Pages

Recent Posts

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Monday, July 18, 2011

Hackers Planning Their Own Social Network?

squirell-hacker

By: Kareem 

Some cats either from or supporters of anonymous have decided that enough is enough with what they view as BS social networks and decided to start their own.

The site is called anonplus is already up, although all it contains right now is a single page outlining their plans along with the names of some of the key devs, and a developers forum where people can contribute ideas and skills. According to the anonplus website the plan is to create a social network free from forced accounts, information mining and censorship.

There’s no official announcement from anonymous as of this writing, so no one really knows if they’re members or just some developers sympathetic to anonymous’ cause. So you can make of it what you will. According to the rumors the idea for the site came after a number of anonymous members were censored on other social networking sites.

I’m fairly neutral when it comes to social networking. Most of the time social networking sites seem to dissolve into madness with people having 3000+ “friends” and no one really using the sites to do any real networking or socializing. It seems to me that most people use Facebook as a personal cloud scrapbook storage app, or to make money. There are a lot of ‘jobs’ out there for people who have massive Facebook and Twitter followings regardless of how many of their ‘friends’ are total hack accounts or how many of their followers are ‘marketing experts’. 

I wish these guys the best of luck and hope they succeed if for no other reason than just to see what /b/ version 3.0 will look like. We can’t be certain this isn’t a prank or that it will go anywhere, but still it’s some pretty interesting news nonetheless.

Related stuffs:

Source: Information Week

Wednesday, June 22, 2011

Law Enforcement Getting Desperate In The Hunt For LulzSec

Anyone who's been on the web recently surely knows all about LulzSec and their exploits shutting down gaming companies websites, hacking into FBI and CIA servers and posting a false Tupac story on the PBS website. Your also most defiantly privy to Lulz and Anonymous joining forces. Well it would seem law enforcement in the U.S and U.K have the internet and are actively searching for the group(s).

I can't go any further without pointing out the irony here. Remember when the U.S invaded Afghanistan about 9 years ago? Y'know looking for the douchebags responsible for the 9/11 attacks. Do you also remember how Osama Bin Laden  was apparently so good at hide and go seek that the combined forces of the U.S and it's allies could not find him? I do. I also remember how since they couldn't find Bin Laden they just went ahead and hunted down the loudest terrorist/dictator they could find, Saddam Huessein. I see some pretty glaring similarities (not in groups involved naturally, but definitely in the course of action.

It's no secret that Anonymous is a group every major government would love to see exposed. It's also no secret that the governments and security experts have failed miserably in this task (much like they did looking for Bin Laden the first go around) so it would seem they're looking for another target that's more structured and easier to hunt down, enter LulzSec. The law enforcers of the U.K and U.S are feverishly hunting down LulzSec. According to reports going around recently, LulzSec does have an hierarchy and they are being very loud about all their exploits. Since Lulzsec is pretty new it might be only a matter of time before they make a mistake and get caught up, kinda like Huessein. That would give the law enforcers the boost in moral they need right now in order to continue the fight against anonymous.


Now here's where it gets sad/funny/interesting. Just recently (yesterday) the British police arrested a 19 year old kid named Ryan Cleary. The arrest is really a sad attempt at getting closer to LulzSec, Cleary did not have anything to do with the attacks as far as all knowns are known. He merely hosted some of their chats, of course the British police are charging him with some other crimes and claiming he's responsible for DDoS'ing some porn sites as well as SOCA (Serious Organized Crime Agency) which handles the U.K's um, serious crime's or something. Anywho they're still holding the poor kid and probably asking him questions like who do you hang out with? and what movies do these LulzSec characters go to? In other words wasting theirs and his time.

Oh and that's not all, according to some unnamed source the U.S, not to be outdone in stupidity and harassment by the Brits, (we wouldn't want anyone looking worse than us would we?)  went ahead and raided a data center run by a company called Digital One over in Arizona in order to get some intel on LulzSec. Not only is this raid kinda pointless, it also shut down 10's of users servers according to Sergej Ostroumow, the companies owner. Although the number of people affected by the shutdowns isn't large, it's still a slap in the face of someone who most likely has nothing to do with or supports the actions of LulzSec. Great way to waste a day F.B.I, what did all the celebrities finally learn not to take, send or store naked pictures of themselves online? You guys got no more bloggers to hunt down for practicing their first amendment rights? Is that why your going after the Lulz? 

All i have to say is that when your tactics are this desperate and you cant even narrow your suspects search down to even a country, your probably doing something wrong and should re-evaluate your tactics. I would suggest that you stop going after the people doing this for Lulz and to release information the public might want to see and maybe go after people who might be planning some nasty cyber attacks, there's also the little fact that catching and arresting the people smart enough to secure your servers, will not make them safer. Maybe you should ask some of your 'security experts' to go ahead and shore up your defenses a little. I'm just saying is all. 


Source: Information Week

Sunday, June 19, 2011

Sega Gets Hacked LulzSec Offers Help

 

sega-dreamcast

By: Syeed 

Sega had one of their databases broken into recently and lost about 1.3 million users information. LulzSec has decided their going to help out this time, apparently they really love the Dreamcast.

So first off here’s the details on the breach.  According to an email sent out by Sega to it’s Sega Pass users on Friday, the breach occurred on June 15th and on June 16th they shut down the Sega Pass system for safety reasons. The email goes on to say that Sega identified some of their users email addresses, dates of birth and encrypted passwords were stolen. Sega says they took immediate action, isolated the problem, closed off the system and reset all the passwords. They recommend that users who night use the same email/password combination for other sites should go and change those ASAP, and to be cautious of all emails you receive as the information could be used for spear phishing.

The real kicker here (for Sony at least) is that no payment information was stolen because Sega is either not financially capable of, or not stupid enough to take payment information on their own. All users payments go through external payment providers which is a good thing, a very very good thing.

That’s not all either. In an odd twist the biggest suspect is actually offering to help Sega catch the people who did this, LulzSec. The mentioned in a tweet yesterday aimed at Sega that they want to help them destroy the hackers that attacked them. Their reason, they love the Dreamcast. It’s still tough to say if their honestly offering their services (I would wager they are) or if LulzSec is just pulling an O.J and trying to make themselves look more innocent by going after “the real killers”. Either way that’s one hell of a twist.

Related stuffs:

Friday, June 17, 2011

U.S Government Building Fake Internet To Practice It’s Skills

hacking

By: Kareem 

So apparently the U.S government is getting sick of losing so many battles to hackers. They’re building a fake internet to model the real internet so they can practice defending against attacks from hackers. All while hackers are busy on the real internet finding real vulnerabilities to exploit.

I don’t blame the government, I’d be a little concerned too if people kept hacking my servers and users. However I really don’t see this doing much in the way of helping defend against cyber attacks. First off the government seems to think that defending all of our electric grids and sensitive information is only worth $500 million. A drop in the bucket compared to how much is spent on other security issues. That amount will buy you a whole lot of college-educated ‘security experts’ and probably 0 hackers. What the government dosen’t seem to understand is that hackers for the most part are not bad people. That’s why we have the term cybercriminal. Hackers are defiantly poking around on systems all over the world, but very few want to do more than just take a peek or earn bragging rights. If the government considers this a ‘war’ than they better start learning their enemy and stop going after the people who might have the skill and be willing to help. Secondly, this is a control environment, their whole test web can be reset and wiped at any time… not a very good thing when there are people on the real internet taking advantage of the fact it can not be shutdown, using zero-day exploits and other various means that are fairly difficult to reproduce. Hackers tend to be the type that look for a way around, over, under or through whatever obstacle is preventing them from getting access. Well I can see the benefits of a controlled environment to test on, I really don’t think they have the know-how to take advantage, they are, after all the ones who left the vulnerabilities there in the first place.

My biggest beef by far coming out of all this is the fact the U.S government wants to treat hacking as an act of war. This is just plain stupid. Hackers are not ‘warriors’ they are smart, curious people. Treating them like warriors and forcing them into a situation where it’s us vs them is a terrible thing for any government to do. Attacking your own citizens for pointing out your stupidity and oversight is not the way to win over anyone or stop any hacker. What they should do is extend an olive branch. Allow hackers to stay anonymous and put them to work defending against foreign attacks. Tap the resource that is their minds, the same minds that spend countless hours learning the ins-and-outs of computer systems in order to get around barriers. These are the only people that are skilled enough and willing enough to spend all day and night hacking and sending you the information you need to defend your servers. Unfortunately this will not happen. The U.S government will turn hackers who were just curious before into their greatest enemy. An enemy with no face, no country, nothing to lose and that if pushed too hard (see Sony) will own your systems with no remorse or regret, no matter how many ‘fake’ internets you create or how many 9-5ers you hire.

So let this stand as a caution to the U.S government. If you go down this route there is no turning back, if you decide to try and catch hackers you will get a pretty nasty surprise. You should just sit back ignore them and let them do their thing. Go ahead and hunt down the ones who are criminal, no one will fault you for that. But leave the lulz (and I don’t mean LulzSec) alone. Thank your god that they haven’t had good reason to show their teeth and don’t start wars you know you can’t win. It’s like Canada trying to invade America by building a small ‘America’ in their county and working on different invasion tactics. You will have the same success they would if they were dumb enough to try.

Related Stuffs:

Source: BBC

New Trojan Target’s Bitcoins

By: Kareem 

The security company Symantec is warning user’s of the somewhat popular Bitcoin virtual currency that their ‘virtual wallets’ might be under attack.

For those of you who might not know, bit coin is a Peer to Peer virtual currency that’s supposed to be more secure than making a ‘traditional’ online purchase using a credit card or checking account. Users are given what’s known as digital wallets where they store all their virtual money. Users can buy as many Bitcoins as they want and then use them for various transactions amongst others who have opted in to the service.

It would seem however, that the service isn’t entirely secure (and honestly is anything on the internet?) as hackers have already compromised some users accounts using a Trojan virus. The Trojan is called infoseaker.Coinbit and according to reports, locates your Bitcoin wallet, steals all the necessary data, and then dumps the file via FTP to the hackers servers. The reports say that there has already been a theft of 25,000 Bitcoins. The Bitcoins are valued at $23.50 which makes the theft worth about $500,000. Not exactly peanuts.

So if you use Bitcoins make sure you encrypt your wallet and that you make a very very difficult password as the attack is using brute-force to guess the passwords. If yours is too difficult there is a good chance whoever is doing this will not want to waste the time and move on to another, easier target.

Related Stuffs:

Source: International Business Times

Virtual Navigator: A Real “Virtual Currency” Emerges: Could BitCoins Threaten “Real” Currencies?

Monday, June 13, 2011

Lulzsec Strikes Again Releases Tons Of Email/Passwords For Adult Site

LulzBoat

By: Syeed 

You may remember Lulzsec/Lulzboat as the group that recently hacked PBS and Sony. Well it would appear they’re in full stride still.

Recently the group released the login information of over 25,000 members of the hardcore porn site pron as well as the credentials of 55 administrators of other adult sites. Not only did they steal the login credentials, they also posted a link on their twitter account telling their followers people were probably using the same emails/passwords for their Facebook accounts and that they should login as them and send out messages and posts linking their friends and family to their pron accounts.  Facebook reacted by immediately running a check for the compromised accounts on their servers and changing the passwords, saving many many many people from sure embarrassment.

Lulz

 

Among the accounts found were numerous .mil and .gov accounts which means some government types are very likely to be getting a stern talking to at the very least. I find it kind of funny that someone would be stupid enough to link their .mil or .gov email account to a porn site, however there isn’t much funny about what Lulzsec did seeing as I’m an adult now and not allowed to get my Lulz from embarrassing innocent people (ah the good ‘ol days) it would be ‘immature’ of me to say that these people deserve this because there too stupid or lazy to differentiate their email accounts by personal, business, and other. It would be extremely childish of me to say that these hackers are just having fun and in reality not causing any significant harm, and I would be an outright fool if I said I agree with what they did and laughed when I first read the news. So I won’t say those things I um just said. Instead I’ll leave you with a more cliché and ‘PC’ response:

What these hackers did is wrong and criminal and blah blah no ones allowed to have fun or laugh at other peoples misfortunes etc etc and they should be caught wonka wonka and their just kids with nothing better to do wah wah…There I hope that pleases those of you with a-holes so tight you haven’t had a good shit in years.

Related Stuffs:

Source:  MSNBC

Friday, June 3, 2011

Sony Hacked Again? Seriously? WTF?

mr-lulz

By: Kareem 

Apparently the hacker group LulzSec has made a joke of Sony security once again. They reportedly stole 1 million users personal information and published some of it online. This after Sony apparently fixed up all their security holes.

LulzSec recently hacked into PBS for making a stupid, god-awful documentary on Bradley Manning/WikiLeaks and reigned all sorts of prankery on the site. Most notably posting an article saying Tupac is alive and well, living in New Zealand.  That was pretty funny, however the Sony attack might cause a little more harm than just a BS post about a 90’s rapper.

The attack on Sony came via what’s known as an SQL injection attack, which basically involves writing SQL code into a text entry field, once the code is entered the database receives it and if not well protected enough executes it. It’s a pretty basic attack and one Sony shouldn’t have left open, especially after their recent overhaul in security. One would think they’d cover something as simple and obvious as and SQL inject. It seems like Sony is pretty damned stupid when it comes to hacking, the hacker community and encrypting the personal information they collect on their users… that’s right, according to LulzSec the data was unencrypted and stored in plain text on Sony’s servers.

LulzSec also went ahead and released some of the info they had stolen, the Associated Press made some calls and validated that the information was correct, not all however. Some of the accounts were obviously fake, but that’s being attributed to users who didn’t want to give up their personal information. 

LulzSec took to Twitter saying:

“I hear there's been some funny scamming with jacked Sony accounts. That's what you get for using the same password everywhere”

"Hey innocent people whose data we leaked: blame @Sony.”

So who’s fault is it really?

If you ask me both parties are equally responsible, Sony should’ve triple checked their systems before going live again. It’s  better to have a delay in service than suffer the embarrassment of being hacked multiple times after you supposedly worked day and night pen testing and upgrading your security.

LulzSec is obviously responsible due to the fact they carried out the attack and posted the information.

There seems to be a lack of understanding on why LulzSec would post the information, possibly damaging quite a few innocent people, but it makes pretty good sense when you know a little about hacking culture When LulzSec hacked PBS they obviously had enough control of their servers to wipe out tons of data and do massive damage but they didn’t. Instead the benignly changed some pages and pulled a couple of harmless pranks, why? because the pranks were proof enough that they got in, compromised the servers and had almost total control. Hackers like to show off and in the case of Sony, LulzSec had to prove that they actually got in and stole legitimate information. Sony is a huge target right now, not just because the way they treated GeoHot but also because hackers really want to see how many holes Sony left unpatched.  Unfortunately for users that means proving you got in and the only way to really do that is to post the info so people can see for themselves.  At least they didn’t release all 1 million users information.

 

Related Stuffs:

Video:

Wednesday, June 1, 2011

Supposed Chinese Spear Phishing Attack Targets US Government

gmail-hacked

By: Syeed 

Google reported in a blog post yesterday that they found evidence of a spear phishing attack that compromised the emails of some high ranking US and Asian government officials as well as civilian contractors with military interests.

According to the blog post by Google, the attackers sent out highly personalized emails to the unnamed officials, pretending to be friends, associates and collaborating organizations. The emails contained attachments which led them to false Gmail login pages that stole their passwords.

After harvesting the passwords, Google says the attackers created rules that forwarded the victims emails to their email accounts. The hackers probably also monitored the victims emails and gathered tons of personal information on them an their contacts which allowed them access to even more accounts. Google says they believe the goal of the attack seemed to be monitoring the victims emails. I would guess in an attempt to steal some military secrets.

Google is saying the  attacks originated from Jinan China, however they haven’t released any evidence to support that claim. 

Google said that they want to be as transparent about security issues as possible so that more people can be aware of potential threats. They said they have already alerted all the proper authorities, notified those who were compromised and put a stop to a hack already.

Related Stuffs:

Saturday, May 28, 2011

Quick Hit:Lockheed Martin Hacked?

 

Lockheed-Martin

According to recent reports, the U.S’ biggest defense contractor, Lockheed Martin might have fallen victim to a recent hacking attempt.

The attack was apparently carried out using RSA SecureID tokens from EMC that were stolen in another hack this past March. According to reports someone used the ID’s to break into Lockheed Martin’s company network.

Lockheed Martin isn’t commenting on what data was stolen if any. It’s pretty safe to assume that anything exceedingly top secret wouldn’t be stored on any network whatsoever, so I don’t see there really being much cause for panic. Not to mention no one knows who broke in or their intentions so it would be kind of silly to get too worried now.

Reports are also saying that once Lockheed Martin was made aware of the breach they forced everyone to change their passwords company-wide and ordered another 90,000 SecureID tokens from EMC.

Related Stuffs:

Sunday, May 22, 2011

Sony Gets Hacked Again

SONYFAIL

By: Kareem Ali

Sony got their PSN service up again last week, after about a month of making repairs to their network that were supposed to increase security. However Sony is still facing attacks they can’t seem to keep up with or defend against.

First off Sony left a gaping hole in their security when they put the PSN back on-line, although they forced users to change their passwords before being able to log on to the service, they overlooked a pretty gaping hole by only asking users to supply their birthdate and email address in order to change their passwords. Those two pieces of information were taken in the first PSN/Qriocity breach. So the jerk-asses who stole the information in the first place could easily go in and start changing users passwords to whatever they wanted to over the PSN account recovery website. Thankfully Sony reacted quickly and shutdown the website, so now the only way to change your PSN password is through your console.

It’s good that Sony reacted quick to patch the hole, but really? After a month of intense security auditing no one caught that? I guess it’s forgivable, but I would’ve hoped Sony hire a couple of pen test teams to check every single security hole, both physical and digital. I know they were in a rush to restore service but I think users would’ve waited another week for Sony to go real deep and check everything out before risking millions of their users data again online. What with them knowing they’re a target and all.

And that’s not all…

According to recent reports Sony’s So-net (an ISP subsidiary of Sony), was attacked as well. Attackers got in an stole about $1,200 worth of gift points from 211 users accounts. 128 of those accounts had their points redeemed while another 73 accounts were just owned and not used. Along with those 211 accounts, another 90 email accounts were compromised on the So-net.

According to Sony there is no evidence that any personal data was viewed or stolen, however they discovered the breach on the 18th but found that the attack started two days earlier on the 16th. So there really is no telling how many accounts were compromised or what data was taken and viewed. Seeing as by the time they found it the hacker could have covered most of their traces pretty well.

The crazy thing to me is how the attacker got in, sheer brute force. Apparently the hacker used a good old dictionary-password-generator script to hit the (So-net point service) site 10,000 times, from the same IP address. It’s kind of mind boggling that So-net could be hit for password requests 10,000 times without having any red flags go off, for two days.

Sony is saying that they don’t believe that the latest attack has anything to do with the PSN attack last month, but I disagree. Sony has made themselves a target by showing the hacker’s and cybercriminal’s out there that they have weak security. These people (hackers and cybercriminals) are not stupid people, and they will dig and dig through all of Sony’s websites and online services or anything related. The idea being that if a service as valuable to the company as PSN can be owned so easily, Sony’s other sites must just be wide open. Especially during these incredibly distracting times for the company. It was, by Sony’s own admission, anonymous’ fault that PSN got owned in the first place, not because they did it, but because they distracted them enough to allow the attack to happen. There is no way they can deal with all these new distractions and keep all their online assets safe, so I would assume the attacks will continue.

Related Stuffs:

Saturday, May 14, 2011

Quick Hit:Sony Starts Restoring PSN And Qriocity

Sony-lawsuit

By: Syeed

So after about a month of being down, Sony is announcing today that they will be restoring the PSN and Qriocity services throughout the next couple weeks and that everything should be up and running by May 31st.

Although service is being restored and Sony is offering a few freebies for your hassles, the whole thing is far from over. Sony still has to find out who stole the 77 Million user logins, keep posted on whether or not the card numbers in the encrypted database that was stolen are getting used, and stay vigilant against future attacks.

According to Sony this whole thing was planned and carried out by some pretty hardcore pros, so they have their work cut out for them.

Related Stuffs:

Last Past Security Breach Not As Bad As I Thought

shame-on-me

By: Kareem@techsual.com

The password hack at LastPass was not as  bad as I originally thought. Here's the facts of what really went down.

Last week I reported on a story about the password security software LastPass getting hacked. One reader pointed out that I had gotten my facts wrong, I’m not one to let pride get in the way of facts so I looked it up and it turns out he was right. Here’s the facts.

According to LastPass, they experienced some suspicious activity on their network last week and locked down all the accounts immediately. I originally stated that there had been up to 1.25 million passwords stolen, but that number is insanely inflated. I got my news from Bloomberg and my guess is they got that number from the fact that so many accounts were locked down by LastPass. The truth of the matter is that they locked down all the accounts due to the suspicious activity. It’s a good move because if they had been hacked (having not been certain at the time) then they would prevent the hacker from getting more information than they already had.

According to LastPass there was no evidence that any customer data was leaked, and that if it was it was encrypted. Normally I would balk at the encryption factor, since given enough time any encryption can be cracked. However in this case LastPass did something very very very smart…they forced everyone to change their passwords, here’s a piece from their blog:

“To counter that potential threat, we're going to force everyone to change their master passwords. Additionally, we're going to want an indication that you're you, by either ensuring that you're coming from an IP block you've used before or by validating your email address. The reason is that if an attacker had your master password through a brute force method, LastPass still wouldn't give access to this theoretical attacker because they wouldn't have access to your email account or your IP.”

They mentioned on the their blog that it might have been a little overreaction, but better safe than sorry I say.

LastPass also mentioned on their blog that they don’t have any details on what exactly happened yet, but they’re working on finding all that out. I say kudos to LastPass for being transparent on this matter and handling it so well….maybe it isn’t such a horrible idea to put all your password eggs in one basket after all.

Also I offer my apologizes for feeding into the media hyperbole and not doing my homework properly. I’ll do my best to make sure it dosen’t happen again, and thanks to the reader who pointed this out to me. I want to bring you guys the facts if I’m wrong and you know it I will make sure I fix it, no ego’s here.

Related Stuffs:

Monday, May 9, 2011

Sony Saying PSN Will Be Back Up By May 31 Now

 

psfail

By: Kareem@techsual.com

Sony is still struggling to get their PSN and Qriocity services back online, according to the Official PlayStation Blog, they were unaware of the full extent of the damaged that was caused and are having to take extra measures to ensure that the services will be safe and secure once they return.

Sony has been giving PSN users hope since the network went down on April 20, first saying it would take a few days, then another week, and another… I guess they got tired of crushing peoples hopes and came up with the more realistic May 31st date yesterday. May 31st is still a hope though as Sony still needs to do a lot more testing and no ones really sure what they will find when they do.

Related Stuffs:

Friday, May 6, 2011

Is Sony Regretting Going After GeoHot?

SONYFAIL

By: Kareem@techsual.com

Hmmm I wonder if Sony is regretting suing GeoHot yet? It is, after all the reason all this madness started. Had they just let things be, avoided getting ‘all legal’ and suing the poor guy, their network would still be up, no one would be complaining and everyone would be getting their game on.

So now Sony is adding to its apology basket, along with the free month of PlayStation Plus access users of PSN and Qriocity will be getting a free year of insurance to protect against identity theft. The policy will cover each user up to $1 Million and comes through an agreement Sony made with Debix, an identity protection company.

So how did all this happen?

First off GeoHot, as far as I know has managed to crack every firmware update Sony’s thrown at him, but it was the latest one that really set the company off. I guess they just had enough. Instead of doing what I would consider a smart move and hiring the young hacker, Sony decided to go after him all guns blazing and took GeoHot to court.

After a few months of both sides’ lawyers going at it GeoHot conceded and reached a settlement with Sony. As all this was going on a few hackers waving the Anonymous flag went ahead and decided they weren’t going to let Sony get away with this and proceeded to DDoS attack some of Sony’s site as well as PSN itself. After getting complaints from gamers that shutting down PSN service was only harming them, the hackers stopped, claiming that they were trying to hurt Sony and not the gamers.

A quick note on Anonymous: I find it pretty damn funny how people keep writing these article trying to explain who anonymous is and whatnot. I have never heard of any hacker who runs around explaining who they are to every one who hits them up in a chat room or forum, I hardly know any regular-non-hacker-people who willingly divulge that info to anyone who asked for it and honestly if you do your pretty naïve, there’s a lot of bad people out there that want to hustle you some way or another. On and off the internet. So with that said most people on the internet have the capability to be entirely anonymous at any time they choose, and if their willing to do a little homework they can get tools to scramble/proxy/hide their IP addresses, MAC ID or any other traceable information. Not to mention theirs plenty of publicly available internet connected computers out there, you don’t always have to be at home to connect to the web. Tracing an idea or movement like anonymous is pointless, there is no end to it, your pretty much fighting a never ending supply of people who believe in something much bigger than a group, its an idea and a concept that what anonymous is. Shure there are websites that take the name but that’s no different than a huge website that’s ran by say, a hardcore group of UFC fans. You might be able to catch the guy who started it, maybe his whole crew, but by the time you try and shut it down one of it’s users, someone who believed in the cause of the page would re-make it. Only this time he’d know he’d have to be more security conscious and make himself harder to find. The only thing your doing is creating generations that are learning from their past mistakes. Every attacking the endless supply of writers, programmers, designers, law enforcement, government workers, soldiers, etc.. etc... etc.. will not stop the idea of anonymity. Plus then you'd have to go through all the trouble of eliminating a word out of multiple languages and that would take probably a couple hundred years, not worth it. Then again America does have a history of liking war:

 

Anyway where was I? Oh yea, so after Anonymous stopped attacking PSN, everything calmed down, at least for a couple of weeks. On April 21st someone hacked into Sony’s San Diego data center and stole tons and tons of people’s information. Which caused the company to shut down their PSN and Qriocity networks in order to halt the attack. Sony then went ahead and got a security company to come in and do an audit which ended up looking not so good for Sony. Apparently they had quite a few holes to fix as PSN has been down since the attack and there is no real word or guarantee on when it will be back (should be this weekend though, it looks like they got everything fixed and there just getting it all updated)

Sony is claiming that over 100 million people’s names, logon information, addresses, credit card numbers and other private information was compromised in the attack. They are also blaming anonymous for the attack which, if you read the above note on anonymous should seem as stupid to you as it does to me.

I see it as one of two things happened:

1. Since the credit card information hasn’t been used, and I don’t see any way whoever has them could use them without getting caught. I think someone did this just to prove a point, and I think they worked for Sony. Not only did Sony do a full security software upgrade they also moved the entire data center to a new location ahead of when they planned. I don’t see why they would go that extra step to move the center unless there was a physical breach.

2. Someone is using the current celebrity of being anonymous and ummm anonymously committing a crime (which, really, who the hell runs around shouting their name and address while their say robbing a bank or selling crack or whatever), they have the credit card numbers but either haven't decrypted them or their waiting for the opportunity to use them anonymously.

Whatever the reason this was done, there is no question that had Sony backed off of GeoHot and the rest of the PlayStation homebrew crew, none of this would have happened.

Related Stuffs:

Thursday, May 5, 2011

Quick Hit: N.Y. Attorney General Wants To Know Why PSN Went Down

 

Sony-lawsuit

By: Syeed@techsual.com

Just this Tuesday Eric Schneiderman, N.Y attorney general subpoenaed Sony. Apparently they have some questions as to how and why the breach happened.

Sony is claiming that the attack was well organized and planned and that it had to be carried out by experts who had been researching the companies security. They’ve gotten the FBI involved in their personal investigation and it looks like they may be getting a little more help in hunting down the person or persons who caused all this havoc.

Sony is claiming that the perpetrators of the crime had only the intent of stealing credit card information in order to use it for ‘illegal purposes’. Even though there hasn’t been any evidence of the cards being used, and beside I thought Sony said the card numbers were encrypted and safe.

We can expect Sony to divulge all the details in court, until then we just have to guess at who might’ve done this and more importantly why. Was it just to prove a point? Or did they have some sort of malicious intent?

Related Stuffs:

LastPass Gets Hacked For 1.25 Million Passwords

 

computer_thief

By: Kareem@techsual.com

In what would seem like the cyber equivalent of turning someone upside down and shaking all the money out of their pockets, some unscrupulous hackers took LastPass for an estimated 1.25 million passwords.

LastPass is a service which allows users to store login information for different websites under one, ‘secure’ password which is kept safe by LastPass and makes it easier for people to create crazy passwords without having to worry about remembering them.

That was, up until yesterday, when apparently someone got behind their firewalls and stole the aforementioned 1.25 million passwords. That’s quite a few passwords, especially considering that since those are taken, whoever has them can login to the users accounts and everything they have linked to it. That means that a lot of people have good reason to check their bank accounts and other sensitive online data.

If your concerned about how much might have been taken, then you should go ahead and change all your passwords ASAP and the email and other info related to your LastPass account.

I would also suggest that you don’t use single login services like LastPass, it’s kind of a bad idea to put all that information under one account, your best bet for safety is creating choke points for everything. Say for instance you want to start a Facebook account, you should have one specific email account for that Facebook account, that way if someone hacks your Facebook and gets your email through it they won’t have a real addy, it’s a choke point it ends with (preferably) totally false data. By creating multiple accounts for things like that you can focus on making your personal email secure and change those passwords daily. Remember to make those other accounts as real as possible, use pictures you find on the internet, make the name as real as possible. Basically what your doing is creating multiple false identities so that you can waste as much of someone who is trying to get your info’s time as possible. If they think it’s real they’ll keep going until thy realize it’s not, and if they do hack or steal anything at least it wont be real, and for the love of god don’t let any of those accounts link to any real personal info. Don’t give an alternate email (unless it too is fake).

I think it works best if I give you an example of what goes through the mind of someone trying to get your personal information via Facebook. For the sake of me not getting carpal tunnel today let’s skip to them already having your Facebook login info, first person mode GO!.

OK so I’m logged in as you, maybe watching you chat with a friend (oh you didn’t know I could do that…maybe I’ll tell you how later Winking smile  but for now, maybe you shouldn’t use FB chat), but that’s boring and I’m not getting much info, I’ll keep monitoring it to see if anything good comes up. I go through your info and find out where you work, went to school, your friends etc.… I can do something with that but I’m not in the mood for that much work, I just want your name, (you were smart enough to make a fake one for Facebook right?) maybe that will pop up in chat, but I don’t feel like sitting here all day waiting for someone to type your name. I’m going to go check out your email since Facebook is looking like it’s going to take some time to get what I need from (I could trick one of your friends or use the information to start building a profile but hopefully if I cared that much you’d know why and be keeping yourself off Facebook altogether). Of course I already have your fake email but what I need is your real one, I’m hoping to find a hole in the only access I currently have. Thanks to the fake email, and fake Facebook info I don’t know your real name, address, phone number or anything. Just your Facebook account login info, which I will lose once it alerts you by email that someone logged in from a computer that wasn’t yours, you change that password, or delete the account altogether and start another and I’m back to square one.

So you see how this works?, it’s the old ‘don’t put all your eggs in one basket’ spiel. If you work for a company and have a responsibility to protect sensitive data then it’s the least you could do to keep yourself a little more safe, stop being so lazy about logging into multiple sites.

Related Stuffs:

Source: Bloomberg Buisnessweek

Wednesday, May 4, 2011

Sony Apparently Can’t Deal With Stress, Blames Anonymous For Data Theft

anona_guy_fawlks

By: Kareem@techsual.com

Sony is saying today that the recent outage of Qriocity and PSN isn't due to anonymous directly, but they’ve still wrangled up a way to blame them somehow.

My guess is Sony is dong this because they want the government to go after anonymous, which is a pretty stupid thing to want to do in and of itself, not because anonymous is dangerous or might retaliate, but because chasing a group of anonymous individuals is basically like chasing ghosts…so good luck with that one Sony.

Any-who back to the issue at hand, Sony is saying that they were distracted by anonymous’ DDoS attacks which were launched about two weeks before the data loss attack occurred and stopped because gamers were being harmed more then Sony and anonymous did not want that. At any rate Sony is still saying that because they were dealing with the DDoS attacks they were overwhelmed and could not handle the separate attack which ended with someone somewhere stealing thousands if not millions of encrypted credit card numbers from PSN and Qriocity users.

This whole thing dosen’t make much sense to me, if the only reason they were breached was because they were dealing with a DDoS attack from anonymous then why did they need to shut down the services and have a security team come in and audit their systems? If security was good in the first place then they would not have needed such a long break in order to patch up what was damaged. They could’ve just shut the hacker out, checked all his backdoors and went right along with business as usual. Instead they halted everything, had what seemed like a massive panic attack and ended up finding numerous flaws and holes in their security which then took them over a week to repair. That’s not the fault being distracted, that;s the fault of Sony not keeping their security up to date and checked out.

Related Stuffs:

Sunday, May 1, 2011

UPDATE(2): PSN Still Down, Might Be Back Next Week, But At Least Your Info’s Safe…Right?

SONYFAIL

BY: kareem@techsual.com

Ok so here we are, over a week since the PSN and Qriocity services were attacked by an intruder, who stole your personal information and caused Sony to do what would seem like a whole re-tooling of their entire network security.

Sony released a statement via the PlayStation blog today which basically says that they turned off the networks after an attack on their San Diego data center in order to prevent the breach from getting any worse (which was actually a good move), then hired some good pen testers to come in and audit their security systems and implement new security measures based on the audits. That’s what the long delay was all about.

But there is good news, the credit card data that was stolen was in an encrypted file and we all know that once something is en-crypted it can never be de-crypted….wait a sec…half the world  just told me that’s not true. Stupid stupid Sony expects people to really believe that whoever was smart enough to get into their systems and steal the information in the first place couldn’t decrypt the file? or at least knows someone who can? I would wager that the people or person who did this is not stupid enough to try and use, sell or do anything with the card numbers at least, it would be too easy to trace back and most likely whomever did this was trying to prove a point. PSN and Sony in general is not secure. Sure they’ll spend millions on lawyers to sue people, but they get real cheap when it comes to hiring proper pen testers to make sure their security is at least somewhat legit. I guess they figured encrypted credit card information was enough. I guess they didn’t take into consideration that people wouldn’t be able to access PSN or Qrocity and didn’t bother to put up proper security to defend against an attack in the first place.

The next bit of good news for al you PSN and Qriocity users out there is that Sony has implemented such cutting-edge and revolutionary new security techniques such as:

  • Automated software monitoring and configuration management to help defend against new attacks
  • Enhanced levels of data protection and encryption
  • Enhanced ability to detect software intrusions within the network, unauthorized access and unusual activity patterns
  • Implementation of additional firewalls

Wooooweeeee that’s secure, I feel real safe now thanks Sony! This looks like a superheroes stat list, not like some wimpy computer security system I-am-impressed. Hold on though, what about physical security, how do we know this wasn’t someone inside the data center in the first place? I’m getting scared again… wait, there is more from Patrick Seybold who is the one posting on their blog:

“The company also expedited an already planned move of the system to a new data center in a different location that has been under construction and development for several months.”

Well ok then, I’m sorry I doubted you Sony.

If all that wasn’t enough Sony felt they’d do right by their users and give them a free 30 day membership to PlayStation plus, which if you were already a year long subscriber saves you all of $4 for that month hooray.

Sony hasn’t given an official date for when service will be restored, they only said their networks should be back up by the end of next week.

More to read:

Source: PlayStation Blog

Article: PSN Still Down And If That's Not Enough Someone Stole Your Info

Old But Funny Vid:

 

Thanks for reading!

Saturday, April 30, 2011

Anonymous Plans To Attack Iran

Anonymous_2

Anonymous recently released a statement saying that they pan to launch an attack against the Iranian government starting on May 1st.

According to their statement:

"The people of Iran have the admiration of Anonymous, and the entire world. We can see that Iran still suffers at the hands of those in power. Your former government has seized control, and tries to silence you. People of Iran--your rights belong to you."

No one’s entirely sure what they plan to do, most are expecting massive DDoS attacks to Iranian Government websites, but there could be more. Anonymous has attacked the Iranian government before to help protestors gain support. I’m not too sure what happened but it would seem that their former government has gotten control and they need a good uprising.

I’ve read a few of the articles and most of them seem to center around the DDoS attacks and totally miss the scale of what anonymous can do, as they’ve shown in the past. It’s more than shutting down websites and denying the ‘bad guys’  access to their computers, it’s more than revealing private, embarrassing information about people until they step aside, it’s about truth in this case. Yes there’s always the revenge ops and other somewhat childish (but still satisfying) attacks on companies that serve no greater purpose than to make people laugh and piss others off. But in this case, it’s about silencing someone who is causing massive harm, removing his propaganda, and replacing it with the truth allowing people to choose which side they want to be on based on facts instead of nonsense censored government propaganda. That’s why anonymous gains support and that’s why people join the protests they support. Because once all the noise is cleared and people can start seeing the real and true things that are going on in their country they tend to get pissed off and want to do something about it. Especially when things are as bad as they seem to be in Iran right now.

It’s different when it’s raw camera footage and people writing from within their own towns as opposed to the censored and biased news you normally get from people who went to school and are paid money to look nice and say the right things in the right way. There are some amazing reporters who go out and get in harms way but none of them have any real stake in the situation, they can always leave. They have no family to protect and no real reason other than, at best a concern for the people involved to be there. Most of them are just there because they’re literally willing to die to get ahead in their career.

So you can say what you want to say about anonymous, and you can keep trying to figure out their names and who they are which is really pointless, it would seem their a global group, and that there are quite a few of them. I really don’t think there are enough jails or people willing to convict them. They can chase the ‘leadership’ but saying anonymous has leadership is just the media’s attempt at trying to make them look like an organization. They’re not an organization, more just like an ethereal idea that people latch onto from time to time when a cause gets their attention. It’s not just for Hackers but for anyone who want to join in their cause at that moment.

Tuesday, April 26, 2011

PSN Still Down And If That’s Not Enough Someone Stole Your Info

By: Kareem

sony-y-u-no-go-fuck-yourselves

So here it is, it’s Tuesday and PSN is still down. Sony is announcing that not only is there no word on when it will be back up, but apparently someone’s pulled all the information off their customer lists.

According to a post on the PlayStation blog today, Patrick Seybold announced that users of Qrocity and PSN have had most of their personal information stolen. Some of the information that was compromised includes users addresses, names, login information and the answers to your security questions.

Sony is warning that PSN and Qrocity users to be on the look out for any suspicious activity on their accounts and to login and change their passwords and other information ASAP.

A lot of PSN users are understandably upset, 7 days without service and now this? What’s next? People are blaming hackers for this, but Sony is the one that instigated it, if you’re a PSN or Qrocity user I would suggest cancelling your memberships and going a different route, nothing's 100% safe but you can at least go to a company that dosen’t put you directly in the line of fire and instigate childish battles.

Source: Digital Trends

Stumble