Follow us on RSS or Twitter for the latest updates.

June 21, 2011

LulzSec Mastermind Suspect Arrested in Essex, England


The international hunt for hackers believed to have staged high-profile attacks on websites ranging from law enforcement bodies to Sony has led to the arrest of a teenager based in Essex, police say.

The hackers known as LulzSec claim to have been behind attacks on websites around the world, including the UK's Serious Organised Crime Agency (Soca), the US Senate and the CIA, as well as the games firms Nintendo and Sony.

British police said intelligence led them to arrest the 19-year-old at a home in Wickford, Essex, over the distributed denial of service (DDoS) attacks.

The teenager is Ryan Cleary, who lived at his family home. Investigators believe the arrest is significant and linked to the attacks based mainly at websites belonging to US institutions and organisations.

The operation involved two British forces as well as the US Federal Bureau of Investigation (FBI).

The police said they believed the attacks were linked and were carried out by the same group of hackers.

The teenager was being questioned at a London police station while specialist officers examined computer equipment seized from the address he was arrested at.

The Metropolitan police said: "Officers from the Metropolitan police central e-crime unit (PCeU) have arrested a 19-year-old man in a pre-planned intelligence-led operation.

"The arrest follows an investigation into network intrusions and DDoS attacks against a number of international business and intelligence agencies by what is believed to be the same hacking group.

"The teenager was arrested on suspicion of Computer Misuse Act and Fraud Act offences and was taken to a central London police station, where he currently remains in custody for questioning.

"Searches at a residential address in Wickford, Essex, following the arrest last night have led to the examination of a significant amount of material. These forensic examinations remain ongoing.

"The PCeU was assisted by officers from Essex police and has been working in co-operation with the FBI."

On Monday, Soca, the UK national law enforcement unit dubbed the "British FBI", was forced to take its website offline after an apparent attack.

The website was still down early on Tuesday but was back in service later in the morning.

In a message posted on Twitter on Monday, LulzSec said: "Tango down – soca.gov.uk – in the name of #AntiSec." The group later added: "DDoS is of course our least powerful and most abundant ammunition. Government hacking is taking place right now behind the scenes. #AntiSec."

The next day, LulzSec warned again on Twitter of its plans to step up the attacks by hacking into government websites and stealing confidential documents. "Our next step is to categorise and format leaked items we acquire and release them in #AntiSec 'payloads' on our website and The Pirate Bay," the group said.

Separately, the Office for National Statistics said on Tuesday it was investigating claims that the UK census data had been unlawfully accessed, following a message purporting to be from LulzSec.

It said: "We are aware of the suggestion that census data has been accessed. We are working with our security advisers and contractors to establish whether there is any substance to this.

"The 2011 census places the highest priority on maintaining the security of personal data. At this stage we have no evidence to suggest that any such compromise has occurred."

A post to the @LulzSec Twitter account later said: "Not sure we claimed to hack the UK census or where that rumour started."

Author: dfgdfg,

June 17, 2011

LulzSec - 1000th tweet statement


Lulz Security logo
Dear Internets,

This is Lulz Security, better known as those evil bastards from twitter. We just hit 1000 tweets, and as such we thought it best to have a little chit-chat with our friends (and foes).

For the past month and a bit, we've been causing mayhem and chaos throughout the Internet, attacking several targets including PBS, Sony, Fox, porn websites, FBI, CIA, the U.S. government, Sony some more, online gaming servers (by request of callers, not by our own choice), Sony again, and of course our good friend Sony.

While we've gained many, many supporters, we do have a mass of enemies, albeit mainly gamers. The main anti-LulzSec argument suggests that we're going to bring down more Internet laws by continuing our public shenanigans, and that our actions are causing clowns with pens to write new rules for you. But what if we just hadn't released anything? What if we were silent? That would mean we would be secretly inside FBI affiliates right now, inside PBS, inside Sony... watching... abusing...

Do you think every hacker announces everything they've hacked? We certainly haven't, and we're damn sure others are playing the silent game. Do you feel safe with your Facebook accounts, your Google Mail accounts, your Skype accounts? What makes you think a hacker isn't silently sitting inside all of these right now, sniping out individual people, or perhaps selling them off? You are a peon to these people. A toy. A string of characters with a value.

This is what you should be fearful of, not us releasing things publicly, but the fact that someone hasn't released something publicly. We're sitting on 200,000 Brink users right now that we never gave out. It might make you feel safe knowing we told you, so that Brink users may change their passwords. What if we hadn't told you? No one would be aware of this theft, and we'd have a fresh 200,000 peons to abuse, completely unaware of a breach.

Yes, yes, there's always the argument that releasing everything in full is just as evil, what with accounts being stolen and abused, but welcome to 2011. This is the lulz lizard era, where we do things just because we find it entertaining. Watching someone's Facebook picture turn into a penis and seeing their sister's shocked response is priceless. Receiving angry emails from the man you just sent 10 dildos to because he can't secure his Amazon password is priceless. You find it funny to watch havoc unfold, and we find it funny to cause it. We release personal data so that equally evil people can entertain us with what they do with it.

Most of you reading this love the idea of wrecking someone else's online experience anonymously. It's appealing and unique, there are no two account hijackings that are the same, no two suddenly enraged girlfriends with the same expression when you admit to killing prostitutes from her boyfriend's recently stolen MSN account, and there's certainly no limit to the lulz lizardry that we all partake in on some level.

And that's all there is to it, that's what appeals to our Internet generation. We're attracted to fast-changing scenarios, we can't stand repetitiveness, and we want our shot of entertainment or we just go and browse something else, like an unimpressed zombie. Nyan-nyan-nyan-nyan-nyan-nyan-nyan-nyan, anyway...

Nobody is truly causing the Internet to slip one way or the other, it's an inevitable outcome for us humans. We find, we nom nom nom, we move onto something else that's yummier. We've been entertaining you 1000 times with 140 characters or less, and we'll continue creating things that are exciting and new until we're brought to justice, which we might well be. But you know, we just don't give a living fuck at this point - you'll forget about us in 3 months' time when there's a new scandal to gawk at, or a new shiny thing to click on via your 2D light-filled rectangle. People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled.

This is the Internet, where we screw each other over for a jolt of satisfaction. There are peons and lulz lizards; trolls and victims. There's losers that post shit they think matters, and other losers telling them their shit does not matter. In this situation, we are both of these parties, because we're fully aware that every single person that reached this final sentence just wasted a few moments of their time.

Thank you, bitches.
Lulz Security

Author: dfgdfg,

June 16, 2011

LulzSec hackers claim breach of CIA website


The infamous rogue hacker group, Lulz Security, is back again with claims of packet-flooding the CIA’s Web site and leaking another lengthy list of email addresses and passwords.
CIA

Following their recent exploits with the U.S. Senate website, LulzSec has now made the CIA their target via a packet-flooding attack. While it’s highly unlikely that the CIA’s Website has any sensitive data residing on it, the notion of such a high profile target being attacked is bad enough. To be fair, packet-flooding simply means they crashed the CIA’s server, but it can be a rather problematic issue to network health if certain precautions aren’t taken. The key takeaway here is the target of the attack. Per LulzSec’s Twitter feed:
LulzSec Target CIA

LulzSec says they packet-flooded the CIA


In the second tweet, their proclamation of their most severe exploit at this point is the release of internal information from Bethesda Software. The release included server admin configurations, admin staff and blog user hashes, server logs, and mappings of Arkane, Bethblog, Brink codes, Brink signups, IDSoftware, Rage, and more.

While far more data was released with the Bethesda attack, the reason the CIA attack is considered their biggest is because of who it is, thus the potential repercussions.

Emails and Passwords

The last LulzSec-released list of email addresses and passwords totaled 26,000, and they were all obtained via hacked pornographic sites. This time, they’re keeping quiet about the sources of this latest list of culminated addresses. Regardless of the sources, here are 62,000+ email addresses and passwords just released. From their Twitter feed:

LulzSec releases 62,000 emails/passwords


Many users have taken to Twitter to let LulzSec know either how they have been attacked due to the leaked list, or how they have benefited by exploiting the leaked information. Make no mistake, LulzSec is essentially releasing this information into the hands of people with malicious intentions.

As with before, it is highly advised that you download the list and check for your email address so as to change your password. You can obtain the leaked list here (visit the link to download the file). Use the “find/search” functionality of your browser/text viewer to search for your email address once you download the 2.25 MB text file.

While neither of these latest activities were posted to LulzSec’s blog as official releases, it’s clear that they intend on utilizing any and every avenue they can to show off their exploits.

Lastly, while the image of a small group of individuals comes to mind in regards to the make-up of LulzSec, there is increasing speculation that the group — along with the equally-notorious rogue hacker group, Anonymous — is actually comprised of many people; possibly thousands. If true, this makes the efforts of these groups much more difficult to stop. However, as entities like the CIA and the U.S. Senate are targets of these groups, we may all soon find out just what the make of these groups really is.

How do you feel about LulzSec’s latest actions? Share your thoughts in the comments below!

Author: dfgdfg,

Lulzsec Leaked 150,000 Emails / Passwords. Check if you’re one of them here




Hacker group Lulz Security has been busy over the past five weeks. It has successfully managed to hack Sony BMG, Nintendo.com, Sonypictures.com, PBS.org, Fox.com and its US X Factor contestant database, Sonymusic.co.jp and InfraGard websites and has released over 150,000 names, emails, phone numbers, da.

Recently, the group has been taking hacking requests, bringing down a number of gaming servers, publishing a large number of login details for premium porn websites and on Thursday released a set of 62,000 usernames and passwords, reportedly stolen from Writerspace.com.

If you are worried that your email address, passwords and other sensitive information has been compromised, I saw a useful tool that checks if your details have been revealed online. Just type in the e-mail address and it will tell you if your details have surfaced online.

If you have, we advise changing your passwords immediately, or possibly consider setting up a new account.

This widget checks the lists with an email address and is the absolute best way to see if any of your personal information, such as email accounts, passwords, home addresses, telephone numbers and more, have been compromised. If your email is there, your other information very well may be as well. This widget checks all of LulzSec’s publicly released lists, not just the latest one. This makes it a more complete check than tools.


Kick off your day with our daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Author: dfgdfg,