CIA.gov Possibly Down, LulzSec Claims Responsibility
readwriteweb.com
readwriteweb.com
It puts me on edge that these idiots would pick such media-friendly targets to strafe with their clueless bandwidth wastage; not looking forward to the next round of "cyber security" laws one bit.
"Hey dad, tell me just one more time about how when you were a kid you used to be able to make TCP connections freely and without the connection first being authorized by the NSA." "Go to sleep, son."
I really hope that scenario never happens, but if we get more Lulzsec like things we will get laws making sure everything is regulated and monitored.
Here is the whatweb output: ./whatweb https://online.citibank.com https://online.citibank.com [200] X-UA-Compatible[IE=EmulateIE7, IE=EmulateIE7], UncommonHeaders[jid], Cookies[JFPWebAppInfo,JSESSIONID], Title[Citibank Online], Country[UNITED STATES][US]
Looks like something Java-based. It's fun that sometimes software gets so large that they miss a gaping security hole like this.
I suspect telecoms would actually oppose most forms of regulation a government may be interested in, not out of any desire to protect their customers, but simply because it would decrease profits.
I enjoy John Wayne's The Shootist more and more.
http://www.youtube.com/watch?v=7JUfOIglaSc "Books, this is nineteen-ought one, the old days are gone and you don't know it."
"God made crackers, Metasploit made 'em equal."
http://en.wikipedia.org/wiki/Rainbows_End
Note: one of the many interesting things about the book is that it creates a scenario where this kind of control is very much a grey area.
Nothing that would make anything better, and everything that would mean they have more powers.
Also, whenever a government really wants to do something, they'll use any excuse that's available. For example; PATRIOT ACT, DMCA, Iraq Wars, etc. etc. For cyber-security, if none of this Anon or LulzSec stuff happened, it would be Russian or Chinese hackers that are infiltrating and by god we must protect Americans from those evil foreign hackers. Or they would rely on the terrorist excuse: the terrorists are losing in real life so they need to re-build support and attract younger people so why not hack some sites and gain new supporters that way? Beheadings and suicide bombings really fuck up the recruitment rate for terrorist organizations.
See how easy it is to come up with an excuse that the internet needs to be locked down?
Wiretapping scandal became public circa late 2005 - http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_co...
Random collection of additional federal political 'scandals' since 2005:
1) This goes from 2001 - 2008 so skip to 2006 - http://en.wikipedia.org/wiki/List_of_federal_political_scand...
2) http://en.wikipedia.org/wiki/List_of_federal_political_scand...
Additional 'scandals' with solid link to US Government:
1) http://www.wired.com/threatlevel/2011/05/gps/
2) http://www.techdirt.com/articles/20110218/02143213163/more-h...
3) http://www.thenation.com/article/161057/wikileaks-haiti-let-...
4) http://www.ban.org/ban_news/2010/101022_caught_exporting.htm...
5) http://www.theinquirer.net/inquirer/news/1026810/us-governme...
6) http://www.elizabethwatson.org/featured/wikileaks-reveals-a-...
Just some random examples I pulled in 5 minutes. I don't believe the argument "...not to mention illegal that would be." or "The US govt doesn't need any more scandals..." has any bearing whatsoever on their decision making process at the level of authority needed to authorize something as a false flag operation for various reasons.
Since when has the government decided what to do based on need?
Come on. Since when did that stop a government from doing something?
headlines like 'witty 19 year old college student breaks into CIA' is a lot less scary to the general public than 'chinese hackers exploit CIA website'.
Is there any evidence at all, though, that it's a false flag operation? So far as I can tell, the argument is implicitly "It's impossible for anyone in the world to be anywhere near as stupid as LulzSec appears to be, so it has to be a government plant." Unfortunately, that runs afoul of the maxim to never underestimate the depths of human stupidity...
Or is this more said in jest, a way of just pointing out that the script kiddies behind LulzSec are really, really stupid and doing something that threatens to undermine a free and open Internet?
And lastly: Always ask the question "Cui bono?" (Latin for "who's gonna profit from it?"). In the Anon case it was clear; they were activists trying to express their support for wikileaks and their anger on organizations that ceased support for wikileaks. But who's profiting from what LulzSec does? They themselves? Think again!
* I do not condone this course of events, just a prediction.
What happens when 11 year olds can Metasploit a predator drone and drop a Hellfire on their school?
But the most surprising thing about them is how confident they are they won't be caught. Can they really be that sure that they will never be caught doing these attacks? Or are they just reckless?
But if they are for real, it might be understandable if they actually had a cause, and a good one. Doing it for the lulz, doesn't seem like a very good cause, and it's only going to give politicians more ammo to restrict the Internet because of "these crazy hackers" that prove the Internet is very "chaotic".
At least when Anonymous attacks they have a pretty good cause, that could actually be supported by most of the public. LulzSec attacks are getting less and less defensible, and maybe even suspicious.
In that case, the publicity could translate into dollars.
Hacking websites isn't really that hard. Especially if you're just shopping around the net for vulnerabilities and then announcing what you hit post-facto (a "called shot" would be a bit more impressive). This is well within reach of invincible-feeling teens. It's a statement about the poor level of security we have; this stuff really is way easier than it should be.
Briefly DDOSing a government website is not a "worst case scenario" by anybody's reckoning.
Kind of self-fulfilling prophecy, it'd be; also a neat hack. Truly anonymous DDoS, too ;-)
Or more interestingly, if they were in the process of hacking or something and wanted the cover of a torrent of strangers trying to reach their site.
Would this effect happen so quick? I guess they do have a lot of followers, but I'd hope that even if all of them did what I did they could survive that amount of hits?
This actually serves two purposes:
1) provides some security by sufficiently isolating the actual system from public access (it can be locked down to only serve requests from the CDN)
2) Prevent the type of DDoS described in the parent comment. Akamai is designed to handle the load from things like the Grammies or Superbowl.
For example, it's been documented that the White House uses Akamai extensively.
Usually (always?), when a site is using akamai, a reverse DNS lookup for the site's IP yields some akamai domain name, rather than the original one. (This is the case for whitehouse.gov, for example.) This is /not/ the case for the CIA - they seem to do their own hosting. (root.ucia.gov and relay1.ucia.gov come up)
So, it's plausible that the site is in fact run by a very small collection of servers, and that they were sitting ducks for the next red-bull-drinking teen wanting to "hack the CIA".
I can load cia.gov just fine. It doesn't even appear to be slow. I opened up the CIA World Factbook then checked their press section & what's new on cia.gov and there was nothing about it going down.
Also, kudos to the CIA for flipping to HTTPS by default.
2 hours ago: your comment on this post. Don't you think they had some time to take it back up?
I wonder what the CIA are going to do, especially because LulzSec is directly targeting them now.
@Below and HBGary was a IT security firm after all...
Mostly, though, I'd say this is just egg on their face.
Great article btw in the current Popular Mechanics [1] about the new militarized CIA and whether or not that's a Good Thing.
[1] http://www.popularmechanics.com/technology/military/news/spi...
I posted this news 15 minutes before this submission. http://news.ycombinator.com/item?id=2659263
Can someone explain to this newbie why mine disappeared so quickly, but this stayed? I don't have a problem at all, I just wish to understand the system thanks.
A broken link gets it immediately marked down? Makes sense.
If we can't open the site, we scratch our heads and move on. On the other hand, if we can open the site, we scratch our heads and say: "Yeah right! The site isn't down! No upvote for you!"
If I understand HN correctly, nobody can now submit the CIA home page as a story again.
Maybe a good start-up idea, Internet 911. Grey/White hats find vulns => report => issue gets the attention it deserves. Made me laugh, but something like cyber-police :D
From - Sat Aug 07 23:58:30
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00800000
X-Mozilla-Keys: Message-ID: <[re-dictated]@gmail.com>
Date: Sat, 07 Aug 2010 23:58:24 -0500
From: Chris <[my email]@gmail.com>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.11) Gecko/20100713 Thunderbird/3.0.6 MIME-Version: 1.0
To: sanjose@f-secure.com
Subject: fox news
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Dear F-Secure:
Many Fox news opinion sites(Glen Beck, Hannity, ect) are vulnerable to multiple attacks- read LFI(getfile.php), XSS(search), ect. I would try to contact them, however, the LFI leaves their mail servers vulnerable to ease dropping. As a well established security reseach company I feel disclosure of this should be left to you(the pros); plus it would make a good blog post.
LulzSec feels (to me) like just a group of bored teenagers messing around, randomly attacking whatever websites they can. I suspect if the gov't wanted to scare people, they wouldn't just sponsor/create a group doing things "for the lulz" - they'd make it out to be something larger and scarier.
[1]https://www.cia.gov/library/publications/the-world-factbook/
Why bother running stories about random DDOS's and defacings? It's even less interesting or important news than mainstream media's celebrity gossip.
lol parallels
Xerxes: http://th3j35t3r.wordpress.com/2010/12/09/time-to-speak-up-p...
He's actually laid another ultimatum (for the umpteenth time in the last 3 months) promising revenge. His first act seems to be that irc.lulzco.org is down. We shall see if anything else comes from his indignation.
What other fun wars can we just toss these people into?
No, I don't actually want an answer to that. Calling him a "greyhat patriot" is sufficiently descriptive to mark him out as some kind of Lulzsec mirror image.
If we're gonna have a Lulzsec, we might as well have an anti-Lulzsec as well. Makes life slightly more entertaining.
I bet The Jester is as middle-class as the LulzSec people.
Well, almost certainly. I doubt he'd claim to be anything else (isn't everybody middle-class nowadays? [1]) so I'm not sure the point of this comment.
[1] OK, not everybody is middle-class. The people who aren't are either too uneducated to use a computer, or too busy snorting coke off hookers asses on their private jets to be interested in this crap.
There's a bigger game that's being played: making the internet safe for commerce. The Jester is not playing that game, he's going to be playing the "middle-class squabbles" game that distracts people from the bigger game.
I like the ad hominem though, keep it coming.
Seriously, at what point can we start attributing things to malice? Attributing such large things to incompetence is kinda scary; we're hiring or voting for morons. That doesn't frighten you?
If, that is, we still care.
Seems like a false flag to get DDOS tool anti-laws passed
Do I need to remind people that these laws are voted on by your elected representatives?
The patriot act is a result of democracy. Don't want cyber security laws? Start by educating people and voting for people who don't want cyber security laws.
Where is the evidence of this false-flag operation? There is none. Why would congress need to conduct such a false-flag operation when they wouldn't have much trouble passing such a law regardless?