Hackers Who Shut Down PSN and Xbox Live Now Attacking Tor
gizmodo.com
gizmodo.com
https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
If you use Tor, I would follow the suggestion by another member of the mailing list [1], simply add to your torrc file:
ExcludeNodes US
StrictNodes 1
That will disallow using any US nodes, which works since all of LizardNSA's nodes are currently in the US.[1] https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
> Why? I assure you, our exits are just fine. What's with people responding so negatively to us donating 360Gbit/s of exit BW?
EDIT: From @lizardmafia:
> To clarify, we are no longer attacking PSN or Xbox. We are testing our new Tor 0day.
> Only hackers, miscreants and pedophiles use Tor.
https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
Oh please. They're trying to take the moral high ground to justify their behaviour.
Amateurs.
The kind of person whose sense of moral outrage gets activated by such nonsense bullshit doesn't know what the word "miscreant" means, and by not mentioning "terrorists" they're just confusing their target audience. If you don't say "terrorist", how are we supposed to know you're the good guys?
http://gizmodo.com/hackers-who-shut-down-psn-and-xbox-live-n...
Even if you held majority for just an hour, it seems you could still build a useful database of identities and their usage. I was trying to imagine how much just an hour Tor snapshot might be worth to somebody.
Maybe? Or no?
see: https://blog.torproject.org/blog/lifecycle-of-a-new-relay
On one hand, I guess I understand (yet don't condone) the motivation for the 'vigilante' justice they're trying to do. On the other, I really don't understand what benefit you can get from attacking Xbox, then Sony, and finally Tor.
When I think of the people doing this, I tend to think of them as understanding the importance of Tor and the benefit of anonymity it brings. However, here are people doing a DDOS attack (obviously illegal) trying to bring down the biggest illegal goods marketplace on the internet.
Maybe I'm alone in this, but outside of attention, I really don't understand any logical reason for this happening, and that really makes me dismiss any message they may have. I can comprehend being motivated by anger or some event, or just being a douchey company, but I just really don't understand what anyone besides the US Government would gain by attacking Tor.
I guess I'm not sure, but my guess is there could be a few entities outside the US that would appreciate that kind of skill.
A plausible example is hiring a team to DDoS another State-sponsored infrastructure from outside of U.S. soil. Or hire some elite crackers to write custom software for them.
If they just need a crack tool, they just need an agent to pay someone to write the tool and that doesn't give away information. Maybe I am spoiled by TV shows how they contact elite hackers in the black market.
“Microsoft and Sony are fucking retarded, literally monkeys behind computers,” Omari said. “They would have better luck if they actually hired someone who knew what they were doing. Like, if they went around prisons and hired people who were convicted for stuff like this, they would have a better chance at preventing attacks.”
“If I was working [at Microsoft or Sony] and had a big enough budget, I could totally stop these attacks,” Cleary claimed. “I’d buy more bandwidth, some specific equipment, and configure it correctly. It’s just about programming skill. With an attack of this scale, it could go up to the millions. But that’s really no problem for Sony and Microsoft.”
"If I get caught, then I get caught. Maybe I'll end up serving time, or maybe I'll end up helping companies, help them get better I guess."
Up until new blood walks up, points out a flaw, and fucks shit up because the "senior" desk jockey can barely squirm out of his $1000 computer chair to reach his keyboard.
That's just my take on it, if Lizard Squad states that it has taken them minimal effort to setup these attacks; then what's stopping a larger organization from doing such things?
Maybe it is the federal government trying to bolster their case for stronger control of the internet with a false flag operation.
For the record I'm not a conspiracy nut, but at the same time, given what we know about our government now and in the past, I can't completely dismiss the possibility.
If you're curious about validating this first hand, some of the members are active over at digitalgangster.com to give you an idea of the level of sophistication.
How about China, the EU, and ISIS/ISIL (if they even have any technology whatsoever)?
All names appear to begin with LizardNSA.
It must be said, however, that all exit and non-exit nodes go through acceptance process over 88 days
But it appears this is all running from Google's Compute Engine. They can easily shut it down, although they're probably using stolen credit cards, so there's no real traceability there.
You'd think Google wouldn't want to give away free computer resources to these 'hackers' since the banks will almost assuredly take back any mis-gotten money from stolen credit cards.
They attack the PSN and XBox networks. Kim Schmitz gives them 3000 vouchers for Mega to save christmas (what?) and/or the world. Then they claim, he's the reason they stopped the attacks.
And then they target their next victim. My point is: one might not like Kim but he is way too smart to expect such a barter to be successful.
So, given his own background, what makes him this? A stupid hero? Or is there a much smarter option?
Also, he probably wanted to play some video games and it's not like Mega vouchers cost him all that much, particularly considering this is basically an advertising expense.
Seriously, he just ended up passing the hot potato to someone else. That someone else is now Tor. I think I would've preferred to let Microsoft deal with the DDoS (they have the means).
Giving in to criminals's demands really ends up making things worse in the long term, whether it's bank robbers, CryptoLocker creators or the owners of botnets that can DDOS sites.
Attacks have not been stopped though. PSN is still down (or was this morning) and Xbox Live is still under DDOS, it's just being able to mitigate it better than yesterday.
But I still have to drop a line: please arrest these "hackers" / "crackers" / cyber criminals.
Luckily, neither am I.
Or is the NSA so large that it dwarfs the resources the rest of the world could contribute?
If a few hundred thousands nodes or a few massive large nodes suddenly popped up, then the admins of the tor directory servers (or some security research) would start asking question. It wasn't that long time ago that a rather large cluster came into discussion because it looked suspicious, and the situation got resolved a few days later.
Then it need to say quiet since nodes require up-time in order to be weighted favorable compare to other nodes. During this time they will generate traffic, noise and like a few abuse letters. That mean the ISP will be in communication with the intelligence agency, which in turn either require lies which could fail or agreements which can leak.
Simply put, it is likely easier, more cost effective and less fragile tap the back bone ISP network and sort out tor chains when needed.
http://torrentfreak.com/kim-dotcom-stops-xbox-and-playstatio...
More likely is they're using the same botnet that was attacking PSN/XBL to run Tor relays.
Given the resources of large intelligence operations funded worldwide, would can you be sure one or more aren't really behind Lizard (or LulzSec or Anonymous even)?
The way in which these people are acting right now is just asking for a mistake. I would guess they have made some huge opsec mistakes already. There's a supposed dox on them already (find it yourself on Twitter).
[1] http://thelede.blogs.nytimes.com/2007/10/08/interpol-untwirl...
They're not hacking anything any more that 4chan users "hack" websites by flooding them, there's no "hack" involved in any meaning of the word. I'm sure they love being called "hackers" by the media.
So yeah, I'm definitely in favor of calling them script kiddies. It's much easier to understand, even for a mainstream audience. And I assume they'd find the attention they're getting less rewarding if they were called script kiddies everywhere...
They really aren't.
> Being pompous about terms just comes across to the general public as nerd rage, much like gun aficionados whining about terminological niceties following reports of a mass shooting incident.
Words matter. If some fools are caught with a Molotov cocktail and the media starts reporting that they had a "nuclear weapon" because gasoline contains some radioactive carbon-14, the sane people are the ones telling anyone who will listen how stupid that is.
Calling those who maliciously break shit "hackers" is like calling those who drink too much "Irishmen." It's an offensive misuse of the word.
Languages change. That doesn't mean its offensive when somebody still uses the old meaning, because its how they grew up using it.
Maybe we should call this script kiddies "scriddies" since it seems the average Joe and TV/newspapers like a single catchy word.
Words do matter, but some are abused to a point wherein they take on new meanings; grating as that may be for those who knew and appreciated the original meanings.
Words matter. If some fools are caught with a Molotov cocktail and the media starts reporting that they had a "nuclear weapon" because gasoline contains some radioactive carbon-14, the sane people are the ones telling anyone who will listen how stupid that is.
Wildly disproportionate analogies are not a good way to get taken more seriously.
I don't think his point is that the term shouldn't be used in a negative way, but that the negative way is more along the lines of someone who breaks in to computers, not just floods them with a bunch of packets. Is someone who pours water on a computer and fries the circuits a hacker now too? Petty vandalism just doesn't seem the same as actually gaining unauthorized access, which is how I've always understood to be the popular definition of the word.
Hackers is just a generic term these days, no use getting upset about it.
Calling them Hackers is giving in, as is looking at it as "that ship has sailed". Language is fluid, it's always changing, and all we have to do to keep the term Hacker is to keep correcting people who mis-use it.
Did Electrical Engineers give in and start calling it "sodder"? No. They correct you when you mis-pronounce the word solder. I argue this is no different.
Google will probably shut them down quicker than the consensus gives them those. They are tiny; it's an attempted Sybil, but it's worse than GCHQ's one that used Amazon nodes.
Edit: Down.
If so, it'd be simple for Google to wipe them. Otherwise, I have no doubt the tor directory authorities will be keeping an eye on these for malicious activity and will mark them as Bad Relays if any is detected.
IIRC LizardSquad did allegedly "disband" awhile back, I think when some heat got applied to them, but I don't know. They were repeatedly DDOSing the servers of a game I play so I started following their exploits. I do hope law enforcement catches up with these guys sooner rather than later.
Me not. Sony and MS need to be taught that online DRM is a massive customer experience clusterfuck, and they will only listen and learn one way: hit 'em in their pockets. Only when enough customers are angry and demand refunds that it hurts their bottom lines, then maybe online DRM measures will be finally allowed to rot in hell.
And if they are, how does online DRM justify illegal activity? I'm not going to flood someone's shop so they can't open for business because I don't like their product.
If you don't like it, don't buy it, and educate consumers on why they shouldn't buy it either. Boycotts are the most direct way to harm a company's bottom line.
It's time for more drastic measures.
There's some successful boycotts, when there's a hell of a lot more on the line than just the inability to play COD. They're not doing anything illegal, and they don't need to.
> Console and title sales are through the roof, despite tech-savvy people and press all over the world calling bullshit on DRM. It's time for more drastic measures.
It's never time for more drastic (illegal) measures if someone provides a product you don't like. They're providing a shitty "feature" that frustrates you when your shitty internet connection is down. If it frustrates you so much, don't use it, get your friends not to use it, blog about it, post about it, spread the word. Look what happened to Sim City last year.
Perhaps the members of LizardSquad should reflect on that.
Nothing has changed there. We've just added homosexual to the list of things associated with the word "gay."
When "gay" is used in the "happy" sense, context is what differentiates it from the more recent homosexual sense.
"hacker" is no different.
Really then, it's about more effective writing, insuring the context of "hacker" is clear from the surrounding context.
What we lost in both instances was easy, utilitarian use of the word as more words are now required to convey information accurately.
I had to explain the shift to my kids once. It was sort of interesting after that time. We notice it, and they will often comment on something picking up a new meaning now.
That suggests to me a lot of people remain unaware of "overloading" words in that way.
I think this may be a slight on the this site being called "hacker news" and while PG is a "lisp nerd", he never attended MIT.
When someone has the possibility of doing a Sybil attack, no matter what they did before, you take that shit seriously. As of now, we don't know if the goal is to really test their 0day (which, if it's a Sybil isn't exactly 0day) or just popping up 3360 exit nodes to give "free" bandwidth.
English isn't one, and all the hurfing and durfing in the world won't change that because a techie doesn't like the word "hacker" being used in a way despite his...wait for it...proscription.
Please be aware that the lizard community as a whole is appalled by these circumstances.
I hope that this whole bag of shenanigans does not prejudice your fine selves against lizards - whether they be lizards of the past, present, or future.
Thank you for your time.
Why, yes, it is pointless.
Tell me, are you okay with this website being associated with illegal activity because the media is lazy and you'd rather just shrug your shoulders than correct that misconception? How would you like that used against you in real life? You're a member of a scary "hacker" forum, after all.
Words matter. Take this attitude when we're talking about "kek" vs "lol", not when we're talking about something that's being used to denigrate entire groups of people.
>Tell me, are you okay with this website being associated with illegal activity because the media is lazy and you'd rather just shrug your shoulders than correct that misconception? How would you like that used against you in real life? You're a member of a scary "hacker" forum, after all.
I would explain that hacker has multiple meanings and be done with it.
>Words matter.
Sure and when it comes to meanings majority rules and the majority made up their mind over 15 years ago. You're not just in the extreme minority that uses it for a different meaning. You're in the extreme minority of that extreme minority that still cares that other people use it for the newer meaning.
I'll give you a hint, it's the one that outrages the most people. You don't explain away misconceptions like that.
Whatever. You may be okay with being lumped in with criminals. I am not. I will continue correcting people that make this mistake regardless of how much it annoys them to be wrong.
>You don't explain away misconceptions like that.
I've never had any problems. Maybe it is just your delivery?
>I will continue correcting people that make this mistake regardless of how much it annoys them to be wrong.
The thing is unless you believe English should be static(and as we've already discussed you clearly don't) it isn't them that is wrong it is you.
Colour me surprised.
Given that a bunch affiliated with the group's names, addresses, numbers and the like have been compromised, this doesn't seem like a very smart plan.
Is it just me, or are there huge parallels between gang culture and hacker culture?