Follow us on RSS or Twitter for the latest updates.

January 14, 2013

Anonymous hacks MIT after Aaron Swartz's Suicide


On Sunday, the official site of the Massachusetts Institute of Technology (MIT) went offline. On a couple of the website’s subdomains, Anonymous hackers published a message in memory of Aaron Swartz, the Reddit co-founder and activist who recently committed suicide.

“Whether or not the government contributed to his suicide, the government's prosecution of Swartz was a grotesque miscarriage of justice, a distorted and perverse shadow of the justice that Aaron died fighting for […],” the hacktivists wrote on the defaced pages.

“Moreover, the situation Aaron found himself in highlights the injustice of U.S. computer crime laws, particularly their punishment regimes, and the highly-questionable justice of pre-trial bargaining. Aaron's act was undoubtedly political activism; it had tragic consequences,” they added.

The hackers ask the government to “reform” computer crime and copyright and intellectual property laws.

“We call for this tragedy to be a basis for greater recognition of the oppression and injustices heaped daily by certain persons and institutions of authority upon anyone who dares to stand up and be counted for their beliefs, and for greater solidarity and mutual aid in response,” they wrote.

“We call for this tragedy to be a basis for a renewed and unwavering commitment to a free and unfettered internet, spared from censorship with equality of access and franchise for all.”

They concluded their statement by apologizing to MIT administrators for temporarily taking over the website.

MIT has ordered an internal investigation into the case of Swartz. Furthermore, JSTOR – the digital library that accused him of illegally downloading content – has released its own statement regarding Swartz’s death.

At the time of writing, the main MIT site appeared to be working properly. The subdomains that hosted the hacktivists’ message have been taken offline.

In the meantime, a petition to remove United States District Attorney Carmen Ortiz from office for overreach in the case of Aaron Swartz has been created. The petition appears to be supported by both Anonymous and the controversial Kim Dotcom.
Add me on Google+
FILED UNDER:MIT ANONYMOUS HACKTIVISM PROTEST DEFACED WEBSITE

Author: dfgdfg,

September 4, 2012

Hackers stole and leaked Over 1 Million Apple IOS Device ID From FBI


fbi_logo
Hackers have dumped online the unique identification codes for one million Apple iPhones and iPads allegedly lifted from an FBI agent's laptop. The leak, if genuine, proves Feds are walking around with data on at least 12 million iOS devices.

The 20-byte ID codes were, we're told, copied from a file extracted from the Dell notebook of a senior federal agent, who was tracking the activities of hacktivists in LulzSec, Anonymous and related groups. Supervisor Special Agent Christopher Stangl's machine was compromised via a AtomicReferenceArray vulnerability in Java in March, the black hats claim.

Once his computer was infiltrated by the hackers, a file was allegedly seized containing 12 million device records that included Unique Device Identifiers (UDIDs), usernames and push notification tokens as well as a smaller number of names, mobile phone numbers, addresses and zip codes. Members of the AntiSec crew leaked edited extracts of this data, having mostly stripped it of fanbois' personal information, on Monday.

The listed UDIDs, which include gadget serial numbers and other data so apps can distinguish between individual devices, appear to be genuine. However, by themselves they may pose only a minimal privacy risk once leaked online, so the effect of the dump is largely confined to embarrassing the Feds - and raising questions as to why agents have the information in the first place.

The most likely source of the data was either an iOS app developer or multiple developers, Mac Rumours speculates.

The Java exploit used in the attack is unrelated to the mega-bugs finally patched by Oracle last week.

It's a matter of record that Stangl was among the agents invited to an FBI-Scotland Yard conference call about the progress of investigations into members of Anonymous back in January. Members of LulzSec infamously eavesdropped on this call and leaked a recording after intercepting an email arranging the chat.

Email addresses exposed by this breach may have been used in a follow-up targeted attack that tricked investigators into visiting a booby-trapped website exploiting an at-the-time Java 0-day vulnerability. Rob Graham of Errata Security expands this plausible theory in this How the FBI might've been owned blog post.

The AntiSec activists behind this week's leak suggest the device info data was used as part of some FBI tracking project involving iOS devices, such as iPhones. Even they are a bit vague on what that might be. However the group goes into some detail in explaining how it apparently swiped the data:

During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of "NCFTA_iOS_devices_intel.csv" turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose.

The AntiSec group says it decide to published a portion of the leaked data in response to a keynote speech by the NSA's General Keith Alexander at the DefCon hacker convention in July. In part, Alexander sought to persuade hackers at the convention to consider a career at the NSA, a suggestion that predictably galled the black hats.

Author: dfgdfg,

August 28, 2012

Hackers Reveals over 1 Million Accounts of Banks and Websites


hacker
Hacker collective Team GhostShell leaked a cache of more than one million user account records from 100 websites over the weekend.

The group, which is affiliated with hacktivists Anonymous, claimed they broke into databases maintained by banks, US government agencies and consultancy firms to leak passwords and documents. Some of the pinched data includes credit histories from banks among other files, many of which were lifted from content management systems. Some of the breached databases each contained more than 30,000 records.

An analysis of the hacks by security biz Imperva reveals that most of the breaches were pulled off using SQL injection attacks - simply tricking the servers into handing over a bit more information than they should. "Looking at the data dumps reveals the use of the tool SQLmap, one of two main SQL injection tools typically deployed by hackers," the company's researchers explained in a blog post.

Team GhostShell said the online leaks, which are part of its Project Hellfire campaign, were made in protest against banks and in revenge for the rounding up of hacktivists by cops and government agents.

The team said it worked with other hacking crews, MidasBank and OphiusLab, on the attacks - and claims to have accessed a Chinese technology vendor’s mainframe, a US stock exchange and the Department of Homeland Security. It plans to offer access to these compromised systems to hackers who have the chops to handle them.

In a statement, the group threatened to carry out further attacks, leak more sensitive data and generally unleash hell.

“All aboard the Smoke & Flames Train, Last stop, Hell," Team GhostShell wrote. "Two more projects are still scheduled for this fall and winter. It's only the beginning."

Team GhostShell is lead by self-proclaimed black hat hacker DeadMellox.

Author: dfgdfg,

October 18, 2011

Hackers exposes Citibank CEO's private datas


citigroup
Hacktivists have published a dossier of personal information on the head of Citigroup in retaliation for the cuffing of protesters at an Occupy Wall Street demo.

Members of a group called CabinCr3w, a hacking gang affiliated with Anonymous, revealed phone numbers, an address, email address and financial information on Vikram Pandit, Citigroup's chief executive officer.

The exposé follows the arrest of a group of anti-capitalist protesters who allegedly sparked a ruckus inside a Citibank branch while withdrawing funds and closing their accounts. About 24 people were detained and charged with criminal trespass on Saturday afternoon, The Wall Street Journal reports.

In a statement, Citibank said only one of the protesters was actually trying to close an account, a request that it said was accommodated. The rest of the group were causing a nuisance and were repeatedly asked to leave before the New York City plod were called.

Last week Citigroup supremo Pandit offered to meet protesters, telling Businessweek that their sentiments were "completely understandable".

CabinCr3w previously published the personal information on the chief executives of JP Morgan Chase and Goldman Sachs. It also published the details of an NYPD officer accused of pepper-spraying Occupy Wall Street protesters.

The Citibank branch hubbub, whatever the rights and wrongs of what actually happened, has spawned a new campaign within the Occupy Wall Street umbrella. Op Take Back is encouraging people to close their accounts at high street banks and deposit their money with credit unions instead.

Author: dfgdfg,

August 9, 2011

BlackBerry blog hacked with riot-related threats


RIM’s Inside BlackBerry blog was just hacked some few hours ago after the company declared it would cooperate with UK Police to help bring individuals involved in the London riots to justice.

Although RIM really acted fast in removing the annoying blog post, I have embedded the page for you to view. Click the image to enlarge it.

blackberry blog hacked

Yesterday, the Canadian smartphone giant said it had engaged with the authorities and would local communications operators, police authorities and regulatory officials, issuing the following statement:

We feel for those impacted by this weekend’s riots in London. We have engaged with the authorities to assist in any way we can. As in all markets around the world Where BlackBerry is available, we cooperate with local telecommunications operators, law enforcement and regulatory officials. Similar to other technology providers in the UK we comply with The Regulation of Investigatory Powers Act and co-operate fully with the Home Office and UK police forces.
The blog section of the BlackBerry website was defaced by hacking crew TeaMp0isoN, which proceeded to boast about the attack on Twitter. "No Blackberry you will NOT assist the police," it said.

The defacement itself (archived by Zone-h here) contains a manifesto by the group, threatening the release of sensitive corporate directories supposedly stolen from the site if RIM carries through its promise to help the police.

BlackBerry Messenger service has reportedly become the communication medium of choice for rioters and arsonists who have attacked business across London and beyond in three successive nights since violence flared in the aftermath of peaceful protests in Tottenham on Saturday. TeaMp0isoN has threatened RIM that the addresses and names of RIM employees that TeaMp0isoN supposedly holds will be passed on to rioters if RIM assists the authorities.

Dear RIM,

You Will _NOT_ assist the UK Police because if u do innocent members of the public who were at the wrong place at the wrong time and owned a blackberry will get charged for no reason at all, the Police are looking to arrest as many people as possible to save themselves from embarrassment…. if you do assist the police by giving them chat logs, gps locations, customer information & access to peoples BlackBerryMessengers you will regret it, we have access to your database which includes your employees information; e.g – Addresses, Names, Phone Numbers etc. – now if u assist the police, we _WILL_ make this information public and pass it onto rioters…. do you really want a bunch of angry youths on your employees doorsteps? Think about it…. and don’t think that the police will protect your employees, the police can’t protect themselves let alone protect others….. if you make the wrong choice your database will be made public, save yourself the embarrassment and make the right choice. don’t be a puppet..

p.s – we do not condone in innocent people being attacked in these riots nor do we condone in small businesses being looted, but we are all for the rioters that are engaging in attacks on the police and government…. and before anyone says “the blackberry employees are innocent” no they are not! They are the ones that would be assisting the police.
The defacement itself looks like a standard run-of-the-mill hack and there's nothing to suggest, on the face of it at least, that TeaMp0isoN actually obtained access to corporate directory databases. Even if it did, RIM would doubtless stick to its previous promises to help authorities in any way it could.

TeaMp0isoN was previously best known for defacing the website of the far right English Defence League back in February.

Image credit: @jhfisher

Author: dfgdfg,

June 29, 2011

Anonymous releases Doc's containing Sophisticated Hacking Techniques


anon_displayv2.jpg
Anonymous has issued a beginner's guide to hacking online under the title, School4Lulz, which also contains sophisticated SQL Injection methods used by both Hacking Groups in their Hacking Attacks.

Shortly after the famous hacking group "Lulzsec" announced their disbandment, it now seems the online 'hacktivist' collective are clearly looking for buddies to continue its fight under the banner Operation InfoSec - and one way of recruiting fellow travellers, it seems, is to issue them with a Hacking 101.

School4Lulz is available at the group's 'Lolhackers' site, and provides information on hacking techniques including as the so-called 'SQL injection' method used by both Anonymous and LulzSec in a number of their high-profile hacking attacks. Instructor-in-chief 'Hatter' also dishes out some advice on probing site vulnerabilities.

A downloadable 'Basic to Advance (sic) hacking guide' Zip file containing PDF versions of the school's lessons, has also been posted at a well-known online cyber locker site and file hosting site.

Author: dfgdfg,