNN, eBay, Yahoo and Amazon, but now you’re a security specialist and author as well.

Michael Calce (00:41.026)
Yes, I since the attacks I devoted my life to raising awareness around this topic and I authored a book that discusses my story and I use sort of that platform to to help companies, individuals and governments.

He learned about hackers and hacking at a very early age

Mattias Jadesköld (00:57.24)
All right. But okay, let’s go back in time a bit. Can you please tell me how everything started?

Michael Calce (01:03.146)
Sure. My journey started out at a really young age. I was six years old when I got my first computer and I was nine years old when I accessed the internet for the first time. And I was quickly exposed to this community of hackers. I found it on my journey when I was looking for pirated software. And as it turns out, hackers ran the distribution of this pirated software.

So I wanted to gain quicker access to it and I decided at this point that I should become a hacker. All right. And I joined on an IRC network of EFnet, which is Internet Relay Chat, and there was tens of thousands of hackers and I devoted my time to becoming the number one hacker.

Mattias Jadesköld (01:47.446)
Yeah. But how how how was your first experience when you received your computer? You you I I read that you received it at your father’s house and when you opened it up and how it was like a new world for you or something.

Michael Calce (01:59.458)
What an amazing feeling. Honestly, I remember like it was like yesterday. I my dad put the box in front of me and he said, Here you figure it out. And I couldn’t wait. I plugged it in, powered it on. I heard all the beeping noises and churning sounds and after it booted in the system just sat there and it was waiting for me to input a command. And that’s when I realized at that very moment I am the master of this device.

How he came into the dark side of the Internet

Mattias Jadesköld (02:26.198)
All right. But h how come you came into the the dark side, so to speak?

Michael Calce (02:31.87)
Yeah, that was not intentional or planned, but at a certain point I wanted to buy video games and pieces of software for my system, and I wasn’t sure if my dad was gonna give me his credit card, especially since a lot of video games and software were expensive. So I needed to find a way to illegally download this stuff, which was known as ”warez” back in the day, which was pirated software. And

I couldn’t I found it but I couldn’t get immediate access to it. I would ask the automated bot to give me the program that I wanted or the game that I wanted, but it would put me in a huge queue order and I was on a 14.400 modem. So I wasn’t gonna get this this game or software that I wanted for a very long time. Then when I realized that hackers were the ones distributing it, that’s when I decided I’m gonna go into the dark side.

A picture of the infamous "AOL diskette".

Mattias Jadesköld (03:25.738)
Alright. Yeah, y I I’ve heard that you you also used social engineering only as like ten years old kid who who described yourself as an administrator of the American online community and can you nine years old.

Michael Calce (03:44.556)
Yeah, I was actually nine.

Big difference there. Of course. So when I was on America online (AOL) for the first time, it was actually given to me as a 30 day free trial period. And again, same issue, wasn’t sure if my dad was going to give me his credit card to stay online and reinstate the AOL internet service. So I needed to find a way to continue online without paying for it. That’s when I had access to a program known as AOHELL.

Which granted me the ability to simply appear as an administrator to other AOL users. Because the administrator are administrators on America Online, their name was in a different color.

Erik Zalitis (04:28.898)
You were also w capable to throw people off AOL I mean.

Michael Calce (04:33.592)
Right, in the same program there was the ability to punt a user which would basically sever their internet connection to AOL. And I think that was my first actual interest in hacking and kind of having that power and capability. So I needed to find a way to stay online and I use this administrative capability to fool other users, convincing them that I was an administrator to give me their login and password.

Mattias Jadesköld (04:48.748)
Right.

Mattias Jadesköld (05:03.36)
Okay. And but you are most f famous for hacking, one of the major sites as that at that time, as I started with. How did you do that?

How mafiaboy became a member of a Russian hacker group at a very young age

Michael Calce (05:16.59)
So in the late nineties when I was a part of a really well known elite Russian hacker group that went by the name of TNT Force, when I joined them I became under fire by denial of service attacks by other hackers that were trying to take out me and other members.

Mattias Jadesköld (05:35.559)
The TNT group, they recruited you, right.

Michael Calce (05:38.648)
Yeah, they recruited me at the age of twelve.

Erik Zalitis (05:41.262)
Did they know that?

Michael Calce (05:43.078)
No, nobody knew anybody’s age online. Right. to be fair, even in the private channel of TNT, like two of the main members were literally from Russia and I didn’t understand half of the things that they were saying ’cause it was broken English and r mixed with Russian and so it was an interesting experience, but I had access to some of the brightest minds in the world in terms of technology.

Mattias Jadesköld (06:10.66)
Yeah, and and about the dis distributed…

Michael Calce (06:13.848)
So when I joined them, I I again I became the focus fire of the other hacker groups and other hackers. And denial of service was really potent style of attack used at this point in time. So I decided I decided to start using D DOS attacks against my competition. Now the problem was when I wanted to launch a large scale attack, nobody nobody was able to do so because we had limited resources.

And and our actual physical computer was, you know, a Pentium one thirty three or something similar. so I needed to find a way and create a concept that would solve this problem. That’s when I decided to hack into thirty thousand plus networks and combine them all into one network and created a massive, the probably the world’s first ever denial of service botnet. So no one had ever seen this.

Mattias Jadesköld (07:08.366)
Okay, so you actually you actually planted the malicious code y by yourself? Alright, okay.

Michael Calce (07:14.261)
Absolutely.

Erik Zalitis (07:15.975)
Did you write the program yourself?

Michael Calce (07:17.942)
Yeah, so I used a variation of several programs. The main one that I used for the majority of my attacks were my own creation and I used a co author which went by the name of Sinkhole, who was a a hacker from another group that wasn’t a rival to us, but and he was a very close friend of mine. And I also sampled some other programs that were being created in the space. There was one known as Stacheldracht, which means ”barbed wire” in German.

yeah. so I’ve sampled with other people’s technology that and software that they were creating, but the program that I created was the most effective.

Mattias Jadesköld (07:59.178)
All right. So h how did you have time for all this to to program? W I mean you w went to school and did some sports and okay.

Michael Calce (08:06.892)
I didn’t sleep very much. Yeah. it was interesting ’cause I still maintained somewhat of a social life. Like I balanced it out. I played soccer, I played basketball and I hacked all night, every night.

Mattias Jadesköld (08:25.218)
Okay. And and what w what sites did you did you hack? Yeah, I mentioned a f some of them.

Bringing down the Internet – but not doing it silently enough – what Mafiaboy learned the hard way

Michael Calce (08:31.276)
Yeah, Yahoo, eBay, CNN, Dell, Amazon.

Mattias Jadesköld (08:36.076)
And and no one was on to you like you you didn’t at the beginning.

Michael Calce (08:40.206)
I was the the you know, I fell victim to my own ego at this point. Right. I was young, I was fifteen years old, you know, and I started boasting to other hackers in the community that I was the one responsible for these attacks and the FBI started to catch up on that.

Erik Zalitis (09:00.042)
by the time wasn’t it so that there were very little protection on sites for DDoS attacks?

Michael Calce (09:07.252)
Absolutely. It was more of a a lot of it came down to certain packet types. There was packet filters in place. And it was also when you look at a giant like Yahoo, the amount of bandwidth that they had available to them in comparison to everyone else was literally scary. So you needed massive amounts of bandwidth. But even to this day there’s you know, I mean there’s obviously Cloudflare, you have solutions and stuff, but

Mattias Jadesköld (09:30.187)
Yeah.

Michael Calce (09:36.654)
The denial of Service will always remain potent.

Mattias Jadesköld (09:39.404)
Yeah. But when you saw the news, as a fifteen year old kid, you saw the news that these sites were hacked and there there was a cyber attack going on, what did you think? Is this me? Did you know that it was you or

Michael Calce (09:54.17)
I knew it was me, trust me. And pretty much crapped my pants at that point. you know, being a fifteen year old kid and sitting on a couch and watching live TV and watching the president of the United States, well sorry, the former president of the United States, Bill Clinton, go live on TV and convene the first ever cybersecurity summit based on what you did, that’s a lot to to digest.

Mattias Jadesköld (10:20.754)
yes. Yeah. It’s more like a it’s big difference between like a normal fifteen year old.

Michael Calce (10:27.638)
Yeah, some of my friends would have fun on Halloween, throwing an egg at a house or a toilet paper in a tree. And you know, I was shutting down major ecommerce sites.

A bad call – the news you don’t want

Mattias Jadesköld (10:37.326)
And I read that you were at a friend’s house watching movie and your father called like 3 a.m. in the morning. Yeah? What happened?

Michael Calce (10:45.166)
You have very good intel.

So when they actually came to place the arrest, I don’t know if it was strategy on their part or they just made a mistake because I know they were monitoring my house.

Mattias Jadesköld (10:57.966)
How how do you need all that?

Michael Calce (10:59.65)
Because so there’s a provider that provides all the internet and well, the majority of the internet in the TV in my area, which was known as Bell. Like based after Alexander Graham Bell who created the telephone. So that’s our basically they have pretty much a monopoly. There’s only one other company that competes with them. Anyways, they were always at the end of my street in plain view, I could see them and they were there every day.

all night and the truth is is like if your internet or your T V went down in that in that time frame, like they they would take like a week to come fix it. And here they were every single day, every night, in front of my house. So I mean it was it was pretty obvious.

Mattias Jadesköld (11:45.206)
Yeah.

Erik Zalitis (11:45.834)
It’s like they say, it’s not paranoia if they’re really out to get you.

Michael Calce (11:49.614)
That’s that’s that’s exactly accurate.

Mattias Jadesköld (11:53.204)
Okay, so b back to that call during night, what did your father tell you?

Michael Calce (11:57.718)
So it was a Friday night, which was strategic, which I’ll get into in a little bit. my father called me, it was approximately three AM and he said, – ”Michael, they’re here for you” and as you know, I asked who’s there, I knew exactly just from the tone of his voice what he meant. And of course the FBI and the RCMP, which is the Royal Canadian Mounted Police, were raiding my house and taking every piece of electronic and they requested that I go to the end of my friend’s street.

And wait to be picked up to be arrested.

Mattias Jadesköld (12:30.09)
Okay, so you gotta ride home at least.

Michael Calce (12:32.682)
I gotta ride home waiting in the dark at three three fifteen, three thirty AM at this point.

Mattias Jadesköld (12:38.978)
Your parents reacted to that? Did didn’t they suspect anything or… No?

Michael Calce (12:43.178)
I had spoken to my father prior and I let him know that I was the one responsible for these attacks, which was not an easy conversation, but I needed to prepare and he was shocked but at the same time was responsive and said we need to seek legal counsel so we went to see a lawyer friend of his and we started to prepare ourselves.

A bad day in court for Michael Calce

Mattias Jadesköld (13:08.266)
Okay. And you went to court?

Michael Calce (13:10.88)
I did. After the arrest took place, which was about four and a half months after the attacks took place in February of 2000.

Mattias Jadesköld (13:20.206)
So were you in custody for four months then?

Michael Calce (13:22.644)
No no, I mean that it took them four and a half months to actually from the time of the attack that took place to actually arresting me, to place the arrest. So after they arrested me so they arrested me on a Friday because they wanted me ’cause you can’t see a judge until Monday. So it was strategic on their end that they wanted me to stay inside lock up and I guess get a taste of

Mattias Jadesköld (13:30.893)
okay.

Mattias Jadesköld (13:43.758)
Yeah.

Michael Calce (13:50.294)
what prison would be like over the weekend.

Mattias Jadesköld (13:53.417)
okay. Did that ev affect you or anything during that weekend? No.

A story just for us, Mafiaboy tells us something special

Michael Calce (13:57.794)
Not work. in fact I’m gonna give you a interesting piece of information here that I don’t talk about too often, but when they arrested me, they took me to their head office in the downtown area of Montreal, and this was literally like right out of the scene of the Matrix. Okay? Okay. I was in a waiting room with just a desk and a chair, and an agent came in the room and took a stack of folders

And slapped it on the desk and he said, This is what we got on you. So you’re either gonna start talking or you’re gonna go to jail for a very long time. And I remember just giving him the finger. But it was literally like right out of the Matrix when they first pick up Neo.

Mattias Jadesköld (14:48.43)
All right. And then you were sentenced to eight months in…

A verdict? A slap on the wrist

Michael Calce (14:54.004)
Yeah, so the trial lasted a year and eight months. And I pleaded guilty to over fifty five accusations and I received a sentence of eight months in a group home facility and a two hundred fifty dollar fine.

Mattias Jadesköld (15:08.142)
Two hundred and fifty. It’s not that much, but because I read that that it was all you did the damage for over one billion dollars. Two billion dollars. Two billion dollars. Okay.

Michael Calce (15:16.59)
But that was the maximum penalty per Canadian law to a juvenile. Huh? So I got lucky in that sense for sure. If I was over 18, those companies would have been able to sue me civilly and then I’d be in debt for the rest of my life.

Mattias Jadesköld (15:20.342)
Okay, so that’s not

Mattias Jadesköld (15:31.339)
yeah. But I guess during that time people didn’t know so much about these type of crimes. Even the FBI or something or

Michael Calce (15:38.41)
Laws were literally written and passed based on the attacks that I launched. Yeah.

Mattias Jadesköld (15:42.584)
Yeah. But somewhere during this sentence you became more of a s some sort of white hat, so to speak.

On the Internet, is crime victimless? How Mafiaboy came back to the light side

Michael Calce (15:50.412)
Yeah, I mean through the process and through the transition, like here’s the thing I’m not actually a bad person. I was never a bad person. A a hacker at this point in time was more of an explorer, exploring uncharted seas. Now it’s very easy to go down the wrong path because also on a computer, you don’t really get a sense of what’s right or wrong. Yeah. I feel like if you do a physical crime

There’s more of an an immediate sense of remorse, whereas online you push a keyboard and you push a button, you don’t really like feel what’s happening. so you don’t get that immediate response, but I wanted to do good with my life and I realized that I wanted to raise awareness and I wanted to educate companies, individuals, governments in every way that I possibly can.

Mattias Jadesköld (16:43.35)
Yeah. Yeah, it it feels more like you started your hacking more of a curiosity or maybe it’s communicate with others in tech technology.

Michael Calce (16:54.71)
I just like puzzles and problem solving and that’s very parallel to what hacking was. Yeah. Understanding assembly code and understanding stack and memory address allocation and kind of putting all these pieces of the puzzle together. Yeah. Was was what I really enjoyed.

Mattias Jadesköld (17:11.694)
Okay, so we take it to present time, what you do right now.

Michael Calce (17:16.396)
So I am the president of Optimal Secure, which is a penetration testing firm. I also have an award winning book, which is ”Mafia Boy, How I Cracked the Internet and Why It’s Still Broken”. Yeah. I

Mattias Jadesköld (17:29.656)
2008 or 2009?

Michael Calce (17:31.906)
The book? Yeah. Yeah. Two thousand eight. my god, is it ever? I mean basic rudimentary like protocols haven’t changed, right? Like TCP/IP, like the stack, like it’s all the same stuff. The fundamentals are still there. We’re just tacking on security as an additional layer now, but it’s like building a house, right? If your foundation is not sound, then it doesn’t matter how pretty the house is on top of it.

Mattias Jadesköld (17:34.378)
Is it still broken internet?

Human being, the biggest risk according to Calce

Mattias Jadesköld (18:01.25)
So when you’re doing this sic security risks assessments and and things like that, w what what are the what are the common things you you find as a vulnerability t in the companies? Human beings.

Michael Calce (18:12.504)
Human beings. Yeah. Yeah. I put human beings right at the top. there’s a severe lack of education in the space. Companies are not doing enough to put their employees through cyber resilience training. And human beings are just gullible. So it’s very easy to manipulate a human to do what you want.

Mattias Jadesköld (18:30.36)
Yeah.

The pentesting role

Mattias Jadesköld (18:35.672)
Can you give us an example of how how you

Michael Calce (18:38.274)
I mean look obviously the traditional, you know, spearheaded fishing vectors have existed for a while, but I go above and beyond that. I like physical type of breaches as well and don’t just rely on remote technology. Meaning I’ll gain physical access to a building by abusing a supposed level of authority over someone, by misrepresenting who I am, whether I’m from a

electrical company or I’m a VP from another region and give me access to this now. And people don’t question authority.

Erik Zalitis (19:14.85)
Yeah. I think it was kinda cool when you told me you had a uniform from a Canadian electrical company.

Michael Calce (19:22.946)
Yes. I mean dress up is part of the environment and you need to act apart and look the part. It’s it’s it’s a combined tactic.

Mattias Jadesköld (19:35.454)
So that’s one part you actually do right now. Dress up when you’re doing vulnerability…

Michael Calce (19:42.954)
Look, obviously I cater to what my clients needs are. Yeah. It really depends on the type of testing that they want because I offer a wide array of services. Yeah. But absolutely in a lot of instances they want me to test the physical access to the building as well.

Mattias Jadesköld (20:01.09)
How how often do you succeed breaching the the companies? One hundred percent. Okay. Yeah. All right. So if we look on a global level, what what are the biggest risks c right now? Because it’s a bit different between fifteen year old kid and and today we have

Michael Calce (20:04.662)
One hundred percent.

Michael Calce (20:17.623)
Yeah.

So the times have changed and we’ve incorporated technology in more and more of our lives. The government uses more and more technology as well. I think the biggest issue right now is probably in my mind, nation state sponsored attacks. And and doing damage to critical infrastructure. So we saw an attack a few years ago that took place against the Ukrainian power grid. So just imagine, you know, your your power is taken out because of a hacker.

Solving the crisis – no clear answer on how to do this

Mattias Jadesköld (20:50.786)
Yeah. And h how how can we prevent this? How can we face this?

Michael Calce (20:56.554)
There isn’t one easy answer. It’s a collective that we need to all come together. Governments, enterprises, people, we need to view security as a holistic approach. Yeah. I think overall people don’t understand the importance of security. I feel like some governments lack in security. And I think that we need to put security at the very top because if you look at

How technology has taken over our lives. It is literally an extension of our fingertips. Babies are born and by the age of three they have a tablet in their hand. Yeah. This is the world that we live in. And the fact that nobody bothers to read up on security or basic measures, I think that’s a big problem.

Mattias Jadesköld (21:43.618)
But do you think we are on the right track, that people are getting more and more aware of the…

Michael Calce (21:49.004)
Not really. I’d like to think so, I’m hopeful that we can get to that place, but based on my experience, I feel like still people might hear about it or they might read about it, but they’re like, ”Eh, I’m not a target. Yeah. Nobody’s focusing on me”. When in reality, like that’s not how things work. Hackers are mass scanning, just having an IP address you’re at risk. Just having a name and an identification, you’re at risk.

Mattias Jadesköld (22:17.1)
And you are a target. Yeah. Even though you don’t even if I see myself I only have a computer, I don’t have any…

Michael Calce (22:18.465)
Everyone is a target.

Michael Calce (22:25.656)
Doesn’t matter the data, you have a name, you have I don’t know what they use here in Sweden, but we have social insurance numbers. I’m sure you have you know a number, a birth number associated to you. I could steal that information, go buy a car in your name, make fake identifications and there’s just a plethora of of how you could manipulate that situation. So many ways.

Can can Zero trust networking help?

Erik Zalitis (22:49.359)
But but do you think do you think that things like s zero trust networks and stuff, is that something that could mitigate the situation and make it better?

Michael Calce (22:59.766)
Look, there’s a lot of hopeful ideas that I’m that I’m looking towards. I think that there’s definitely steps in the right direction that are being made. But I would almost like to see some governments intervene and pass more legislation. For instance, there’s a lot of vendors and creators of technology that release things that are that have known vulnerabilities in them, but they’re still allowed to do so because their their mentality is rushed to market.

And you’re just a consumer, you’re buying the product, right? You want the newest iPhone, you want the newest gadget. Or smart fridge, sure, why not? people are sold on this there’s like a panic and hysteria that people like they freak out if they don’t get the latest gadget. And the reality is a lot of these vendors and creators of these products, they will release these products knowing that there is vulnerabilities in them and they and they they’ll just say, okay.

Mattias Jadesköld (23:33.741)
Or fridge.

Michael Calce (23:58.05)
We’ll release a vendor patch for that later. This mentality needs to stop. Security should be at number one and you shouldn’t be so I would like to see some form of governance that you have to meet a certain criteria or compliance before you’re allowed to release a product.

Mattias Jadesköld (24:15.082)
Like a s smart fridge or something. Yeah. Yeah, you told me about your friend in the in the medical care who who was worried about pacemakers. Can you explain?

Michael Calce (24:17.134)
Smart fridge, smart TV, everything is getting hacked.

Hacking can be lethal

Michael Calce (24:27.266)
Yes.

So, I mean th there’s there’s a lot of concepts around like the medical devices and what ifs and and my friend wanted to put that to the test and was able to to breach over a million pacemakers and for example incorporate ransomware on them, meaning you would need to pay a fee in Bitcoin or your heart stops ticking.

Mattias Jadesköld (24:51.144)
Okay. Well that’s a bit scary.

Michael Calce (24:54.452)
I know. It goes beyond that. They’re they’re making devices in hospitals now where a doctor can remotely administer drugs to you. That device has already been hacked. So now you can purposely make the person overdose on drugs remotely.

Mattias Jadesköld (25:04.653)
Oof.

So what’s the plan right now, Michael?

Mattias Jadesköld (25:11.382)
Okay, before we end I’d like to know a bit b what what’s going on next. You gonna stay here in Sweden until over the weekend and so on? Yeah.

Michael Calce (25:18.112)
I’m here over the weekend. I’m excited. I’ve been loving my stay here so far. It’s a gorgeous city and it reminds me a lot of Canada. The people are very friendly here. seem like some friendly type of Canadian type of mentality. Gorgeous city. I’m I’m looking forward to exploring it and I’m I’m very intrigued because it seems like there’s a lot of tech offerings here as well and I’m I’m curious to to look around. Right.

Mattias Jadesköld (25:44.152)
So anything anything anything new from your company that’s going on or

Michael Calce (25:49.086)
Look, I mean I’ve I’ve assumed the role of chairman for the security advisory board for HP and I think that that’s a critical role and a critical position I have to help shape you know a Fortune 50 company worldwide and and what their goal and their mission is and and help them achieve that. So that’s what I’m working on right now.

Mattias Jadesköld (26:09.046)
Right. Okay. Thank you so much.

Michael Calce (26:11.822)
Thank you very much for having me. I appreciate it.

(The transcript was automatically generated and may contain errors)

An episode of Flashback, tracks from the past based on this interview

https://www.youtube.com/watch?v=Ddqgis-oY78

Länkar – MafiaBoy Michael Calce

Errors and omission

Please report any errors or omissions to us at info@itsakerhetspodden.se.

 


Reader's opinions

Lämna ett svar

Denna webbplats använder Akismet för att minska skräppost. Lär dig om hur din kommentarsdata bearbetas.



[There are no radio stations in the database]