Anonymous Pledges to Take Down Facebook
news.cnet.com
news.cnet.com
They aren't stupid. They surely know that waging war against Facebook would be silly.
I'd bet this is someone completely different, looking to pose as Anonymous. Try looking at the sources --- you won't be able to trace it back to an announcement by Anonymous. So who are these guys?
EDIT: Rough translation:
----
Greetings, world. We are anonymous.
In this short time lapse, we've heard and saw the panic of Facebook progrmmers. It seems that now they are offering US$ 500 to find errors on their webpage. It is clear that nothing of this is real. They only do this to make the world believe that they have the power, and nothing can be done against them. As we have said before, we are tired of Facebook stealing people's information and selling it to powerful people like pieces of paper. This regime has come to an end.
Facebook will cease to exist.
In November 5th the Facebook Operation will take place succesfully, and nothing will be able to stop it.
We are anonymous, we are legion. We don't forget, we don't forgive. Expect us.
----
Now that I listen to it carefully, the way they put it sounds pretty weird, to say the least.
Sounds about right to me. Seemingly random target fits their MO.
That's not to say that Facebook won't be attacked, but most likely not by the people that form that Anonymous that WE think of when we think Anonymous. Although I suppose that any one or group could be Anonymous because of how they define themselves.
Of course, their strength is also their weakness. Without any names, what is and is not 'Anonymous' can forever be questioned. Like others, I want to say "they are too smart for this," but then they ('they') also attacked Amazon a few months back and that certainly did not go as well as the Visa attacks...
meant to say - if you're posting as Anonymous, you're Anonymous.
"#OpFacebook is being organised by some Anons. This does not necessarily mean that all of #Anonymous agrees with it."
First, they try to look united on twitter and to media, but they quite aren't. Second, they are INCREDIBLY naive. Third, they are OBSESSED with attention of the media.
They were actually planning the attack on #OpFacebook channel (so no, it was not fake - and the channel still exists, but they probably realized it is a joke so they turned it into a joke). After they realized they quite can't attack their servers, they thought it would be better to get people passwords by "botnet keylogger" (and I am not making it up), steal about 1 million accounts and then DEACTIVATE THEM ALL, which would I guess do something terribly evil to Facebook.
Someone brought the question if this doesn't give media and police the right to label them as terrorist, and someone else replied that "police and media are the real terrorists". After that sentence, I laughed too loud and had to leave the IRC.
edit: and apparently, it is still going on - http://pastebin.com/nzaNLWfF . Or maybe not, who knows
edit2: ....and they closed the channel for speaking now. Oh well, it was fun while it lasted.
That is not a bad approach. If you assume Facebook's network infrastructure is rock solid, then attack Facebook's human infrastructure by flooding them customer services calls.
I don't think you need a botnet keylogger to grab Facebook passwords because their users are easily confused or duped. For example, ReadWriteWeb wrote about Facebook's plans for login federation and many Facebook users, googling for "facebook login", found this blog and tried to login there!
https://www.readwriteweb.com/archives/facebook_wants_to_be_y...
The 'original anonymous press release' was Uploaded to youtube by FacebookOp on Jul 16, 2011, and picked up by media only recently.
None of the usual anonymous twitter accounts (http://twitter.com/anonymousirc http://twitter.com/youranonnews http://twitter.com/anonops http://twitter.com/#!/AnonymousPress etc) or the irc channel (irc.anonops.li) have any mention of the operation.
It is of course not impossible to create a new youtube user and a new twitter account called 'facebookop' and post a video proclaiming to attack facebook in the name of anonymous. Anyone can do it.
I'm wondering if this is an spinoff from Anonymous, a false flag, or even both things at the same time (possible).
No. FacebookOp has gone entirely unmentioned by #AnonOps. Not because #AnonOps is unable to post - both Twitter and the blogspot account have posted multiple times about the London mess today.
Best of luck, Anon!
I'm not sure if Anon fully understands the level of infrastructure and the level of preparation Facebook has... They'll need to come up with something a lot more compelling than a bunch of guys at home with LOIC.
Palish might be right that this doesn't sound like its from any of the main group.
Uh... did I get something wrong here? A correction or something would be nice.
if this is in fact anonymous. i'm not convinced, too big a target for them to have so little fanfare/flair.
"The tool is very effective, a 17-seconds attack from a single machine resulting in a 42-minute outage on Pastebin yesterday. As expected, the Pastebin admins weren't very happy with their platform being used for such tests and tweeted 'Please do not test your software on us again.'"
"The effectiveness of RefRef is due to the fact that it exploits a vulnerability in a widespread SQL service. The flaw is apparently known but not widely patched yet. The tool's creators don't expect their attacks to work on a high-profile target more than a couple of times before being blocked, but they don't believe organizations will rush to patch this flaw en masse before being hit."
http://www.thehackernews.com/2011/07/refref-denial-of-servic...
first of all, there's no javascript "engine" on most websites. and every major vendor of SQL databases has it's own, so good luck in finding a vulnerability that works with MSSQL/Oracle/Mysql/Postgresql.
also, even if you manage to store a .js file in a temp directory (which would be handled by the web server, btw. nothing to do with sql/js) it's usually a very locked down directory (you can't even execute from /tmp by default in most GNU/Linux servers)
even so, you would still need to execute that .js file (and how? most servers can't run javascript)
I'm not saying this tool doesn't exist, but I'm pretty sure that's not how it works
Then, around eight am, when the US gets to work, and anyone at Facebook who took you seriously is sleeping in after the late night? Then. That's when you pull out the big guns.
I wonder which hour of the day is their busiest... That would be my true target time.
If basically grabs a bunch of tor connects from a single machine and uses them to bombard the hosts.
I am quite sure that someone good could find attacks against facebook. I am dubious that anonymous can.
Facebook's is vast.
It's like, I may be able to find some way to force all the toilets at CIA Headquarters to back up. That's not the same thing as compromising their spies' identities. Not all exploits are equal.
Gunpowder, treason and plot.
I see no reason why gunpowder, treason
Should ever be forgot...
If I were them and wanted the data I'd hack a big Facebook application' account and since most of them are very intrusive with their permissions I'd get a lot of data that way.
I bet from the backend it'd be very hard to do it, and the data might be encrypted using a key that only a Facebook user has (the user might have multiple keys and share them with friends... etc etc), anyways, I'm thinking too much about this, it's too late already :).
http://blogs.villagevoice.com/runninscared/2011/08/anonymous...
tl;dr: The action is motivated because of the poor privacy policy of Facebook.
As said in other comments, it isn't clear if this is Anonymous because their twitter accounts didn't echo the manifesto. It could be a spinoff, a false flag op, or anything in between.
Perhaps as effective as cutting those users off from playing PS3 games they'd already purchased.
#OpFacebook is being organised by some Anons. This does not necessarily mean that all of #Anonymous agrees with it.
We prefer to face the real power and not to face to the same medias that we use as tools. #OpFacebook #Anonymous
REMEMBER THIS ARTICLE: "Are Hacker Attacks Government Operation To Push Internet Censorship Laws?"
The last one doesn't specifically mention FB, but it does seem that that sort of event - where the MSM attributes X to anon when anon isn't behind X - is beginning to worry them.
Look at http://news.yahoo.com/anonymous-targets-norway-killers-manif... That's an attack on something, but not by technical means.
Maybe they are planning something they need lots of people to help with and so want the publicity in advance?
Not a clue what that could be tho.
(Yes, I have seen the tweet saying its fake but as others point out there are many anonymous, and in fact the whole anonymous thing is that everyone is anonymous, so who knows?)
"Facebook has been selling information to government agencies and giving clandestine access to information security firms so that they can spy on people from all around the world. Some of these so-called whitehat infosec firms are working for authoritarian governments, such as those of Egypt and Syria."
^ Besides, if Anonymous wanted to disgrace facebook, I think a better way to do that would be to show evidence backing up this claim.
As much as I admire anon's technical prowess, I seriously doubt that they can take down significant portions of FB which seems very well prepared (unless, of course, some former employee reveals a trapdoor or something to them). Up to now, their targets have been clueless corporations (i.e. Sony) or government agencies mostly.
So there is much FUD involved here.
After seeing what they did over the summer,if I were FB...I would take a very guarded position over this latest claim.
Remember that an actual hack requires a both a great deal of skill and great deal of luck, especially when reasonably secure installations (FB obviously qualifying as "reasonably secure") are the target. If this group had the skill required, they would know enough not to be counting on getting lucky. Thus, either they already have knowledge of some vulnerability, or they're not going to find one. The former is highly unlikely - if they had that knowledge, it would require a great deal of stupidity to count on FB not discovering it for nearly three months.
Very droll sir. Very droll.
This is something they do to be on the news.. that's all. They're not going to be able to shut it down.
(1) availability - DNS or route hijacking. With https they may not be able to fake their own copy, but redirecting to a 'AnOnYmOus ownz yoo' page may be possible.
(2) privacy - a pretty big profile dump, maybe of key facebook employees?
(3) quality - have the news feed, groups, walls, etc flooded with (even more?) crap. A few cracked apps could flood a lot of users.
Sorry, the terms I'm using are pretty bad.
Hell, according to Alexa, Hypem gets more traffic than Visa. http://www.alexa.com/siteinfo/visa.com http://www.alexa.com/siteinfo/hypem.com
1) Facebook is powered by massive infrastructure which can be only be compared to likes of Google. Visa, Mastercard are too small even to be compared.
2) People at Facebook are Smart - as Facebook hired top talent. those "hackers@Facebook" know their sh!t & together they are better prepared that any of us here for thwarting ddos attacks.
so my message to annon is: Kids, Please don't understand facebook's infrastructure & the smart people who work there.