NBC sites were hacked
nbc.com
nbc.com
"Just because we type in all caps and use 'elite' speak doesn't mean we are kids, or we don't own your dumb ass. For everyone who calls us immature kids, it shows one more person has underestimated us. And worse, what does that say about their security? That 'immature kids' were able to bypass their 25,000 dollar firewalls, bypass the security put there by admins with XX years of experience or a XXX degree from some college. Nyah Nyah. [...] The injustice Markoff has committed is criminal. He belongs in a jail rotting instead of Kevin Mitnick. Kevin is no dark side hacker. He is not malicious. He is not a demon. He did not abuse credit cards, distribute the software he found, or deny service to a single machine. Is that so hard to comprehend?" (http://everything2.com/title/Hidden+Message+behind+the+New+Y...)
In 2012 when PYK defaces the Saturday Night Live site, they post "Greetz to oday, BRUT4L & S4VAGE Fuck the Feds, 419 is just a game~~ USER INFO - EXPOSED PASSWORDS - DUMPED".
Is this now the worst they can imagine? Grabbing my Saturday Night Live password?
Bring back the heartfelt screeds and the poets! At least HFG thought what they did was important.
Sheesh, kids these days.
Also, grabbing an SNL password means nothing for the SNL site, and everything for the security of users that reuse passwords. The value of a password database rarely has to do with the site it's from.
Imagine: one day, the biggest papers in the country simultaneously run stories about an alien takeover of the government. Then, minutes or hours later, "poof!".
"Oh, nothing happened. Nothing you care about. It was just hackers. And swamp gas."
Here's a screenshot for when they notice: http://i.imgur.com/UT4we.png
Then again, I'm calling these people technical, apparently it's a simpler game now with scripts that any regular Joe (or his 14-year old kid) can run.
Because the point isn't to cause damage to the user in any way (usually), but rather to (some combination of) 1) show off your skills, 2) embarrass the site owners, 3) get a message out, 4) have bragging rights. It's generally a fairly non-destructive practice, just silly.
What would give them more technical credibility in you eyes? If they wrote the attack themselves? In C? In Assembly? We all automate the hell out of things and lean toward the highest level languages for server automation anyway, why demean them when everything is a 'simpler game now with scripts that any regular Joe can run.' Have you seen Chef or Puppet, Flask or Rails?
A hacker doesn't care what the way is. He thinks about the goal, the end result.
If there's a ready-made script that can help or do it for him? Sure why not?
Having said that I agree that it does require skill and it is not as easy as downloading some random scripts and typing in a website and pressing the 'hack' button.
Tagging - an ugly pointless form of graffiti is popular for similar reasons. It's easy to do, and more tags == more credit among a small group of peers.
It's a good thing that people want to deface websites rather than hunker down and learn the long game. We'd be in real trouble if all the people doing minor stuff turned to major cyber[1] crime.
[1] "cyber" feels so old to me. Neuromancer was written in 1984.
In a way the ugly page represents the ugly terminal screens that the hacker was probably staring at for some time.