Done, that was easy. Keep your money, we do it for the lulz
blackbergsecurity.us
blackbergsecurity.us
And .us domains, really?
Done right and to extremes it's quite a schizophrenic art form. His commitment to the craft is impressive, I can't really recall ever having seen someone sell it so hard and so long without breaking character. The youtube videos [1] from last year especially, even when he throws in an obvious gimme like a letter from a fan that's over the top he does the whole thing without a crack of a smile.
He must work in the infosec world somewhere, it's funny that those that know him don't out him. Not many trolls are willing to go the extra mile and commit their real likeness, etc.
With all that said I'd give it a 50/50 shot the intrusion wasn't fake, I could see a website with an intentional vulnerability or two added to troll the skiddies. It certainly would fit with the rest of the commitment to the performance.
Admit it, you still do. Look at how you talk about it. You haven't moved on.
Not that that's super relevant; it's a hacker game, hacker website, SHODAN is something of a hacker icon, too, I'd wager, and I happened to notice it. Bleh.
Just from the look of the site, it seems so much like a farcical joke on HBGary-type companies, I wonder if it's not a viral marketing campaign.
The site owner, with no sense of design or marketing, will then crap all over what little structure remains with each new addition, until the final result looks like a Geocities page.
[0] http://www.csoonline.com/article/220336/how-a-bookmaker-and-...
Are there any security firms that actually know what they're doing? I'm beginning to think there isn't.
I think the takeaway is that knowing what you're doing is less then half the battle here.
Just as most people know how to lose weight (diet and exercise), actually making those lifestyle changes can be very difficult. Similarly businesses, even security companies, let their security lapse because it's hard to take the time, effort and focus away from products, sales, cash to set up proper standards and controls.
Shouldn't they be able to prove their own concepts internally?
If you've got a handful of employees and your expertise is DDOS protection then are you going to use your next hire on a DDOS specialist to work on your DDOS protection product or bring in someone to make your website safer?
It was LulzSec. They've been attacking a number of security firms, lately.
Step 1) Don't use a CMS for your web site. Step 2) see step 1.
we've had , HB Gary, Sony, and a couple of others get hacked by sql injection or poorly configured web facing CMS systems.
Is it really that hard to figure out that if you're a target that is a stupid way to do things?
Put your CMS inside your firewall and "publish" it by generating a copy of your website as write only output.
Its not up to me of course. Sure put your open FTP server up there, maybe turn on anonymous access. Its like leaving the keys in your car in the long term parking lot, sure its convenient when you get back from your trip but are you really surprised when your car is stolen? Really?
In this day of drive-by malware injection by JPG or Flash zero-day vulnerabilities every single web site in the frickin' universe is fair game to get 0wned. Used to be if you ran some off the beaten path blog or enthusiast site it was pretty much too small to worry about. Not any more. Put up a machine with a web server and watch them come at you, Brazil, Argentina, the Ukraine. Blam, Blam, blam, test after test. IIS exploits? Apache Exploits? Got a CGI in there? Can you do local page execution? All your .htaccess files correct? Odd UIDs have logins?
I believe that there are better (and by that I mean less prone to being compromised) ways to manage the content on a web site of the OP's caliber than connecting it to a database.
Maybe I should sponsor a CMS version of the Pwn2Own contest.
Contemplate all possible interpretations of "technical debt" until enlightenment is achieved.
Attention is what this guy wants. Why are we even bothering about this on the first page?
Warning: INSERT command denied to user 'dbo325141527'@'74.208.180.97' for table 'bs_watchdog' query: INSERT INTO bs_watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:636:\"INSERT command denied to user 'dbo325141527'@'74.208.180.97' for table 'bs_accesslog'\nquery: INSERT INTO bs_accesslog (title, path, url, hostname, uid, sid, timer, timestamp) values('Cybersecurity For The 21st Century, Hacking Challenge: Change this website's homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black. DONE, THAT WAS EASY. KEEP YOUR MONEY WE DO IT FOR THE LULZ', 'node/1', 'http://news.ycombinator.com/item?id=2639058' in /homepages/6/d325020610/htdocs/includes/database.mysql.inc on line 128