Showing posts with label wikileaks. Show all posts
Showing posts with label wikileaks. Show all posts

Thursday, June 23, 2011

Identifying the hacktivists of the emerging cyberwar

The hacktivist landscape has become increasingly cluttered, and while the anonymity they cling to makes clearly labeling each player difficult, the rising division between these groups is beginning to give them distinct identities.
The Internet has never been a safe place, and since its inception, and introduction to consumers, privacy and security have been a major concern. Of course, now that the average person’s computer skills are many times over what they used to be, that only amplifies the problem. Couple this with the fact that millions and millions of people are uploading mass amounts of personal and sensitive data and you’ve got a recipe for some serious cyber-insecurity. The advent of hackers with a conscience has exacerbated the situation while also putting a new twist on Web ethics.
Anonymous and LulzSec have become household names, and their Internet antics have captured the attention of just about everyone, including the CIA. But as identities and opponents merge, the cyberwar landscape has become confusing. Consider this an introductory course to the who’s who of hackers.

Anonymous

Anonymous first largely appeared on many radars after making worldwide headlines for its attack on the Church of Scientology in what they called Project Chanology. But more recently the group became a household name shortly after the WikiLeaks Cablegate debacle.
When various websites refused to host WikiLeak’s site, and credit card companies wouldn’t offer a way for people to make donations to the group, the hacktivists took it upon themselves to fight WikiLeak’s enemies. Anonymous used a series of DDoS to take down MasterCard, Visa, PayPal and drew the ire of international law authorities.
So where did Anonymous come from? The group organized via popular forum 4chan and past victims include the Church of Scientology, Internet predator Chris Forcand, and censorship proponents worldwide. Many of its actions have been motivated by the groups’ personal morals, which largely focus on freedom of information. Much of its recent work has centered on the Middle East rebellions, and the group has publicly announced its fight against Iran and Egypt. Other notable targets were HB Gary, Sony PlayStation (although Anonymous claimed innocence for the PSN collapse), and Bank of America.
The group’s various press releases and announcements are typically well written and almost business-like, as have been its denials. It has often had to defend itself against many groups claiming to be hacked by Anonymous. There have been rumors of inner turmoil that has led to different factions with separate agendas and personalities. At the moment, AnonNews is down due to DDoS attacks.

LulzSecLulzSec

If Anonymous is the student body president of hackers, LulzSec is the class clown. The group hasn’t been on the public scene very long, first gaining notoriety about a month ago when attacked Fox.com in retaliation for calling the rapper Common “vile.” But LulzSec’s first breakthrough performance came when it hacked PBS and posted a fake report that Tupac Shakur was alive. The group claimed that this was in response to negative attention directed toward WikiLeaks and Bradley Manning. LulzSec also claimed responsibility for some of Sony’s hacked web properties. Over the last month, LulzSec has also hit the FBI, Nintendo, and the CIA websites.
Despite some of its very serious and established opponents, LulzSec has time and time again affirmed it’s “in it for the lulz.” The group has also been extremely communicative with the public via its Twitter feed and even a phone request line, where it will take suggestions for hacks. The group has more of a prankster air to it then serious freedom defender, although its beliefs seem to align with Anonymous’. LulzSec has taking to mocking its victims more openly and in a more lighthearted tone than Anonymous has, though, giving it an entirely different reputation than its more serious counterpart.

Anonymous vs. LulzSec?

There were rumors that Anonymous and LulzSec were opponents. After a series of DDoS attacks that slowed down various online games because of malicious traffic, some frustrated 4chan users decided to begin their own DDoS retaliation against LulzSec. The group then used its massively popular Twitter account to attack 4chan, which Anonymous took as a personal affront. By later that day, however, both had denied such a rivalry, and the two have since united for Operation Anti-Security to expose faulty handling of user data.

Web NinjasWeb Ninjas vs. Anonymous and LulzSec

It’s a good thing Anonymous and LulzSec teamed up when they did, because Web Ninjas has its eye on them. It’s rumored Web Ninjas is the home of Th3J35t3r, who took down WikiLeaks shortly after it posted its stash of confidential diplomatic cables in fall 2010. Whether or not he’s a part of the coalition, the group insists it’s working for a “safer and peaceful Internet for everyone, not some bunch of kids threatening [the] Web and trying to own it for LULZ or in the name of publicity or financial gain or anti-government agenda.” The group released a large amount of information about the alleged identities of LulzSec hackers, including their whereabouts. LulzSec has denied the seriousness and truth behind these revelations, but an associate of the group was arrested today. LulzSec downplayed the amount of his involvement in the group, saying he is largely inconsequential to their operations. LulzSec also released the information of someone they believe attempted to out them.

IdahcIdahc

Residing (purportedly) outside this interwoven ring of hackers is Idahc. The Lebanese hacker is reportedly an 18-year-old computer science student and runs a one-man operation seemingly focused on Sony and Sony alone. He personally has moral issues with Sony, particularly for its treatment of George “GeoHot” Hotz and has said “If you want ethics, go cry to Anonymous. True lulz fans, stay tuned in.” He is thought to be behind many if not all of the hacks to various Sony Web properties. Idahc calls himself a grey hat focused on exposing the insecurity of Sony user accounts.

Despite their claims of independence and purported ethical intentions, the very nature of the groups inspires distrust. And it’s difficult to admit that with the apprehension toward supporting what are legally cyber-criminals, comes some sort of interest mixed with understanding: Whether or not you agree with all of their ploys, combating oppressive regimes and censorship while also exposing the careless liberties large corporations is difficult to oppose. Of course if you’re one of the many who’s had their email and password plastered all over PasteBin recently, you might feel otherwise.
http://www.digitaltrends.com/computing/identifying-the-hacktivists-of-the-emerging-cyberwar/

Tuesday, February 15, 2011

Anonymous could launch Stuxnet attack on Iran



Anonymous, the leaderless 'hacktivist' collective that recently launched DDoS attacks in support of WikiLeaks, claims to have got hold of the Stuxnet worm - and could use it to launch further attacks on targets including Iran's nuclear programme.


Israeli and US secret services are alleged to have created Stuxnet in order to launch the sophisticated cyber attack on Iran.
Anonymous claims it has obtained details of the worm from the emails of security researchers HBGary, after the collective attacked the company's website earlier this month in revenge for the US firm's help for the FBI in identifying alleged members of Anonymous.
As yet, Anonymous has not announced its intention to use the malicious code - but the 'online living consciousness' has signalled its disapproval of the Tehran regime in an open letter to the Iranian people, stating:
"People of Iran, you will not be denied your right to free speech and free press; your right to freedom of assembly, uncensored information and unlimited access to the Internet; your right to a life without oppression and fear."
The group plans to launch attacks in support of the country's pro-democracy 'green movement'.
But security experts have raised doubts over Anonymous's ability to exploit the worm in order to carry out attacks on Iran - in particular with regard to high-profile targets such as the Bushehr nuclear reactor complex, the target of the original attacks last year.

Russian experts working on the reactor recently warned the Kremlin that damage caused by the earlier Stuxnet attack could cause 'another Chernobyl' if Iranian nuclear chiefs press ahead with their existing timetable for bringing the site on-stream.
"It would be possible [for Anonymous to use Stuxnet in an attack]," Orla Cox of security analysts Symantec told the UK's Guardian newspaper. "But it would require a lot of work, it's certainly not trivial.
"The impressive thing about Stuxnet is the knowledge its creators had about their target. So even if you have got access to it you need to understand the target - that requires a lot of research."
http://www.thinq.co.uk/2011/2/14/anonymous-may-launch-stuxnet-attack-iran/

Anonymous releases 71,800 HBGary e-mails through new site



Try to take on Anonymous or WikiLeaks, and they'll get you back: The hacktivist site is single-handedly destroying HBGary's reputation for threatening its members and planning to sabotage WikiLeaks.

Any companies out there considering taking down Anonymous in return for the various DDoS attacks the group staged earlier this year might want to think twice. The hacktivist group recently infiltrated security firm HBGary Federal’s network and accumulated various confidential material and internal e-mails. The firm’s CEO Aaron Barr allegedly had plans to rat out Anonymous members to the FBI, and as revenge he can now find his and various other HBGary employees’ e-mails publicly posted (HBGary is HBGary Federal’s sister company). In addition to outing Anonymous members, HBGary was one of the handful firms orchestrating an image attack to destroy WikiLeaks’ reputation. WikiLeaks is reportedly preparing to release confidential documents belonging to Bank of America, and according to Forbes, HBGary would work for the company by “spreading misinformation, launching cyberattacks against [WikiLeaks], and pressuring journalists.”
Anonymous is now hosting a site (and there are a variety of mirrors as well) giving anyone access to 71,800 e-mails from the inboxes of HBGary executives Greg Hogland, Aaron Barr, Ted Vera, and Phil Wallisch. Subject matter ranges from a PowerPoint presentation detailing intentions to plant false stories about WikiLeaks to embarrassing love letters between company execs.
This is more than humiliating for HBGary – it’s financially ruining the company. Security firms Berico Technologies and Palantir Technologies have cut ties with HBGary. The released documents tied both firms to the operations defending Bank of American by sabotaging WikiLeaks, and now they’re wiping their hands of the situation. Aside from any business relationships Anonymous’ latest hack and release damaged for HBGary, the fact that a security firm was infiltrated by the group in the first place speaks volumes.
WikiLeaks holds powerful information, and it seems like security firms will stop at nothing to retain it – or at least threaten the group and its supporters to the point of keeping their mouths shut. But it appears that Anonymous has more in its arsenal than unsophisticated DDoS attacks, and the group is ready to use them.

 http://www.digitaltrends.com/computing/anonymous-releases-71800-hbgary-e-mails-through-new-site/

Tuesday, February 1, 2011

Arbor Networks targeted after DDoS report




Update:

Arbor Networks has sent over the following statement / Q&A:
Q: What is going on with arbornetworks.com?
A: We are experiencing intermittent outages of our Website and are working with our upstream provider to address the issue. 
Q: Is Arbor under a DDoS attack?
A: As a security vendor, Arbor is constantly the target of attacks and attack threats.  It is part of doing business in this space. 
Q: Anonymous is taking credit, is that true?
A: We are not going to comment on any group’s claims, nor are we going to comment on what we are doing to resolve this or any other Website outages.
[Note: The questions and answers were emailed to TTH by Arbor Networks. They are not our own.]
Original Article:
Arbor Networks was made an official target of Operation Payback for a short time earlier this afternoon. The Distributed Denial-of-Service (DDoS) campaign started after some of the individuals gathered online noticed Arbor Networks' commentary on Operation Payback’s recent DDoS actions, including a comment that they were small and unsophisticated.

Global messages sent to users on the AnonOps IRC network said that Arbor Networks insulted them “...by saying a number of things. It is your job to show them we are sophisticated and organized.”
The insult appeared in a blog post by Craig Labovitz, the chief security scientist with Arbor Networks. The post, titled “The Internet Goes to War”, said that the recent actions taken by Operation Payback, such as the DDoS attacks on MasterCard, Post Finance, Visa, and PayPal were both “relatively small and unsophisticated”.
“In short, other than [the] intense media scrutiny, the attacks were unremarkable… While the last round of attacks lead to brief outages, most of the carriers and hosting providers were able to quickly filter the attack traffic,” Labovitz said.
“In addition, these attacks mostly targeted web pages or lightly read blogs — not the far more critical back-end infrastructure servicing commercial transactions. By the end of the week, Anonymous followers had mostly abandoned their attack plans as ineffective.”
The Tech Herald has been online speaking with, and observing those Anons who are loosely associated with Operation Payback, for some time. The halt in DDoS operations was not due to a perceived failure. They stopped mostly because many of them felt that the point had been made. Others moved on to things such as Operation Leakspin.
This afternoon, as word of the Arbor Networks’ blog post filtered out, links to The Register started to spread in the IRC chatrooms. This led to calls for manual DDoS targeting. Soon after that, what started as a manual and unofficial DDoS campaign on www.arbornetworks.com, was quickly picked up by others. At 13:40 EST they were named an official target.
In true Anonymous fashion, some immediately followed the fold and targeted Arbor Networks, while others questioned the logic of such a response. Many viewed Labovitz’s comments as a calling out of sorts, so a response was needed. Think of it as a “this is what you get” type of DDoS.
Others took his comments at face value, and saw no reason for a response at all.
We spoke to a few people who refrained from participating in the Arbor Networks DDoS. Their reasons were that such an attack denies people access to the blog post, and as such removed Arbor Networks’ freedom of speech. The exact thing that Operation Payback was defending last week.
The targeting lasted about an hour. During that time Arbor Networks’ domain was reduced to a crawl or down completely. As we post this, the domain remains offline.
Online, one Anon reminded the others that they needed to remember the whole point of Operation Payback.
“Things like this [DDoS attacks] cause little harm and get publicity. Publicity grows the ranks. Arbor Networks simply said we're powerless. We simply demonstrated that they're wrong. It's a statement and it’s the sentiment that counts. No harm will be caused.”
Another remarked that the DDoS was a good test against Arbor Networks anti-DDoS software. "...their DDoS prevention failed, and their statement has been discredited."
We’ve reached out to Arbor Networks for comment, but calls were not returned by the time this went to press. As more information becomes available, we will update this post.

http://www.thetechherald.com/article.php/201050/6571/Arbor-Networks-targeted-after-DDoS-report-Update

Wednesday, December 15, 2010

Wikileaks movie....what all the fuss is about!

We have reverse engineered the opt in bot net malware (LOIC)

We have reverse engineered the opt in bot net malware (LOIC) and have been briefing our large global online presences on this particular threat as we provide ongoing threat alerts and briefings as part of our service.

As as sign of good will and information sharing, we are available to brief you as well - perhaps there will be some valuable data that could be of use to your organisation.

Feel free to get in touch to arrange a date and time.




How was it that a loosely-coupled group of cyber-protestors could launch -- with varying degrees of success -- targeted distributed denial-of-service (DDoS) attacks against sites such as MasterCard, PayPal, PostFinance, and the website belonging to a Swedish prosecutor?
Turns out it's quite simple. All an attacker need do is download the open source network stress testing tool known as LOIC (the Low Orbit Ion Cannon) that is widely available. Launching an attack with LOIC is mind-numbingly easy: just point and shoot. LOIC will then flood the target with HTTP requests, UDP and TCP packets.

Those participating in the pro-Wikileaks riots could operate on their own, or choose to connect their system to the "LOIC Hivemind" voluntary botnet that is centrally controlled by those behind Operation Payback.
Since the launch of the attacks, LOIC has been downloaded nearly 70,000 times.
Cyber protestors engaging in digital rioting such as web-site defacements, and denial-of-service attacks, and even inserting messages in malware have existed for some time. Such attacks being highly connected isn't new, either. They have been socializing on message boards and instantly communicating in Internet Relay Chat for many years.
What is new is the ease of which a tool such as LOIC can be put into action. "LOIC is extremely easy to use. It is designed so someone with little or no technical knowledge can quickly download and install it, and participate in DDoS activities," said Alex Cox, principal analyst at security firm NetWitness. "It also has the ability to be remotely controlled by a central IRC server, so that more technically competent operators can direct attacks en masse at targets, regardless of the participant's technical knowledge."
"There is a false belief that we are fending off casual attackers," said Joshua Corman, research director, enterprise security at the 451 Group. "However, I don't think the casual attacker exists any more. Just consider how powerful tools like Metasploit have become. There's also the malware kits that make obfuscating malware or building botnets trivial. You don't need to know anything to launch a successful attack anymore," said Corman.
Anyone on the receiving end of a LOIC packet burst would be sure to agree, and how technically savvy the attacker happens to be is made mute by the ease and power of the attack.
Cox agrees: "The attacker landscape is moving more toward "point-and-click" attack and exploitation tools. This is reflected in the many crimeware systems available in the underground, which includes DDOS, do-it-yourself botnet kits (Zeus, Spyeye, and many others) as well as exploit kits," he said. "In the past you had to have a certain amount of technical skill to participate, but now anyone can."
For security practitioners the big story within the pro-Wikileak and LOIC attacks may not have much to do about Wikileaks and the legalities or the politics of it all -- and everything to do about how swiftly, and easily, online attackers can be called into action against any target they wish.

http://www.csoonline.com/article/646813/loic-tool-enables-easy-wikileaks-driven-ddos-attacks

Monday, December 13, 2010

Friday, December 10, 2010

Police arrest boy of 16 over WikiLeaks attacks

Twitter and Facebook have also deleted accounts believed to be affiliated with Anonymous



Dutch authorities have arrested a 16-year-old boy in relation to the cyberattacks against Visa, MasterCard and PayPal, which were aimed at punishing those companies for cutting off services to WikiLeaks.
The boy was arrested in The Hague, and he will be arraigned before a judge on Friday in Rotterdam, according to a press release from the Netherlands' Public Prosecution Service. The boy, whose computer equipment was seized, has allegedly confessed to taking part in the attacks.
The Public Prosecution Service said he is likely part of a larger group of hackers.
The arrest follows a series of distributed denial-of-service (DDOS) attacks aimed at websites that have been critical of WikiLeaks, which has been releasing portions of 250,000 secret US diplomatic cables since late last month. The attacks seek to overwhelm websites and services by sending streams of meaningless traffic.
Part of the attacks originated in the Netherlands and the main site coordinating the attacks, anonops.net, was hosted in a Dutch data center in Haarlem. The site is down since police actions Wednesday.
Right after the police found out that there were cyberattacks coming from the Netherlands, the Team High Tech Crime started an investigation, the Dutch attorney general reported.
The attorney general also noted that "probably thousands of computers" took part in the attacks. The police are still investigating and will probably arrest more people.
Since the release of the documents began, several companies have decided to cut WikiLeaks off from their services, including PayPal, MasterCard, Visa and the Swiss payment transaction firm PostFinance, where WikiLeaks founder Julian Assange held an account.
In response, a loose affiliation of hackers called Anonymous have orchestrated DDoS attacks against those websites over the past two days or so, knocking many of the sites offline. The group has dubbed that effort "Operation: Payback." Other websites that have been attacked include those of vocal critics of WikiLeaks, including US Senator Joseph Lieberman and former Alaska Governor and vice presidential candidate Sarah Palin.
Twitter and Facebook have also deleted accounts believed to be affiliated with Anonymous.
On Thursday, BBC Radio 4  broadcast an interview with a 22-year-old who goes by the nickname "Cold Blood" and claims he is part of Anonymous. Cold Blood, who appeared in the BBC's studios, said that more people were downloading a botnet tool that enables them to perform a DDoS attack.
The campaign is aimed at companies that have decided not to deal with WikiLeaks, Cold Blood said, and is also a protest against what Anonymous believes is increasing control over the Internet by governments and the European Union.
"We are trying to keep the Internet open and free for everyone," said Cold Blood, who described himself as a software engineer.
WikiLeaks and its founder and editor Assange have come under fierce criticism from U.S. government officials and politicians for releasing the information, which is believed to have been leaked to the site by US Army Private Bradley E. Manning.
Manning has been charged with mishandling and transferring classified information in connection with the cables and a video of an Apache helicopter shooting civilians in Iraq.

http://www.computerworlduk.com/news/security/3252776/police-arrest-boy-of-16-over-wikileaks-attacks/

Operation Leakspin....


If this image is to be believed—and I have no reason not to, other than that I found it on the internet—the rebel squadrons behind Anonymous (attn. "news" hacks - that would be an entirely different group from Wikileaks and/or Wikipedia) are about to change their approach. So far, as we've witnessed, they have been launching point-and-click distributed denial of service (DDoS) attacks at companies perceived as the enemies of Wikileaks. Those targets included Mastercard, Paypal, and Visa (companies that froze donation funding), and Amazon (which denied hosting services). The new approach suggests more sophisticated thinking. This new mission, apparently, is to actually read the cables Wikileaks has published and find the most interesting bits that haven't been publicized yet, then publicize them.
In my opinion, this action would have far more positive impact. Anonymous often repeats the Orwell quote, "In a time of universal deceit, telling the truth becomes a revolutionary act." Looks like they decided to take those words to heart.

http://www.boingboing.net/2010/12/09/anonymous-stops-drop.html

Wednesday, December 8, 2010

DDoS Wars ...and now Mastercard!


Online hacktivist collective Anonymous, operating under the banners Operation:Payback and "Operation Avenge Assange" have launched a series of DDoS attacks against organisations and people seen as being opposed to Wikileaks and its spokesman Julian Assange.
Meanwhile, Operation:Payback itself has been subjected to counter-DDoS attacks thought to originate with US "patriotic" contra-hacktivistas.
Sites attacked by the Anonymous group have included PostFinance.ch, belonging to the Swiss bank which recently froze an account controlled by Assange, and also ThePayPalblog.com - the main blog operated by PayPal, targeted for refusing to process Wikileaks contributions. DNS outfit EveryDNS has also come into the Operation:Payback gunsights for cutting off Wikileaks' DNS service, saying that online attacks targeted at the leak site were crippling its other customers.
Over the last couple of days, other sites have been DDoS'd for various reasons by the Anonymous group, including the Swedish lawyers representing the women Assange is alleged to have committed sexual offences against. Charges made by Swedish prosecutors have since resulted in the issue of a European arrest warrant and Assange was yesterday cuffed in London: British judges have elected to refuse bail and the colourful Wikileaks impresario is now in jail pending an extradition hearing.
This process has angered the members of Operation:Payback sufficiently that they have also elected to mount strikes against the website of the Swedish prosecutors' office and briefly, according to anonymous* claims received by the Reg, against Interpol. (Interpol did issue a "Red Notice" calling for Assange's arrest at the behest of Swedish authorities, but in fact this has no relevance for British police dealing with a request from another EU nation: in such cases a European warrant is required for the UK cops to act.)
Yesterday, the Anonymous hacktivists decided to attack the site of US Senator Joe Lieberman as well, presumably as a result of remarks he has made describing Wikileaks operations as crimes violating the US Espionage Act - and hinting that Wikileaks' mainstream-media partners, collaborating on trawling and redacting files prior to public release, have violated the law also.
Some Operation:Payback members also elected to attack the site of former Alaska governor and vice-presidential candidate Sarah Palin for suggesting that Assange should be hunted down like a terrorist.
The Anonymous attacks have been run on through a chatroom, with users attaching their computers to a voluntary botnet for use in the DDoS strikes. Panda Security reported that as the Lieberman attacks began there were almost 1,000 users in the chatroom and nearly 600 machines in the botnet.
Naturally enough Operation:Payback itself has been subject to counter-DDoS efforts of varying strength almost since it began, but following the decision to attack Lieberman's official US government site the Anonymous operation began to be hit much harder and suffered dozens of outages itself, one lasting almost two hours. Panda Security analysts assessed that the intensified counter-DDoS attacks were coming from self-described American "patriot" hackers - playing contra to the Anonymous hacktivistas, perhaps.
Meanwhile US Army private soldier Bradley Manning, believed to have supplied not only the vast stash of diplomatic cables now being drip-fed by Wikileaks but most of its previous significant material as well (the Baghdad gunship videos, Iraq and Afghanistan "war logs" etc) remains in military prison charged with an array of security violations. His name is seldom mentioned any more in the ongoing saga of Wikileaks, Assange and the online scufflers aligned with and against them.
Operation:Payback uses a banner quote from John Perry Barlow, a founder of the Electronic Frontier Foundation:

http://www.theregister.co.uk/2010/12/08/wikileaks_assange_ddos_dustup/

Friday, December 3, 2010

Wikileaks Domainless




The DNS of Wikileaks.org and Cablegate.org have been erased in a move that may torpedo efforts to access the websites.
Amazon has terminated its cloud services relationship with the whistleblower site after pressure from a US government committee, according to a US senator

The websites can still be accessed via their IP addresses - http://88.80.13.160/ and http://204.236.131.131/, respectively, according to a Wikileaks list of IP address mirrors. Alternatives are also on the mirror site.
However, the DNS registration that allows a user to enter an alphabetical web address, such as www.wikileaks.org, no longer exists. Users attempting to type in the address will be served a blank page.
Wikileaks' DNS provider EveryDNS.net pulled the DNS registration at 10pm EST (3am GMT) after the site suffered a massive distributed denial-of-service (DDoS) attack. EveryDNS.net said in a post on its site that it had done so because the DoS contravened acceptable use policy.

http://www.ukfast.co.uk/internet-news/wikileaks-loses-domain-name-after-dos-attacks.html