SAFE IRC-ING Abridged Log From #TownHall Note: This log has been edited for clarity and privacy. None of the relevant information in the presentation has been removed. Session Start: Mon Dec 14 17:54:02 1998 *** DaTeach sets mode: +m Good Evening First, I want to welcome and thank you all for coming to this evenings session on "Safe Irc'ing". For many experieanced users this should be a useful refresher class, and for those newer to chat it will give a new awareness about security and safety! It our intention to present the Do's and Dont's that will help you preserve your personal safety and enjoyment, while online! We are fortunate to have professionals like chief and Lt_Ed here tonight and I am sure that Itsy will feel the need to comment occasionaly. hey We will moderate the channel for the lecture and have an open Q and A period afterwards. Please refrain from nick changes during the lesson and try to keep parts and joins to a minimum. If you at any time have a question, comment or suggestion, type /msg #Question < your question > And now I'll turn it over to chief for the main event! good evening everyone for those of you that do not know I am a Police chief in OHio one of the newest crimes were dealing with is Internet crime tonight Lt_Ed Itsy and I are gonna touch on just some of the problems the internet can cause for you if your not safety concious Several months ago Our department was called to a residence about computer problems when the officers got there we found that a young lady had been corrisponding with someone via IRC because of information this person obtained from IRC about the woman he found out where she was in college at and paid her a very unwanted visit ...thank GOD someone else was near by but her parents were very scared. the girl was attacked at her school by the person she believes she met on IRC She basis her accusations on notes left on her car calls to her dorm and to her parents home. The mistake she made was telling someone she did not really know very well...who she was and gave this NUT way to much personal information. Now I am not by any means trying to scare anyone but this stuff does happen I urge each of you as I do when I meet ppl at work with this problme to be careful how much personal information you give someone many times we give information in our WHOis that for a computer wiz is very telling information many of you put real names and email addresses in quit msg or in your whois, and everyone that sees you finds this information out. Itsy our resident Puter Guy can tell you that its very easy to find out information about someone via email via IRC or via any of the other internet sources... I am gonna pause here and let Itsy describe how this works.. One good example is information you CANT hide lets see do a /whois on Itsy now if you were to look that up http://rs.internic.net/cgi-bin/whois there for instance.. Registrant: Somehost SOME-DOM 9999 Somewhere Court New York NY 999999 US tells you my ISP is in which means i'm probably within 20 miles of there or so see how simple that was? and for the most part, unless deliberately spoofed... you cant really hide it. now on big ISPs like erols,or AOL or others thats not quite as telling.. but the header tells you even uu.net has sections in it like fw.tx.uu.net for Fort Worth Now, thats not very useful mine has the town right in it as well until you tell them you live 'near the school' or 'near the bridge' that your dad's name is Tom now i have enough to start searching email listings by region, isp if you ever give anyone your zip code (9 digits) .. they can generate a mapquest map with directions to your house this is the simplest type of information to gather I tell everyone, PLEASE treat a conversation on IRC like a telephone conversation with a stranger..... im sure you were taught what not to tell people.... and it applies here as well.. if you KNOW them, personally, thats different We have actually used this type of information...to locate someone who has threatened to harm themselves..and it works very well believe me but its very easy to forget you dont really KNOW the people here. you just have nicks and what they've told you. also its VERY important in the whois info you set... do NOT use your login id for your isp, or your mail account, or anything even close to your real name every bit of information lets a stalker or lamer narrow down who you might be or wehere you live Now, thats how easy it is to piece together some bits of information just on IRC ... I'll turn it over to Lt_Ed to go into some of the things an investigator can do with that type of information males have been the target of stalkers too, btw Hi folks. a little background on me. I am a retired Lt. Detective, then Investigator for a Major Company. Now Director of Security at a Hospital. To rehash a little. Personal information in a whois or given in a channel or to someone you really do not know is dangerous. If I have your real name, I can find out where you live, your drivers license information, who and how many people live at your address, who your neighbors are and so on There are several information services that supply this information and they are readily accessable to those who know how to use them. We are all here to have fun, but we can not overemphasize the importance of keeping personal information to yourself. There are programs available to anyone on the internet that can give much of the information I stated above. www.switchboard.com is one of them hundreds of thousands of people use this service monthly. If you are listed in the telephone book, you are on switchboard.com We are hearing more and more stories from Law Enforcement like what happened in Chief's town. And, not just in big cities, this is from even small communities. In small communities, by the way.. a little bit of information goes a LONG way locating someone The bottom line on this is, BE AWARE of what your are saying in IRC. Ft Shawnee where I work only has 4500 ppl Think, just as has been said.... Treat IRC just like a telephone call with a stranger. You can locate yourself or anyone I suggest that when you get a chance go to www.switchboard.com and look yourself or family up. on most any browser service its really very easy Also, anyone with a HAM Radio license or other type of license is easy to locate. Most of the licensing agencies post a list of licensees on the Internet. remember.. If you at any time have a question, comment or suggestion, type /msg #Question < your question > Now, before everybody gets totally paranoid, logs off and burns their modems ..... These usually give full name, address and date of birty. IRC is no more or less safe than a 'walk in the park' ..... Treat strangers AS strangers There is a telephone number search engine in Canada also it is Canada 411 Also, other countries have the same types of search engines. one major suggestion here if you think someone is getting to forward break off contact if they contact you off the internet Giving someone something as simple as your exact date of birth can also lead someone right to your when you couple it with other information that Itsy spoke with you about. and you have not ask them to call the police let them know about this before it becomes more serious if someone is harassing you ON here, talk to one of the ops in #channels or #terranova and parents please er, if theyre just being lame, set /ignore :) watch your kids on the internet it is so so very easy to have a kid doing homework end up in web sites that you would never believe and they don't all have sex names Every time someone complains about advertising on this net we check it out and you would be surprised what kind of sites example -- www.whitehouse.com that are out there hehe that is NOT whitehouse.gov :) thats the one I was gonna suggest all though going there lately is not much better heh I would like to mention though, if folks make threatening or 'scary' remarks... theres no 'magic' on the net there are many sources, but some use that to just scare people if you are concerned, ask someone who knows for example, its virtually impossible to 'intercept' a dcc chat and anyone who COULD do it, is NOT listening in on irc chats.. theyre out breaking into a bank somewhere one very bad thing that ISPs often do is they dont disable the FINGER command on the other hand, it is never a godd idea to auto-get any DCC's either. it is NEVER a good idea to auto get dccs type /finger you can try it on your own isp too.. there are even sites on the net that make it easy to do a finger on a user yeah like if your isp supports finger, call them and ask them to change the information so it doesnt show your true name and address more and more, they are disabling it, or providing 'no ' information but the only fix, if its there, is to get your ISP to remove it Also, within the past couple of years, the U.S Attorney General's Office has added Internet Crime Units to their local branches - mostly in major Metro areas. They can be called, and desire to be called, if Internet threats are received. the state of OHIO just started its Internet Crime Unit this summer so its becoming a need everywhere and don't ever believe you have erased anything from your computer its unbelievable what the can find on a hard drive If you ever feel threatened please seek one of us out Oh .. and another thing... the folks who chase down the bad ones DO want the info we can help in many ways yeah yes and what YOU see may be part of a pattern and at least point you in the right direction to put a stop to the prollem Do a /whois on the person, cut and paste the info. You can always use the Amazing Security method and UnPlug your computer. if you type /msg cstar help but then thats going a bit too far you will get a short list of the things to do in case of any sort of abuse logging and timestamping can be very useful later were gonna open the channel for Q/A pertaining to this session and we thank sinbad for his contributions as well hip hip hoooray *** DaTeach sets mode: -m please feel free to chat with us about tonights topic But is it if you have a registered IRC? I don't have my IRC registered, am I still a victim? Question: what about firewalls? what do they protect and how much? netmeeting has a feature called sharing that lets someone else control your puter and that scares me what? registering doesnt have anything to do with it firewalls protect you from direct attacks oh ok the things we've been talking about are info freely available on the internet and other sources but not prying eyes if you look at your options for netmeeting, Betty, I bet you will find a button for shutting that off this is just a reminder of two important things.... yep treat IRC like a chance encounte with a stranger and ASK somebody if you are concerned wouldn't Mirc's firewall protect you from IRC people trying to get info?...Or are these people going to the persons server itself..? there is no personal information stored on irc servers in the case I had Downboy it was email other than whatever you put in setup in your client btw! I want to thank chief, Ed and Itsy for a great lecture tonight ! thanks Chief, Ed and Itsy ditto and Wullie thank you for doing this :))) double ditto yes thanks so much thank you for a good talk tonight. good night. thanx greatly and, i want to mention something im not sure we hit before.... BE CAREFUL WHO YOU GIVE YOUR EMAIL ADDRESS TO personally i don't know any of you !!!!! Hi Justin! Thanks for the class! Great teachers!!! WOO WOO! lol chee lol itsy stole the snax's again OK thanks for the info ppl Hi KathySmith! good to know we have some police that r good in ohio sorry folk's about the greet.... :o( Thanks, guys...lots of good info! Buck: where? a hotmail e-mail account is not a bad idea, and it is free (so far ) that was a great session DaTeach, Itsy, chiefy and Ed - many thanks! :) hehe look at op sin yep....and ya don't have to put any identifying stuff in to get it wullie to anyone who helped with the presentation tonight, a big round of applause well it was not much of my doing, I only turned the lights on :) pobox is good for email as well.. i have lied on so many accounts i can't remember my own p/w, now thats security !! (((((((((hugs to all for this session))))))))) it costs a bit but well worth it isnt that some kinda disease?> ;o)> i had pobox one time.... pobox is a very good email proxy it ITCHED!!! add in postoffice lol they have good features and a very nice anti spam policy lol that was YOU, Downboy???? I think Bill has a problem with alot of words..... Thanks again ya'll! ;o) I still got a rash from all the cratchin ya did clinton has problems with the word "NO" more than anything again thanks for the session and good night :))))) > lol cratchin On behalf of us all at slirc, I wish everyone a safe and happy holiday season. :) oh and by the way too :) I can see the bottom of the nicknames list :) (and no scroll bar needed) the users we have here really ARE our best collective defense against the dinks of the world Thanks for the info and an interesting presentation; think I'd better change my name! Night all. I know that itsy, Thanks again, nite nite all, God Bless.... :o) ok thanx again nite ttfn Fitzie thanks for the info everyone, good night Thanks everyone, good meeting :)) we will post the class on the docs page asap Babyglowwo k thnk you do u have the addy baby? do i have what? http://www.starlink-irc.org/index.docs.html thhx s wullie thanks wullie :) knew u would put it up for me > thanks Wullie ;) thanks when will that be posted wullie? Holiday Vacation: no more classes until the new year :) :( I'll try to bet it edited tommorrw, Babyglowwo er get cani go there now and get that info i just missed now? oic...thanks i can send the raw log to you now see ya all later > g'night {{chief301, Itsy, Lt_Ed, Wullie, Amazing, Autty, Babyglowwo, chee, Corinne, DebA, Downboy, Frankee, Fuzzy, Guston, Jamela, John, Juju^, lois, Punkin, RuffDog, simmey, sinbad, Sonnybuck, tigger, treecat, Z_Brad_AFK}} thanks chiefy itsy sp_ed etc for the leson - very interetsing and well presented bye all k wullie how do you send it? 'nite all, and thanks again! hang on a sec niters lois :) at e-mail? night all night night bbl thanks for the info..........later..... thank you for all the great info......nighters glad everybody enjoyed the presentation