Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Wednesday, August 3, 2011

Biggest series of cyber-attacks in history uncovered


Security experts have discovered the biggest series of cyber attacks to date, involving the infiltration of the networks of 72 organisations including the United Nations, governments and companies around the world.

The security company McAfee, which uncovered the intrusions, said it believed there was one "state actor" behind the attacks but declined to name it, though one security expert who has been briefed on the hacking said the evidence points to China.

The long list of victims in the five-year campaign include the governments of the US, Taiwan, India, South Korea, Vietnam and Canada; the Association of South-east Asian Nations ; the International Olympic Committee (IOC); the World Anti-Doping Agency; and an array of companies, from defence contractors to high-tech enterprises.

In the case of the UN, the hackers broke into the computer system of the secretariat in Geneva in 2008, hid there unnoticed for nearly two years, and quietly combed through reams of secret data, according to McAfee.

"Even we were surprised by the enormous diversity of the victim organisations and were taken aback by the audacity of the perpetrators," McAfee's vice president of threat research, Dmitri Alperovitch, wrote in a 14-page report released on Wednesday.

"What is happening to all this data ... is still largely an open question. However, if even a fraction of it is used to build better competing products or beat a competitor at a key negotiation (due to having stolen the other team's playbook), the loss represents a massive economic threat."

McAfee learned of the extent of the hacking campaign in March this year, when its researchers discovered logs of the attacks while reviewing the contents of a "command and control" server that they had discovered in 2009 as part of an investigation into security breaches at defence companies.

He said that McAfee had notified all the 72 victims of the attacks, which are under investigation by law enforcement agencies around the world. He declined to give more details, such as the names of the companies hacked.

Jim Lewis, a cyber expert with the Centre for Strategic and International Studies, was briefed on the discovery by McAfee. He said it was very likely that China was behind the campaign because some of the targets had information that would be of particular interest to Beijing.

The systems of the IOC and several national Olympic Committees were breached in the run-up to the 2008 Beijing Games, for example. And China views Taiwan as a renegade province, and political issues between them remain contentious even as economic ties have strengthened in recent years.

"Everything points to China. It could be the Russians, but there is more that points to China than Russia," Lewis said.

He added that the US and Britain have capabilities to pull off this kind of campaign, but said: "We wouldn't spy on ourselves and the Brits wouldn't spy on us."

Friday, June 24, 2011

LulzSec Hacks Arizona Police Computers


The Arizona Department of Public Safety apparently has been victimized by the LulzSec hactivist group's "Operation Anti-Security" campaign.

On Friday the group posted a torrent on The Pirate Bay containing internal documents from the Arizona DPS to protest its anti-immigration policies, according to documentation accompanying the torrent link.


The torrent contains documents including "private intelligence bulletins, training manuals, and personal email correspondence," as well as names, phone numbers, addresses, and passwords of state law-enforcement personnel, according to the documentation.
"We are targeting AZDPS specifically because we are against SB1070 and the racial profiling anti-immigrant police state that is Arizona," the group said in the documentation.


SB1070 is a controversial anti-illegal immigration measure in Arizona that makes it a misdemeanor crime for aliens in Arizona who have been required to register with the U.S. government to not have their registration documents with them. It also imposes stiff penalties on people who harbor illegal aliens.

A cursory look at the AZ DPS documents available through the torrent show a mishmash of unrelated and largely inconsequential files, including various situational awareness bulletins, a complementary invitation to a border security conference, and a street price list for various illegal drugs. There also are personal photos of men holding fish, ostensibly after catching them.

Additionally, the torrent contains a graphic video--apparently taken from a camera inside a police cruiser--showing an AZ law-enforcement officer throwing an unidentifiable metal object across a highway and then being hit by a car. The files are assumed to have been extracted from the email accounts of AZ DPS personnel.

The AZ DPS did not respond to multiple attempts to contact them. However, several published reports claim the department acknowledged it indeed had been hacked and that the documents posted in the torrent are from within the organization. Reports also said the agency took down its website and disabled Web-based email in response. Indeed, the department's website remained unavailable Friday afternoon EDT.

LulzSec--also known as Lulz Security and LulzBoat--has gone on a hacking spree in the last several weeks, hitting government-related sites such as the U.S. Senate and Atlanta chapter of FBI affiliate InfraGard, as well as companies like Sega and Nintendo.

The FBI has increased its efforts to track down those behind LulzSec as well as another hactivist group, Anonymous, since the two released plans to "open fire" with an onslaught of cybercrimes against world governments.


Wednesday, June 15, 2011

Hacker Group Goes After CIA Site


A hacker group claimed Wednesday to have successfully knocked the Central Intelligence Agency's website offline, the latest in a string of attacks on U.S. government websites.
"Tango down - cia.gov - for the lulz," the group, known as Lulz Security, said on its Twitter account. Lulz is Internet slang for laughs.
CIA spokesman Preston Golson said the agency was aware its website was malfunctioning, but couldn't provide additional details.
"We're looking into the matter," he said.
The purported attack on the CIA's public information website is the latest in a spree of high-profile attacks by the hacker group, which also calls itself LulzSec. The group has also attacked Japanese technology giant Sony Corp., as well as a few videogame companies.
Earlier this week, the group posted information stolen from the U.S. Senate's public website, along with a taunting comment, "Is this an act of war, gentlemen?"
LulzSec also attacked a Federal Bureau of Investigation affiliate, Infragard. It used information stolen from Infragard to break into a small research company, Unveillance.
The group also claimed to defile the website of broadcaster PBS.
LulzSec isn't alone in hacking into companies and government organizations, but it has attracted online attention because it publishes much of the pilfered information on its website.

Tuesday, June 14, 2011

Facebook, Twitter Kick Out Indian Hacker Group

Facebook and Twitter have kicked out the Indian arm of a hacker group known as Anonymous, known as Anonymous Operation India, one week after they hacked into major Indian government websites, threatening to compromise national security. Therefore, the Operation India Facebook page and @operationindia Twitter handle owned by the group, have now become inaccessible. You may already know that the Anonymous group was responsible for recently attacking Sony's servers, in addition to acts of online aggression against the governments of Iran, Spain, New Zealand and Colombia.

While little was known about their activity in India until recently, they came into the limelight with the hacking of the websites of the National Informatics Centre (NIC) and the Indian Army, last week. The group defaced the NIC website URL with a graffiti and declaration stating, "We exist without nationality. We exist with humanity. NIC took 3 mins." They did the same to the Indian Army's website, taking it down for an hour, and releasing login names and password details, as well as forensic logs of indianarmy.nic.in.

Though the DoS attack, reportedly did not cause any loss of data, the group later boasted on the site, "We took Down Indian Army Official Site and NIC knows more what we did." Anonymous claimed responsibility for both hacks in a message posted on their IRC group saying, "The NIC hack, was merely a taste of what may come...The time has come now, when we'll wage a war of independence - from corruption and we promise to fight till the end." In addition to boasting of their achievements, they have placed some demands, most of them being reasonable, though we do agree that the method used is a bit crude.


Anonymous Operation India posted this message, boasting of their achievements and stating their demands

Anonymous Operation India posted this message, boasting of their achievements and stating their demands