Showing posts with label offshore sportsbook. Show all posts
Showing posts with label offshore sportsbook. Show all posts

Tuesday, April 12, 2011

Half-Time Betting & The importance of line movement

100% Sign Up Sportsbook Bonus
Bet at Wagerweb
WAGERWEB BONUS CODE: AF4517


You spent the last two hours handicapping a football game that is now approaching kick-off. Your efforts tell you that the Green Bay Packers should win the contest by at least three points. At the time you started picking apart this Monday night game, stat by stat and injury by injury, your sportsbooks were offering a tasty -3 +105, BUT the line moved against you while you were checking your almanac. Your bookmaker is now asking you to give up -3.5 points at -110 for a play on the cheese heads. If you don’t have access to a bookie who is still hanging the -3, you are either forced to pass on the event or go for it, risking more than you know you should. Many of us are action junkies and would lay the extra half point, although        betting in this manner will eventually eat away at our bank roll.

Handicapping an event and forming an opinion is only part of the battle. Every profitable gambler and bookmaker knows that line shopping, and more specifically, line movement is the key to a player’s success. Following the path of changing odds offers an enormous advantage over the long haul. A NFL bettor may follow football lines all week in order to gauge the right time to strike as betting lines gradually move in and out of his favor.
We have all pushed on a play where we would have won had we put more effort into getting that half point.

For most gamblers, sitting in front of online betting screens all day is not a realistic option; although many of us will not hit the magic winning percentage of 53% without at least tracking the quick moving odds right before the game. If you are on the verge of understanding the importance of paying less and obtaining the better line, but do not plan on wagering for a living, the half time bet may be a valuable option for you.


Following Line Movement

Halftime odds offer you the ability to get a fresh line and follow it until it comes off the board. Without going into another article about line movement, watching a normal line through its lifespan is something that can take anywhere from half of the day to a week. A 2nd half bettor watching multiple books is able to get a great feel on which way the line is headed and pounce on the offering that suits his play. He may use the same techniques in a span of only 5 minutes.


Soft Lines 

A soft line is one that deviates from the consensus. Bookmakers only have a short span of time to take in action, and on occasion will stray from the pack in order to take the bets it desires. Other bookies will consistently be the last one to move their numbers which offers value when it has changed against you at most other sportsbooks.
In the course of setting full game odds, bookmakers will frequently peek at what one another are offering. Many will base their odds on what their neighbor is doing and go from there.
During halftime there is little opportunity for them to consult with others. Out of five sportsbooks at least one book’s opinion will likely drastically differ from the rest. This line will adjust quickly as people bet into it, but this initial soft line offers the occasional shot at an extra two points you may not see offered again during the intermission.


The Half-Time Line Advantage 

Hypothetically, let us say you wanted to play the over on a NBA total that was set at 190. You were able to follow the line movement and earn a valuable 3 points towards your bet. From time to time, these big line moves do happen, and they also happen to 2nd half odds. Even though you are wagering on half of the event, that doesn’t necessarily mean you will get half of the line movement. Getting 3 points from that 190 is a great find, but getting 3 points on the 2nd half over/under total of 95 provides an even better advantage. It is a larger percentage of the line you are trying to beat. Think of this advantage as a head start in a race. A 20-foot head start would be much more effective in a sprint than in a marathon.


A Level Playing Field 
I have heard gamblers say that they do not like this quick betting style because it does not offer adequate time to crunch numbers and trends. My response is that bookies have already utilized much of the information you are weighing into your normal capping.
At a game’s intermission, the player may gain the knowledge edge. Linesmen are often forced to offer odds on many mid-game events at the same time. It would be impossible for them to follow every individual game as closely as the one you are watching, and a week’s worth of inside information no longer comes into play. This line is largely based on what happened in the first 24 minutes.


Your Best Bet
The fast pace of halftime wagering is not for everyone. If you don’t enjoy getting numbers dumped on you all at once in order to get more for your buck then you may want to spend the 2nd half on the bench. If you want the ability to follow the life of a line, take advantage of more unique or soft numbers, apply your effort to a smaller contest and know as much as or more than your bookmaker, then the 2nd half may be your best bet!


Half Time Sports Betting 100% Bonus CODE: AF4517 @ Wagerweb.com

Monday, April 11, 2011

Fantastic Five!



100% Sign Up Sportsbook Bonus
Bet at Wagerweb

WAGERWEB BONUS CODE: AF4517



Two decades of Las Vegas experience exposed me to both the dangerous risks and thrilling rewards of sports gambling. I've witnessed plenty of winners and losers on both sides of the counter, while experiencing a few of the highs and lows myself. I'm not only an observer of the sports betting scene, but also an active participant.


During my first year in Las Vegas, I received valuable advice from a good friend, Richard Witt, who now writes for the New York Post. Witt instructed me to "keep my eyes open and my mouth shut."
Witt's words of advice paid off as I forged relationships with some of the most influential members of Nevada's race and sports book industry, including Jimmy Vaccaro (Lucky's), Nick Bogdanovich (Cal-Neva), Bob Scucci (Coast Casinos) and John Avello (Wynn Las Vegas), just to name a few.

Fast forward to late 2011. I'm applying the same Witt strategy, but only in a different venue. I arrived in Costa Rica maybe 10 years ago, and saw the full birth a the so called know, offshore sports betting mecca. Beautiful Costa Rica is home to literally hundreds of gaming companies. They operate outside the United States because gambling laws in the U.S. are nearly impossible to negotiate. The U.S. loss is Costa Rica's again.

In no particular order: 

MICKEY RICHARDSON (BookMaker.com).....The 40-year-old Richardson is widely considered the most respected man in the industry. The Pittsburgh native looks like a barroom bouncer, but talks like a family man, and for good reason. He's married with children, plus he's the leader of nearly 500 BookMaker.com employees.
When asked about his title and job description, Richardson responds, "We're not big on titles around here. If you want, call me General Manager or CEO, but I'll do anything it takes to get the job done."
Richardson's office sits on the top floor of an impressive seven-floor office building in the higher elevations of the valley's mountain region. BookMaker.com owns the entire complex unlike most Costa Rican gaming operations that lease their space.
While the U.S. media is quick to point out the evils of gambling, Richardson prefers to highlight the positive impact of offshore sports gambling by citing the number of college-aged, Costa Rican employees who are bettering their lives through capitalism.

WILLY LOMAN .....Here's a streetwise bookmaker who enjoys the "pura vida" in Costa Rica. Loman has a story for every occasion and all the stories are true, including his time as a soap opera actor in New York where he once appeared as a "dead man moaning" in an episode of One Life To Live.
When Loman was asked about the future of sports betting in Costa Rica, he said, "We're not going anywhere. People love to bet. Everyone loves to bet...from the doctors and lawyers to the policemen and politicians. Hell, I even booked a couple of priests back in New York."

BOB EVANS (Hollywoodsportsbook.com).....If marketing is part research and part intuition, then Evans has mastered the discipline. His slick-looking website (www.hollywoodsportsbook.com) receives high marks for layout and design.
A native of Rhode Island, Evans spent time in Las Vegas, owning and operating a successful marketing company before heading to Costa Rica for bigger challenges and greater rewards. "Expect big things from our new and improved product," said a confident Evans.

RICHARD JONES (BetPhoenix.com).....Jones is wise beyond his years. As General Manager of the rapidly-growing BetPhoenix.com operation, Jones combines the skills to market to gamblers with the ability to manage operations.
Jones credits his adherence to building "processes and procedures" as one of the keys to his success.
"I love to build things," said Jones. "I'm constantly looking for business opportunities to push the boundaries of the sports betting industry."
The most impressive feature of the BetPhoenix.com brand: a business where it's not unusual for top management to step in and take calls to lead by example.

JACK LYSAGHT (BookMaker.com).....Modest to a fault, Lysaght is the head linesman at an establishment whose slogan proudly proclaims Bookmaker.com as the place "where the line originates." Lysaght's opening prices at BookMaker.com are respected worldwide, stealing from Las Vegas its ownership of America's first line.
Lysaght came to Costa Rica from Las Vegas in the early 1990s after serving as sports book director at both the Riviera Hotel and Casino and the ill-fated Sport of Kings. Popular among bettors, Lysaght never received the credit he deserved in Las Vegas.

Sports Betting 100% Bonus CODE: AF4517 @ Wagerweb.com

Tuesday, May 12, 2009

Finding Value With NFL Futures

                                    100% Sign Up Sportsbook Bonus
            Bet at Wagerweb
                   WAGERWEB BONUS CODE: AF4517

Finding Value With NFL FuturesOne of the biggest misconceptions about professional gamblers is that they are all top-notch handicappers. They aren't. But they do one thing far better than the average bettor. They know how to shop for lines.
Getting the best available betting lines can often make the difference between a winning season and a losing one. Those who bet for a living are quick to acknowledge that fact. If you want to see the value in shopping for lines, look no farther than the NFL futures market for odds to win the 2009 Super Bowl.

A number of smart bettors will typically avoid placing futures bets, as the house typically has an estimated 30- to 50-percent advantage over bettors. But for those willing to shop for the best odds, those percentages can be drastically reduced.
What we'll do here is look at the odds to win the 2009 Super Bowl from four well-known sportsbooks - Bodog, Intertops, Olympic, and Wagerweb. We'll compare the odds for each team and point out which sportsbook the player should wager at.
NOTE: Odds can change at any time depending on bets received by the sportsbook. You usually get the best odds by acting early, as most sportsbooks will lower the odds on one team, without raising the odds on others to make up the difference.
Odds to Win the 2009 Super Bowl

Arizona Cardinals 30.5-1 to 50-1
Three of our four sportsbooks have the Cardinals at 50-1 to win the Super Bowl, while Olympic has Arizona at just 30-.5-1 to bring home the big trophy, so obviously, Arizona should be bet at Intertops, Wagerweb, or Bodog.

Atlanta Falcons 100-1 to 165.5-1
None of the four sportsbooks gives the Falcons much of a chance to win the Super Bowl and its hard to blame them, as Atlanta figures to be a few years away from even competing for the playoffs. The worst odds on the Falcons are the 100-1 offered at Olympic, while bettors who place a bet at Wagerweb will get the best odds, 165.5-1.

Baltimore Ravens 50-1 to 75-1
The Baltimore Ravens are another team that shows a good-sized difference in odds depending on which sportsbook a wager is placed through. Wagerweb offers the best odds on Baltimore at 75-1.

Buffalo Bills 48.5-1 to 80-1
The best place to bet the Buffalo Bills is Intertops, where bettors can get a lofty 80-1, while Wagerweb and Olympic are both offering the Bills at 50-1 or less. There is no reason to wager on Buffalo at either of those two books.

Carolina Panthers 40-1 to 52.5-1
Bodog and Olympic are both listing the Panthers at 40-1, while Intertops lists Carolina at 50-1 and Wagerweb is offering 52.5-1 odds. The spread range isn't nearly as great for Carolina as it is for a number of other teams.

Chicago Bears 35-1 to 40-1
There is a general consensus among all for of the sportsbooks here, as the odds difference is minimal for Chicago. The Bears' biggest challenge could be making the playoffs, as Green Bay and Minnesota also figure to be in the hunt for the division title and Wildcard spots.

Cincinnati Bengals 40-1 to 60-1
Those who like the Bengals should look to Wagerweb where they can find a hefty 60-1 on Carson Palmer and the boys. The Bengals are one of the most inconsistent teams in the league, but if they put things together, who knows?

Cleveland Browns 25-1 to 33-1
The Browns are getting a bit of respect among all of the different sportsbooks listed. The price range is fairly narrow, with Intertops having the best odds at 33-1.

Dallas Cowboys 6-1 to 8-1
The Cowboys are the favorites to make it to the Super Bowl from the NFC, but are only about the fourth choice to win the Super Bowl, as San Diego and the Colts have comparable odds. Intertops is where you'll find 8-1 odds.

Denver Broncos 40-1 to 50-1
The Broncos have fallen on some hard times and are now considered a sizable longshot to do anything in the postseason, if they get there at all. Wagerweb has the team at 50-1.

Detroit Lions 52.5-1 to 80-1
The Lions are one of the biggest longshots on the board, as the team appears to be in transition once again. Detroit is 80-1 at both Intertops and Wagerweb.

Green Bay 20-1 to 35.1
he Packers are still expected to do well without Brett Favre, as Aaron Rodgers is ready to take the helm. He has done well in spot duty and has patiently waited for his chance. Wagerweb is where Cheeseheads should look to wager with odds of 35.5-1.

Houston Texans 60-1 to 80-1
The Houston Texans are another team still looking for an identity, thus the lofty odds, which are pretty well deserved. Wagerweb is the place to bet the Texans at 80-1.

Indianapolis Colts 7-1 to 7.85-1
There's minimal difference in the odds on the Colts, as all four sportsbooks have the team between 7-1 and 7.85-1. The Colts, along with the Chargers, are expected to be the toughest test for New England. Wagerweb is where you can find 7.85-1 on Manning and crew.

Jacksonville Jaguars 10.15-1 to 14-1
The Jaguars are getting a good amount of respect from the sportsbooks. There is a bit of a price range on the team, with Intertops offering the best odds at 14-1.

Kansas City Chiefs 90-1 to 145.5-1
The Chiefs are another team that has fallen on hard times as of late. The once potent offense has dropped quite a bit, while the defense has gotten better, but not nearly enough. Wagerweb is where you'll find 145.5-1 odds.

Miami Dolphins 90-1 to 145.5-1
The Dolphins were clearly the worst team in the NFL last season, so it isn't surprising to see them listed here. Only the Falcons are listed as a longer shot than Miami. Wagerweb is the book offering the 145.5-1 odds.

Minnesota Vikings 18-1 to 25-1
The Minnesota Vikings are getting a bit of respect from the sportsbooks and have the potential to be a very dangerous team if Tarvaris Jackson continues to show the improvement expected of him. Intertops is where you'll find the 25-1 odds.

New England Patriots 3-1 to 3.55-1
The Patriots are once again favored to win the Super Bowl, as well they should be. The price range is pretty slim for the Pats, with Olympic narrowly offering the best odds at 3.55-1, with Sportsbook right behind at 3.5-1.

New Orleans Saints 16.5-1 to 25-1
The Saints are another of the teams in the NFC that have potential to pull a few surprises. If the defense steps up a notch, the Saints have a good enough offense to make a playoff run. Wagerweb is where you'll find the 25-1 odds.

New York Giants 14-1 to 22.5-1
The Giants aren't given a great chance of repeating as Super Bowl champions, but they are certainly one of the favorites in the NFC. It's difficult to repeat and things certainly fell the right way for New York last year. Wagerweb is where you'll find the 22.5-1 odds.

New York Jets 35-1 to 105.5-1
The New York Jets hold the distinction of having the largest difference in odds of any team, being a paltry 35-1 at one sportsbook and a lofty 105.5-1 at Wagerweb.

Oakland Raiders 50-1 to 100-1
The Raiders are another team with a large gap in odds. Those wishing to back the Raiders should look to Wagerweb and the 100-1 odds being offered.

Philadelphia Eagles 20-1 to 25-1
The Eagles are another one of the NFC teams that have the potential for a deep playoff run, but it's a matter of how things fall into place for them. Wagerweb is where you'll find the 25-1 odds.

Pittsburgh Steelers 14-1 to 25-1
There is a bit of a price range on the Steelers, who are just a few years removed from winning the Super Bowl. Pittsburgh is one of those teams who can beat anybody on a given day. Bodog and Wagerweb each have Pittsburgh at 25-1.

San Diego Chargers 7-1 to 8-1
The Chargers are seen as one of the three main contenders from the AFC, with New Egland and the Colts the other two. San Diego does have the luxury of playing in a relatively week division, which should guarantee a solid playoff seed. Bodog is where you'll find 8-1.

San Francisco 49ers 52.5-1 to 80-1
The 49ers made some improvements last season, but still have plenty of question marks heading into the new season. Wagerweb and Intertops both have San Francisco at 80-1.

Seattle 25-1 to 35.5-1
The Seahawks are another team that has the advantage of playing a relatively week division, which should be enough to get them into the playoffs. That's the first step towards the Super Bowl, which is one reason the odds are somewhat low for Seattle. Olympic is the place to get the 35.5-1.

St. Louis Rams 60.5-1 to 80-1
Defense has never been a strong suit for the Rams, even when St. Louis was a Super Bowl contender, but this unit was just horrendous last year. The Rams have some offensive talent, but giving up 438 points isn't going to get the job done. Wagerweb has the Rams at 80-1.

Tampa Bay Buccaneers 35-1 to 52.5-1Tampa Bay quietly allowed fewer points than any other team in the NFC last season and figure to be strong defensively once again. Wagerweb is where you'll find the 52.5-1 odds.

Tennessee Titans 35-1 to 42.5-1The Titans will need Vince Young to play up to his potential to be considered a serious Super Bowl threat. While Young improved in some areas last year, his interceptions were up and his touchdowns were down. That's never a good thing for your quarterback. Wagerweb has the 42.5-1 odds.

Washington Redskins 35-1 to 52.5-1Washington was a bit of a disappointment last year, despite making the playoffs, as the team has the talent to do better. It will be interesting to see how Washington responds to new head coach Jim Zorn. Wagerweb is where you'll find the 52.5-1 odds.

Remember, these are the odds at just the four listed sportsbooks. If you can mange the time, don't be afraid to shop for lines at other places. As the old sports gambling adage goes, "What you save is what you earn."


NFL Odds 100% Bonus CODE: AF4517 @ Wagerweb.com

Sunday, May 10, 2009

How a Bookmaker and a Whiz Kid Took On a DDOS-based Online Extortion Attack PART II

100% Sign Up Sportsbook Bonus
Bet at Wagerweb
WAGERWEB BONUS CODE: AF4517


Hackers create zombies by scanning for exposed systems that they can manipulate remotely. Often these are home and office broadband users. (Lately, existing bot networks have been found scanning for more computers to turn into bots when they're not launching attacks of their own—akin to an army recruiting its soldiers in peacetime. One security consultant said he connected an unsecured computer to the Internet to see what would happen, and it was recruited within three minutes.) Hackers can also insert their attack code through phishing, spyware, viruses and social engineering. Universities have long been popular spots for creating zombies because of the number of easily accessible, unsecured public computers. With a zombie network in place, the only issue left is scale. The more zombies on a network, and the more aggregate upstream bandwidth they have, the swifter and more severe havoc they can wreak. Several hundred computers could generate 100MB of traffic, enough to knock a small network offline. A 10,000-computer bot network could deliver a 1Gb attack, enough to knock anyone offline who hasn't installed some rudimentary anti-DDoS infrastructure. Some experts believe that right now different sets of hackers are engaged in an arms race to see who can build the biggest zombie network. Not for bragging rights, but for renting out the networks to anyone who wants to launch an attack, the raw capitalist idea being that the biggest network will generate the best rental business. Tuesday, Nov. 25, 2003: Running Out of Time The extortionists' e-mail that arrived on this morning demonstrated that they were losing whatever patience they had: [all typos sic] "I told you that if you try and f*** with us that your site will be down forever.... The excuse that you were in the hospital does not matter to me. So here are your choices: 1) You have until 4pm est today to send us our $40K. 2) You have until 4pm est Wednesday to send us $50K if you can not send the $40K today. 3) You do not pay and your site will be down for 4 days starting Thursday and it will cost you $75K to come back up Monday. 4) You do nothing and do not respond to this email within an hour and we will make sure you are down forever...." Richardson was panicked. He can't remember precisely when—the entire week has blurred in his memory—but by this time, he had reported the crime to the National Hi-Tech Crime Unit (NHTCU) in Scotland Yard. According to an NHTCU spokeswoman, the unit had already opened a similar investigation with a British gaming site called CanBet.
According to Richardson and Lyon, the NHTCU encouraged Richardson to wire two extortion payments of a few thousand dollars each to separate Western Union offices in Eastern Europe. The NHTCU wanted to nab anyone who showed up to take the cash. (NHTCU won't confirm this; the spokeswoman said the unit does not discuss investigative tactics.) Richardson agreed, but for a different reason: He wanted his site back up. "I knew another person [in the industry] who was successful getting back online by sending three or four small payments like this," Richardson says, "and those guys didn't even have a solution to the problem when they paid. I knew Barrett was getting closer and closer to a solution. So I sent the payments, thinking maybe I can get a good week out of this." But no one took the bait. After about two weeks, Richardson pulled the money back. Wednesday, Nov. 26, 2003: Barrett's Big Bet From Sacramento, Lyon instructed the PureGig engineers who would turn on his system 630 miles southeast, in Phoenix. Another 2,400 miles southeast from Phoenix, everyone at BetCris waited impatiently. Lyon's system intercepted traffic headed for BetCris's servers in Costa Rica, diverted it to his creation in Phoenix, scrubbed off the attack traffic and delivered legitimate traffic back to Costa Rica. It was designed to bar DDoS traffic from touching BetCris. If the system failed, it couldn't defend BetCris, and it wouldn't be able to send legitimate traffic to Costa Rica. But BetCris itself wasn't getting attacked. The system did a lot of other stuff too: monitoring, capacity planning, logging and analysis. It wasn't perfect. After it was installed, Lyon had to tweak routers on the network, install new versions of software and add capacity to his system. The extortionists kept changing attack vectors, and Lyon and his team kept tweaking. It was a constant battle, but Lyon was confident that the system would enable BetCris.com to stay online. Wilson at PureGig called Lyon's system "ingenious" not because it was unique—it was monitoring and filtering at a proxy location—but because Lyon's monitoring and filtering seemed to stop attacks better than any other effort he'd seen. But when it was first turned on, the extortionists stuffed too much traffic down its throat. Wilson recalls the math: "We had 100MB links to the DNS servers. We went from handling under 2MB per link to, all of a sudden, 600MB." That's six times a full load. Imagine Fenway Park, which holds about 35,000 people. Now imagine 200,000 people trying to get inside Fenway Park at one time. The DNS servers were overloaded, and Phoenix got tense. Costa Rica had been tense for nearly a week (as much as half a million dollars in lost revenue), but now BetCris was bordering on despair. Mickey Richardson lacked sleep, and he struggled to make decisions and lead. His IT staff was fracturing, feeling impotent as they watched the attacks and waited for Lyon. BetCris's small call center staff was getting abused around the clock by customers calling in to vent frustration and demand to know what the heck was going on. The simple task of creating a smart message about what was happening eluded Richardson. "You can't just have your call center staff tell people you were hacked," Richardson says, because it creates more questions than answers. At the same time, his decision not to pay the extortionists was affecting other wagering sites that shared the same ISP and were experiencing network problems. "I'm getting calls from friendly competitors saying, 'Look, Mickey, we paid. Just pay. We're going down because of you.'" He was running out of time and energy. Richardson remembers around this time having to update his staff—275 or so people who weren't entirely sure they'd have a job soon—and he couldn't even find words. He thought, "I wish they could read my mind because I'm too exhausted to explain it anymore. I don't have any answers." In hindsight, Richardson says, he would have spent more time preparing for these human issues attached to the crisis—decision making under pressure, keeping the staff together—and less time worrying about technical defenses. Yes, create those technical defenses and make sure you have a crisis response plan. But also focus more on issues like exhaustion and emotional distress, and how they can be handled. It was in this context that Richardson received an e-mail, at 11:12 a.m. It caused him to feel, for the first time, "blind fear." "I would like to thank you for not keeping your end of the deal and making this upcoming weekend an enjoyable one for me." The extortionists demanded $75,000, but then seemed to disregard the money. "I do not care how long I have to destroy your business and I will. You will learn the hard way that you do not make a deal and then f*** around with us.... Let the games begin." Richardson would soon learn they were not bluffing. They could destroy his business, and they were going to try. For BetCris to survive, Lyon's slapdash system in Phoenix, which was just starting to find its purchase, would have to stand up to the biggest DDoS attack any of them had ever seen.


The DNS servers that had overloaded in Phoenix were brought back online in a couple of hours, after Lyon and Wilson adapted some filtering scripts and increased the size of their network pipes. Lyon then spent Thanksgiving and Friday eating leftover turkey his girlfriend delivered and tweaking his system to absorb bigger DDoS attacks. On Friday, he believed it could handle a 1Gb attack, and he felt good about that. He assured a frayed Richardson that he'd never see an attack that big. It would take tens of thousands of zombie computers. Which is exactly what happened. It turns out the extortionists had more than 20,000 zombies. PureGig's data center suffered badly, which affected several of its ISP customers. PureGig decided to take Lyon's system offline to fix it. "The attack went to 1.5Gb, with bursts up to 3Gb. It wasn't targeted at one thing. It was going to routers, DNS servers, mail servers, websites. It was like a battlefield, where there's an explosion over here, then over there, then it's quiet, then another explosion somewhere else," says Lyon. "They threw everything they had at us. I was just in shock." Richardson recalls the attack: "So I have Barrett on the line, who I think is the second coming, and he says, 'Let me think about this. Give me some time.' And I say, 'OK, I don't want to pressure you. I have faith. But if you don't fix it, I'm out of business.'" Why Online Extortion Works It was never supposed to have gotten to this point; Richardson was supposed to have paid long ago. The extortionists expertly optimized the chances of it. To ensure a quick, quiet transaction, the extortionists did what all extortionists (in the physical or online world) do: They exploited the problem of the commons. An ecological principle, the problem of the commons states that people will act in self-interest if it profits them in the short term, even if that act will hurt everyone, including themselves, in the long term. Every act, every threat, every negotiation tactic, every single move extortionists make is designed to make paying the protection fee not only appealing, but in fact, the smartest business decision you can make in the short term, even if you know in the long run that you haven't stopped the problem at all. Thus, extortionists attack when it hurts the target the most; they ask for $10,000 to $100,000 (generally considered the sweet spot of extortionist profitability versus victim willingness to pay, depending on the size of the victim company).


In BetCris's case, the extortionists revealed they were Eastern European, which would make them hard to find, never mind prosecute. Online crime laws are weaker in Eastern Europe than in the United States and the desire to enforce them weaker still (and the FBI wouldn't get involved with offshore gaming sites being extorted from overseas). The online version of extortion provides unique advantages (relative anonymity, low probability of prosecution, lots of easy targets, diminished chance of physical violence) that have made it a highly lucrative business alternative for bad guys. BetCris was just another easy target. What the extortionists didn't count on was the unlikely confluence of Richardson's resolve, Lyon's ingenuity and an ISP that would provide them a place to fight back. Friday, Dec. 12, 2003: BetCris Wins the War of Attrition The extortionists must have screamed "Hooy na ny!" or some other Russian expletive after their blitzkrieg, when Lyon "got the chemistry down" and managed to absorb the massive amounts of attack traffic and get PureGig and BetCris back up and running. Lyon assumed the bad guys would come back with something bigger, as hard as that was to imagine, so he set out to scale up his system "for whatever was next, a 6Gb attack or something." But for the next week, the attack stayed steady at around 1Gb. BetCris, Lyon and PureGig had entered a war of attrition. The extortionists would find a way to kick Lyon's system, Lyon and Lebumfacil would tweak it and get back up. Cat and mouse. "Attack, counterattack, back and forth," Lebumfacil says. "It was 24-by-7 monitoring for two weeks." Wilson and PureGig stopped noticing any of this because the attacks had been segregated from PureGig's other traffic. And then, suddenly, the attacks stopped. At 8:46 a.m. on Friday, Dec. 12, two weeks after the assault that nearly put him out of business and three weeks after he first read the words "Your site is under attack," Richardson received an e-mail: "Dear Mickey, I tried getting to your site today and I could not. I thought with all the money you spent you would not have these problems anymore. I guess you wasted your money instead of keeping your word. Good luck. P.S. I bet you feel real stupid that you did not keep your word. I figure by now you have lost 5 times what we asked and by the end of the year your decision will cost you more than 20 times what we asked."
Richardson knew this was an admission of defeat, even if it was disguised as braggadocio. His site was up. The extortionists couldn't get to it because they were blocked. He hadn't paid them a dime. They made no more threats. They couldn't because they couldn't back them up with action. The extortionists had lost. And yet, the e-mail was not far off. Richardson figures it cost him a million dollars in lost revenue and IT investments to win this war. "It was worth it," he says. "I just didn't know it would take a couple years off my life." "It was amazing we made that system work against that attack," Lyon says. "It was a wake-up call on how good the bad guys had gotten." And Lyon knows the bad guys have gotten even better since. They've built zombie networks of 35,000 machines, capable of delivering a steady stream of 3Gb traffic. Peter Rendell, CEO of Top Layer Networks, which makes intrusion prevention and anti-DDoS hardware, says he expects botnets to pass 50,000 machines (and 4Gb to 5Gb) by the end of this year. It's an arms race, as defenses scale, then offenses scale, though Lyon is convinced the defenses have far outpaced what extortionists can throw at them. But the bad guys have a response. Extortionists have encrypted DoS attack scripts and have put them on peer-to-peer networks, making criminals who use them nearly impossible to track or contain. They're registering domains and then attacking those domains, only those domains are redirected to other targets. "The only way to stop that is to delete the domain," Lyon says, "and that's not something you can just do." Lyon stopped an attack but certainly didn't stop the problem. Still, he wouldn't learn of all this until later, after he decided to start a business and, as he did with Don Best, track down the BetCris extortionists. At that moment, though, after the extortionists admitted defeat, he was ready to relax. He booked a vacation in San Jose, Costa Rica, for New Year's. Finally, he'd meet the people he saved and celebrate with them. New Year's, 2004: Visit to an Online Gaming Hotbed Costa Rica is about the size of West Virginia, bookended by Nicaragua to the northwest and Panama to the southeast on the Central American isthmus. With coastlines on both the Pacific Ocean and Caribbean Sea, and mountainous terrain inland, Costa Rica sits along the Ring of Fire, so volcanoes and earthquakes are native. Political strife is not. The CIA calls Costa Rica a "Central American success story."
Lured by its stability, BetCris located there in 1993. Richardson joined as a "utility man" in 1996. Back then, the business wasn't online, it was a call center. BetCris's call center once employed more than 500 operators at peak hours, but the number dwindled as the business moved online. Today, maybe 30 operators will man a call center at peak hours, or during an extortion crisis. As the Internet took off, so did San Jose as an offshore gaming mecca, for several reasons. The government encouraged the industry to expand its economy. (BetCris supports an industry group to lobby local politicians.) Also, the people are educated, with an excellent work ethic, Richardson says. Costa Rica has a 96 percent literacy rate. More high-level employees at gaming companies are Costa Ricans, including all of BetCris's accounting staff and 90 percent of its managers. The other reason gaming companies swarmed here is, of course, because it's not the United States, where gambling laws are difficult to negotiate. Today, hundreds of offshore gaming companies, most of them online ventures, operate from San Jose. In BetCris's seven-story headquarters alone, Richardson says, there are 10 such enterprises, two software companies and a telecom company—pretty much offering everything you need to get started in the online gambling business in one building. The competition is mostly friendly. Richardson says it's not unusual to bump into competitors at a restaurant and join them for dinner. The valley that makes up the San Jose metropolitan area holds almost half the country's 4 million people. Richardson says the valley gets blistering hot, and downtown San Jose is "undesirable." But BetCris, and most of the gaming and tourism industries, are above all that, nestled in the higher elevations of the valley's surrounding mountains, where Richardson compares the weather—and the lifestyle—favorably to San Diego. When Lyon arrived here, he felt a sense of pride for helping. He saw "this beautiful building with this top-notch data center," he recalls. "And I met all the people who work there, and I kept thinking, I protected all of this. Me and my keyboard helped all these people keep their jobs. It was so neat to see how good a thing it was that we did." Richardson and Lyon bonded immediately. There was a party with professional-grade fireworks launched from Richardson's front lawn. They went to dinner, talked about life and the attacks. Lyon had developed antipathy to the extortionists; he wanted to nail them. He told Richardson and Lebumfacil he was going to start a business, a service whereby people could subscribe to his anti-DDoS attack infrastructure. Lyon recruited Lebumfacil to help him start DigiDefense. BetCris was his first customer. Richardson gave them office space to start.




NFL Betting 100% Bonus CODE: AF4517 @ Wagerweb.com

Thursday, April 30, 2009

How a Bookmaker and a Whiz Kid Took On a DDOS-based Online Extortion Attack PART I

100% Sign Up Sportsbook Bonus
Bet at Wagerweb
WAGERWEB BONUS CODE: AF4517

Saturday, Nov. 22, 2003, 7:57 a.m. Origins of an Onslaught
The e-mail that started the online extortion demands began, "Your site is under attack," and it gave Mickey Richardson two choices: "You can send us $40K by Western Union [and] your site will be protected not just this weekend but for the next 12 months," or, "If you choose not to pay...you will be under attack each weekend for the next 20 weeks, or until you close your doors."
Richardson runs BetCris.com, an online wagering site, one of hundreds of sites ensconced in Costa Rica that take bets from Americans (and others around the world) without concern for U.S. bookmaking laws. Richardson received the e-mail just as he and his competitors were preparing for the year's busiest wagering season. With pro and college football, pro and college basketball and other sports in full swing, and with Thanksgiving and Christmas about to create plenty of free time, BetCris and the others stood to rake in millions over the holidays. Richardson was even planning an advertising blitz for the season to drive new traffic to his site.
If BetCris went down, he knew his customers would find another online bookmaker, "which will cost you tens of thousands of dollars in lost wagers and customers," the extortionists reminded him.
Despite all that, the e-mail didn't have the fearsome effect on Richardson that the extortionists hoped it would. He just asked his network administrator, Glenn Lebumfacil, if they should be concerned. "I said—God, in hindsight, what an idiot—I said, 'We should be safe. I think our network is nice and tight,'" recalls Lebumfacil.
As a precaution, Richardson alerted his ISP, but essentially, he says, "We kind of fluffed it off." The veteran bookmaker didn't panic because, in fact, he had dealt with online extortionists before. Two years earlier, hackers crashed BetCris.com with a denial-of-service (DoS) attack, and then demanded by e-mail a $500 protection fee in eGold (an online form of trading bullion). Richardson paid without a second thought. Compared to downtime, $500 was trivial.
That first attack got his attention, though. Richardson consulted another industry veteran who confessed to having a similar problem, and who told Richardson to call a consultant named Barrett Lyon in Sacramento, Calif. Lyon didn't come to BetCris's offices—he had no interest in baby-sitting infrastructure in Costa Rica—but he did recommend some off-the-shelf products that had recently been developed specifically to fight DoS attacks. Lyon thought (actually he hoped) that he'd never hear from them again. Richardson and Lebumfacil were confident they had protected themselves.

When the attack finally came on that Saturday in November, sometime after that first e-mail but before 11:30 a.m., BetCris crashed hard. The off-the-shelf products Lyon had recommended survived less than 10 minutes. BetCris's ISP crashed, and then the ISP for BetCris's ISP crashed. Richardson ran to the IT department, where Lebumfacil was watching the biggest DoS attack he'd ever seen. He remembers feeling sick to his stomach.
At 1:03 p.m., another e-mail arrived. "I guess you have decided to fight instead of making a deal. We thought you were smart.... You have 1 hour to make a deal today or it will cost you $50K to make a deal on Sunday." Then they knocked BetCris.com offline again.
The Extortion Problem
We know this about online extortion: It happens. Evidence of its prevalence or damage is speculative and anecdotal but useful nonetheless in guiding CSOs to understand the nature of the crime. Anecdotally, experts from law enforcement and information security consultants believe that perhaps one in 10 companies has been threatened with online extortion; in one survey by Carnegie Mellon University researchers, 17 out of 100 small and midsize businesses reported being targeted. Interviews with security consultants and industry players suggest that as many as three out of four cases of online extortion are never reported. Maybe a third or more of targeted companies pay extortion fees, drawing the money from disaster funds, acceptable loss budgets or insurance. Consultants like to tell stories of being called for help after companies pay protection money twice.
For CSOs and CISOs, it would be easy to view online extortion as indigenous to gambling sites, the karmic price one pays for choosing that line of work. It would also be wrong. True, the Thanksgiving-week attack on BetCris fronted a wave of extortion against gaming sites, but that wave has since ebbed (in part, we'll see, due to BetCris) while the online extortion phenomenon has not.
In fact, that wave of attacks against gaming sites, starting in late 2003 and going through mid-2004, appears to have been a training ground for extortionists. Now they've moved on, applying what they learned, along with more sophisticated technical tools, to attack far less prepared and more mainstream targets—such as online payment services, foreign currency exchanges and financial services companies. Here is a good rule of thumb: Anyone who could lose money by being offline is a potential online extortion target. And the more one stands to lose, the bigger the bull's-eye.
Yet you probably haven't thought much about online extortion unless you've been targeted. As with fraud, a certain shame attaches itself to victims, especially those who choose to pay protection fees. Even antiextortion consultants participate in a code of silence. One such company contacted for this story declined to comment "because we feel it brings attention to the crime."
That's why we're telling this story—to bring attention to the crime. To enable readers to learn from a real-world case what worked in an extortion crisis and what didn't. To sort out the choices one has before the choices one has are dictated by an e-mail.
Saturday, Nov. 22, 2003: Pleas for Time—and Help
Richardson and Lebumfacil decided to reply to the extortionists' e-mail. They stalled. Lebumfacil, the network administrator, recalls the pleading tone of their missives. (They sent several.) They'd say that they would lose their jobs if they didn't get more time. Richardson reluctantly admits that he feigned a family emergency and begged the extortionists to give him time until he could return from that to set up a payment.
Meanwhile, Lebumfacil and the IT team tried in vain to stop the attacks and get BetCris back online. The equation was simple: Downtime equals lost revenue. Richardson says the company stood to lose $1.16 every second, as much as $100,000 per day.
He tracked down Barrett Lyon, who was in Phoenix helping another company fight off a DoS attack. Lyon told Richardson to call the off-the-shelf equipment vendor. (He did. No help.) Call the ISP. (It couldn't help, either.)
Lyon says he sensed desperation, and he was right. Lebumfacil, who had a 5-month-old daughter at home, says, "I thought about losing my job. I thought about the company going out of business. There was a lot of money on the line. It was a constant state of panic." That night he tried in vain to sleep and says he even entertained the fantasy that "everything could be OK in the morning."
But it wasn't OK in the morning. At 10:01 a.m. on Sunday, Richardson got another e-mail. This one sounded less like a threat and more like the start of negotiations. "Dear Mickey, The attacks have been stopped 2 hours prior to the last e-mail. Your site is back up for most and should be up for all shortly...P.S. We will e-mail you Monday."
Still, Richardson wasn't encouraged. The site wasn't up at all; it only came to life sporadically and for short periods of time. No one knows for sure, but the extortionists might have stopped their attack. At some point, the downtime was the result of BetCris's ISP deciding to null-route the site's traffic. Null-routing means the ISP collects all of the traffic going to a site and drives it into the ground. This frees up the ISP's pipes when a site it hosts is receiving massive amounts of DoS attack traffic; even if the extortionists stopped attacking, the site would stay down.

Confusion and stress reigned. Richardson called Lyon again. This time, Lyon agreed to help. "I was thinking this would be a big mess for me," he says. "But they had no one to turn to. I knew by Sunday I couldn't pass them off any longer." Lyon flew back to Sacramento and started working on the problem. He, too, had dealt with online extortionists before.
Sunday, July 21, 2002: Flashback: The Kid Who Saved Vegas Sports Books
From a low-slung building off of Flamingo Drive in Las Vegas, a company called Don Best delivers the ever-fluctuating odds on sporting events to most of the glitzy sports books on the Strip. All of this is done by computers, and late in the evening on July 21, files started moving around one of those computers by themselves. An employee working late called Don Best's general manager, Rick Allec, and asked him what to do. Allec told him to turn off the server. The employee couldn't, so he literally pulled the plug out of the wall.
Allec rushed to the office, and soon he was holding the printout of an extortion e-mail demanding $200,000. He replied—and stalled—just as Richardson would a year later.
The next day, a security consultant told Allec to call Barrett Lyon for help. "When Barrett showed up," Allec recalls, "I remember thinking, There's no way he can help us."
Lyon was 23 and looked at least that young. His blond hair offset a tan, handsome face. Allec says Lyon looked like he had given up a day of surfing to swing by and help out.
Lyon had never taken a computer science class. His degree from California State University, Sacramento, was in philosophy, applied law and ethics. And yet he was cocky about computers. Once, he bet some friends he could map the entire Internet in a day. They scoffed. He launched Opte.org and mapped the entire Internet in a day. (Sort of. The open-source project is ongoing.) "People have never worried about my background," Lyon says, "because when they ask questions, I can answer them."
He had to win over Allec quickly, since Allec's customers were irate. A sports book forced to turn away wagers is like a bank turning down deposits. "We were down for three hours at one point, which was absolutely unheard of in our business," says Allec. "But Barrett made me comfortable. He would say, 'They're going to do this next, and we'll fight it this way.' And every time, he was exactly right. It was almost eerie."

At the time, off-the-shelf anti-DoS hardware wasn't readily available. Lyon's solution for Don Best was not to turn back the attack, but to scale Don Best's infrastructure of Web servers, load balancers and other hardware so that it was bigger than the volume of attack traffic coming in. "We basically built a humongous Web farm in, like, four days," Lyon says.
It proved to be enough to fend off the extortionists, who were sloppy. They attacked during the slowest gambling season, when the mark had less impetus to capitulate under pressure. They also asked for so much money that Allec didn't immediately determine that paying would be his smartest option.
Within a week, it was over. Except—and this impressed Allec the most—"a couple of weeks later I get a call from Barrett, and he says, 'I know who attacked your site.'"
Lyon says, "I could have left it alone, but I had gotten attached, and I started investigating. I came up with some interesting techniques to trace back the attacks." He turned over his work to several law enforcement agencies, but he never heard about it again.
It was Allec who recommended Lyon to Richardson after the $500 eGold incident. "During that time when all those sites were getting extorted, you only stopped it one of two ways," Allec says. "You either paid them off, or you called Barrett."
Monday, Nov. 24, 2003: Building the Defense
Lyon's plan for BetCris was to build a system that would absorb huge DoS attacks, and he had an idea how, technically, he might do that. But he had little idea how he would convince a tier-one hosting facility (essentially an ISP's ISP), to host his system—to voluntarily accept massive DoS attacks to see if his little project could thwart them.
Through his Opte.org project, Lyon knew of an ISP called PureGig in Phoenix with a 10Gbps pipe, plenty of bandwidth to host his system without disturbing PureGig's other customers. Lyon called Matt Wilson at PureGig. He begged.
A heated internal debate took place at PureGig. The company was ready to say no, Wilson told Lyon. Lyon begged harder.
Lyon believes what tipped PureGig to support his cause was altruism. "They told me they don't like to back down from challenges," he recalls. But it probably had as much to do with generating business. For, if Lyon and PureGig did figure out how to stop DoS attacks, they would have something that their competitors didn't.

"There was a great deal of skepticism here; it was not a popular idea," recalls Wilson. "My thinking was that normally the ISP's solution for DoS attacks is to shut off the customer," he says. (In other words, null-route them like the ISP did in shutting down BetCris.) Wilson adds, "In our minds, that wasn't a good long-term solution. Revenue issues aside, we thought maybe we could learn how to fix the problem. But still, it was a huge risk."
With PureGig committed, Lyon worked for the next three days without sleep, designing, building, testing, rebuilding and retesting his system. "I used all the methodologies I knew, all the code I knew, plus some new ideas."
Lyon kept in constant contact with PureGig and with Lebumfacil in Costa Rica. Lebumfacil deferred to Lyon. "I was part of it, I stayed up all night with him on the line," Lebumfacil says. "I was never allowed to touch any of the boxes. I would make suggestions, and he'd take some of it and not take some of it.
"Barrett had his idea. There was so much uncertainty. Many times I thought, I hope he knows what he's doing. But Barrett had this calm confidence. You want to freak out, and he just works. He's so focused."
By Wednesday, Lyon had something. A patchwork of original code stitched together with commercial products, he described it as "a highly fortified data center with proxy and security software and some monitoring, and more bandwidth than the bad guys."
Denial of Service, Deconstructed
Denial-of-service attacks are an old and crass way to disrupt a network, and yet still are immensely effective. DoS attacks overload the pipes that connect computers to the Internet with massive amounts of legitimate but useless data. DoS attacks create epic traffic jams. The cars in this analogy would be requests for service that hackers send to the target website. Each time the target site gets a request, it must deny it. But because the hacker sends massive numbers of requests from thousands of computers, the target must use nearly all of its time and resources just to deny these requests for service, effectively blocking access to anyone with a legitimate request.
Before that, though, the hacker must create a network of computers big enough to overwhelm the target. They don't buy these computers, they commandeer them. They plant software scripts on systems distributed throughout the world (hence, distributed denial of service, or DDoS). These compromised computers are called zombies, or bots, because they generate attack traffic automatically, without the owners' knowledge.

Sportsbook 100% Bonus CODE: AF4517 @ Wagerweb.com