Play Online Poker
 

Poker Discussion Post

 
Sign in | Join
in
Bodog
$100K Guaranteed
Every Sunday! 
Sign Up Today!
Rakeback
Get cash back after
playing poker!
Sign up now!
CarbonPoker 
$15,000 Rake Chase
Plus 30% Rakeback!
Cake Poker 
33% Rakeback
$25k extra each month!

Poker Discussion


Please help support pocketfives by using our links when choosing to download a new site!
CarbonPoker · Full Tilt · Cake Poker · PokerStars · Ultimate Bet · Players Only · Bodog

   

Explaining the AP investigation
N 82 50 24 (Cayman Islands) 5,677 Posts. Joined 06-12-2005.
10-17-2007 4:19 AM

I posted a summary of how things went down, along with screenshots, on my blog: http://www.natarem.com

Here is a x-post of what I put on my blog, but I had to remove the screenshots because they are too wide.

Hopefully this will explain it clearly for people.

---------

Okay, so, anyone who follows 2p2 or P5s or a lot of other forums has probably noticed all of the Absolute Poker uproar. If you don’t know about it, here’s the basic idea…

CrazyMarco, a well-known online tourney player, played in a 1K AP tournament on 9/12/07. The tournament was won by a player named POTRIPPER who made a crazy call with T high against Marco’s 9 high flush draw. In the following days, Marco emailed with AP support and asked for a hand history so he could review POTRIPPER’s play at the final table. There were rumors that POTRIPPER could see hole cards and he wanted to follow up because of the possibility that he was cheated. On Friday Sept 21st, AP sent Marco a huge excel file (10 mb and a full 65,536 rows, the excel limit for most versions being used currently). He didn’t think much of it and it was too scambled and complicated to analyze, so he put it on the backburner for the time being.

Fast forward a few weeks. Marco, along with his roommate Jared “TheWacoKidd” Hamby, decided to take a look at the file. This happened sometime around October 12th or 13th as I understand it. They realized soon after that AP had send Marco ALL of the hole cards in the hand history. This, of course, allowed them to watch how POTRIPPER played and to examine what hands were at the table when POTRIPPER was/was not playing hands. It quickly became apparent to all who saw the history that POTRIPPER was cheating and, somehow, knew peoples’ hole cards. You can view the hand history on PokerXFactor here. One thing to note is that the spreadsheet only had the first 2 hours and 20 minutes of the tournament because of the Excel line limit, so the hole card access somewhat cuts off around hand 94.

Anyway, I noticed posts talking about this Excel file. On Saturday, MrTimCaum sent me a copy of the spreadsheet. I started to play around with it and noticed that there was random IP/email/user id numbers interspersed with the player actions. It wasn’t clear at first exactly what the info meant. It didn’t seem like the info pointed to people at tables for the following reason:

[SCREENSHOT REMOVED]

The IP info looked something like that. It told me when someone “entered” a table, what their email was, what their IP was, what their user id was, etc. Note that I changed all of the info in this line to protect the privacy of the real data. I put in my email address for the hell of it. Anyway, there were 845 lines with either “TABLE_ENTER” or “TABLE_LEAVE” and through some analysis, I realized that there were tons of players in the event who I knew and they never appeared in the “TABLE_ENTER” or “TABLE_LEAVE” lines. Eventually, we figured out that Enter and Leave lines were recorded for people who were logged into the software and opening or closing the table, but not seated at the table.

Next, I analyzed the lines related to table 13, where POTRIPPER was seated. 2+2er snagglepuss, who I forwarded the spreadsheet to, had already pointed out to me two sketchy observers, one of whom opened up table 13. And when I looked at the data, I noticed something a little weird. One of the sketchy observers opened up table 13 and he was user number 363! This number is incredibly low and I instantly knew that the account had been created by AP or someone who was associated in some way with AP. It had to be a test account of some kind to be made that early in the system.

[SCREENSHOT REMOVED]

I am still hiding some of the sensitive info, but this line in the spreadsheet was probably the key to cracking the case in my opinion. It showed a number of things:

  • A Costa Rican IP address (and this IP address becomes more important)
  • An observer entering the table and never leaving the table until at least 11:20 PM (or over two hours later when the spreadsheet cuts off)
  • A very very low user number that indicates AP involvement in some way — not that the company as a whole knows, but that SOMEONE on the inside was involved.

The next step was to cross reference the IP address within the file. When I did that, some info on the other “sketchy” guy came up.

[SCREENSHOT REMOVED]

Once again I blacked out some of the info, but the important thing is that SCOTT@RIVIERALTD.COM had the same IP address as user 363. He stopped by table 9 for whatever reason for about 20 seconds. The only real significance of table 9, as far as I know, was that Mark Seif, an AP sponsored player and AP co-owner (I think?) was playing on it. That doesn’t mean that Mark was involved, but it is a relevant fact with regards to table 9.

The next step, which I think I did the next day, was to figure out some info on rivieraltd.com. I pinged the domain and found the IP to be 66.212.244.147. Note that someone has since changed this, but the IP can still be connected to the mail server as of this writing. Then upon doing further research on that IP address, I traced it to what I believed to be the Kahnawake gaming commission. I posted my findings on 2+2 and P5s. Then a poster on P5s named JackBileDuct pointed out the following:

66.212.244.147 is mail.riveraltd.com telneting to it on port 25 gets a greeting from a mail server. It *IS* a mail server.

Also that IP is NOT the Kahnawake Gaming Commission. Are you ready for this… It is AP.

Mohawk Internet Technologies MIT-BLK-01 (NET-66-212-224-0-1)
66.212.224.0 - 66.212.255.255
Absolute Entertainment S.A. MIT-ABPOK-02 (NET-66-212-244-128-1)
66.212.244.128 - 66.212.244.255

Go to http://www.arin.net and enter the IP address in a whois search. That connection is from one of their own IP’s….

CustName: Absolute Entertainment S.A.
Address: Plaza Mayor 2nd building 2nd floor
City: San Jose
StateProv:
PostalCode:
Country: CR
RegDate: 2006-08-16
Updated: 2006-09-26

That might be kind of technical, but the general idea is that the email address was hosted by Kahnawake but actually belong to AP! So this SCOTT@RIVIERALTD.COM fellow was actually connected to AP. This was overwhelming evidence in my mind… remember:

  1. There was a low numbered user watching the table (and probably sharing hole card info) with the suspicious player POTRIPPER
  2. The low numbered user was connecting from Costa Rica
  3. An AP-associated person was on the same IP address and even though he wasn’t watching table 13, he revealed himself nonetheless

My head was spinning. I kept posting more and more of these revelations online. One issue was that I didn’t know who Scott was. So I sent out a feeler email (PM in some cases) asking various places to check on the IP address that was used by the two sketchy accounts.

Sure enough, I woke up Tuesday morning to find a rash of evidence sitting in front of me. 2+2 moderator Adanthar found that the IP address was used by a 2+2 account with the login name scotttom. P5s admin Adam Small told me that he knew one of the AP owners was named Scott (although he didn’t say the last name). A few other sources who do not want to be named told me that Scott Tom was associated with that IP address. It was also pointed out to me that there was an online blog post where some girl said that Scott and Phil Tom (brothers I think, although only Scott seems to have been implicated) were AP owners and executives. Adanthar posted his findings on 2+2 and revealed that he’d connected the somewhat mysterious IP address to an actual person. Also, other sources that do not want to be named confirmed that the IP address was a residential cable modem tied specifically to the Tom family.

So that’s how everything was tied together on as simple a level as I can make it. I am not including a ton of various leads that I’ve followed or some of the inside info that I received, but this is the general gist of it. I’ll post more as time goes on, especially on things like the media, AP and community reactions to this stuff.


 
 
 

Mr_BigQueso (Czech Republic) 5,794 Posts. Joined 03-23-2007.
10-17-2007 4:20 AM - In reply to

hellaneato   BAHHHHHHHHHHHHHHHHHH

pickup_styx (United States) 604 Posts. Joined 10-09-2007.
10-17-2007 4:21 AM - In reply to

You and Adanthar do some amazing work.  Keep it up and bust these mofo's.

pu_s

dbuzz (United States) 650 Posts. Joined 08-01-2005.
10-17-2007 4:53 AM - In reply to

GG AP?

Camronius (Canada) 4,272 Posts. Joined 07-09-2007.
10-17-2007 4:57 AM - In reply to

Amazing work. Although I love reading this and find it intriguing, I think nothing more should be posted on this. The community has by far more than enough information to know that this has happened. I think it's pretty easy to conclude that the criminals behind this are reading P5's and 2+2. Posting anything more on this is only going to help them. I would be very careful, you never know who you are dealing with, this could have the potential to get very ugly. Im sure you have already taken precautions but please have multiple copies of the factual evidence stored at several safe places. I would even advocate removing this post and and others with this much evidence.

Again, simply amazing and take care!


HateMeNow (United States) 46 Posts. Joined 07-21-2007.
10-17-2007 4:58 AM - In reply to

So where is the Scott Tom person now?  Is there enough evidence to actually pin it on him and get him locked up?  Last but not least, doesnt this post kinda serve as a "heads up" for this guy possibly giving him the chance to get on the run before po po show up at the door?


N 82 50 24 (Cayman Islands) 5,677 Posts. Joined 06-12-2005.
10-17-2007 5:00 AM - In reply to

I'm guessing you didn't read the other posts.

HateMeNow (United States) 46 Posts. Joined 07-21-2007.
10-17-2007 5:00 AM - In reply to

no not all, there are so many i lost track lol

N 82 50 24 (Cayman Islands) 5,677 Posts. Joined 06-12-2005.
10-17-2007 5:00 AM - In reply to

I guess I've resigned myself to the fact that I might be at risk here.  The evidence I posted has already been posted on 2p2 and elsewhere online.

Also, it should be noted that I wasn't the person who posted that it was Scott Tom who is apparently the owner of the IP used by #363 that day.  Adanthar did.

On top of the fact that snagglepuss, Josem, Adanthar and a number of others helped along the way.  I gave myself way more credit in that blog entry than I deserved.

sketchy1 (United States) 7,970 Posts. Joined 04-17-2005.
10-17-2007 5:10 AM - In reply to

do you really think that we're going to get this guy in jail?  lol.

ellizizcute (United States) 218 Posts. Joined 05-08-2006.
10-17-2007 5:29 AM - In reply to

how do you know the internet so well

SQQTED (United States) 479 Posts. Joined 05-12-2006.
10-17-2007 5:43 AM - In reply to

I am definately glad this file was sent out but this leak of sensitive information with everyone's email address, IP address, exposed hole cards, etc. is a serious privacy violation by AP as well.

Am I wrong?

Camronius (Canada) 4,272 Posts. Joined 07-09-2007.
10-17-2007 6:07 AM - In reply to

This tom guy is apparently the CEO of AP. My question is why would a CEO of a billion dollar industry need to steal this money? , And in such a sloppy manor. Makes me think it may have been someone close to him.


hoosier (United Kingdom) 148 Posts. Joined 02-19-2006.
10-17-2007 6:10 AM - In reply to

Thank you, thank you, for all the time you put into this, you should work for homeland security!  The amazing thing to me, and a testament against the Online Gambling Prohibition Enforcement Act, is that PLAYERS figured this all out, because they have SKILL - they have a sense for the game, and all this didn't make sense.  Of course the OGPEA proponents will say this is proof why it is needed.  I think we all say it is proof why we all want it regulated, and taxed too, just like Party Gaming (party poker) over here in the U.K.

I hope the players all get their money back.  gg Absolute Poker.

Anyone found a picture of Scott Tom?  I sat next to one of the Absolute Poker founders at the 2005 WSOP.  At the time this guy was from Seattle, he used to be a stock broker and had some of his former clients as investors, plus his son was one of the original IT guys.

A__theKevlar__2 (United States) 277 Posts. Joined 06-23-2006.
10-17-2007 6:14 AM - In reply to

note to self: never do anything to piss nat off. 

amazing work nat, much apprecciated
 
Return to Top
Page 1 of 5 (69 items) 1 2 3 4 5 Next >


 
Daniel Alaei Wins!
2009-12-20 03:56:56
Faraz Jaka 3rd ($571,374)
2009-12-20 02:57:50
P5's Member Blogs
Let's Slow It Down...
By Cre8ive - added Feb 05 2010, 03:52 AM
Finding a New Home
By dtools22 - added Feb 04 2010, 07:46 PM
My 1st Decent Tourney Win...
By surefirebets - added Feb 04 2010, 01:18 AM
 
Mid-stakes online tournament specialists 'shanetrain22' and 'funnygut' are this week's featured guests.

P5s Podcast, February 4, 2010
Thur, 4 Feb 2010 12:00:00 EST
Jon Wein is our podcast guest, fresh off a couple of 3rd place finishes in the Sunday Million for around $300,000 combined.

P5s Podcast, Jan 28, 2010
Thur, 28 Jan 2010 12:00:00 EST
PocketFives.com Rankings
Rank PLB PRO
1. Doc Sands 1 4
2. moorman1 2 2
3. djk123 4 3
4. 1SickDisease 5 8
5. govshark2 8 7
6. TravestyFund 6 9
7. gboro780 17 1
8. apestyles 11 6
9. kleath 9 12
10. bigdogpckt5s 3 16
Carbon Poker Sorting Tables
Rank PLB
 1. 1SickDisease 7863.37
 2. djk123 7704.21
 3. TravestyFund 7514.85
 4. govshark2 7510.07
 5. kleath 7431.15
 6. hoodini10 7418.59
 7. apestyles 7190.94
 8. ImaLuckSac 7139.30
 9. taypaur 7125.99
 10. jet5087 7054.87
Go