LulzSec Exposed
seclists.org
seclists.org
There will always be another garishly-named group willing to sql-inject and xss the low-hanging fruit.
edit: Indeed, following the thread reveals http://seclists.org/fulldisclosure/2011/Jun/88 -> http://pastebin.com/mmvBT7n5 The root entry dated May 13.
I think these kids have exposed the true lack of security around the world in general and it has raised some serious attention for other people to take a look at their own defence, which is good in some respects.
What they have also successfully done is lowered peoples trust in massive corporations which in turn is going to hurt the economy globally, which is not good in any respect.
I think they should have hacked it then made the companies aware, not the whole world. It's hard enough getting someone to trust and pay for services from a company when they think they are safe, they really won't when there is no trust there at all.
And I'll remind everybody that we are dealing with SQL injections and plain-text passwords. And it's 2011.
You said, the hackers "lowered people's trust in massive corporations [...] which is not good in any respect."
It seems pretty clear to me that Sony is most decidedly not deserving of consumer's trust - and without these public disclosures, we would have never known that.
Certainly - as I learned in the Gawker security breach - it sucks to have your login details broadcasted to the rest of the internets. But, after a few hours restting passwords across the internet, I was good to go. I expect the affected consumers in this case will have a similar experience.
And, that experience is a far better one than having your data stolen by a more malicious group of hackers, who use it for far more damaging means, without your knowledge.
So, I don't believe that this group of hackers are any kind of heroic. But even if their motivation is suspect, I do believe they're performing a type of public service. Teaching us all that it's the height of ludicrous to hand over your sensitive data to Sony, and expect them to keep it reasonably secure from basic script-kiddie tactics.
High - These are high security risk, such as email accounts, and anything that can gain access to or control something that relates to it (domain names, server access, stuff like that). Medium - Passwords that give you access to very specific systems that if someone gained access would ruin your day but won't allow them to do anything really bad (personal home file server, the password to your FTP, web forums where you have a trust based relationship with people) Low - If it gets hacked, who cares. Won't make a bit of difference (throwaway accounts on forums, news sites, stuff like that).
Also, defacing the other music sites does nothing more than raise the profile of their hacking "skills".
As I mentioned, yes they are making people aware that there are security issues that companies need to iron out and Sony are having some serious bad media recently but who is this really helping? It's not helping the market and its not helping consumers?
You and I both know that they should not be storing stuff plain text or with some bad security practice and we understand what it takes to make it right but to the common person they are instantly put off all places where they have to put card details. The overall perception of the web is stepping back 15 years in the eyes of the general consumer, soon people will be afraid to put their details anywhere.
I agree completely with what you are saying but that's from my point of view, I'm thinking general consumer confidence.
But not throwing egg on their face was helping less. As long as security bugs are mostly invisible they don't get fixed.
> They should have informed Sony of the issue.
If Sony needed to be told to lock their doors it's only because they didn't care. (At least in 2011. It might have been different in 1997...)
> It's not helping the market and its not helping consumers?
In the end, it helps the market and the consumers. If companies get away with broken security that penalizes, by comparison, other companies who spend more to develop a secure product, or who produce a less ambitious product because they know it's all that can be done securely.
Customers win because they get a more realistic view of what they're buying.
> You and I both know that they should not be storing stuff plain text or with some bad security practice and we understand what it takes to make it right but to the common person they are instantly put off all places where they have to put card details. The overall perception of the web is stepping back 15 years in the eyes of the general consumer, soon people will be afraid to put their details anywhere.
As they should be. You can see how well protected everything isn't.
> I agree completely with what you are saying but that's from my point of view, I'm thinking general consumer confidence.
Confidence through ignorance doesn't seem like a gift.
Some people see the end of the internet as we know it in these stories, I see new opportunities to sell locks :-)
As reported here some logs are old: http://seclists.org/fulldisclosure/2011/Jun/88
http://pastebin.com/mmvBT7n5 (May 13th, 2011)
boards.808chan.org/fail/res/263.html (2010)Guess this was a joke/defamation attempt after all.
"Someone just sent over $7200 worth of BitCoins. Whoever you are... thank you... Balance: 7853.35 USD #Speechless"
From what I observe, it just keeps getting progressively easier for the FBI to do that. Not harder.
The truly paranoid might like to rent a botnet and build their own tor network on top of it or something like that.
In short: the fundamental nature of TCP/IP is such that if you are sufficiently motivated, and dont mind horrible latency, even the FBI/tptacek cant identify you.
We break apps and build products and that is just about it. (We've also never done business, to my knowledge, with the government.)
[1]
Btw, what will be the jail-sentence in US for this you think? Let's hope he's a minor - looks like a teenager.
(edit: seriously, though, something seems just a bit off here.)
Lulzsec response here: http://pastebin.com/yut4P6qN
I like the picture of the kid doing coke.
Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.
The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it.
The highest-risk category is true information warfare, targeted attacks by other governments and large entities. As the previous replier said, just look at Stuxnet. You don't have to be a government for this to be a real threat. Imagine if Nintendo had compromised Sony's servers, and somehow loaded corrupt firmware onto the Playstation update system...
These threats are real and constant, and anyone with sensitive data needs to be aware of them. Simply firing up iptables and disabling root SSH isn't sufficient - you need to be aware of the intricacies of your system on a day-to-day basis.
Computers and especially networks are just fundamentally insecure for the purposes of high-value information.
This is the same reason why internet voting will never be a good idea.
http://www.youtube.com/watch?v=_GjmRwfkRXY
Electronic and Internet Voting (The Threat of Internet Voting in Public Elections)
It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some US local elections a while back.
In brief, that system isn't safe because someone can obtain your reciept and therefore your voting rights from you by coercion/incentives. Votes should never be verifiable, because then they can be bought. Vote reciepts would be pretty valuable...
It's nearly legal to buy votes anyway, but they just call it advertising.
That's one thing a lot of non-experts don't appreciate about these sorts of attacks. They are not terribly sophisticated, nor are they terribly malicious. This is why I put so much blame on Sony and Gizmodo, because they're not being attacked by some elite team of super hackers with an elaborate plot to destroy the company. Rather, they're being attacked by bored teens who are using crude techniques that no public facing website should be vulnerable to in 2011 and they are just dumping what data they gain access to on the internet. Compared to the sort of mischief a talented and dedicated hacker could achieve this is nothing.
starts off with <Topiary> telling everyone to get off this network, ED IRC (it could be a server in their own network, but if that were the case their network would already be breached)
<pwnsauce> calls for a new operation (similar to how anon has various operations).
Then <Topiary> admits to hiring a botnet to help them.
<joepie91> chimes in, talking about an irc server exploit is basically killing his computer.
<storm> asks for an exploit, <lol> says he has it, but is scared to get it out and give it to him (meaning that, for all his "security knowledge" he still managed to get viruses on his stuff.
About half an hour later, <Topiary> insults a few people they want to crack, and mentions an apache 0 day exploit. The rest is them asserting their masculinity, and a mention of the gawker root.
oh, and then a message saying one of the guys is in FBI custody, but I assume that's not part of what you wanted translated.
Check this email, it's the USA looking to hack Libya's oil infrastructure: http://pastebin.com/Jf406RVs
I didn't know war got that advanced:)