Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.
Loading in …3
×
1 of 30

Conspiracy angle at inforum.in

1

Share

Download to read offline

I am being followed and bugged by CIA of USA and Intelligence
Bureau of India. This story is just one more dimension of the
story.

Related Books

Free with a 30 day trial from Scribd

See all

Related Audiobooks

Free with a 30 day trial from Scribd

See all

Conspiracy angle at inforum.in

  1. 1. Conspiracy angle and coordination at InForum.in I am being followed and bugged by CIA of USA and Intelligence Bureau of India. This story is just one more dimension of the story. CatchNames aka Anjan Bhushan 292/C, Ashok Nagar, Ranchi, India - 834002 http://twitter.com/hifivc Date – 11th August, 2013 1
  2. 2. Disclaimer • Even if your name has been used in presentation as a tool by government agencies of primarily USA and India, I have nothing against you personally. Aim is to showcase what these agencies are capable of doing. 2
  3. 3. What is inforum.in • Inforum.in is a domain name forum primarily targeted for .in country code top level domain (ccTLD). • If you not know what is a domain name please read it a wikipedia. http://en.wikipedia.org/wiki/Domain_name 3
  4. 4. What is .in domain name drop • This story is around .in ccTLD domain dropping. If you are not aware of domain name drop please find it on internet. • .in ccTLD eligible expired domains are released after 20:00:00 UTC every day. That would be 1.30 AM IST. • There are people around the globe who try to register these available domains when they drop. • Other term you may want to get acqainted with are Domain Name Registry and Registrar. 4
  5. 5. User id and names in inforum.in User ID Name Primary Location Remarks MITSU Sanjeev Goyal Mumbai, India a .in Registrar Jeff Jeffrey Behrendt Ontario, Canada owner of inforum.in NameTrader Ravi Nanda Ontario, Canada Neo Suresh Kumar Hyderabad, India Chandan Chandan MA Bangalore, India Danny Danny Zoetemelk Netherland German domainer - - Catchnames Anjan Bhushan Ranchi, India me Ryanmlanane Ryan Lanane Illnois, USA Started drop catching with Mitsu Vaasu India Neo’s friend Meditang Shajeem Md. Picnic Vidyabhushan 5
  6. 6. Background • On 1 Feb 2012, Mitsu announced that they are starting .in domain drop catch services. • .IN Drop Catch Services (In case, this thread is deleted you may read cached version in PDF format (Page1, Page2) • On 4th April 2012, Mitsu modified his posts and first message in this thread is now “We do provide support to customers who wants to secure their own domain name back......You may contact Mitsu...” • If you read the complete thread, Mitsu did announce catch of domainappraisal.in and given it to Jeff. Next he gave dalhousie.co.in to Jeff as well free of cost. If you see whois of domainappraisal.in, previously it was owned by a different owner. So for sure the service was not about “securing own domain” name back. In same thread, the user “Germain Domainer” and “Nametrader” did raise legality of Mitsu move. “German Domainer” did also raised that when previously another registrar Hexonet had started domain drop catch service of .in TLD, Registry did ask it to be closed. • domainappraisal.in-whois-history dalhousie.co.in-whois-history 6
  7. 7. Background • On 16th March, 2012,ryanmlanane posted a thread “What would you pay for drop catching”. • On 18th March, 2012,ryanmlanane posted a thread “Catchname.in drop catching announcment”. In this thread, he mentioned “please send requests by email to both drops@mitsu.in , ryanmlanane@gmail.com”. So, then Mitsu was no more announcing this service after objection by Nametrader and German Domainer. Ryan become the front name in this service. In case, this thread would be removed, cached content in PDF format is here. • Mitsu with help of ryanmlanane caught many domains, although, he had said in forum that he will pass it to people for low fix fee. The domains that was being caught at Mitsu was not moving to other registrant. They put email id drops@mitsu.in on those caught name. One of the last domain (I might have missed other, if any) they caught using this credential was probably, classic.in. You may view classic.in whois history here. • Around same time, A thread was started at inforum.in which was later deleted. If I remember correctly, thread was started by ryanmlanane. As Jeff (the owner of the forum, who got some freebies by Mitsu as told earlier), was editing the post targeted against Mitsu. I saved a few pages smelling fishy. • In above mentioned thread, as Mitsu’s success rate became very high, and it seemed to many people that they are misusing their registrar status to profit from selling catched domains at lucrative price. As the domains caught by drops@mitsu.in was not going anywhere. People raised that issue in the deleted thread. • The deleted thread was located at http://www.inforum.in/sale-advertising/10977-lets- compete-drop-catchers-cornering-market.html 7
  8. 8. Background-content of deleted thread • After people questioned about domains caught by Mitsu still showing Mitsu credentials in whois of the domain (drops@mitsu.in). And why not its changing to end user registrant? Suddenly, around 6th-April-2012, Domains caught by Mitsu started showing email jimandy.usa@gmail.com . Like financial.in, toy.co.in, pec.in, hooker.in . • I have a saved copy of page-9 of deleted thread. This thread was saved on 8th April 2012, Indian standard time.In this page, read a post by Mitsu #83 (permalink), he posted about who is Jim Andy “Jim is real person having big business in UK and having business interest in USA and Europe. He is customer just like you all, when we closed the services they ask for account in our all registrar setup and we gave the account to them ? till date did we refuse any one of you from creating account with us ? so they created account and took our API and highly modified them to connect to us and they got the domain name ? just like other customers do.” Most of the people didn’t believe it. And Germain Domainer replied, “Jim managed to grab 8 domains in a second using your logicbox API? You seem to have blessed him with some super power.” Vaasu also agreeded with German Domainer. 8
  9. 9. Background-content of deleted thread • I have saved 3 versions of page-12 of the thread that was deleted. • Page-12-version-1 Page-12-version-2 Page-12-version-3 • In Page-12-version-1, Mitsu says to Vaasu – “Then what will happen to your friend who built all his portfolio on drop names only”. The friend of Vaasu that MITSU was talking is Neo. Just keep this in mind, will use this fact later. • Also , In Page-12-version-1, NameTrader aka Nanda posted a big reply (#119 permalink), he mainly raised 3 points, - “Why is only Jim Andy allowed to DROP CATCH, not anyone else for the past 2 days.” - “Why is Sanjeev holding the domains that are caught at drop time till 31- 03-2012, why is he giving excuses to customers and not delivering their domains to them. “ - “@Jeff I see you are being one sided, you deleted and cleaned up this thread in such a way that, almost everything against Sanjeev's deeds is deleted.” • Jeff, edited Nametrader’s post and deleted all the points he has raised. (Read Page-12- version-2). Message id #116 permalink. Not only this Jeff banned Nametrader. • Read, Page-12-version-3, I (catchnames) was unhappy with Jeff’s act of manipulating the posts and banning Nametrader. I wished Jeff, “Good Luck”. Meditang raised issue of previously corrupt act by Mitsu. Page-12-version-3 was saved on 9th, April 2012, IST. 9
  10. 10. Background-content of deleted thread • You may read – page-13-deleted-thread to view posts in aftermath of Nametrader banning and my reaction. • Also, after 7th April,2012 domains that started caught using Mitsu bear a new name, Raj G. of Vcom. Between, 8th and 11th April, I found 3 such names (there may be more which I don’t know.). Ksf.in, biscuits.in, rishikesh.co.in. All these names use email id, admin@vcom.uk.com • I checked, in May 2013, and Raj G was still catching names but email has been changed to jimandy.usa@gmail.com instead of admin@vcom.uk.com .So at least this is proved than Jim andy and Raj G are same person. Whois of freehosting.in, pyar.in, cars.co.in . • One aspect has changed now is this guy is catching domain not inside first minute of release of domains but after 1 minute (20:01:xx). So,he is catching only domains not caught be others. • Mitsu group have 4 .in registrar accreditation. One is mitsu.in, others are inregistrar..com, bharat.in, business solutions. So whois so far provided may belong to any of these 4 registrar. 10
  11. 11. Recap - 1 • So far, we saw Mitsu starting drop catching service. • A few domains were given to forum admin Jeff, but other domains caught by Mitsu drops@mitsu.in was being kept by Mitsu. • After issue was raised, all domains caught by two person Jim Andy and Raj G. Both were same person. Since mitsu didn’t gave drops to end user, its valid assumption that these might be fake identity used by Mitsu to caught names. • Also, Jeff was protecting Mitsu and a lot of people raised the voice against it, including me (catchnames), Nametrader, Geman Domainer, Vaasu, Meditang.And Nametrader was even banned. 11
  12. 12. Background –FB group Projectglass • On 9th April, 2012. I started a “secret” Facebook group and named it ProjectGlass. Complete page of this FB group is here. Read this page from bottom up. • Purpose of group as written by me : Its confidential and "secret" facebook group, to discuss the stratgy of Mitsu drop gate and Directi "domain manager" gate. Also to find out what we can and should do. Chalkout a strategy that's going to have a effect to cleanup .in registry and shark registrars. • I invited Neo, Picnic, Chandan,Nametrader,Meditang, Chris to the group. Chandan, Chris(Christoph Hartmann) and Meditang were already in FB friendlist.And chandan was also in my gmail chat list for long time.Chris is a German who reads inforum.in. I know that from one of the conversation. I am not sure if he is “german-domainer” on inforum.in or not. Sanjeev (Mitsu) was also in my FB friend list before the mention incidents in inforum.in • On, projectglass group page Suresh (Neo) posted a comment “Instead of FB.. How about i set up a separate site for us ?” and “Lets discuss about avoiding inforum.in, As jeff totally supporting mitsu we need a better community.. what are your thoughts” • On, 10th April, 2012 added Neo (Suresh) to gtalk friendlist. And had a good conversation about starting alternative of inforum.in besides projectglass. We agreed that Suresh would take a lead and start the alternative forum. Here is transcript of the chat. 12
  13. 13. Background -Theory based on incidents in past • Based on previous incidents, I had a theory which I wrote earlier. “my communication is bugged. My home, computer, mobile,car, phone line everything is bugged. Any person that knows me in my circle they reached to the person via common friends, anyone who is in my phone contacts, email contacts, facebook contacts etc they reached to the person.” link of my earlier blog post. • Based on this theory, at least, Chandan and Jeff were already compromised. So that, this presentation doesn’t go of the track and bulky, will only provide proof that conspirators (CIA and IB) had reached Jeff earlier and will leave Chandan for other presentation. I am reproducing content from one of my earlier post on blog. http://fbiplease.blogspot.in/2012/10/my-complete-story-part- 7.html • Please read Jeff and Anjan(me) mail exchange in April 2011 from bottom to top and relevant Facebook pm where user later deleted the account. In next slide, I will narrate it in tabular form. 13
  14. 14. Background – communication with Jeff 1. Apr 11,2011 I sent an email to a group of .in domain investor that I was starting a secret group on FB, Where I will auction drop caught domains. 2. Then sent a mail about domains that were in auction. 3. Jeff responded that he was not on facebook, but would be interested in caught domains 4. I responded to Jeff that it would easy and transparent auction if he joins Facebook. 5. After that I received a pm on facebook by someone who claimed to be Jeff. He said, “It's Jeff from INforum.in - please add me to your group”. I tried sending a friend request to that user, but couldn’t. 6. I sent mail to Jeff, “Probably you have deactivated your facebook profile or kept too much security” 7. On 13th April 2011, Jeff said “Did you get my message on facebook? I don't think I have any special security setting”. 8. 13th itself, I replied, “If you didn't send that means either mine or your gmail or facebook account is compromised!”. 9, Again sent a message to Jeff, “Can you confirm your mail id is not compromised, in that case I need to worry.The user has deleted his profile but message is in my still my facebook inbox.” 10. Jeff replied,” I did send that message.Very strange - my profile is publicly viewable: http://www.facebook.com/pages/AmazingDomainscouk/142359895812317 ” 14
  15. 15. Background – communication with Jeff • Please note initially Jeff replied that he didn’t have a FB account. After someone sent a message on Facebook representing Jeff and soon after deactivated his profile. Jeff replied, it was him and his profile was visible. The link Jeff sent of his profile was a Facebook page. Which was deleted after I posted this incident on my blog in 2012. • Question : Why would fake Jeff deactivate his profile and real Jeff had to lie that FB page was his profile? • Answer : It were these agencies (CIA and/or IB) who created fake Fb profile to see what was my “secret domain group” on FB.They couldn’t reach Jeff on time,and when they reached Jeff they asked him(Jeff) to cook a lie. They had done a great job by convincing me from 2008 to 2011 that my theory was because of mental illness. What my thought was by that time that there was surely some coordination in USA but things happened in India had became vague. One angle of conspiracy is they don’t want to succeed me on internet. They have to track everyone who knows me. As long as, acquaintance are not on internet, its easier to reach them. • If you don’t believe me please continue to read this presentation. You will get some “fishy” sign ahead. 15
  16. 16. Background – inforum.in hacked! • Now lets comeback to inforum,On 12th April,2012,at about 7.30 pm IST inforum.in was hacked by someone (as per Jeff’s post) – incase, it is removed, you may access the cached copy. Inforum.in was down for about 8 hours. • On 14th April,2012 9:45 pm UTC, Jeff posted a message that forum was hacked again.(cached copy). • On 16th April,2012 3:35 am UTC, Jeff posted a message that forum was hacked for third time and 13.5 hours of posts were lost because of it. He added further that “ This attack is obviously very targetted. We've upset someone - perhaps in the drop catching thread.” • In same page, message id #20, Suresh (Neo) offered help to Jeff. 16
  17. 17. Background: Someone was helping me • In projectglass group on FB, Vidyabhushan (picnic), posted on 16th April, “InForum.in hacked thrice in a week ! Any Comments!”, • I replied,” My BSNL was down for 12 hours. It sucks.” • BSNL is my DSL broadband provider and my connection was down since 15th April, in the evening to 16th April in the morning. And still domain was hacked. It might be a coincidence or might be conspirators (CIA and IB), who have bugged my devices to hardware level , wanted to ensure that I was not doing it from some device the they didn’t know.(possibly my computers display is being recorded-read a post on blog).’….And he changed channel. Nishant asked “See the TV” and he added further. Whose Desktop was that. He added further “Its not mine.”’ • How I think, someone was helping me? I had visited many IRC channels and discussed about conspiracy. Someone (I don’t know whom), who did buy my story, might have done it. 17
  18. 18. Recap-2 • Last recap was on page no – 10. • Started Projectglass FB, secret group and invited a few stakholders who are part of inforum.in. Aim was to clean .in registry. • Also, talked with Neo (Suresh) and he replied that he would start a inforum alternative soon. • Based on incidents in past, it was proved that Jeff was compromised since 2011. • In reply of Drop-gate on inforum and related conversation, someone hacked the inforum and it seems he was helping me. • Agencies, disabled my internet connection to make sure, It was not me who had hacked inforum. 18
  19. 19. Theory of Inforum.in Trap • Based on incidents and theory, these agencies, reaches a person who knows me by any means. • But here there was a internet activist, whom I don’t know, was fighting for me. • So, these agencies had approached possibly everyone whom I added in projectglass. Jeff and Sanjeev(Mitsu) were compromised beforehand. You may note that, neither Neo started an alternative forum nor anyone else participated in goal of prjectglass. Don’t believe me just keep patience and read ahead. • This was necessary for few reasons 1. Provoke me (catchnames) and ban me on inforum.in, because I was becoming very visible on inforum.in (They had previously done it successfully on a yahoo group.) . 2. Let the internet activist try hacking the forum again. So, that agencies may catch him/her. 19
  20. 20. Trap – chai.in • Between 18th of April,2012 and 24th April,2012. Chandan talked about illegal restore of domain chai.in from RGP, by Mitsu and changing contact details of the domain to Mitsu. First, Second , Third, Fourth Chat with Chandan. • What the matter was that a domain which is not being renewed can be restored by registrant in RGP (Also Pending Delete Restorable status). What Mitsu did was he restored the domain from RGP and change the contact details to Mitsu. Chandan said he made 2500 usd offer to old owner and he was eager to sell it. It implies that owner had not given consent to Mitsu to restore domain and keep it. You may view Domain Life cycle of .in domain at registry.in website. • This event was being co-ordinated and Since Chandan was in my chat list since early 2011, he was being used. Agencies did know my dislike of Mitsu and they thought I would bring this matter on inforum.in. As Neo, didn’t started the alternative forum, and instead offered helping hand to Jeff after third time hacking of inforum.in. I did see it coming. After this attempt to make a public fight on inforum.in failed. They created a second trap, a more sophisticated one, which I would discuss next. 20
  21. 21. Trap rate.in - urls • For rate.in related discussion will use many urls and cached pdf documents. I am putting all of them here for convenience. These urls would be used in rate.in timeline. Where I would narrate related incidents in chronological order.You may find these urls in timeline document as well. • Chandan’s 1st PM, Suresh’s PM, Chandan’s 2nd PM • Danny’s Hello (cached copy) • Jeff’s Negative posts Thread (cached copy) • Current rate.in thread – page 1, page 2, page 3 • German Domainer unedited post #10 • Rate.in whois history • Rate.in Timeline as PDF and as Excel Sheet 21
  22. 22. Trap – rate.in- Timeline • Serial no 1,Please open rate.in timeline file. Rate.in droped on 1 May 2012, 20.00.xx utc. • There are few other people who participated in co-ordinated drama, but for time being give all of them benefit of doubt and just concentrate on pm I received, Danny and Mitsu • Serial no 2,Chandan sent a pm on 2nd May that Mitsu has deleted the rate.in and re- registered it. (May be it was just and information or may be expectation that I would post against Mitsu, right?) • Serial no 4,On 3rd of May Danny joins the inforum and says Hello! And more than 13 hours posts that rate.in was taken away from him and he couldn’t login into his Mitsu.in account. • Serial no 5, On 4th May Suresh send link of the thread on pm. Without asking he even provided explanation of why he was not posting anything there. (Expectation was I would start writing against Mitsu). In same talk, he informed Nametrader (Nanda) has started alternative of inforum. • Serial no 6, I did smell it fishy that Chandan and Suresh wants me to speak but keeping quite. So asked Danny about his .in portfolio. • Serial no 7,8,9,12,13,16 (4th May) Danny and Mitsu is creating a lot of noise in posts and just seems waiting. Danny claims he had lot of proof and so do Mitsu.But no one posts any proof in forum. 22
  23. 23. Trap-rate.in - Timeline • Serial No 10, posted by German Domainer and compares at other domain theme.in was registred by Mitsu at 1 May 2012,20:00:39 UTC. While rate.in was created on 2 May 2012, 10:14:25 UTC. I am not sure if German Domainer was involved in match-fixing because he hadn’t given any info about any of his domains, hence address was not known. • Serial No 11, Chandan again sends link of the thread in PM. Conspirators were getting desperate as I choose to remain silent. • Serial 14 and 15, Jeff makes a rule against attack on registry or registrar and implements by deleting post #10 of German Domainer. Incidently Only German Domainer is the only person in whole thread who was providing data as proof. He might have also deleted the post because I had attacked Jeff when he edited Nanda’s data and banned him on previous occasion. So, Jeff may had tried to provoke me by editing German Domainer’s post. • So by end of 4th May 2012, Danny and Mitsu have exchanged their skype id and were suppose to talk. • Serial No – 17, posted by Danny, On May 7th 2012, has a lot of noise about why they didn’t talk over skype. • Serial No-18, posted by Mitsu, On May 8th 2012, again just hogwash. A long email about complain why they couldn’t talk. • Serial No-19, posted by Danny, On May 8th 2012, and he posted that he was available on skpye. • Serial No – 20, posted by Danny, On May 8th 2012, He said they talked over skpye and his Mitsu account was restored and Mitsu was “investigating” rate.in issue. And he would get and update from Mitsu on coming Saturday, that would be 12th May. 23
  24. 24. Trap rate.in – Timeline • There wasn’t any update on this thread till 1st June 2012. What he was doing since 8th May? May be waiting for something? • Serial No 21,On 1st June, Danny updated “They did confirm that the domain was registered by me. They claim it was then deleted because of insufficient funds on my account and it then was registered on another account (as I wrote in my OP, the other account was Raj G). After that it was deleted again because the other account also had insufficient funds and it then was re-registered again on that same account. I have reasons not to accept that explanation and that the domain will not be returned to me.” • And after the update the thread was closed. 24
  25. 25. Questions about last thread. • Neither Danny nor Mitsu provided any proof (Danny who was even recording Skype conversation as per his post), Any log, any email etc in any of the posts. • In last post, in this thread Danny provided Mitsu’s explanation and only wrote that he had reason to not accept the explanation. Then why he didn’t provide even a single proof of his explanation. • If you take out what happened (About rate.in)as told by Danny in huge information of noise. • As per Danny (serial no 4-in rate-in-timeline.pdf) – - Domain was registered in his name at 20:00:xx UTC on 1st May - Domain was moved to Raj G account at 20:13:06 UTC on 1st May - Domain still with Raj G but “updated time” was 2nd May 6:37 UTC - Domain still with Raj G but “created time” was 2nd May 10:14:25 UTC (that’s what current whois shows) 25
  26. 26. The Big question? • At any registrar who is using logicboxes solution (from Directi- Mitsu is using them as well),whenever a domain is moved from one account to the other, system sends an email to original account holder about the move. As soon as, domain was moved from Danny’s account to Raj G account an email would have been sent to Danny’s email. Instead of so many posts he could have just posted that particular email as proof and it would have ended the topic. And when Mitsu didn’t gave him the name, still didn’t posted it. Since the thread was coordinated we saw to many posts from Danny and Mitsu, without substance. Danny’s aim was never to get domain back but work as instructed. • A few days back I sold arkansas.in to Umesh (truekumar) and when I moved the domain to his account I received an email from the system. 26
  27. 27. Who can coordinate people around the globe • This event shows people from my gmail chat list to inforum.in member can act in tandem. • Who can coordinate people from different cities in India, Netherland and Canada? • This was not first attempt to sideline me from a discussion forum. Previously, they did it successfully in a social Yahoo group. Read my first post of this blog. 27
  28. 28. Goal : Minimum Visibility • These agencies (CIA, USA and IB of India) want minimum visibility for me. Internet makes their life difficult. • Because, so far they have tried to reach anyone who knows me from School, College, workplace, family (except Sister and Father),FB and some cases even email. 28
  29. 29. Bugging and Stalking • My internet/computing devices, mobile phones,Car are bugged. I have tried using “tails” and boot from linux CD, its not helpful. • Home, Car, possibly mobile and persons whom I visit have listening devices. • They had harassed me and father via my ex- wife by filing a false dowry harassment where they had misused police, lawyers and lower court. 29
  30. 30. How you can help? • Please read blog posts located at http://fbiplease.blogspot.com and help me in spreading the story. In some of initial posts I have written Mafia replace it with CIA and IB. Visibility in best tool that I can have to fight with CIA and IB coordinated conspiracy. • Aim should be to get it published in Wikileaks, Anonymous twitter handles or Mainstream media. • Please DON’T contact me via connecting in any way like email, FB etc or even meeting in person. If you do so, they would reach you as well and you won’t be able to help. • I am regular in IRC irc.anonnet.org in #anonnet and #agora channels, my nick is catchnames • For friends and family who are connected, you can pass me a written note about what you know, and I won’t whisper anything to anyone about the source of info. • Thank you for reading this. 30

×