[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Anonymous. Tampilkan semua postingan
Tampilkan postingan dengan label Anonymous. Tampilkan semua postingan

23/09/12

[Tutor] Setting PPTP pada Linux

Assalamu'alaikum Wr Wb


kalian semua pasti tau VPN,,dimana kita bisa surfing di dunia maya tanpa ketahuan IP asli kita

kemaren ane ada problem ketika selesai order VPN, dimana VPN tersebut tidak support untuk linux

setelah ane browsing, ternyata type yg support untuk linux itu PPTP.

apa itu PPTP? bisa kalian cari sendiri definisinya dari google

oke langsung aja biar gak lama

CEKIDOT !!!

1. Pertama kita cek terlebih dahulu IP kita sebelum memakai PPTP



2. Masuk ke menu System -- > Preferences --> Network Connections

3. Masuk ke menu VPN --> Add --> Pilih Point to Point Tunneling Protocol (PPTP) --> klik Create





4. a. Isi Connection Name dengan nama VPN kita
   b. Isi Gateway server VPN kita
   c. Isi Username beserta Passwordnya




5. Setelah itu klik menu Advanced yang ada dibawah pojok kanan, dan centang pada bagian Use Point to Point Encryption (MPPE) kemudian klik OK



6. Setelah semua dipastikan benar sekarang klik Apply

7. Jika semua tahap diatas sudah benar, maka secara otomatis VPN akan keluar dengan sendiri

8. Untuk menggunakan PPTP bisa langsung klik gambar Sinyal yang ada di pojok kanan atas, kemudian masuk ke menu VPN Connections. Nantinya disana akan keluar nama VPN yang kita tulis pada step ke 4. Tinggal klik aja pada nama VPN yang keluar dan tunggu beberapa saat maka simbol sinyal akan ada gambar gemboknya

9. Setelah ada gambar gembok kita coba cek IP kita setelah memakai VPN PPTP






yups selamat VPN kalian sudah bekerja dengan baik

untuk mengganti server, bisa kita edit di bagian Gateway-nya

sekarang kita bisa surfing di dunia maya dengan aman dan terkendali

mungkin sekian dulu dari ane, klo ada salah mohon maaf yang sebesar-besarnya

semoga bermanfaat untuk semuanya

Wassalamu'alaikum Wr Wb

Sumber
Read More...

12/11/11

Anonymous and LulzSec trawl Google Code search for security holes

Low Orbit Ion CannonExotically named hacking tools such as Low Orbit Ion Cannon and #RefRef have garnered plenty of headlines over the last few months but a new report suggests that the world's favourite search engine might be an equally important weapon in the arsenal of cyber-criminals and hacktivists.

The report explains how a simple search on Google Code is all that's needed to uncover a wealth of information that can be used to break into websites, cloud-based services and secure networks.

Google's Code Search is a tool that makes it easy for those with technical know-how to search the vast amount of computer code that is publicly available online.

Researchers from IT security consultancy Stach & Lui report that hacking groups such as Anonymous and LulzSec are using Google Code search for a number of nefarious activities.

With a few well-crafted searches they can uncover passwords for cloud services, configuration files for Virtual Private Networks and find code  that is vulnerable to common website hacking tactics such as SQL injection.

While the findings provide a much-needed wake up call to online businesses, admins and developers, they also offer a fascinating insight into the motivation of hacking collectives such as Anonymous and LulzSec.

According to Stach & Lui ‘Google Hacking’, as the technique is known, is believed to be Anonymous and LulzSec’s primary means of identifying potential targets.
Rather than being motivated by politics or injustice, hacking groups may simply be targeting organisations because Google Code search has turned up a vulnerability too tempting to ignore, making them less political action groups, more malicious 21st century Wombles.

So what can online businesses do to protect themselves from these online, evil Uncle Bulgarias?

The first line of defence is to make sure that developers are following established best practice and that executives are creating a culture where best practice is encouraged and supported. Including passwords in code has always been a bad idea and techniques to prevent and detect SQL injection vulnerabilities are well established.

Businesses should also prepare so that if they are successfully attacked after a data leak they don't lose their shirt. Data stored in the cloud can be rendered useless to attackers by the simple expedient of encrypting it.

Stach & Lui warn that in the businesses using cloud services should also take a close look at the small print; many cloud service providers state that they don't accept responsibility for leaks.

For more on this take a look at the Stach & Lui's Pulp Google Hacking presentation.
Read More...

05/11/11

Anonymous abandons plan to expose Mexican drug cartel collaborators

Hacker group backs away from exposing people it believes are connected to Zetas cartel after alleged threat of killings

A plan by the international hacker movement Anonymous to expose collaborators of Mexico's notorious Zetas drugs cartel has come to an abrupt end. A US activist backed away from publishing the names after an alleged counter-threat of mass retaliatory killings.

"This moves the operation from being a risk to knowing that I would be murdering people," Anonymous participant Barrett Brown told the Guardian on Friday.

Brown's withdrawal from Operation Cartel puts an end to one of the most bizarre and confusing episodes in Mexico's drug wars.

It began with a video which appeared online in early October and promised to reveal the identities of people working with the Zetas unless the cartel released an Anonymous member kidnapped in the Mexican city of Veracruz.

The video prompted furious online debate: while Anonymous has previously targeted business and government websites and databases around the world, it was unclear how it could confront Mexico's amorphous – and deadly – drug trafficking organisations. Conflicting messages appeared on Twitter and other social networking sites, with some activists saying the operation had been cancelled while others pledged to continue.

This culminated in Mexico on Thursday when Spanish-speaking Anonymous participants, who had previously pledged to continue, announced that the Zetas had let the kidnapped member go.

They also said that she carried with her a message from the cartel threatening to kill 10 people for every person named and that they had decided to abandon their plans.

Brown, a prominent Texas-based activist and one of the few willing to be named, initially said Mexican hackers had promised to give him information on Zeta collaborators that they had taken from Mexican government sites and that it would be released in the next few days.

But while he said he was comfortable with running personal risks and "passing a death sentence" on those he identified, the wider retaliation threat had made him "rethink my position".

He added that Anonymous would continue to explore ways of using the internet to help spark some kind of mass response to "the near collapse" in Mexico, as he claims it did in Tunisia and Egypt.
Read More...

18/10/11

Alleged LulzSec hacker of Sony Pictures faces trial date in December

23-year-old accused of having posted millions of users' details on group's website after hacking into Sony Pictures Europe systems


LulzSec
The background from LulzSec's Twitter page. Leaked IRC logs show the group's inner workings. Photograph: AP
An alleged member of the clandestine hacking group LulzSec pleaded not guilty on Monday to charges of taking part in an extensive computer breach of the Sony Pictures Entertainment film studio's European systems.

Cody Kretsinger, 23, entered not guilty pleas to one count each of conspiracy and unauthorized impairment of a protected computer during a brief hearing in U.S. District Court in Los Angeles.

US Magistrate Judge Victor Kenton set a trial date of 13 December for Kretsinger, who spoke only in response to questions from the judge.

Kenton also ordered that Kretsinger be represented by a court-appointed public defender.

Kretsinger faces a maximum sentence of 15 years in prison if convicted. He declined to comment to the Reuters after the hearing.

A nine-page federal grand jury indictment unsealed in September charges Kretsinger with obtaining confidential information from Sony Pictures' computer systems using an SQL injection attack against its website, a technique commonly used by hackers to steal information.

The indictment asserts that Kretsinger, who it is claimed went by the online handle "recursion", helped post information he and his co-conspirators stole from Sony on LulzSec's website and announced the intrusion via the hacking group's Twitter account.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, e-mails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

"From a single injection we accessed EVERYTHING," the hacking group said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks."

A number of Britons have been charged with offences relating to LulzSec's activities; they are not due to come to trial until early in 2012.

The de facto leader of LulzSec, who goes by the handle Sabu, recently responded to a string of questions on the Reddit website and suggested that he was "effectively on the run" - although he is not believed to have moved from his location, believed to be in New York.

Hackers previously had accessed personal information on 77 million Sony PlayStation Network and Qriocity accounts, the vast majority of which were users in North America and Europe, in what was then the biggest such security breach in history. Nobody and no group has ever directly claimed responsibility, and Sony has never released any details about how the attack was carried out. At one point it did suggest that members of the loose hacking collective Anonymous may have been responsible, but that has never been confirmed by either side.
Read More...

13/10/11

VeriSign Demands The Power To Take Down Websites/Domains

I was scanning the news today, and nothing much was going on. There were some half-arsed stories about Anonymous and LulzSec – but nothing really worth writing about. And then, and then I spotted this, which quite frankly scares the shit out of me.

As much as it may well have a use in law enforcement, I’m sorry but I don’t want any single organization, corporation or entity to have the power to take out domains.

It’s just plain wrong, and well the UK has already started tabling something like this back in September.

VeriSign, which manages the database of all .com internet addresses, wants powers to shut down “non-legitimate” domain names when asked to by law enforcement.

The company said today it wants to be able to enforce the “denial, cancellation or transfer of any registration” in any of a laundry list of scenarios where a domain is deemed to be “abusive”. VeriSign should be able to shut down a .com or .net domain, and therefore its associated website and email, “to comply with any applicable court orders, laws, government rules or requirements, requests of law enforcement or other governmental or quasi-governmental agency, or any dispute resolution process”, according to a document it filed today with domain name industry overseer ICANN.

The company has already helped law enforcement agencies in the US, such as the Immigration and Customs Enforcement agency, seize domains that were allegedly being used to sell counterfeit goods or facilitate online piracy, when the agency first obtained a court order.

That seizure process has come under fire because, in at least one fringe case, a seized .com domain’s website had already been ruled legal by a court in its native Spain.

Senior ICE agents are on record saying that they believe all .com addresses fall under US jurisdiction.

But the new powers would be international and, according to VeriSign’s filing, could enable it to shut down a domain also when it receives “requests from law enforcement”, without a court order.

Yes VeriSign do manage all the .com and .net domains, but they aren’t technically ruled under the US jurisdiction – there are plenty of .com domains that are hosted outside of the US, including the DNS infrastructure.

What I’m especially interested in, is how they plan to handle the fact that lots of things are illegal in some countries and perfectly legal in others. The part that scares me is they will be able to take down a domain without a court order, just on ‘request’ from a law enforcement agency.

To me, that opens it up to abuse – if you are going to do something like this, at least institute a due process to manage it properly.


“Various law enforcement personnel, around the globe, have asked us to mitigate domain name abuse, and have validated our approach to rapid suspension of malicious domain names,” VeriSign told ICANN, describing its system as “an integrated response to criminal activities that utilize Verisign-managed [top-level domains] and DNS infrastructure”.

The company said it has already cooperated with US law enforcement, including the FBI, to craft the suspension policies, and that it intends to also work with police in Europe and elsewhere.

It’s not yet clear how VeriSign would handle a request to suspend a .com domain that was hosting content legal in the US and Europe but illegal in, for example, Saudi Arabia or Uganda.

VeriSign made the request in a Registry Services Evaluation Process (RSEP) document filed today with ICANN. The RSEP is currently the primary mechanism that registries employ when they want to make significant changes to their contracts with ICANN.

The request also separately asks for permission to launch a “malware scanning service”, not dissimilar to the one recently introduced by ICM Registry, manager of the new .xxx extension.

That service would enable VeriSign to scan all .com websites once per quarter for malware and then provide a free “informational only” security report to the registrar responsible for the domain, which would then be able to take re-mediation action. It would be a voluntary service.

Scary thoughts really. However the malware scanning service sounds like something that would help the Internet clean up all the nasty stuff, but then again – do the registrars really care, and would they respond?

Either way, I don’t like the fact that these draconian control laws may be placed on the Internet as we know – that basically allow US law enforcement agencies to take down domains as they please.

What I’m guessing, if this is implemented, it may well become a major target for Social Engineering efforts. What’s more effective than a traditional DDoS attack? Having the domain completely killed by VeriSign – that’s what.
Read More...

11/10/11

Lulzsec hacker: 'we still have Sun emails, stored in China

Sabu, the erstwhile leader of the hacking crew, says he is effectively on the run as he gives interview to Reddit readers about LulzSec's achievements, Facebook, sentencing and more


The LulzSec hacking group has said it is to disband
 
 
The LulzSec hacking group hit a number of sites in a spree in May and July 2011; now its leader Sabu has given an interview on Reddit. Photograph: Reuters
The hacker who styles himself "Sabu", erstwhile leader of the LulzSec hacking crew, claims to have a cache of emails copied from the Sun which are being stored on a Chinese server, along with data from a number of other hacks.

But he claimed this weekend that they will not be released yet: "there are a lot of interesting dumps we're sitting on due to timing," he wrote on his Twitter feed. He claims that hackers have broken into banks including HSBC and "a few others" but that they have found "no smoking guns yet" in the data there.

Sabu – who says his online handle is a tribute to the American professional wrestler – says that after the arrests in the UK and US of a number of people alleged to have been involved with the crew, he is effectively on the run. But his writing also suggests he is staying put where he lives.

"I'm past the point of no return. Not trying to sound like a bad ass, however, it's the truth," he wrote. Later he added: "The ironic twist will be that my own friends will take me down, and not these idiots who hide behind the patriot veil." He also says that "technically, I'm on the run, so there you go."

LulzSec was an offshoot of the Anonymous hacking collective which during a hacking spree in May and July 2011 broke into a number of sites, including Sony Pictures Europe, Fox.com, PBS and finally the News International site.

At the latter it altered the Sun's web page so that it redirected viewers first to a faked story about Rupert Murdoch's death, and then to their Twitter feed. The group also attacked the US Congress's web site, an FBI affiliate and brought down the web site for the UK's Serious Organised Crime Agency by using a "distributed denial of service" attack.

Sabu effectively acted as the leader of the group, maintaining discipline over what they did, as leaked chatroom logs published in June by the Guardian show.
At that time he told members of the crew not to give interviews – but says his willingness to do so now is because "that was during the height of LulzSec. We all agreed to do no interviews till the end if there was ever one."

LulzSec's achievements, he says, were that it "exposed the sad state of security across the media, social, government online environments".

After the Sun hack, Sabu claimed on his Twitter feed that he was looking at 4GB of emails from the company. The claim was never confirmed, although remote access to News International's systems had been compromised.

Sabu's revelations came in a long and sometimes detailed "Ask Me Anything" (AMA) thread on Reddit. Sabu responds to a number of questions and appears to reveal a number of details about himself, such as that he is married, studied social sciences and English, that his technical hacking skills are self-taught, and that he teaches "sometimes". He claims to speak three languages – English, Spanish and German – fluently, and to have "decent" Portuguese and Italian. He says he turned towards computer hacking in 2000, when the US government "ignored the peoples' please to stop bombing Vieques" – a part of Puerto Rico used by the US navy as a bombing range until 2003. He says he likes working on cars, playing music and spending time with his family: "I'm loving life a lot this year. I barely have time for ops [hacker operations] like I used to."

That confirms other details that have been collected by rival hackers about Sabu which suggest that he is of Puerto Rican extraction, aged about 30 and based in New York.

He insists that he had no knowledge of the identities of any of the other members of LulzSec. "I simply don't know anyone's identity at Anonymous." He says that when one alleged member was arrested in the Shetland Islands, north of Scotland, he had to go and look up its location: "I was a bit impressed, even." He vehemently denies the suggestions by some that he "snitched" on other LulzSec members to the authorities.

The breakup of LulzSec meant he has "lost too many friends. [I] will probably never talk to them ever again." But he thinks that it "has already achieved what it set out to achieve".

He suggests that one of the LulzSec members, called Avunit, who quit the group when it took aim at the FBI, "is relaxing somewhere on a boat".

Asked whether he is "safe", he replies: "no one can prove it's me anyway. The beauty of Anonymous." The closest that the authorities have come to him is when in September they arrested a hacker alleged to have gone by the online handle "Recursion", who was tracked down via logs held by the British company HideMyAss, which unwittingly provided a virtual private network (VPN) connection for the attack on Sony Pictures Europe.

That arrest was "probably the closest they ever got", Sabu says. He also makes a veiled threat against HideMyAss: he alleges it "turns out to be owned by some … people who are going around buying smaller VPN providers ... We should have a nice exposé for HMA and its mother computer/investors soon. Point is: research your VPN provider thoroughly."

He says he takes a number of precautions to evade law enforcement, using prepaid phones and BlackBerrys for calls and Twitter: "they're expendable. I don't ignore you, I simply don't know you." He trusts Twitter – to some extent: "believe it or not, Twitter has not been sleeping in bed with LEAs [law enforcement agencies]. In fact it's a process [for LEAs] to get account info."

He rails at the sentencing guidelines in place for computer activity: "The penalties for any cybercrime (with the exception of child pornography) is severely archaic. And enforced by non-computer users. A DDOS (distributed denial of service) should not [attract a sentence of] 10 years at all especially when rapists and murderers do LESS than time." (The Guardian's James Ball made a similar point earlier this year.)

He thinks a hacking attack against Facebook "is pointless unless some very courages [sic] individual go and burn down its datacenter containing DBs [databases]". But he calls Facebook "a serious global cancer … they have half a billion people's psychology and family down in a database".

LulzSec does not have a Google Plus account, he says: "We do NOT have a g+ account. So whoever is running it is more than likely posing and has no affiliation to us." (Other Reddit users said that files distributed from that account contain malware.) Google Plus was launched well after LulzSec apparently broke up.
His advice to would-be emulators: "Stick to yourselves. If you are in a crew – keep your opsec up 24/7. Friends will try to take you down if they have to."

Anonymous, he says, is "no leaders, no hierarchy, no cointelpro [counter-intelligence program] drama. And we are a living, moving mass of like-minded individuals." He says it is "pure democracy", though that can be anarchic. But he thinks it will spawn "many organisations and political parties". But he says that "you don't need to be 'anonymous' or need to hack to be Anonymous. It's an idea, not a job."

He says he hopes to give a talk at the next HOPE (Hackers on Planet Earth) conference in New York, expected to run in July 2012.
Read More...

04/10/11

Anonymous Twitter Alternative Created For Protesters & Revolutionaries

There was a mass of news back in August about the London riots and how social media (especially Twitter) and the BlackBerry Messenger service (BBM) enabled the rioters to organize themselves via broadcast messages and tweets.

After discovering a lot of rioters got busted from their Tweets and BBM messages (which are of course traceable) – some smart fella game up with a new form of instant messaging anonymously. It works in a geographic location and allows you to broadcast messages within a certain locality that expire after a certain time.

This comes not long after the Anonymous social network Anon+/AnonPlus was announced back in July 2011.

After discovering that BBM and their Twittery playthings fed straight into the hands of the cops, smartphone-toting revolutionaries have taken up a new type of instant messaging – Vibe.

Like Twitter in that it is open and lets you mass-message, Vibe is unlike Twitter in that all messages or “vibes” are anonymous. You can set how far you want them to be available too – from 15 metres to global.

The messages self-destruct after a set period of time: from 15 minutes to forever. That makes it much more attractive to those who want to bring down the Man via the medium of street protest, but don’t want the Man, or their mothers, or the police looking at twitpics of themselves jumping up and down on burning bin-bags.

According to the New York papers, Vibe is now the instant messaging app of choice for the protesters at Manhattan’s #OccupyWallStreet.
It’s an interesting concept and I do think it has a certain place amongst anarchists, activists street protesters and rioters. Case in point – it’s been picked up by the Wall Street protesters, you can search the Twitter hashtag #OccupyWallStreet to see what’s going on with them.

If you have no idea what it’s about at all, check Wikipedia here – Occupy Wall Street
The application itself has a very ‘innocent’ description on iTunes – “Discover and join the vibe around your city, neighborhood, or building. Chat anonymously with people nearby without necessarily knowing them!”
But we all know full well, that’s not it’s main purpose.

Though it is innocently described on the iTunes store as a good way to chat to other people near you at football games or conferences, developer Hazem Sayed is actively keen for his app to be adopted by the protesters – flying out to the Manhattan protest from California with leaflets about his app explaining its uses.

It seems to be catching on:

The NY Daily News interviewed protester Drew Hornbein, a member of the camp’s Internet Committee, who explained its uses to the paper:
 “Let’s say you’re protesting and someone up ahead sees that the cops are getting ready to kettle people, they can send out this vibe that only lasts a few minutes that says, ‘Cops are kettling’,” said Hornbein.

“It’s anonymous too, so not only are you able to send out relevant information to a small radius, but it also disappears, there’s no record of it, so no one can come after the person who sent it.”
It’s a pretty neat use of technology I have to say and I’m wondering if it’s going to picked up by the community and groups such as Anonymous.

The downside, it’s an iOS app so if Apple gets put under pressure or feels the app is being used under nefarious circumstances – they can just pull the plug on it.

You can read more about the app on iTunes here:

Vibe By Zami.com Read More...

27/09/11

How Anonymous emerged to Occupy Wall Street

Mocked at first by some, Occupy Wall Street is showing the potential of online 'hacktivism' allied with street protest
 Occupy Wall Street protesters in Liberty Plaza

     
    Occupy Wall Street protesters in Liberty Plaza, 22 September 2011. Photograph: Stephanie Keith/Demotix/Corbis
    Defying harsh critiques from Stephen Colbert and slews of bloggers who scoffed last week at the "leaderless", "directionless", Frisbee-throwing hipsters camping out on cardboard at a random New York City park in the financial district, Occupy Wall Street appears to be gaining ground. From the modest 200 occupiers last week, numbers of protesters rose to an estimated peak of approximately 3,000 to 5,000 at the weekend's march. Media attention has grown exponentially. After taking their inspiration from the Egyptian "one demand" model, Occupy Wall Street have now released their list of "one" demands, bringing much-needed clarity to their objectives. The movement has moved to reach out to a broader base, including labor unions. Last week's execution of Troy Davis also contributed to the growth of Occupy Wall Street as crowds of protesters in Zucotti Park, renamed Liberty Plaza, swelled to approximately 1,500 last Thursday night demanding an end to capital punishment. Violence caught on camera over the weekend of police arresting approximately 80 protesters and, in one now-notorious case, apparently spraying mace into the faces of female protesters has generated an outcry over the NYPD's "cowardly" use of force on peaceful protesters. Thanks to these two incidents, says one protester, Danny Garza, "Occupy Wall Street has gotten bigger than we ever thought it could be." But the protest's profile cannot be measured purely in numbers of street protesters: on the periphery of Liberty Plaza is a parallel internet-based activism buttressing the movement. Under the banner of the virtual collective Anonymous, these "hacktivists" are now engaged in the physical action of street protest. "Groundfags" in Liberty Park communicate back and forth with online activists. The new dynamics of combined street and online activism have significantly underpinned Occupy Wall Street as a distinctive new movement. "We can physically be at a protest one day and the next day show up online," according to an Anonymous activist who goes by the name of "MotorMouth". The most concrete example of this symbiotic relationship is the rapid online identification by Anonymous activists of an NYPD officer they claim to have been the perpetrator in the pepper-spray incident. Naming an individual police officer may be a controversial tactic, but Occupy Wall Street has used social networking media as a positive organisational tool. When it emerged that a handful of activists were prepared to incite rioting and provoke the police days before Occupy Wall Street was to begin, Anonymous developed a Twitter application called URGE, launching an online campaign designed to quell potential violence. Anonymous "culture-jammed" Twitter with messages to keep protests peaceful, using top Twitter trends from around the world. The involvement of Anonymous activists has also helped the movement make new connections. When activists expressed outrage at Troy Davis's execution on Wednesday night, Anonymous linked the death penalty with the protests. One Anonymous figure, by the name of "Jackal", says:
    "This is a new way to protest. Many of us have done our fair share of street protesting. But they drag us into the streets, and they mace us. Now we have brought our protests into the online social media space. We do it all at once – the street protesting along with our distributed denial of service [DDoS] attacks. We are a bit of an online flash mob."
    What will become of Occupy Wall Street is uncertain: protesters now face eviction from Zucotti Park; yet the movement has sparked similar activism in Chicago, Boston, Denver and other cities throughout the United States. Much has been written about the "Twitter revolution" dimension of the Arab Spring; now it looks as though, in this emerging alliance between street protest and online activism, the Arab Spring is turning to American Fall.
nb : guardian Read More...

Second LulzSec hacker 'Neuron' could be tracked down via UK VPN

Following the arrest last week of alleged LulzSec member 'Recursion', the Guardian has found that another member of the hacking crew used the HideMyAss service for their connection



LulzSec
 
LulzSec: members allegedly used the HideMyAss proxy service to disguise their IP addresses
 
At least one more member of the hacking group LulzSec, known online as "Neuron", may be arrested if traced by their use of a British anonymous VPN (virtual private network) proxy service, following a similar arrest last week.

Hackers have expressed already dismay after it emerged that that Cody Kretsinger, who was arrested by the FBI last Thursday for allegedly hacking into the Sony Pictures website, had been identified via his use of HideMyAss's proxy service to disguise his IP (internet protocol) address when connecting to the Sony Pictures site.

Kretsinger allegedly went by the online handle "Recursion" – which crops up in chatlogs from the group posted on the Pastebin site. "Recursion" boated of hacking into the Sony Pictures site.

However the Pastebin logs also show that another LulzSec member, using the handle "Neuron", also claimed to use the HideMyAss service. Neuron and Recursion are not the same people: the LulzSec chatlog records posted by the Guardian covering a period from 31 May show the two in the same chatroom at the same time, and on one occasion addressing each other directly. "Recursion" quit the group after it attacked an FBI-related site early in June, but "Neuron" remained.

HideMyAss, posted a lengthy defence of its actions on its blog after the news emerged, insisting that it had to retain logs:
Being able to locate abusive users is imperative for the survival of operating a VPN service, if you can not take action to prevent abuse you risk losing server contracts with the underlying upstream providers that empower your network. Common abuse can be anything from spam to fraud, and more serious cases involve terrorism and child porn.

The main type of logging is session logging – this is simply logging when a customer connects and disconnects from the server, this identifies who was connected to X IP address at X time, this is what we do and all we do. Some providers choose not to do session logging and instead try to locate the abusive customer by using the intelligence from the complaint, for example if someone hacks XYZ.com they may monitor traffic to XYZ.com and log which customers have a connection to this website. Ask yourself this: if a provider claims not to do any form of logging, but is able to locate abusive customers, how are they able to do this without any form of logging?
The company added that it would only hand over logs if they were the subject of a valid UK court order: "if a request for information is sent to us from overseas, we will not accept this request unless it is sent through the appropriate UK channels and a UK judge warrants a court order or a court summons that forces us to provide this information. We are not intimidated by the US government as some are claiming. We are simply complying with our countries legal system to avoid being potentially shut down and prosecuted ourselves."

Some questioned whether HideMyAss – which says that it helped people in Egypt to evade crackdowns during the Arab spring protests – would hand over details of individuals to repressive regimes such as Syria. The company says in the blogpost that it would not because "[in] UK law, there isn't a law that prohibits the use of Egyptians gaining access to blocked websites such as Twitter, even if there is one in Egypt."

The revelation that the service retains some log details has caused outrage amid parts of the hacking community, with a number vowing never to use HideMyAss's service again. A rival service, AirVPN, put out a statement saying that it does not keep logs in the way that HideMyAss does: "we would like to reassure our users and our customers that nothing like that [handover of logs] may happen with AirVPN, for a series of legislative (we are based in the EU, not in the USA, and we don't recognize USA jurisdiction, obviously) and above all technical reasons." It says it will accept payments in BitCoin, the cryptocurrency, which can be made via the Tor network, for security.

Four people have been arrested in the UK relating to LulzSec's activities, with three charged so far.

nb : guardian Read More...

26/09/11

Homeless hacker 'Commander X' pleads not guilty [VIDEO]

Commander XThe FBI believes that the homeless man they arrested on Thursday was "Commander X", a member of the People's Liberation Front (PLF) associated with Anonymous hacktivism.

47-year-old Christopher Doyon has entered a not guilty plea to charges of "conspiracy to cause intentional damage to a protected computer, causing intentional damage to a protected computer, and aiding and abetting".

According to an indictment filed against Christopher Doyon and another man, Joshua John Covelli, the charges specifically relate to a denial-of-service attack against the servers of Santa Cruz County in December 2010, after the city put in place a law prohibiting camping inside the city.

Indictment against Christopher Doyon and Joshua John Covelli
The indictment gives Doyon the aliases "PLF", "Commander Adama" (clearly a Battlestar Galactica fan) and "Commander X". Covelli meanwhile is alleged to use the pseudonyms "Absolem" and "Toxic". 26-year-old Covelli was previously named in connection with internet attacks on PayPal.

Someone calling themselves "Commander X" gave an interview to CBS News earlier this year, claiming responsibility for denial-of-service attacks by Anonymous.


According to a CBS News report, "Commander X" told their reporter that he had no fear about being caught:
"We're not going to turn ourselves in. They can come and get us is what I say. Bring it on. Until then, we run... We will remain free and at liberty and at large for as long as we can, and when the time comes that each and every one of us eventually will be brought to justice, we will hold our head high in any court of law and we will defend our actions."
Doyon is scheduled to appear on September 29th for a bail hearing.

nb : nakedsecurity.sophos
Read More...

24/09/11

FBI Snags Lulzsec Member Involved in Sony Hack

LulzsecThe FBI continued its pursuit of members of the hacking group LulzSec on Thursday, arresting a 23 year old Phoenix, Arizona man believed to be part of an online hacking crew that attacked systems belonging to Sony Pictures, the Bureau said in a statement Thursday.

The arrest, conducted by agents from the FBI's Los Angeles office arrested Cody Kretsinger of Phoenix Arizona on Thursday. Kretsinger was named in a September 2 federal grand jury indictment and charged with conspiracy and unauthorized impairment of a protected computer for his role in attacks in May and June against computer systems belonging to Sony Pictures Entertainment, according to the statement. Published reports indicate that other arrests took place in Ohio, San Francisco, California, Montana, Minnesota and New Jersey.

Kretsinger, who used the online handle "recursion" is alleged to have carried out SQL injection attacks on Sony's application servers, connecting through a proxy server to mask his Internet Protocol (IP) address.

After compromising Sony's networks, Kertsinger is alleged to have distributed information stolen from Sony and to have publicized the attack on LulzSec's Web site and through its Twitter account.

Sony's network became a target in April, after Lulzsec targeted the company for its legal pursuit of PS3 hacker George Holtz (aka "GeoHot"). The hackers broke into the company's online gaming network, PSN Network. The company's Sony Online Entertainment and Station.com networks were also breached, with data on around 100 million users exposed, all told.

Kretsinger is just the latest in a string of arrests and searches of both high- and low level members of LulzSec and Anonymous. In June, a 19 year old man, Ryan Cleary of Essex, England, was arrested and charged with five counts of violating that country's Computer Misuse Act and Criminal Law Act. Subsequent raids and arrests of members of LulzSec and Anonymous claim to have targeted high ranking members of both LulzSec and Anonymous, including the member known as "Topiary" (allegedly 18 year old Jake Davis of the remote Shetland Islands in the UK) and, more recently, individuals believed to be linked to the online identity "Kayla," a key player in many of LulzSec's most notable hacks.

nb : threatpost Read More...

23/09/11

Homeless hacker arrested by FBI in LulzSec/Anonymous investigation

Homeless manAccording to media reports, the FBI has arrested two alleged hackers in San Francisco and Phoenix, believed to be associated with the LulzSec and Anonymous hacktivist groups.

And one of them is homeless.

FoxNews reports that search warrants have also been executed in the states of Minnesota, Montana and New Jersey as part of a wider FBI investigation into the groups who have launched attacks against government websites as well as corporations such as Sony.

23-year-old Cody Kretsinger, from Phoenix, Arizona, has been charged with computer offences, and is alleged to be the LulzSec member known as "Recursion". Kretsinger is accused of being involved in an SQL injection attack that stole information from Sony Pictures in June, exposing users email addresses and passwords.

According to the indictment against Kretsinger, he is accused of using the hidemyass.com proxy service to cloak probes he made of Sony Pictures' computer systems in May 2011, hunting for vulnerabilities.

Sony passwords leakedApproximately 150,000 confidential records were subsequently published online by LulzSec who criticised Sony's weak security.

Authorities allege that Kretsinger wiped the hard drives used to carry out the attack on Sony in an attempt to hide forensic evidence.

"Recursion" is one of many handles used by members of the LulzSec hacking gang, and features in internet chat logs that have previously published of the group having what they believed to be private conversations.

Chat log between LulzSec members Topiary and Recursion
Meanwhile, the FBI arrested an alleged Anonymous member in San Francisco. The man, who is reported to be homeless, is said to have been involved in internet attacks against Santa Cruz County government websites.

Just because a man is homeless, of course, doesn't mean that he can't get an internet connection. Coffee houses, cafes, libraries, etc can all offer cheap or free internet access - and because the computer being used can be a shared device, it may be harder to identify who might have been responsible for an attack compared to a PC at a home.

At the same time, public places are often watched with CCTV cameras which means that if the authorities were able to identify a time and place, they may also be able to gather evidence as to who was at the location when an attack was begun from a particular computer.

Both LulzSec and the larger Anonymous hacktivist collective have had a tough time of late, with a series of arrests in the USA, UK and elsewhere around the globe.

Wannabe hackers might be wise to read the FBI's press release about the Kretsinger arrest, which points out that if convicted of the hacking offences he could face up to 15 years in prison.

nb : nakedsecurity.sophos
Read More...

18/09/11

Fake FBI Anonymous psychological profile: a lesson to all internet users

The faceless power of Anonymous rages on.
Like headless horsemen, they gallop across the internet, intent on causing massive headaches and embarrassment for some, while keeping their fans and the media informed via social media.

Sounds even too good for a Hollywood movie plot. You couldn't make it up.

But it turns out that someone did make up the recently disclosed FBI document 'Psychological Profile of the Anonymous Key Personalities' [PDF].

And the story was covered by several reputable media outlets, though admittedly some voiced skepticism.

On September 8, Anonymous used Twitter and Tumblr to distribute the fake document.



The question is why did anyone ever think it was real?
  • Why would Anonymous leak a document that would put their esteemed leaders at risk?
  • Why would the FBI actually use Wikipedia as their sole information source for Anonymous's background?
  • The codename for the field informant is Marotte (which means prop stick, dummy head or fad)
  • Looking at the copious typos and grammar glitches in the document, would the FBI have a profiler without a basic grasp of written communication?
Fake FBI profile of Anonymous
So all this made us at Naked Security a bit suspicious at the time. So no surprise that this so-called FBI document turns out that it is a fake.

The thing is though, it does make for interesting lunchtime reading. I absolutely love some of the profiles in this faux document.

It defines "Kayla" as a violent, amoral bisexual with an inferiority complex, and "Topiary" as a youthful, obsessive idealist, possibly afflicted with Aspergers.

Forgive the quasi-psychology here - couldn't a fake document, if indeed it is written by the Anonymous leaders, be used to help the FBI and other authorities better understand the collective? What seems like nonsense to its authors could accidentally reveal some interesting insights for those that analyse and pigeon-hole personalities.

That said, some of you might remember that great article by Malcolm Gladwell where he concludes that criminal profiling isn't all that helpful to the capture of wanted criminals.

So what is the upshot? Whoever is involved in writing this didn't waste the FBI's time with this forgery, because they must have been aware from the get-go that this did not originate from their internal team.

Those responsible for the document did however manage to get the internet, media and bloggers yacking about it. Yes, even me. Anonymous have notoriety because many people have written about it. And if Anonymous did indeed pull this together, they have just lied to their online followers. tsk tsk.

Please, can we all make sure we take this collective's word with a grain of salt next time?

nb : nakedsecurity.sophos
Read More...

16/09/11

FBI: Psychological Profile of Anonymous Leadership is a Fake

It looks as if Anonymous's latest prank is a damning psychological profile of its own members, allegedly assembled by the FBI.

A spokesperson for the federal law enforcement agency said the document that was published online is a forgery, confirming speculation that it was a fake. The denial points a finger at Anonymous, itself, as the source of the document, in what appears to be an elaborate prank or an effort to sow disinformation.

The fake profile includes assessments of known Anonymous leaders, as identified by their Web-pseudonyms. It includes psychological sketches of Sabu, his described second-in-command, Kayla, the already-arrested and former spokesperson, Topiary, and the so-called autonomous members, JoePie91 and Tflow.

Many of the document's allegations are damning. It characterizes Sabu as a self-perceived martyr and narcissistic American male in his early thirties with a nihilistic world-view, likely an information security professional operating within the business community without alerting his peers to his other online activities. Kayla, characterized as the second-in-command, is profiled as a middle-American male in his early to mid-twenties whose stunted emotional age and inferiority complex may be the result of childhood trauma, perhaps an abusive parent, and who seeks attention as a result of a childhood desire for parental approval. Hmmm.... Very, very interesting.

Links to the document appeared on a Tumblr site and Twitter account affiliated with the group, media outlets ran with the story, even as they cast doubts about its authenticity.  Indeed, from the very first, casual readers and Anonymous sympathizers suspected it was a fake. The tone of the document is sensational and its content is rife with broad and thinly-sourced generalizations about the group and its members. (Wikipedia is cited for its description of the group.) It contains numerous spelling  and grammar errors and, perhaps the biggest red flag, casts aspersions on the FBI's own enforcement actions. In just one example, Topiary, a core member was arrested in the UK, is described as an ego-driven and idealistic youth with "Aspergers syndrome" (sp) who was used as cannon fodder for law enforcement.

It is unclear what the purpose of the document is. Despite its outsize reputation, Anonymous's core leadership is believed to be quite young. Many of those arrested so far in connection with distributed denial of service (DDoS) attacks and other actions are in their teens to early 20s. The profiles document may be a ham-fisted effort to throw investigators off the group's scent, or merely a practical joke from one Anonymous member to another.

nb : threatpost Read More...

07/09/11

Anonymous and LulzSec case: four accused males appear in court

LulzSec
 
They were arrested earlier this year by police investigating online attacks by Anonymous and LulzSec, above
Four British males have been banned from using online nicknames after they appeared in court charged with attacks connected to Anonymous and LulzSec.

The four men – Peter David Gibson, 22, Ashley Rhodes, 26, Christopher Weatherhead, 20, and a 17-year-old student – were released on bail after the hearing at Westminster magistrates court on Wednesday morning.

The group's bail conditions mean they are prohibited from using specific online nicknames on sites including Facebook and Twitter.

Gibson, from Hartlepool, is banned from using the name "Peter" on the internet. Weatherhead, from Northampton, is prohibited from using "Nerdo"; Rhodes, from Kennington, south London, cannot use "NikonElite", and the 17-year-old, from Chester, is also banned from using his online nickname.

The four men are also banned using so-called "internet relay chats", the online forums where Anonymous members are alleged to have coordinated many of the attacks.

The four men are separately charged with conspiracy to carry out an unauthorised act in relation to a computer. They were arrested earlier this year by police investigating online attacks by the notorious hacking groups Anonymous and LulzSec.

Rhodes, the oldest of the group who was arrested in September, appeared in court dressed in a grey waistcoat over a black shirt, with short dark hair.

Weatherhead, who was also arrested in September, wore a blue shirt under a short black jacket. Gibson has been on police bail since his arrest in April. He wore a smart grey suit, with a white open-necked shirt.

They will appear at Southwark crown court on 18 November for a plea and case management hearing.

nb : guardian
Read More...

Anonymous suspects bailed - banned from using online nicknames and IRC

LulzSecFour men appeared at City of Westminster Magistrates' Court today in connection with various Anonymous and LulzSec internet attacks, and were granted bail on the condition that they did not use specific online nicknames on the internet or IRC.

Hackers affiliated with Anonymous and LulzSec have used IRC (Internet Relay Chat) channels as their primary method of coordinating attacks and communicating with each other, using online nicknames as a veil of anonymity.
The men will break the conditions of their bail if they use specific online nicknames on websites:

20-year-old Christopher Jan Weatherhead, from Northampton, cannot use the internet nickname "Nerdo".
Ashley Rhodes, 26, from London, is banned from calling himself "NikonElite" online.

22-year-old student Peter David Gibson, of Hartlepool, County Durham, is banned from using the name "Peter" on the internet (which must be awkward), and a 17-year-old from Chester is not allowed to use his online nickname.

The four are separately charged with conspiracy to impair the operation of a computer or hinder access to a program or data. Police arrested the men earlier this year, following a series of denial-of-service and hacking attacks against the websites of different organisations and companies.

There will, no doubt, be some raised eyebrows that the men's bail conditions do not insist upon a complete ban on internet access, considering the nature of the allegations against them.

nb : nakedsecurity.sophos
Read More...

GlobalSign stops issuing SSL certificates in response to Iranian hacker

 

Earlier today a person calling himself ComodoHacker made a submission to text posting site Pastebin.com. Similar to a previous post by ComodoHacker it is fair to call it a bit of a bragging rant.


Last March ComodoHacker claimed responsibility for the first attack against a certificate authority that resulted in bogus SSL certificates being issued in the wild.

In addition to claiming his attacks are far more sophisticated than Stuxnet and distancing himself from the Iranian government, he also claims to have compromised four other certificate authorities, including GlobalSign.

GlobalSign logoGlobalSign, the fifth largest certificate issuer according to NetCraft, responded to this news by immediately ceasing any further signing of certificates while they investigate.

Their response is interesting. While we don't know if they have been compromised (and arguably, neither do they) they are making a tough choice that is what we should expect from organizations whose business models rely on trust.

It's possible the accusations are simply from an anonymous raving lunatic. Yet they could be true, and rather than put the greater internet community at risk, GlobalSign is forgoing some revenue out of an abundance of caution.

That's great news. Let's hope that the accusations are false and everything is safe and secure at GlobalSign and the other three unnamed victims.

While I have argued for a long time that the certificate system is fragile and arguably broken, I'd rather not have two examples in one week to support my arguments.

nb : nakedsecurity.sophos Read More...