GOBBLES SECURITY

A pseudonymous crew that named itself after a turkey, wrote in the third person like a caveman, and spent two years humiliating the professional security industry with better exploits than the professionals had. GOBBLES settled a public argument about whether the Apache bug was remotely exploitable by simply mailing everyone a working remote exploit — then told the mailing lists they could "return to their normal level of mediocrity." When they announced the RIAA had hired them to build a worm that had already infected 95% of the world's file-sharers, half the internet believed it. It was a joke. Most of GOBBLES was a joke. The exploits were not.

GOBBLES was born into computer security industry scene as GOBBLES during the month of June in the year of 2001 and currently have plans of being immortal in this field and living forever.

GOBBLES Security, "Loopback" self-interview, Phrack 58 (2001) — contact of record: GOBBLES@hushmail.com

WHO
GOBBLES Security — a pseudonymous multi-member exploit-and-satire crew; "not limited to one person, or one gender," by their own account ATTRIBUTED
SCENE
Full-disclosure / anti-security-industry trolling, ~2001–2003; fellow-travelers of the anti-security (anti.security.is) movement; Bugtraq / Phrack regulars
THE DRAMA
Weaponized the Apache chunked-encoding bug to embarrass ISS on remote exploitability; hoaxed the world with a fake RIAA "hydra" worm; roasted every big name in the industry in the third person
RECORD
Real, working exploit code (apache-scalp / apache-nosejob, mpg123 / jinglebellz); one admitted hoax (the RIAA worm); a Phrack "Man of the Year" nod. Never charged, never doxxed to a confirmed identity FACT
STATUS
VANISHED — went quiet after 2003; never unmasked, never immortal, exactly as threatened

This file is not an accusation — GOBBLES was never charged with anything, and the "victims" here were mostly the egos of a lucrative industry. It is a record of a comedy act with root. The through-line is the gap between the bit — the turkey, the broken English, the imaginary 19-member "Labs," the boxed wine — and the code, which was genuine, remote, and better than what the people being mocked had shipped. GOBBLES's targets were doing real disclosure and real OS-hardening work; that work gets its full weight below. But the joke landed because it was aimed at something true.

the drama timeline

ACT I — BIRTH OF A SECURITY TURKEY (2001)

A handle appears on Bugtraq, refers to itself in the third person, claims to be a Lithuanian collective of nineteen, and declares war on the entire commercial security business.

  1. JUN 2001

    The turkey is named

    GOBBLES tells the story on itself: a turkey.jpg off Yahoo made it think of "security community that full of evil turkies, hehe — 'other identity' should now become known as GOBBLES to be security turkey too." The persona — broken English, third person, "GOBBLES Labs," "penetrators" who need every acronym translated — is a running joke from day one. So is the anti-industry politics under it.

  2. 2001–02

    The thesis under the bit

    Between the gags is a real grievance: GOBBLES says it misses "the days when people who were knowledgable about security were respected… rather than people with certification like CISSP who qualified to use Nessus in corporate environment." On SecurityFocus/Bugtraq going commercial — making people pay to see advisories first — GOBBLES's verdict is "holding information hostage probably not best practice for full disclosure." The crew flies the banner of "Information Anarchy" and Jay Dyson's line, "Real men prefer full disclosure."

  3. 2001–02

    An open letter to the sellouts

    GOBBLES issues a mock "open invitation" to Aleph1 (Elias Levy), mudge (Peiter Zatko), and dildog to "leave they high paying jobs and the dark side of the force" and rejoin "the real security community where you don't have to shave you beard and give out real name." It is a joke and a genuine lament at once — the L0pht generation had just been acqui-hired into suits, and GOBBLES turned that into a recurring punchline about the scene growing up and selling out.

ACT II — THE APACHE HUMILIATION (2002)

Internet Security Systems finds a serious Apache bug, ships an advisory the community says jumped the gun, and leaves open the question of how bad it really is. GOBBLES answers with a remote shell.

  1. JUN 17, 2002

    ISS drops the Apache advisory

    Internet Security Systems (ISS) publishes an advisory on a chunked-encoding flaw in Apache 1.3.x / 2.0.x (CAN-2002-0392). It draws heavy fire on Bugtraq for going public ahead of a full coordinated fix — and the industry argues over how exploitable the bug actually is, some downplaying remote code execution beyond OpenBSD. The argument runs for days.

  2. JUN 21, 2002

    "Ending a few arguments with one simple attachment"

    GOBBLES posts apache-nosejob.c (the successor to apache-scalp) to Bugtraq under the subject line "Ending a few arguments with one simple attachment." Their note: "There seems to be some confusion about whether or not this bug can be exploited on any other operating systems than OpenBSD." The attachment — a working remote exploit against Free/Net/OpenBSD — ended the confusion. Sign-off: "The mailing lists may now return to their normal level of mediocrity until we're ready to publicize some more warez." Phrack later crowned apache-scalp its "EXPLOIT of the month."

  3. 2002

    The point, made in C

    The stunt crystallized GOBBLES's whole argument: the vendors with the certifications and the press releases were slower and less capable than an anonymous turkey with a hushmail address. Whatever you thought of their manners, the exploit compiled and it popped a shell. That was the tradecraft receipt; the trolling was the delivery vehicle.

ACT III — THE RIAA HOAX (2003)

GOBBLES's masterpiece was not code. It was a press-release-shaped lie the whole industry printed.

  1. JAN 2003

    "Recruited by the RIAA"

    GOBBLES posts a Bugtraq advisory announcing: "Several months ago, GOBBLES Security was recruited by the RIAA (riaa.org) to invent, create, and finally deploy the future of antipiracy tools." The claim: a "hydra" worm riding real media-player bugs that had already, per GOBBLES, given "the power to actively control the majority of hosts using these networks" — nearly 95% of P2P hosts. Attached was actual exploit code (jinglebellz.c / an mpg123 frame-header bug), which lent the fantasy just enough weight to stick.

  2. JAN 2003

    The world prints it

    The timing was perfect: Congress had just been floated the Berman P2P bill that would have legally shielded copyright holders who hacked file-sharers. GOBBLES's "the RIAA already did it" satire landed in exactly that anxiety, and outlets ran with the alarm before the punchline. The media-player bugs were real; the RIAA contract was not.

  3. JAN 2003

    GOBBLES admits the bit

    Cornered, GOBBLES concedes the whole RIAA recruitment was invented for attention — a hoax. The security press files it under "hackers humble the experts," which was, of course, the entire point of GOBBLES.

ACT IV — LEGEND AND DISSOLUTION (2003–)

The turkey went quiet, the theories started, and the myth outlived the crew.

  1. 2003–

    The disappearing act

    After the RIAA stunt GOBBLES faded out. Years later, Phrack was still name-checking the crew — and still rolling its eyes at "all that 'RIAA employing Gobbles to pwn media players' bullshit" when a new media-player bug came around. That is the shape of a legend: the joke is remembered longer than the exploit.

  2. 2006–08

    "n3td3v and Gobbles are probably the same person"

    A stylometric paper, "Who is n3td3v?" by Hacker Factor (Neal Krawetz), argues by linguistic analysis that the later mailing-list gadfly "n3td3v" and GOBBLES "are probably the same person." n3td3v denied it — reportedly claiming an "A.I. program" generated the text. Nobody proved it either way, and GOBBLES's actual identity was never confirmed. The theory is a footnote, not a dox.

both sides, on the record

They shipped live weapons: apache-scalp / apache-nosejob were not proofs-of-concept behind a responsible-disclosure curtain — they were working remote exploits mailed to a public list, usable by anyone against unpatched servers. Whatever the argument they "ended," the ammunition was real and it went to everybody at once.

The hoax had a cost: the RIAA "hydra" claim was fabricated, and it burned real researcher hours and real press cycles on a lie. The people who took it seriously were not fools; they were doing their jobs against a source that had actual exploits to make the fantasy plausible.

The targets were legitimate: ISS, Theo de Raadt's OpenBSD hardening, SecurityFocus's disclosure infrastructure, the L0pht alumni at @stake — these were people building real defenses. GOBBLES's jabs at them ([1]) were satire, not findings, and the archive keeps them as GOBBLES's opinion, not the verdict.

The bugs were real and the vendors were slow: GOBBLES did not invent the Apache flaw or the mpg123 flaw — they proved them, publicly, faster and more convincingly than the credentialed vendors managed. "Show the exploit or stop arguing" is a defensible full-disclosure ethic, and it was the era's mainstream one [2].

It was satire aimed at something true: the certification-industrial complex, "full disclosure" turned into a paywall, ISS botching a coordinated release — GOBBLES's targets were hypocrisies, not private individuals, and the crew stayed anonymous rather than punching down or cashing in [1].

The hoax was a hoax, and it was legal: no one was hacked by the RIAA "hydra" because it did not exist; GOBBLES made that up and said so. As trolling it satirized a real, pending policy — the Berman bill to legalize corporate hacking of file-sharers — and no charge ever followed, because inventing a scary press release is not a crime [3].

YOU DECIDE

Strip the turkey costume off and you are left with a crew that wrote better exploits than the industry it mocked, used them to win public arguments the professionals were losing, and then told the professionals to go back to being mediocre. The public exploit drops were genuinely dangerous and the RIAA claim was a genuine lie. But GOBBLES never pretended to be anything but a joke with root, never got paid, never got caught, and aimed every shot at power rather than at the powerless. The archive does not deify a troll. It just notes that this one was funny, and that the code worked.

The archive keeps the punchline — and the exploit that made it land.

evidence locker

PRIMARY / FIRST-PARTY

  1. Phrack 58 — GOBBLES "Loopback" self-interview ATTRIBUTED — the origin story, the "evil turkies" naming, the anti-CISSP / anti-SecurityFocus ethos, the "dark side of the force" invitation to Aleph1 / mudge / dildog, and the jabs at named researchers. All GOBBLES's own satirical words. Local mirror: research/zines/phrack/issue58/3.txt. phrack.org/issues/58/3.html
  2. Bugtraq — GOBBLES releases apache-nosejob.c (Jun 21, 2002) FACT — "Ending a few arguments with one simple attachment"; the "confusion… on any other operating systems than OpenBSD" line and the "return to their normal level of mediocrity" sign-off, verbatim. seclists.org/bugtraq/2002/Jun/282
  3. The Register — "Is the RIAA 'hacking you back'?" (Jan 14, 2003) ATTRIBUTED — GOBBLES's RIAA-recruitment claim quoted in full ("recruited by the RIAA… to invent, create, and finally deploy the future of antipiracy tools"; the 95%-of-hosts claim), before it was confirmed a hoax. theregister.com/2003/01/14/is_the_riaa_hacking_you

CONTEXT & CROSS-LINKS

  1. CSO Online — "Hackers Humble Security Experts" FACT — reports the RIAA worm claim was a fabrication GOBBLES admitted to, invented for attention. csoonline.com — hackers-humble-security-experts
  2. SANS/GIAC — Apache chunk-handling (CAN-2002-0392) & apache-nosejob.c FACT — independent technical writeups of the ISS advisory, the coordination dispute, and GOBBLES's exploit. giac.org — Apache chunk-handling
  3. Phrack 59 / Phrack 68 ATTRIBUTED — apache-scalp as "EXPLOIT of the month," and the crew's lasting legend (the RIAA-worm lore, the n3td3v theory). Local mirrors: issue59/2.txt, issue68/13.txt. phrack.org/issues/59/2.html
  4. Hacker Factor — "Who is n3td3v?" (stylometry, DISPUTED) ATTRIBUTED — the contested linguistic theory linking GOBBLES and n3td3v; denied by n3td3v, never proven. hackerfactor.com/papers/who_is_n3td3v.pdf
  5. troll.fan — the anti-security movement CROSS-LINK — GOBBLES's fellow-travelers in the anti-full-disclosure / anti-whitehat scene. troll.fan/dossiers/antisecurity-movement.html
The standard. GOBBLES Security was pseudonymous and this file keeps it that way — no real-name claim is made, and the n3td3v attribution is flagged as a disputed, denied theory, not a dox. The exploits (apache-scalp / apache-nosejob, the mpg123 bug) and the RIAA hoax are documented in the Bugtraq/seclists archives, Phrack, and contemporaneous press, and the RIAA "recruitment" is stated for exactly what GOBBLES admitted it was: a fabrication. GOBBLES's jabs at named researchers and companies — ISS, Theo de Raadt, SecurityFocus, the L0pht alumni — are reproduced as attributed satire, and those targets' legitimate work is stated at full strength. No private data is reproduced. If a line here couldn't survive scrutiny, it wouldn't be on the page.