Follow us on RSS or Twitter for the latest updates.

September 4, 2012

Hackers stole and leaked Over 1 Million Apple IOS Device ID From FBI


fbi_logo
Hackers have dumped online the unique identification codes for one million Apple iPhones and iPads allegedly lifted from an FBI agent's laptop. The leak, if genuine, proves Feds are walking around with data on at least 12 million iOS devices.

The 20-byte ID codes were, we're told, copied from a file extracted from the Dell notebook of a senior federal agent, who was tracking the activities of hacktivists in LulzSec, Anonymous and related groups. Supervisor Special Agent Christopher Stangl's machine was compromised via a AtomicReferenceArray vulnerability in Java in March, the black hats claim.

Once his computer was infiltrated by the hackers, a file was allegedly seized containing 12 million device records that included Unique Device Identifiers (UDIDs), usernames and push notification tokens as well as a smaller number of names, mobile phone numbers, addresses and zip codes. Members of the AntiSec crew leaked edited extracts of this data, having mostly stripped it of fanbois' personal information, on Monday.

The listed UDIDs, which include gadget serial numbers and other data so apps can distinguish between individual devices, appear to be genuine. However, by themselves they may pose only a minimal privacy risk once leaked online, so the effect of the dump is largely confined to embarrassing the Feds - and raising questions as to why agents have the information in the first place.

The most likely source of the data was either an iOS app developer or multiple developers, Mac Rumours speculates.

The Java exploit used in the attack is unrelated to the mega-bugs finally patched by Oracle last week.

It's a matter of record that Stangl was among the agents invited to an FBI-Scotland Yard conference call about the progress of investigations into members of Anonymous back in January. Members of LulzSec infamously eavesdropped on this call and leaked a recording after intercepting an email arranging the chat.

Email addresses exposed by this breach may have been used in a follow-up targeted attack that tricked investigators into visiting a booby-trapped website exploiting an at-the-time Java 0-day vulnerability. Rob Graham of Errata Security expands this plausible theory in this How the FBI might've been owned blog post.

The AntiSec activists behind this week's leak suggest the device info data was used as part of some FBI tracking project involving iOS devices, such as iPhones. Even they are a bit vague on what that might be. However the group goes into some detail in explaining how it apparently swiped the data:

During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of "NCFTA_iOS_devices_intel.csv" turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose.

The AntiSec group says it decide to published a portion of the leaked data in response to a keynote speech by the NSA's General Keith Alexander at the DefCon hacker convention in July. In part, Alexander sought to persuade hackers at the convention to consider a career at the NSA, a suggestion that predictably galled the black hats.

Author: dfgdfg,

July 9, 2011

Anonymous Releases Highly Classified Goverment Documents


In the days following the dispersal of LulzSec, Operation Anti-Security continues on with the rogue hacker group Anonymous releasing a considerable amount of information from IRC Federal, a government contractor with FBI, Army, and DOJ partnerships, to name a few. To quote Anonymous’s release notes:

Today we release the ownage of another government-contracted IT company, IRC Federal. They brag about their multi-million dollar partnership with the FBI, Army, Navy, NASA, and the Department of Justice, selling out their “skills” to the US empire. So we laid nuclear waste to their systems, owning their pathetic windows box, dropping their databases and private emails, and defaced their professional looking website.

In their emails we found various contracts, development schematics, and internal documents for various government institutions including a proposal for the FBI to develop a “Special Identities Modernization (SIM) Project” to “reduce terrorist and criminal activity by protecting all records associated with trusted individuals and revealing the identities of those individuals who may pose serious risk to the United States and its allies”. We also found fingerprinting contracts for the DOJ, biometrics development for the military, and strategy contracts for the “National Nuclear Security Administration Nuclear Weapons Complex”.

Additionally we found login info to various VPNs and several Department of Energy login access panels that we are dumping *live* complete with some URLs to live ASP file browser and upload backdoors - let’s see how long it takes for them to remove it (don’t worry we’ll keep putting it back up until they pull the box.
This is an embarrassing situation for a company dealing with such sensitive information and yet another lesson learned through exploitation that security needs to be much more than what it currently is for many such high-profile/significant sites.

anonymous
And though the information leaked sounds important at first-glance, the coming days will reveal whether or not this is just another forgetful “hacktivist” release that merely reiterates the flaws of current security measures, or if something significant will come of it all.

Rest assured that either way, the continued hammering of governments and government contractors is sure to yield significant changes in approaches to security. But that’s only in the short term. The larger concern of many is how these actions might provoke new legislation that seeks to prohibit certain facets of Internet access/usage. Never mind if these “hacktivists” manage to get a hold of something truly significant that gives some sort of disastrous advantage/insight to feared terrorist/criminal/anti-government organizations.

Source: Zdnet

Author: dfgdfg,

July 4, 2011

AntiSec Targets Apple Survey Server, Releases Post Passwords


apple-logo1.jpg
Hackers have posted a document that allegedly has user names and passwords for an Apple server. The find, posted via the AntiSec hacking campaign, appears to be a warning that Apple “could be a target too.”

The bigger picture here is that Apple will become an increasing target for these hacker groups if the company provides the right trigger. Apple could represent the Holy Grail for malicious hackers given its stash of iTunes customer data. If Sony, AT&T and the CIA can bring hackers headlines just imagine what Apple could do.

According to the Wall Street Journal, AntiSec includes hackers from Anonymous and the now-decommissioned LulzSec. 9to5 Mac considers the document posted by AntiSec to be relatively benign.

That take looks to be roughly correct, but there’s a warning embedded here. Hackers apparently are too “busy elsewhere” to mess with Apple, but that doesn’t mean the company is bulletproof. One trigger—something that may annoy hackers—could set off a larger attack.

Apple hasn’t commented yet and probably won’t. Today Anti-Sec claims a technical support server. It’s not a big deal yet. The big question is whether Apple’s more valuable servers—iTunes and iCloud—will become targets.

apple-flaw.png

Author: dfgdfg,