LulzSec hacks into Bethesda Softworks accessing 200k Brink user accounts
pastebin.com
pastebin.com
I wonder how long before they get their .com taken from them and have to flee for another tld.
we grabbed all their source code
I'm not going to pull down that torrent, but if someone does, can you tell me exactly what they mean by this? Did they just pirate and release the source for a bunch of major video games? Did they grab any of the art?Turns out it's a bunch of mysql-dumps in txt format, some admin passwords and server logs. I am guessing there's a lot of pain in there, but I only had a quick glance.
The packed file was ~15MiB. No code or art in there as far as I could see.
EDIT: Here's a mirror of the files, I'll be taking these down soon for obvious reasons: (removed)
Looks like they're just internal mappings, some sql dumps of users, and a few other things. Nothing fun unless you wanna mass spam some people.
"Contact us: 614-LULZSEC"
A phone number? A cursory google search didn't come up with anything informative, except that someone commented that it was a number pirated by LulzSec with call forwarding (http://mrnumber.com/1-614-585-9732). I'm certainly not going to call it myself, but I'm just curious as to what this is, how they're using it, and what do you find on the other end. Thoughts?
https://secure.wikimedia.org/wikipedia/en/wiki/Area_code_614
It is a noteworthy news event when high profile sites are hacked, regardless of the perpetrators. There are a whole ton of people who use HN to follow tech news.
tl;dr: don't feed the trolls
Lulzsec may have given some people the wrong impression by hitting Sony and thus suggesting that they were activist minded like the AnonOps program they grew out of, but they'd always been honest about the real reason from day one: "we do it for the lulz". The lulz in this case are inexorably intertwined with the attention seeking.
You can bet that this will be used to push through draconian legislation in the interest of "security". I wouldn't be surprised if hacking/cracking/piracy became the new equivalent of possession in these coming decades.
The people saying that this type of thing is going to cause an "internet crackdown" of sorts have had their head in the sand for the last 15 years. Doubly so for the last 5-10.
Media companies have been screaming and crying about multi-billion dollar losses, and using all of their lobbying ability to get an "internet crackdown" to happen.
It already has. You could argue that most of the crackers of today are a result of it.
The government's attitude has largely been static on the issue, but they need a general population outcry to push through/rubber stamp legislation that's no doubt already written somewhere.
Even if you need to insert your drivers license to the computer in order to access it, and every packet you send is signed with a user-specific hash, the only people it's going to matter to are the people who aren't doing anything wrong right now.
Cracking down is just going to create more crackers, and most of us in the middle probably won't really notice.
Dear Senator Lamar:
We have exchanged ideas in the past; see the below message. I am now writing to report a different issue. Website vulnerabilities in the Senate.Gov and House.Gov website. I am not sure if these have been reported to the proper person as of yet; I did email Senator Corker.
Below is a list of vulnerable urls for senate.gov
URL Redirect needs to be sanitized here: >http://www.senate.gov/cgi-bin/exitmsg?url=www.hackersite.com
Here JAVA is not sanitizing input properly. There may be a chance that this can be used to launch a larger exploit on the servers hosting the website: >http://www.senate.gov/artandhistory/art/common/collection_li...
This is called an XSS (Cross Site Scripting) exploit. Here a person might add malicious code to the page to do what ever the language will allow. >http://www.senate.gov/general/contact_information/senators_c...
Below is a list of vulnerable urls for house.gov
This link suffers the same problem as the first one posted for senate.gov; URL redirect needs to be sanitized: >http://clerk.house.gov/redirect.html?title=Library+of+Congre...
I wanted to bring this to you attention in hopes that it will be fixed. Thank you for your time.
Sincerely,
Christopher Woodall
On 03/01/2010 04:04 PM, Correspondence_Reply@Alexander.senate.gov wrote: > > > > March 1, 2010 > > > Mr. Christopher Woodall > > Dear Christopher, > > Thanks for getting in touch with me and letting me know what's on your > mind regarding identifying medical neccessities of government employees. > > Although no legislation has been introduced in the 111th Congress > regarding this issue, I'm always pleased to consider new ideas that will > benefit the people of Tennessee. These are serious times, and the > willingness of good people to get involved is very important. > Suggestions from my constituents play an important role in determining > what initiatives I will pursue in the Senate, and I'll be sure to > consider the issues you've raised. > > Sincerely, > > Lamar
Looks like a few of the issues have been cleared up. I have more for USAJobs.com and a myriad of government sites. No one listens to regular joes.
I'm not sure if they would even know what "website vulnerabilities" are.
As customer (of Bethesda, both Sony divisions and Codemasters) I'm also being even more careful now. I only put information into sign-up forms on a need to know basis. If they don't need to ship me something, they don't need my address (although sometimes this interferes with credit card validation). If they don't need my real name (so other users can identify me, usually), they get a fake one. And there's rarely a good reason to hand out a phone number or birth date anymore.
In addition to this, for many years now I've been using one email address per service, which has served me well in both identifying sites that leak/sell my personal information (very popular after a company goes under) and easily filtering the resulting targeted phishing/spam.
(As far as I can gather, someone they were [potentially rightfully] in a dispute with used the 2600 irc servers. Go figure...)
If they did manage to get 200k Brink accounts, I doubt most of them have any personally-identifiable information tied to them.
It's nice that they did that, but it's kind of like breaking into your house and stealing everything except your Rolodex because, well, that would be a dick thing to do.
I tried to cook-up a comic store analogy where the loyal customer is most concerned about their orders and personal contact info being stolen than the merchandise of their favourite shop, but that analogy ignored the fact that what LulzSec did to Bethesda is essentially the following: making copies of the shop's inventory manifest, latest promotional program, and names of customers in a Rolodex, and then publishing all that info online (or in a local comic hobbist newsletter). Other than the loss of potential business and the trust of their customers, are the owners and employees likely to suffer as a result of this break-in? I tend to think that lost business will be minor, especially if customer privacy and interests are not noticeably compromised by the break-in.
Not trying to start a morality debate (unless that's welcome here?). I just wanted to point out why I tend to see "black hat security audits" as generally to the victims' benefit, when individuals aren't likely to suffer as a direct result. In the reality of my above analogy, the comic shop is likely going to invest in better security after this kind of break in, which is a positive outcome for the business and the customers. Only the very paranoid or "security minded" customers will choose to take their business elsewhere after the break-in, which likely amounts to very little lost business to the shop.
The fireworks would be epic :)
It's all fun and games until someone decides it's just easier to kill you.
I can't help but think what a much better world this would be if every objectionable act was handled in such a way.