Showing posts with label Hacktivism. Show all posts
Showing posts with label Hacktivism. Show all posts

Anonymous hacks MIT after Aaron Swartz's Suicide

On Sunday, the official site of the Massachusetts Institute of Technology (MIT) went offline. On a couple of the website’s subdomains, Anonymous hackers published a message in memory of Aaron Swartz, the Reddit co-founder and activist who recently committed suicide.

“Whether or not the government contributed to his suicide, the government's prosecution of Swartz was a grotesque miscarriage of justice, a distorted and perverse shadow of the justice that Aaron died fighting for […],” the hacktivists wrote on the defaced pages.

“Moreover, the situation Aaron found himself in highlights the injustice of U.S. computer crime laws, particularly their punishment regimes, and the highly-questionable justice of pre-trial bargaining. Aaron's act was undoubtedly political activism; it had tragic consequences,” they added.

The hackers ask the government to “reform” computer crime and copyright and intellectual property laws.

“We call for this tragedy to be a basis for greater recognition of the oppression and injustices heaped daily by certain persons and institutions of authority upon anyone who dares to stand up and be counted for their beliefs, and for greater solidarity and mutual aid in response,” they wrote.

“We call for this tragedy to be a basis for a renewed and unwavering commitment to a free and unfettered internet, spared from censorship with equality of access and franchise for all.”

They concluded their statement by apologizing to MIT administrators for temporarily taking over the website.

MIT has ordered an internal investigation into the case of Swartz. Furthermore, JSTOR – the digital library that accused him of illegally downloading content – has released its own statement regarding Swartz’s death.

At the time of writing, the main MIT site appeared to be working properly. The subdomains that hosted the hacktivists’ message have been taken offline.

In the meantime, a petition to remove United States District Attorney Carmen Ortiz from office for overreach in the case of Aaron Swartz has been created. The petition appears to be supported by both Anonymous and the controversial Kim Dotcom.
Add me on Google+
FILED UNDER:MIT ANONYMOUS HACKTIVISM PROTEST DEFACED WEBSITE

Hackers stole and leaked Over 1 Million Apple IOS Device ID From FBI

fbi_logo
Hackers have dumped online the unique identification codes for one million Apple iPhones and iPads allegedly lifted from an FBI agent's laptop. The leak, if genuine, proves Feds are walking around with data on at least 12 million iOS devices.

The 20-byte ID codes were, we're told, copied from a file extracted from the Dell notebook of a senior federal agent, who was tracking the activities of hacktivists in LulzSec, Anonymous and related groups. Supervisor Special Agent Christopher Stangl's machine was compromised via a AtomicReferenceArray vulnerability in Java in March, the black hats claim.

Once his computer was infiltrated by the hackers, a file was allegedly seized containing 12 million device records that included Unique Device Identifiers (UDIDs), usernames and push notification tokens as well as a smaller number of names, mobile phone numbers, addresses and zip codes. Members of the AntiSec crew leaked edited extracts of this data, having mostly stripped it of fanbois' personal information, on Monday.

The listed UDIDs, which include gadget serial numbers and other data so apps can distinguish between individual devices, appear to be genuine. However, by themselves they may pose only a minimal privacy risk once leaked online, so the effect of the dump is largely confined to embarrassing the Feds - and raising questions as to why agents have the information in the first place.

The most likely source of the data was either an iOS app developer or multiple developers, Mac Rumours speculates.

The Java exploit used in the attack is unrelated to the mega-bugs finally patched by Oracle last week.

It's a matter of record that Stangl was among the agents invited to an FBI-Scotland Yard conference call about the progress of investigations into members of Anonymous back in January. Members of LulzSec infamously eavesdropped on this call and leaked a recording after intercepting an email arranging the chat.

Email addresses exposed by this breach may have been used in a follow-up targeted attack that tricked investigators into visiting a booby-trapped website exploiting an at-the-time Java 0-day vulnerability. Rob Graham of Errata Security expands this plausible theory in this How the FBI might've been owned blog post.

The AntiSec activists behind this week's leak suggest the device info data was used as part of some FBI tracking project involving iOS devices, such as iPhones. Even they are a bit vague on what that might be. However the group goes into some detail in explaining how it apparently swiped the data:

During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of "NCFTA_iOS_devices_intel.csv" turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose.

The AntiSec group says it decide to published a portion of the leaked data in response to a keynote speech by the NSA's General Keith Alexander at the DefCon hacker convention in July. In part, Alexander sought to persuade hackers at the convention to consider a career at the NSA, a suggestion that predictably galled the black hats.

Hackers Reveals over 1 Million Accounts of Banks and Websites

hacker
Hacker collective Team GhostShell leaked a cache of more than one million user account records from 100 websites over the weekend.

The group, which is affiliated with hacktivists Anonymous, claimed they broke into databases maintained by banks, US government agencies and consultancy firms to leak passwords and documents. Some of the pinched data includes credit histories from banks among other files, many of which were lifted from content management systems. Some of the breached databases each contained more than 30,000 records.

An analysis of the hacks by security biz Imperva reveals that most of the breaches were pulled off using SQL injection attacks - simply tricking the servers into handing over a bit more information than they should. "Looking at the data dumps reveals the use of the tool SQLmap, one of two main SQL injection tools typically deployed by hackers," the company's researchers explained in a blog post.

Team GhostShell said the online leaks, which are part of its Project Hellfire campaign, were made in protest against banks and in revenge for the rounding up of hacktivists by cops and government agents.

The team said it worked with other hacking crews, MidasBank and OphiusLab, on the attacks - and claims to have accessed a Chinese technology vendor’s mainframe, a US stock exchange and the Department of Homeland Security. It plans to offer access to these compromised systems to hackers who have the chops to handle them.

In a statement, the group threatened to carry out further attacks, leak more sensitive data and generally unleash hell.

“All aboard the Smoke & Flames Train, Last stop, Hell," Team GhostShell wrote. "Two more projects are still scheduled for this fall and winter. It's only the beginning."

Team GhostShell is lead by self-proclaimed black hat hacker DeadMellox.

Hackers exposes Citibank CEO's private datas

citigroup
Hacktivists have published a dossier of personal information on the head of Citigroup in retaliation for the cuffing of protesters at an Occupy Wall Street demo.

Members of a group called CabinCr3w, a hacking gang affiliated with Anonymous, revealed phone numbers, an address, email address and financial information on Vikram Pandit, Citigroup's chief executive officer.

The exposé follows the arrest of a group of anti-capitalist protesters who allegedly sparked a ruckus inside a Citibank branch while withdrawing funds and closing their accounts. About 24 people were detained and charged with criminal trespass on Saturday afternoon, The Wall Street Journal reports.

In a statement, Citibank said only one of the protesters was actually trying to close an account, a request that it said was accommodated. The rest of the group were causing a nuisance and were repeatedly asked to leave before the New York City plod were called.

Last week Citigroup supremo Pandit offered to meet protesters, telling Businessweek that their sentiments were "completely understandable".

CabinCr3w previously published the personal information on the chief executives of JP Morgan Chase and Goldman Sachs. It also published the details of an NYPD officer accused of pepper-spraying Occupy Wall Street protesters.

The Citibank branch hubbub, whatever the rights and wrongs of what actually happened, has spawned a new campaign within the Occupy Wall Street umbrella. Op Take Back is encouraging people to close their accounts at high street banks and deposit their money with credit unions instead.