CSI: Petty Internet Baby Fights
We were recently briefed on some fandom drama that involved a coalition being made between several bloggers to form what we like to call a “Net” tactic, however before we dwell into that let’s touch basics first and flesh this out so you’re aware of why you need to block statcounter and sanitize your referrals. Please take the time to read this and realize that this involves an almost sinful amount of ignorance on the target’s/victim’s end and an absurd amount of patience and obsession on the doer’s part. So as many of you already know, Tumblr bloggers love to “stalk” each other with the use of Statcounter. Statcounter’s a simple script to help people by providing the service of real-time web analytics. This means that anyone who isn’t blocking this script or others like it by default will be catalogued and have a slew of meta-data captured. This meta-data is quite useless when not in context with other information on the target/victim, ergo not really useful to anyone unless the target/victim does something to leak even more information that could lead to their blog, an account, a username or a website. Without other information to fill in the blanks, no one has any use for it outside of analytic purposes. This information is gathered by every single site you visit, they’ll see this information always unless they’ve taken steps prevent it or the visitor has taken steps to conceal their browser’s print. Yes, your browser has a print. It shows what makes it unique and several other pieces of information, like your fonts and what add-ons you’ve enabled and similar items. This is why it’s encouraged to have cookies and javascript disabled if you’re not logged into anything and are simply browsing the net or searching an article, but I digress. If you look at the below image, you’ll see what Statcounter sees when you visit any bugged site or blog with its script.
As you can see, this information is quite useless, however if the target/victim didn’t sanitize refs at the very least, you may end up with something like this: https://www.tumblr.com/blog/username or https://www.tumblr.com/blog/activity Those two links are usually what gets someone fingered as being behind an anon ask or viewing someone’s blog. Once you mess that up and the script’s owner labels you, you’re basically identifiable until your IP changes or their logs purge (unless they decided to cough up the cash for a premium account). Having both identified the target/victim and having the browser print, all it takes is some basic info hunting VIA digging through the target’s/victim’s blog and looking for identifiable information, even if it’s just general information like weather, time and so on and so forth. Once an established dossier is made, all it takes is simple guess work to dox someone. That’s the easier way to get doxed with Statcounter, however if we were to discuss the net tactic mentioned above, then you’ll see the lengths people go to for petty internet revenge. So, to start you off, one of the many sub-reddits dedicated to poking fun at the users of Tumblr had a thread up about some obsessed woman who was really, really into Pokémon. We’re talking about levels of passion usually reserved for religious cults or serial killers who’re into pre-teen girls and try to impress them by would-be assassination attempts on political figures. This blogger got so upset about someone leaving a simple anon ask that they rushed to statcounter and discovered that they had a referral link from Reddit. Now the usual behavior for Tumblr users is to shout, scream and mistype words while proclaiming they’re totally having a panic-attack. Nope! Not our little obsessed blogger. This woman went out of her way to get several more bloggers involved to create what we’ll refer to as a “net”. A net is composed of several blogs made for one purpose and that’s to filter out false positives until they can find the target/victim they’re searching for, which is quite a lot of work for the average internet user. Each node (Blog) of the net consisted of either “For” or “Against” tier themes (To guage responses). They were either for or against the fandom in question and/or the blogger who received the anon ask in order to try and seem more random and less like an organized effort. From there, these bloggers took to Reddit and put their own personal blogs (not those from the net) onto the sub-reddit in question in order to gather more hits to see if they can find a similar browser print to that of the anon-ask. Now, take a minute and let this sink in: Without knowing about browser printing, profiling or behavior analysis… these bloggers naturally came to using these things to help single out an individual. They deployed tactics usually used by forensic-nerds to dox a person over words on the internet. Using the little bit of information from the original hit, these users used their own blogs to see if they can gather a similar hit. Once that hit was achieved, they feigned some drama to provoke the target/victim into sending a few more anon-asks. They used these asks to isolate key terms that the individual used besides an overall textual print. Once they had this established, they deployed their net to provoke the target/victim into exposing themselves through a series of canaries. They used false information sent through PMs to give the potential targets/victims a unique blog to visit that was bugged with Statcounter. Once they matched the browser prints up (and thus the intended target/victim), they worked on digging through the target’s/victim’s Reddit account history to learn more details about them until they could create a dossier and use it to sniff out an old, abandoned forum used to shit post among a few friends that stayed on. From that forum they sent out several PMs to the potential target/victim until they once against got a hit on their net. Once they confirmed this was the individual they sought, they dug up old forum posts and traced usernames across the internet to get not only a High school name but also a full name, a previous home address, a Facebook account and a current business address. Using a liberal amount of social engineering, they got the business to give out the target’s/victim’s current address, thus giving them everything they needed to dox the victim/target on Tumblr over a simple ask. Yes, while more time consuming and not officially doxing with Statcounter, this does show how someone with enough patience and obsession could, technically, exploit the analytical service to gain information on someone and devise a plan to gain further information that could potentially in jeopardy. Simple way to beat this is: Sanitize your refs, block 3rd party cookies, block Statcounter (and similar scripts and install and use Hostman. Note: Fandom changed, info left out to prevent the target/victim from getting their doxed leaked again. Also because attention shouldn't be paid to the Type-Bs involved. Further readings: Sanitize your refs | Hostman | Paranoid's Bible | OPSEC | Uncle Daddy's Big Book of Deception | Autism and Selfies | Meta Data and You


















