Google Search

Showing posts with label Anonymous. Show all posts
Showing posts with label Anonymous. Show all posts

Friday, September 13, 2013

Interview with 'We are Anonymous' author Parmy Olson [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

WeAreAnonCover170I had the privilege of interviewing Forbes journalist and author Parmy Olson after the RSA Conference in San Francisco in February.

We sat down in the beautiful Yerba Buena Gardens to discuss her book "We are Anonymous" and her thoughts on the upcoming (at the time) sentencing of the LulzSec hackers.

We also discussed her recent visit to Mobile World Congress in Barcelona and her thoughts on Firefox OS.

It might seem a bit late to publish this podcast, but there was a press embargo in the UK at the time it was recorded and we decided to be respectful of that and wait to publish until the accused were convicted and sentenced.

You may notice some odd noises in the background -- a dog barking, a shopping cart and birds tweeting. I interviewed Parmy in the middle of the park, so you should consider any extraneous noises as ambiance.

(If this is your first time listening to a Sophos podcast they are ideal for your daily commute or for a spot of lunchtime listening. There's an archive of previous podcasts - you can also get our podcasts via RSS or iTunes.)

http://twitter.com/chetwisniewski

Tags: anonymous, Firefox OS, Forbes, interview, Jake Davis, LulzSec, Lust for Lulz, Parmy Olson, Podcast, Sabu, Topiary


View the original article here

Monday, August 12, 2013

Former Reuters editor pleads not guilty in Anonymous hacking case

SACRAMENTO (Reuters) - Former Reuters.com Deputy Social Media Editor Matthew Keys pleaded not guilty on Tuesday to federal charges that he aided members of the Anonymous hacking collective.

Keys, 26, on Monday said he was fired by Thomson Reuters , the parent company of Reuters News.

Keys was indicted in March by a federal grand jury in Sacramento on three criminal counts, alleging he entered an Internet chatroom used by members of the hacking collective Anonymous and helped hackers gain access to the computer system of Tribune Co. in December 2010. A story on the Tribune's Los Angeles Times website was altered by one of those hackers, the indictment said.

The alleged events occurred before he joined Reuters in 2012, the indictment indicated.

Keys was silent during the hearing in federal district court in Sacramento as his lawyer Jay Leiderman entered the plea. A status conference was set for June 12.

"He was a journalist in that chatroom, absolutely, but he didn't do the acts he was accused of doing," Leiderman told reporters outside the courtroom. It appeared as if someone else assumed Keys' chatroom identity, he said.

Since the indictment, Keys has continued to tweet about himself and about news events. Thomson Reuters has confirmed that he no longer works at the company.

The maximum for conviction on all three counts would be 25 years in prison, although actual sentences handed down by judges are often far less than the maximum.

In his job at Reuters, Keys posted news from Reuters and other sources on both company Twitter feeds and other means, including his own Twitter account.

He was suspended from Reuters after last month's indictment and his access to his Reuters email account was cut off. He continued to tweet from a personal account, @TheMatthewKeys, and identified himself as an editor at Reuters.

Keys in a blog post on Monday wrote that his coverage of the Boston Marathon bombing last week — such as tweeting information from police scanners that ended up being incorrect — was one of the reasons he was given for his termination. He has changed his profile description to "Former Deputy Social Media Editor at @Reuters".

A Thomson Reuters spokeswoman declined to comment.

The case in U.S. District Court, Eastern District of California, is United States of America v. Matthew Keys, 13-82. The case in U.S. District Court, Eastern District of California, is United States of America v. Matthew Keys, 13-82.

(Reporting By Peter Henderson; Editing by Martin Howell)


View the original article here

Saturday, May 25, 2013

Reuters journalist who allegedly conspired with Anonymous hackers is suspended

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Matthew KeysA Reuters journalist has been indicted by a US federal grand jury for allegedly handing over the login credentials of his former employer, Los Angeles Times parent company Tribune Co., to people claiming allegiance to the hacker movement Anonymous.

Reuters.com, which currently employs 26-year-old Matthew Keys as a deputy social media editor, suspended him with pay on Friday.

An employee at the company's New York office said that Keys's workstation was being dismantled and that his security pass had been deactivated, according to subsequent reporting from Reuters.

The US Department of Justice announced the indictment [PDF] on Thursday.

Keys was indicted on three criminal counts:

Conspiracy to transmit information to damage a protected computer, Transmitting information to damage a protected computer, and Attempted transmission of information to damage a protected computer.

Prosecutors claim that Keys promised to give hackers access to Tribune Co. websites, and that one went on to deface a story on the company's Los Angeles Times website.

From a Department of Justice statement:

"Keys identified himself on an Internet chat forum as a former Tribune Company employee and provided members of Anonymous with a login and password to the Tribune Company server... After providing log-in credentials, Keys allegedly encouraged the Anonymous members to disrupt the website."

The exact wording of said encouragement, according to the indictment, being Keys telling the hackers to "go f**k some s**t up."

Part of indictment against Matthew Keys

On Thursday, Keys tweeted that he had found out about the indictment the same way most of us did: via Twitter.

The story told by court filings is of a disgruntled former employee who acted as a double agent with Anonymous hackers, working both with them and against them.

The case began in December 2010, when Keys allegedly provided the login credentials for a computer server belonging to KTXL FOX 40's corporate parent, the Tribune Company.

The indictment maintains that Keys identified himself on an Internet chat forum as a former Tribune Company employee and that he handed over a login and password for the server.

According to the indictment, the hacker ultimately defaced a Los Angles Time news story, changing its headline, byline and sub-headline to include the name "CHIPPY 1337".

Also, a line in the article was changed to read:

"House Democratic leader Steny Hoyer sees 'very good things' in the deal cut which will see uber skid Chippy 1337 take his rightful place, as head of the Senate, reluctant House Democrats told to SUCK IT UP."

The indictment further claims that Keys chatted with the hacker who claimed credit for the defacement, offering to try to regain access for him after system administrators fended off the hacker and locked him out.

When he learned of the hacker's ultimate success in defacing the Los Angeles Times page, Keys allegedly responded, "nice."

It's a long and twisty story, involving famed (and subsequently busted) former Anonymous top dog Sabu having outed Keys back in March 2011.

Buzzfeed has done a great job of pulling together all the intricacies of Keys's story, including an image of the defaced Los Angeles Times new story, a blog post from Keys about losing his job at the local FOX Affiliate in Sacramento, California, and more, including this statement from Keys's current employer, Thomson Reuters:

"We are aware of the charges brought by the Department of Justice against Matthew Keys, an employee of our news organization... Thomson Reuters is committed to obeying the rules and regulations in every jurisdiction in which it operates. Any legal violations, or failures to comply with the company's own strict set of principles and standards, can result in disciplinary action. We would also observe the indictment alleges the conduct occurred in December 2010; Mr. Keys joined Reuters in 2012, and while investigations continue we will have no further comment."

Will Keys get fired from Reuters? Should he?

Reuters logoBuzzfeed checked in with a Reuters employee who said that yes, if Keys is found guilty of divulging login credentials while at Reuters, he will have violated the company's Trust Principles, which is grounds for immediate dismissal.

What if Keys is found guilty of working with Anonymous only before Reuters hired him?

It's hard to imagine any reputable news venue countenancing the type of betrayal alleged in these charges.

If I were a Reuters editor or lawyer, I'd be finding ways to ensure Keys didn't come back from his suspension in the eventuality of a guilty verdict.

This case may look a little muddy given that journalists working undercover can act as double agents, but the fact is, Keys wasn't working for the news outlet at the time of the breach he allegedly helped to bring about.

As far as what non-journalists can take away from this, the lesson is this: priority No. 1 should be to shut down accounts for terminated employees.

Shuttering accounts should be a priority, but it often isn't.

You can't assume that a disgruntled former employee won't open up your systems to spammers, plant malware, or replace the CEO's presentation with porn.

If found guilty, Keys is looking at a maximum of 10 years in prison and a fine of up to $250,000.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Monday, March 18, 2013

Not-so anonymous Anonymouses head off to prison over PayPal DDoS

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Four young Englishmen who went on an Anonymous rampage back in 2010 weren't as anonymous as they might have hoped.

They were traced, identified and arrested.

We wrote at the end of 2011 that they'd been released on bail after being charged with running Distributed Denial of Service (DDoS) attacks against a number of high-profile payment processing companies.

PayPal, Mastercard and Visa ended up under the pump in the attacks, which were carried out in revenge for those companies refusing to process donations to controversial whistle-blowing outfit Wikileaks.

The fact that the DDoS might have prevented many other not-for-profit organisations from receiving donations as a side-effect didn't seem to worry the attackers.

Interestingly, the judge who granted them bail didn't ban them from using the internet during their temporary freedom, but he did place them under an unusual restriction: they weren't allowed to use their online handles, or nicknames.

That probably wasn't too onerous for Christopher Weatherhead, now 22, who had to stop going by "Nerdo", nor for Ashley Rhodes, 28, who could no longer strut his stuff as "NikonElite". But it might have been tricky for 24 year old Peter Gibson, who was apparently banned from calling himself "Peter".

(It's not clear if he had to go by the rather formal "Mr Gibson" instead, or if, paradoxically, he was permitted to adopt a pseudonym, provided it was one he hadn't used before.)

All four pleaded guilty. Three have now been sentenced: Nerdo got 18 months, NikonElite got seven and Peter, also known as Peter, got a six month suspended sentence.

The fourth hacktivist, whom we now know to be Jake Birchall, was just 16 at the time of the offence and will be sentenced separately. He too was banned from using his nick while on bail, but the court never told us what it was.

You'll find widespread reports suggesting that this attack alone cost PayPal £3.5 million (about $5.5 million), if you're wondering just how harmful a DDoS can be for an online business.

You need to take this sort of damage figure with a pinch of salt - it seems to include the cost of precautions taken after the attack by PayPal that were an investment to protect the company into the future, so it seems a little counter-intuitive to include this in the retrospective cost of recovering from an attack.

But there is little doubt that the hacktivist quartet did, and intended to do, as much damage as they could. They're said to have bragged on IRC, saying:

We have probably done some million pound of dmg to mc

(The word dmg, of course, means damage, while mc is shorthand for Mastercard.)

Now they get to regret.

Follow @duckblog


View the original article here

Monday, December 17, 2012

Petraeus tripped up by trust in supposedly anonymous email account

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

David PetraeusIt turns out that a surprisingly naïve trust in the supposed anonymity of pseudonymous email accounts has triggered the downfall of the US's top spy chief.

FBI agents who were investigating what they initially thought was a cyber breach stumbled onto intimate messages on Gmail passed between David Petraeus, who on Friday abruptly resigned from his job as head of the Central Intelligence Agency, and his biographer, Paula Broadwell.

According to the New York Times, the scandal began when a Florida woman, Jill Kelley, received threatening, harassing email from an anonymous person who accused her of flirting with an unidentified man.

Kelley is a volunteer social planner for events at MacDill Air Force Base in Tampa, Florida, also home to the military's Central Command, where Petraeus served as commander from 2008 to 2010 before stepping into his role as head of the CIA.

Wired reports that the anonymous harassment was contained in between five and 10 emails that began to arrive last May and that reportedly warned Kelley to "back off" and to "stay away" from an unnamed man.

Kelley contacted a friend at the FBI, unsure of whether the threats constituted cybercrime.

Investigators took it up, eventually tracing the anonymous account that sent the threatening emails (it's not clear whether this was a Gmail or some other type of account) to a home in North Carolina that belongs to Broadwell and her husband.

Petraeus biography by Paula Broadwell

As Wired points out, it's unclear exactly how investigators tracked Broadwell down, but given our knowledge of email headers, we can make some guesses.

If the threatening mail came from a Gmail account, the FBI would have had to get the IP address from Google, given that Gmail headers only include the IP address and domains of the servers that pass along the email.

But other webmail providers, such as Yahoo, include the sender's IP address in their email header metadata.

However they did it, FBI agents spent weeks piecing together the identity of the harassing emails, the Wall Street Journal reports.

To do so, they determined the locations from which the emails were sent, including not only the Broadwell home but also hotels where Ms. Broadwell was staying when some of the emails were sent.

FBI agents and federal prosecutors then used the information as probable cause to seek a warrant to monitor what other email accounts Ms. Broadwell might have used.

They learned that Broadwell and Petraeus had set up a private Gmail account to communicate, exchanging heaps of sexually explicit messages.

Eventually, in late summer, investigators determined the real identity behind Petraeus's psuedonym.

As it turns out, Petraeus didn't pass on classified documents during his relations with Broadwell. That had been a national security worry when the story first emerged.

IP address. Image from Shutterstock

The saga continues as details emerge, but from a security standpoint, there's a takeaway for all of us who believe that an anonymous email account shields our identities.

If you'd like to see what your own Gmail, Yahoo or other email header is telling the world about you, I found this handy guide for looking at the information of 19 different webmail clients, third-party email applications and third-party webmail clients.

The X-Originating-IP header, which you can find in headers such as Yahoo's, will tell you the IP address of the computer that sent a given email.

You can then use an IP address locator such as WhatIsMyIPAddress to find out the ISP or webhost to which an email account belongs, plus its geolocation.

That's handy when tracking spam email, if you want to track down the owner of the originating IP address of spam in order to lodge a complaint.

It's also handy to do it to yourself, to see how easily people can find information on you, even when you're tucked away behind a supposedly anonymous email account.

Remember, that invisibility cloak has plenty of holes.

Follow @LisaVaas
Follow @NakedSecurity

IP address image from Shutterstock.

Tags: affair, Broadwell, CIA, David Petraeus, email headers, gmail, Paula Broadwell, Petraeus, psuedonym, resignation, resigns, scandal, webmail


View the original article here

Friday, September 21, 2012

12 million iPhone and iPad device IDs hacked from the FBI, Anonymous claims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Hackers have published a collection of what they say is over a million Unique Device Identifiers (UDID), connected with Apple iPhones and iPads.

Headline used by hackers in their posting

The data, claims the hackers, is just part of a larger database of 12,367,232 UDIDs, and personal information such as full names, cellphone numbers, addresses and zipcodes belonging to Apple customers. The data was allegedly stolen via a Java vulnerability from a laptop belonging to an FBI cybersecurity agent:

"During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of ”NCFTA_iOS_devices_intel.csv” turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose."

Quite why the FBI was collecting the UDIDs and personal information of millions of iPhone and iPad users is not yet clear - but it's obvious that the data (and the computer it was apparently stored on) was not adequately secured.

iPhone

I suppose we should be pleased that the hackers have not, as yet, published the majority of the information they claim to have purloined from the FBI though the hack - including the personal information about members of the public.

As such, my suspicion is that the hackers were more interested in embarrassing the FBI's team than endangering innocent users.

All the same, hacking into computers is a criminal act - and I would anticipate that the FBI and other law enforcement agencies will be keen to hunt down those responsible.

Mitt Romney, journalists wearing tutus, and a shoe on head

If it helps cut down the number of suspects at all, here's a clue to help the FBI with their investigation.

Attached to the end of the hackers' announcement is the following phrase in German:

"Romney aber, sag's ihm, er kann mich im Arsche lecken!"

This translates into English as:

"Romney, however, tell him he can kiss the asses!"

Clearly not a fan of the Republican party then..

Adrian Chen. Image from TwitterAnd someone else that the hackers aren't huge fans of is Gawker journalist Adrian Chen.

Chen has become something of a bête noire for the likes of 4Chan and Anonymous.

Whoever was responsible for the latest hack says that they will only agree to speak to the press if a photo of Chen, dressed as a ballerina with a shoe on his head, is published on the main page of Gawker.

Hackers demand Chen wears a tutu

The whole "shoe on the head" thing is a 4Chan meme - victims are told they have to take a photograph of themselves wearing a shoe on their head for the amusement of hackers.

Whatever tickles your fancy I suppose..

Follow @gcluley

Tags: Adrian Chen, anonymous, antisec, Apple, Christopher Stangl, FBI, hacking, iPad, iPhone, Java, LulzSec, UDID, vulnerability


View the original article here

Sunday, May 20, 2012

The Pirate Bay gives thumbs-down on Anonymous DDoS attack on Virgin Media

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

anonymous and pirate bayFile-sharing site The Pirate Bay has denounced an Anonymous DDoS campaign that took down Virgin Media, calling it an "ugly" method that's no better than the UK court order for ISPs to block users from getting to The Pirate Bay.

On Tuesday, The Pirate Bay tweeted and posted to Facebook their disapproval.

The Facebook post recommends a list of actions that The Pirate Bay would much rather see - in essence, just about anything, including calling your mum, as opposed to DDoS or government-mandated site blockage:

The DDoS that rattled The Pirate Bay's bones was an Anonymous-branded outage imposed on virginmedia.com as payback for Virgin Media's having been the first ISP to comply with the court's command to block access to the file-sharing site.

The court order mandates the country's ISPs - Everything Everywhere, O2, Sky, TalkTalk, and Virgin Media - to stop users from accessing the file-sharing site, which includes many torrent links to pirated movies, music and TV shows, as well as original music released and promoted exclusively on The Pirate Bay.

As far as the Anonymous DDoS goes, Virgin Media put out a statement that said the attack lasted one hour.

Virgin Media also reiterated that it didn't have a choice to block The Pirate Bay; rather, the government forced its hand.

From Virgin Media's statement:

As a responsible ISP, Virgin Media complies with court orders but we strongly believe that tackling the issue of copyright infringement needs compelling legal alternatives, giving consumers access to great content at the right price, to help change consumer behaviour.

The irony of Anonymous's OpTPB is that the court-ordered block actually didn't seem to stop anybody from getting to the site - in fact, just the opposite.

As Sophos's Carole Theriault reported last week, the block was more like free advertising on all the major news outlets.

Thanks to all the coverage, The Pirate Bay actually walked away from the feeble, so-called block boasting 12 million more visitors than the site had ever seen.

The Pirate Bay opted to take advantage of the extra serving of eyeballs by giving tutorials on how to skirt censorship.

From their site:

"As usual there are easy ways to circumvent the block. Use a VPN service to be anonymous and get an uncensored internet access, you should do this anyhow. Or use TOR, I2P or some other darknet with access to the internets. Change your DNS settings with OpenDNS. Or use googles DNS servers... we could go on..."

TorrentFreak, in reporting on the traffic boost, offers a wealth of additional tips to get around the block.

It's worth noting, of course, that pirating copyrighted material can get you into trouble. It's illegal.

A lot of people don't care. And a lot of those people are going to be provoked as more ISPs are forced to bend to the government decree.

That doesn't make ISPs the bad guys, though. ISPs like Virgin Media are just the middlemen. It won't help matters to take them down.

What might matter is advocacy, as The Pirate Bay suggests. Contacting your ISP to voice your opinion on the block could matter. Writing to politicians could matter.

The bonus? Those actions are legal.

Follow @LisaVaas

View the original article here

Wednesday, April 4, 2012

Trayvon Martin, Anonymous, and the problem with vigilantism

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

DEFCON hoodie photoOccasionally Mrs W. gets a bee in her bonnet and decides to direct her energies toward a guest post on Naked Security. With vigilantism increasingly making headlines, she points out the futility of it all. Over to you Mrs. W...

Yesterday morning, as I drank my coffee and read my Twitter feed, I came across an article on The Atlantic's website describing the spread of George Zimmerman's purported address across social media sites.

George Zimmerman is the man who is claiming self-defense under Florida's "Stand Your Ground" law in the shooting of Trayvon Martin, the black kid whose hoodie, Skittles, and can of iced tea have become symbols in a wave of protests against racial profiling.

Much evidence points to Zimmerman as the aggressor: Among other things, he was the one who was armed, he followed Martin after being told by a dispatcher not to, his story doesn't jive with the evidence, and he has a history of, well, suspicious behavior towards young black males.

Because some people think a good way to combat alleged vigilantism is apparently more vigilante justice, a bounty has been placed on Zimmerman's head and he has gone into hiding.

As the article points out, it has now come to light that the address of one supposed hiding spot that is making its way virally across social media is actually that of an elderly Florida couple.

Masked hackerThis instantly brought Anonymous and its offshoots to mind. We've seen them, time and again, post addresses and other personal details of people who are sometimes directly responsible for and sometimes only tangentially related to the evils Anonymous et al. are targetting.

Whether or not the addresses posted do indeed belong to accountable parties and whether those parties are guilty is not the point. The point is that some who purport to be the good guys are, because of the tactics they use, barely distinguishable from the bad guys.

What makes hacktivists who publish your personal details to intimidate you all that different from phishers who collect and sell them? The motive of personal gain?

Never forget that, while committing supposedly altruistic acts of hacktivism, Sabu took the opportunity to line his own pockets. If that had been your credit card he charged his overdue bills to, would you let him off the hook?

Vigilantism may damage or destroy its targets, but even if you could eliminate Zimmerman or Monsanto, another would, soon enough, crop up in its place.

These are deep-rooted societal problems that require ongoing conversations about how things got that way in the first place and what sustained efforts we can make to change them -- indeed, how to hack human systems -- but the very nature of Anonymous makes dialogue impossible.

The Federalist PapersContrast this with a handful of Founding Fathers who provided a consistent voice and considered arguments in the Federalist Papers under the pseudonym "Publius." Arguably, these four men accomplished more in the space of a year than all of Anonymous and its offshoots since their inception almost a decade ago.

Contrast this also with participants in the Civil Rights Movement, who deserve more than a passing nod in light of the circumstances surrounding Trayvon Martin's death.

Hacktivists are, by comparison, mere script kiddies when it comes to creating change in the world. They are a cheap sideshow to the main event.

I am proud of all the Americans who are exercising their rights of free speech and peaceable assembly, donning their hoodies, blogging, signing petitions, and turning up at peaceful protests to demand that Zimmerman be properly investigated for the shooting. I hope justice, whatever that looks like, is served.

I am also proud of the folks who took down their own websites to protest SOPA and organizations like the EFF who work tirelessly to educate the public and stand up for our rights, all within the bounds of the law.

And I hope the dialogue continues.

Follow @bfwriter

View the original article here

Monday, March 5, 2012

Concern Rises Over the Capabilities of Anonymous Hacktivists - PCWorld

When a few members of the politically motivated hacking group Anonymous floated a plan recently to cripple the Internet's core address system, the idea was roundly dismissed by other members of the group.

Trying to disable the Internet by attacking servers critical to the Domain Name System -- the Internet's address look-up system -- would be counter to the group's actions, which depend on a constant online presence, they said.

In any case, experts have said an attack against the root servers that deliver address information for top-level domains would be extremely difficult because of the redundancy built into the system.

"Anonymous understands the strength of these servers and would never have any intention of touching them," said Raven, the screen name for a 23-year-old, U.S.-based member of Anonymous, who is active on its IRC channels. "Same goes for the power grid," he said in an interview via email.

But as Anonymous continues to flex its hacking muscle, it is making officials increasingly nervous. Its actions lately have included the theft of millions of emails from analyst firm Stratfor Global Intelligence, to the recording last month of a conference call between U.S. and British law enforcement agencies.

The director of the U.S. National Security Agency, Gen. Keith Alexander, has warned the White House that Anonymous might have the capability to cause a limited power outage within a year or two, according to a recent report in the Wall Street Journal.

Assessing the motives of Anonymous is difficult since it comprises several groups of hackers and activists and has no central leadership, said Joshua Corman, director of security intelligence for Akamai Technologies, who studies the group.

Cybercriminals motivated by profit are unlikely to try to take down the Internet because it would be contrary to their financial interests, Corman said. But within Anonymous are some "chaotic actors" who can have a "real nasty streak," he said.

"When you don't have centralized leadership, it doesn't matter what most will do, it matters what one of them will do," Corman said.

Only a small core of Anonymous is thought to have the technical know-how to carry out such advanced hacking operations. Like most grassroots organizations, its strength comes from the masses who join its cause, whether through electronic attacks or in physical protests wearing the Guy Fawkes masks that have become a hallmark of the group.

For example, Anonymous encouraged its supporters to download a Web-based tool in November 2010 to conduct distributed denial-of-service attacks against financial companies that turned off payment processing for the whistle-blowing site WikiLeaks.

But security analysts said the crude tool left activists' IP addresses exposed, which could provide a way for authorities to try to track them down.

"There's really only a few hackers out in the movement that really deserve the term 'hackers,'" said Barrett Brown, a writer and activist who works closely with Anonymous and the affiliated AntiSec group and is the founder of Project PM.

While Anonymous could develop the skills to damage power plants within a year or so, attacks on large-scale infrastructure "don't really serve our purposes," Brown said.

Anonymous' decentralized structure also has a big disadvantage: Other groups of hackers, for example from China or Russia, could strike critical targets and then blame Anonymous in an attempt to confuse investigators, a so-called "false flag" attack.

"I see the benefit for others who would want to sow fear and use the Anonymous name as the shield to do whatever they like, and it will be blamed on Anonymous," said Scot A. Terban, an independent information security and open-source intelligence analyst.

If something happened to a water or power plant and was attributed to Anonymous, the "group will be branded a terrorist organization quicker than you can blink an eye," Terban said.

Brown said U.S. officials are already edging close to conflating Anonymous with terrorist groups such as al-Qaida, which could push Anonymous in the direction of wanting to become more accountable in order to credibly deflect false flags.

But the rapidly changing make-up of the group makes it hard even for people within Anonymous to keep current, Brown said. It also makes it harder to coordinate a unified voice for the group.

"It's really a lot of work to keep up with what's going on, even if you're in Anonymous. I wouldn't want to be in law enforcement right now. It's a difficult job," he said.

Send news tips and comments to jeremy_kirk@idg.com


View the original article here

Sunday, March 4, 2012

Anonymous Hackers Claim They Were Infiltrated

People identifying themselves as activists in the Anonymous hacker movement said Wednesday it wasn't technical prowess but police infiltration that yielded 25 arrests in a sweep in Europe and South America.

In conversations in an online chat room where Spanish-speaking activists in the Americas and Spain regularly gather, they said nearly all of those arrested had been active on a single website used by the group.

Among those detained were a Spaniard known by the online nickname "Pacotron" or "Thunder," according to Spanish police and a communique issued by Anonymous Iberoamerica, which said he lives in Malaga.

The statement by the loosely organized collective's Spanish-language branch identified another of those arrested as a Spaniard known as "Troy" who it said owned computer servers in "such distant places as Slovakia and Romania."

Interpol, which announced the arrests Tuesday, did not say how it encountered the 25 suspects, who it says were involved in cyberattacks originating from Argentina, Chile, Colombia and Spain that targeted sites including Colombia's defense ministry and presidency and Chile's Endesa electricity company and national library.

Activists encountered in the chat room said some of those arrested belonged to a group of hackers called Sector404 while others were unsophisticated activists who took part in denial-of-service attacks, which overwhelm websites with data requests.

"The GREAT majority of those implicated were people inhabiting the servers of anonworld.info, something that disconcerts us," said the activist "Skao," who identified herself as a law student.

In the communique released on its blog, Anonymous Iberoamerica said the 25 were snared not through "inteligence work or informatics strategy" but rather through "the use of spies and informants within the movement."

The activists said many of those arrested had been careless, leaving digital tracks.

A spokeswoman for Chile's chief prosecutor, Marlis Pfeiffer, told The Associated Press on Wednesday that authorities had released the five people arrested there in the sweep, two of whom were 17-year-olds. Anonymous Iberoamerica said three of them were computer science students, one a programmer and one a Colombian.

Pfeiffer said investigators were examining computers confiscated from the five to determine if criminal charges will be filed but were encountering difficulties, presumably encrypted data.

An Argentine police official said Wednesday that 10 adults were still being detained. The official said he had no further information and spoke on condition he not be further identified. Anonymous Iberoamerica said those arrested in Argentina included Colombians and that many were minors.

The arrests followed an investigation begun in mid-February and also led to the seizure of 250 items of IT equipment in 15 cities, according to Interpol, the international police agency that announced them.

Anonymous activists deface websites, carrying out denial-of-service attacks and publish data obtained in computer break-ins.

They are engaged in a number of political causes, including opposition to the global clampdown on file-sharing sites and defense of the secret-spilling site WikiLeaks. The Vatican has also been a target.

In Brazil, Anonymous hacktivists attacked nine banks last month.

Elsewhere in Latin America, they have targed government agencies and ministries they claim are corrupt.

"We hope you understand and reveal that we are not hackers on steroids. We are activists and what happens in the world matters to us," said Skao.

Authorities in Europe, North America and elsewhere have made dozens of arrests of Anonymous activists. In response, the group has increasingly attacked law enforcement, military and intelligence-linked targets.

Anonymous has no real membership structure. Hackers, activists, and supporters can claim allegiance to its freewheeling principles at their convenience, so it's unclear what impact the arrests will have.

———

Associated Press writer Raphael Satter in London contributed to this report.


View the original article here

Interpol swoop nets 25 suspected 'Anonymous' hackers

Interpol has arrested 25 suspected members of the 'Anonymous' hackers group in a swoop covering more than a dozen cities in Europe and Latin America, the global police body said Tuesday.

"Operation Unmask was launched in mid-February following a series of coordinated cyber-attacks originating from Argentina, Chile, Colombia and Spain," said Interpol, based in the French city of Lyon.

The statement cited attacks on the websites of the Colombian Ministry of Defence and the presidency, as well as on Chile's Endesa electricity company and its National Library, among others.

The operation was carried out by police from Argentina, Chile, Colombia and Spain, the statement said, with 250 items of computer equipment and mobile phones seized in raids on 40 premises in 15 cities.

Police also seized credit cards and cash from the suspects, aged 17 to 40.

"This operation shows that crime in the virtual world does have real consequences for those involved, and that the Internet cannot be seen as a safe haven for criminal activity," said Bernd Rossbach, Interpol's acting director of police services.

However, it was not clear what evidence there was to prove those arrested were part of Anonymous, an extremely loose-knit international movement of online activists, or "hacktivists."

Spanish police said earlier they had arrested four suspected hackers accused of sabotaging websites and publishing confidential data on the Internet.

They were accused of hacking the websites of political parties and companies and adding fangs to the faces of leaders in photographs online, and publishing data identifying top officials' security guards, Spanish police said.

The operation, carried out after trawling through computer logs in order to trace IP addresses, also netted 10 suspects in Argentina, six in Chile and five in Colombia, Spanish police said.

They said one of the suspects went by the nicknames Thunder and Pacotron and was suspected of running the computer network used by Anonymous in Spain and Latin America, via servers in the Czech Republic and Bulgaria.

He was arrested in the southern Spanish city of Malaga.

Two of the suspects were in detention while one was bailed and the fourth was a minor who was left in the care of his parents.

In Santiago, deputy prefect Jaime Jara said police confiscated computer equipment belonging to five Chileans and a Colombian, aged between 17 and 23.

Jara said the suspects appeared to have hacked web pages in Chile, Colombia and Spain.

The six suspects did not know each other and were released after voluntarily giving statements, police said, though they will likely be ordered to appear in court to face possible charges relating to online crimes.

Anonymous has in recent weeks targeted the websites of a series of police organisations, with subgroup "Antisec" on Friday vandalising the website of a major US prison contractor.

Anonymous took credit Thursday for an online raid on the Los Angeles Police Canine Association and previously attacked websites of the Central Intelligence Agency and the Federal Bureau of Investigation.

Anonymous has notably defended WikiLeaks when it was facing a funding cutoff and recently collaborated with the anti-secrecy site for the release of a swathe of emails from Texas-based private intelligence firm Stratfor.

In December 2010, Anonymous attacked the websites of Mastercard, PayPal, Visa and others for blocking donations to WikiLeaks after it began releasing thousands of classified US diplomatic cables.


View the original article here

Interpol arrests Anonymous hackers: Do they warrant the attention?

Yesterday, police coordinating through Interpol conducted a sweep of arrests in Europe and South America of 25 suspected hackers from the group Anonymous. The hackers were allegedly preparing to deface and to launch “denial of service” attacks against key government websites, such as Colombia’s Ministry of Defense and presidential website, Chile’s electric company Endesa, and Chile’s national library. If found guilty, the accused hackers could face sentences of 541 days to five years in prison.

Skip to next paragraph

In retaliation, hackers briefly shut down the website of Interpol itself. Somewhere out there, a girl with a dragon tattoo is smiling, lopsidedly.

It all sounds very dramatic, and past website attacks by the Anonymous collective have been effective at getting a rather clever or satirical point across about what they see as the wrong-headedness of government policies.

But cyber-attacks of this sort against government websites are only a slightly higher-tech version of spray-paint attacks against a high-school wall. One wonders why Anonymous, or Interpol, even bothered.

Compared with the cyber-warfare attack against Iran’s nuclear program – remember the 2010 Stuxnet computer virus which effectively destroyed one-fifth of Iran's uranium-enrichment centrifuges and delayed its nuclear program? – defacing a website is rather tame. If hackers are peeved enough at the Chilean or Colombian governments to declare “war,” then this is of the “war is heck” variety.

The issues that hacker activists, or hactivists, focus on are serious ones. When WikiLeaks founder Julian Assange published hundreds of thousands of US diplomatic cables last year, he did so to protest against excesses of the US government during the ongoing "war against terror." Mr. Assange – who faces charges of sexual assault in Sweden – has since turned his sights onto a private website Stratfor, a subscription-based news service that focuses on terrorism and security issues.

When hackers broke into the website of the Boston Police Department in early February, posting a video of KRS-One’s rap video “Sound of Da Police,” they were making a satirical point about supposed police brutality in the breakup of the Occupy Boston campsite last year.


View the original article here

Friday, March 2, 2012

Police arrest four suspected Anonymous hacktivists

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

AnonymousPolice say that they have arrested four people, in connection with a series of Anonymous internet attacks against Spanish websites.

The four, who were arrested in Madrid and Malaga, are said to be affiliated with the loosely-knit Anonymous hacktivist group, and are suspected of involvement in a series of attacks against the websites of Spanish political parties, companies and the Spanish police force.

Websites were not just hit by denial-of-service attacks, but in some cases were also defaced and had information stolen from them.

Political websites like that of the 'Union Progress and Democracy' party (UpyD), for instance, were infiltrated and replaced with images of people bearing vampire-like fangs.

Defaced UPyD website

One of those arrested by police, who they claim went by the internet handles of 'Thunder' or 'Pacotron', is alleged to have been responsible for managing the IT infrastructure used by Anonymous in Spain and Latin America.

The group is said to have communicated via internet chat servers based in the Czech Republic and Bulgaria but managed from Spain by 'Thunder', which have now been shut down.

Spanish police have searched four addresses, and seized 25 computers and other storage devices for examination. No doubt they are hoping to uncover evidence which may lead to more arrests, or help with the case against the Anonymous suspects they have detained.

In addition to the arrests in Spain, ten Anonymous suspects were also indicted in Argentina, six in Chile and five in Colombia, according to a Spanish police press release.

Once again, those responsible for administering websites are reminded to take security seriously - ensuring that sensitive data is securely encrypted, and that websites are built with security in mind, and are not vulnerable to attacks that could leave them embarrassingly exposed.

Follow @gcluley

View the original article here

Wednesday, October 26, 2011

Anonymous Takes Down Massive Child Pornography Server, Leaks User Names - Geekosystem

In a move that we can all get behind, hacker group Anonymous has announced that they have taken down a huge cache of child pornography and released 1,589 usernames of the website’s patrons. The action came as part of Operation Darknet, which targets illicit websites that are part of an unindexed and therefore unsearchable corner of the Internet.

The server in question is owned by Freedom Hosting, and apparently services over 40 child pornography websites. The largest of these, disturbingly called Lolita City, was said to contain over 100gb of child pornography.

Interestingly, the Anonymous hack is extremely well documented. In two separate Pastebin posts, the hackers involved provide a timeline of events, as well as some of the methodologies they used in tracking and taking down the servers.

According to their timeline, the hackers first became aware of Lolita City while leading a related campaign against a portion of the Hidden Wiki which included links to child pornography. While working to suppress the Hidden Wiki for linking to child pornography, the group turned their attentions to the websites linked on the Wiki. Through their investigations, they discovered that many of the sites shared a similar “fingerprint” in that they were supported and hosted by a company called Freedom Hosting.

The group then issued an ultimatum to Freedom Hosting to remove the content, or be shut down through their attacks. Freedom Hosting refused, and has since been the target of the hacker’s ire.

While attacks by the hacker group have often been divisive, going after the supporters of child pornography is something that is hard to criticize. In fact, this might be the best application of the groups’ talents; an intersection of Internet knowledge and the ability to carry out electronic attacks. Of course, preventing child pornography from being moved around the Internet doesn’t stop the predators that created the materials. Hopefully, law enforcement will take up the information gleaned by the group and start making some arrests.

(via Security News Daily, Examiner)

Relevant to your interests


View the original article here

Tuesday, October 25, 2011

DHS: Anonymous Interested in Hacking Nation's Infrastructure - Wired News (blog)

The hacker collective known as Anonymous has expressed interest in hacking industrial systems that control critical infrastructures, such as gas and oil pipelines, chemical plants and water and sewage treatment facilities, according to a Department of Homeland Security bulletin.

But DHS doubts the anarchic group has the necessary skills. At least for now.

Anonymous efforts to attack such systems could be thwarted by the lack of centralized leadership in the loosely collected group, the bulletin says, as well as a lack of “specific expertise” about how the systems work and how to attack them. However, the report notes, the latter could easily be overcome through study of publicly available information.

“The information available on Anonymous suggests they currently have a limited ability to conduct attacks targeting [industrial control systems],” according to DHS. “However, experienced and skilled members of Anonymous in hacking could be able to develop capabilities to gain access and trespass on control system networks very quickly.”

The assessment comes in a bulletin issued recently (.pdf) by the Department of Homeland Security’s National Cybersecurity and Communications Integration Center, and published Monday by the web site Public Intelligence. The bulletin was marked “For Official Use Only,” a designation that means the data isn’t classified but is meant only to be shared with government agencies and trusted outside sources.

The bulletin says that members of Anonymous have not yet demonstrated attacks on such systems, instead choosing to “harass and embarrass their targets using rudimentary attack methods.” But the group’s interest in attacking these systems could grow once they realize how poorly the systems are secured, and they figure out how to leverage information that is already publicly available about vulnerabilities in the systems.

NCCIC predicts a ”moderate likelihood” that the group’s protest activities could be accompanied by hacking attacks on core infrastructure in the future.

“[T]here are control systems that are currently accessible directly from the internet and easy to locate through internet search engine tools and applications,” the bulletin notes. “These systems could be easily located and accessed with minimal skills in order to trespass, carry out nefarious activities, or conduct reconnaissance activities to be used in future operations.”

As evidence of Anonymous’ interest in control systems, the bulletin points to a July 11 post at Pastebin, a site where programmers and hackers post code and missives. The post discussed a denial-of-service attack against Monsanto and possible future plans against the company.

We blasted their web infrastructure to shit for 2 days straight, crippling all 3 of their mail servers as well as taking down their main websites world-wide. We dropped dox on 2500+ employees and associates, including full names, addresses, phone numbers, and exactly where they work. We are also in the process of setting up a wiki, to try and get all collected information in a more centralized and stable environment. Not bad for 2 months, I’d say.

What’s next? Not sure… it might have something to do with that open 6666 IRC port on their nexus server though.

And on July 19, a known member of Anonymous tweeted the results of browsing the directory tree for Siemens SIMATIC software, the same industrial control system software that was exploited by the Stuxnet worm last year to sabotage uranium-enriching centrifuges at an Iranian nuclear plant.

Another Anonymous member subsequently pointed to XML and HTML code that could be used to query the SIMATIC system to find vulnerabilities in it, and also indicated he was already inside multiple control systems.

The posted xml and html code reveals that the individual understands the content of the code in relation to common hacking techniques to obtain elevated privileges. It does not indicate knowledge of ICS; rather, it indicates that the individual has interest in the application software used in control systems.

The posted xml and html contained administration code used to create password dump files for a human-machine interface control system software product from Siemens. The code also contained OLE for Process Control (OPC) foundation code that is used in server communication with control system devices such as programmable logic controllers, remote terminal units, intelligent-electronic devices, and industrial controllers.

While the latter information indicated the individual had an interest in control systems, NCCIC could find nothing to indicate that the person actually possessed the capabilities necessary to hack an ICS. 

“There are no indications of knowledge or skill in control systems operations, design, or components,” the bulletin notes. “The individual may possess the necessary skill to exploit elevated privileges by hijacking credentials of valid users of the ICS software product posted based on traditional exploitation methods, not anything ICS specific. ”

According to the NCCIC bulletin, oil and gas companies could become particularly attractive targets to Anonymous and its sympathizers, owing to the hacking collective’s “green energy” agenda and its members’ past opposition to pipeline projects.

“This targeting could likely extend beyond Anonymous to the broader [hacker activist] community, resulting in larger-scope actions against energy companies,” DHS warns in the bulletin.

The security of industrial control systems, which are used in commercial manufacturing facilities and critical infrastructure systems around the world, was thrown into the spotlight over the last year, after the Stuxnet worm infected more than 100,000 computers in Iran and elsewhere. Although the worm was designed to target the SIMATIC industrial control system made by Siemens, it only released its destructive payload on a specific Simatic system – believed to be the system that controls centrifuges at Iran’s uranium enrichment plant in Natanz.

The discovery of the worm helped bring attention to the serious security vulnerabilities that exist in the Siemens system. Researchers who have further examined Siemens systems, as well as industrial control systems made by other manufacturers, have found them all to share the same kinds of security vulnerabilities.

Photo: matti.frisk / Flickr

Kim Zetter is a senior reporter at Wired covering cybercrime, privacy, security and civil liberties.
Follow @KimZetter and @ThreatLevel on Twitter.

View the original article here

Thursday, August 25, 2011

Vanguard Defense Industries suffers Anonymous hack attack

Facebook logoOver 30,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest internet and Facebook security threats. X

Twitter logoHi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats. X

VanGuard's ShadowHawk helicopterAnonymous hackers working under the flag of AntiSec have targeted a US defense contractor, stealing and publishing thousands of emails and documents.

Vanguard Defense Industries (VDI) works closely with government agencies such as the Department of Homeland Security and FBI, developing the unmanned remote-controlled ShadowHawk helicopter which can be used for aerial surveillance and fly at up to 70mph, shooting grenades and shotgun rounds in combat situations.

Of course, real life battlefield technology like that is no protection against cybercriminals, who appear to have published emails and documents containing VDI meeting notes, contracts, schematics and other confidential information as part of the hackers' ongoing "F**k FBI Friday" campaign.

VanguardA statement from the hackers will remind readers of past hack attacks on Monsanto and Infragard, and makes clear that VDI's senior vice president Richard T. Garcia was being singled out for particular attention:

The emails belong to Senior Vice President of VDI Richard T. Garcia, who has previously worked as Assistant Director to the Los Angeles FBI office as well as the Global Security Manager for Shell Oil Corporation. This leak contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen "counter-terrorism" documents classified as "law enforcement sensitive" and "for official use only".

Richard T. Garcia is also an executive board member of InfraGard, a sinister alliance of law enforcement, military, and private security contractors dedicated to protecting the infrastructure of the very systems we aim to destroy. It is our pleasure to make a mockery of InfraGard for the third time, once again dumping their internal meeting notes, membership rosters, and other private business matters.

AnonymousThe hackers seemed keen to underline that they weren't planning to cease their activities anytime soon:

We are doing this not only to cause embarrassment and disruption to Vanguard Defense Industries, but to send a strong message to the hacker community. White hat sellouts, law enforcement collaborators, and military contractors beware: we're coming for your mail spools, bash history files, and confidential documents.

Operation AntiSec is the name that has been given to a series of hacking attacks, born out of the activities of Anonymous and the burning embers (or should that be watery grave?) of LulzSec.

Past victims have included US government security contractor ManTech and DHS contractor Booz Allen Hamilton.

Once again, a defense contractor is learning a lesson the hard way about the importance of strong computer security.


View the original article here

Sunday, August 21, 2011

Punk Anonymous BART Hackers Should Be Unplugged for Life

COMMENTARY | There is such a thing as going too far. I can't personally blame frustrated activists (who turned into computer hackers) for recent attacks on San Francisco's BART system. What BART officials did to cell phone service was unconscionable and worthy of retribution. I've even said so.

However, there is a difference between attacking the BART system, and attacking the personal lives of the those working for BART, thereby purposely endangering their families. Posting the personal information of the officers, as the group known as "Anonymous" did Wednesday, is as reprehensible as what BART did to provoke the attacks. Uncool, guys!

According to the San Francisco Gate, the hacker group breached the website of the unions representing the agency's police, and obtained a roster of 102 officers and other employees, including home addresses, e-mail addresses, and passwords for the site. The hackers then posted the information on a separate website, and wrote, of their deed, "Yet another success." Earlier in the week, they released the personal information of more than 2000 customers.

In any revolution, there are those who "get it" and those who "miss it." True success lies not in creating mayhem, but in successfully gaining public support for your actions. The average person will applaud you for hacking into the BART System and posting web graffiti that makes it difficult for them to do their jobs-- especially when the victims are guilty of a crime themselves. Most of us are angry, and rightly so, about the BART's Mubarak-esque approach to crowd control. We can get behind a little retribution.

What we don't like though, are punk kids messing with individual families of people who by and large are simply doing their jobs, and (I might add) doing the best they can to keep commuters safe. I once had a verbal altercation with Dell Computers over their lame customer service on a broken computer. I was rightly angry. I retaliated against Dell by refusing to pay my bill to them. For two years we were at odds until I finally settled with them for 30% of the bill. That was fair dealing, and fair retribution. What would have been unfair would have been for me to go down to the Dell headquarters and slapped a secretary across the face for the company's grievous error. For one action I am applauded, and the other rightfully punished.

So for that reason, because you "Anonymous" people without the integrity to own your choices chose to attack individuals rather than the structure that is truly to blame, I not only withdraw any support I might have fostered for you, but I step further to advocate that you be prohibited upon capture (and you will be caught) from ever operating a computer or other online device again. You may think you found success. I think you're just a bunch of disappointing failures.


View the original article here

Sunday, July 3, 2011

Anonymous launches "WikiLeaks" for hackers - GMANews.TV

The hacktivist group Anonymous has launched a WikiLeaks-type site to boost efforts to leak "material(s) of interest" to the public.

The "HackerLeaks" site seeks to provide a "safe, secure and anonymous" way for hackers to disclose sensitive information they may come across.

"In both security as well as overall strategy, HackerLeaks is closely modeled on WikiLeaks. Our first
priority is to provide a safe, secure - and anonymous way for hackers to disclose sensitive information.
Our team of analysts first carefully screens each submission for any possible trace of the senders
identity," the founders of the site said.

"Our second commitment is to ensure that each and every leak receives the maximum exposure
possible in order to achieve the most profound political impact for the risks taken by those submitting
material. To that end, we work with media outlets all over the world," they added.

As of Friday afternoon (Manila time), HackerLeaks has been making its "disclosures" public on a href="http://hackerleaks2011.blogspot.com/" target="_blank">Hackerleaks2011.blogspot.com.

Hacktivist group Anonymous said HackerLeaks "openly invites" data thieves to upload documents for screening and possible publication.

It noted that since the initial dump of State Department cables on WikiLeaks, there have been few "WikiLeaks-sized scoops."

"So instead of waiting for insider whistleblowers, the hacker movement Anonymous hopes that a few outside intruders might start the leaks flowing," it said (http://anonops.blogspot.com/2011/06/anonymous-launches-wikileaks-for.html).

Earlier this week, a hacker sub-group People?s Liberation Front launched two new leaking sites, LocalLeaks.tk and HackerLeaks.tk.

First leak

Anonymous said that one of the hackers involved, Commander X, received the site's first submission: a list of the personal details of Orlando officials including addresses, home values, incomes and other data.

The leak came as Anonymous has been engaged in what it calls ?Operation Orlando," attacks on Orlando-based targets including OrlandoFloridaGuide.com and the websites of the Orlando Chamber of Commerce and Universal Studios.

The attacks were in retaliation for arrests of Orlando workers for the non-profit Food Not Bombs.

Connection to media outlets

Commander X said that Anonymous and the PLF have already established connections to the media outlets that can help better expose important data, and that they hope to also provide ?unique and enlightening analysis."

?We just wanted to make our own offering, compete in the disclosure marketplace and maybe fill a unique role if we can," he said.

He said part of that unique role is that HackerLeaks will be legal, despite publishing hacked materials.

?We don?t obtain this material. We merely publish it. This violates no sane law anywhere," he said. ? TJD, GMA News


View the original article here