6 ms·
LulzSec: 50 Days of Lulz statement
- estel 15y agoThe torrent appears to contain hacked personal data from: * EA (Battlefield Heroes) * Hackforums.net * Nato-bookshop.org * Misc other forums The first of these purports to be 200K+ users.
- ianterrell 15y agoAlso of note, AOL and AT&T data. AT&T's rar is 329.9 MB.
- Strom 15y agoThe Battlefield Heroes passwords are unsalted MD5. Way to go EA.
- ianterrell 15y agoThat still beats the NATO bookstore's plaintext. :)
- 1880 15y agoHm, are you sure? I have a couple accounts there (and they are appearing in the dump) and they are not simply md5(password). Of course they were long, random passwords and I don't play this game anymore, but I'm curious. Where did you read that?
- veeti 15y agoSome BF Heroes beta server was hacked over 2 years ago. I wonder if this could be the same hack.
- lhnz 15y agoQuitting or rebranding is the question I find myself asking.
- chao- 15y agoGiven that the LulzSec name was a clique from AnonOps rebranding itself to begin with, I would bet on the latter. Although it may be a while before we hear of them pulling such flamboyant stunts again.
- BasDirks 15y agoLike a wave they will again become sea, only to rise later as a different wave. Or to put my high school poetics into plain English: They will want to blend in with the Anonymous masses, until they deem it safe to once again to craft new identities for themselves.
- ianterrell 15y agoConsidering they'd even earlier today advertised a Monday booty release, I suspect that, rather than abandoning the Lulzsec facade after 50 days, it's that the fuzz is a little too hot on their trail for comfort.
- 46Bit 15y agoI'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.
- redthrowaway 15y agoReally though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe. All of the people who were arrested for hacking the CIA or DoD were caught many years ago, when anonymization tools weren't nearly so well developed, and the need for anonymization wasn't so clearly recognized. I'd like to see a modern story of the authorities finding someone who was hidden by TOR + vpn. I just don't see it happening any time soon.
- ianterrell 15y agoJust like the low security systems they crack, the weakest link in their own chain is the human element. Think password reuse is a problem? So is screen name reuse. So is having the same friends over time. So is trusting people. A person's digital fingerprint is huge these days, and a human weakness can break the chain apart. And once one person's in custody? How much discipline do you think each member has to not snitch in the face of prison time?
- awakeasleep 15y ago
- dmix 15y agoNATO press release about the break in to their ebookstore by LulzSec: http://www.nato.int/cps/en/SID-40BE0A99-F4F5EB32/natolive/news_75729.htm http://www.nato.int/cps/en/SID-40BE0A99-F4F5EB32/natolive/ne...
- ianterrell 15y agoNote that the press release was two days ago, after NATO was notified by police. AFAIK, this is the first that Lulzsec has disclosed that the NATO bookstore was hit, which means the police knew before we did. That can't be good for those behind the mask.
- rhizome 15y agoAFAIK, this is the first that Lulzsec has disclosed that the NATO bookstore was hit, which means the police knew before we did. That can't be good for those behind the mask. Maybe they were seeing how long it would take for the news to come out without their help.
- dmix 15y agoMy guess is that they spent a few days trying to see if they can access accounts of anyone important from the NATO dump. The passwords were in plaintext. They would only release the data to the public once they are done using it.
- jfb 15y agoNATO has an ebook store? What are the hell?
- p4bl0 15y agoThat's also what strikes me in this story. Anyone can explain this?
- deleted 15y ago[deleted]
- mrb 15y agoWho is LulzSec?
- redthrowaway 15y agoI was going to say something snarky, but I checked your comment history and it seems you are on here seldom enough to explain an honest lack of knowledge about them. Basically, LulzSec is a hacking group that has been attacking many targets very publicly over the past 2 months. They've been all over HN, /., reddit, etc. They've even earned some mentions in the MSM. Basically, they're notable for a) the number of targets they've hit, b) how brazen they are about it (hitting the FBI, CIA, and other law enforcement agencies), and c) how vigorously they court publicity (270k followers on Twitter).
- mrb 15y agoI was being sarcastic :-)
- redthrowaway 15y agoAnd here I was, sparing you my snark. You've made me re-evaluate humanity, sir, and I'm not impressed with the results.
- jaremy 15y agoI appreciated your brief synopsis. I only know a little bit about LulzSec, and the added information helped. So your efforts were not entirely lost...
- redthrowaway 15y agoI appreciate your appreciation. If you want to learn more, the wikipedia article on them [1] is pretty decent. [1]http://en.wikipedia.org/wiki/Lulzsec http://en.wikipedia.org/wiki/Lulzsec
- Periodic 15y ago
- shareme 15y agoYup, fuzz on their tails.. Not too smart either why include the number of Lulzsec members?
- sbierwagen 15y ago1.) What useful information does "there are six of them" convey? 2.) What makes you think that they're not lying?
- ianterrell 15y agoDisinformation is most likely, but I've been hoping for some steganography from their Pastbins from day one.
- shareme 15y agochat logs show more than 6.. But its only 6 that are active in illegal stuff
- redthrowaway 15y ago1.) What information does the number of columns in a MySQL database convey? It's not just that there are six of them, but that records could be poured over for various irc servers in an attempt to link the 6 accounts that interacted with eachother the most. It allows for deeper inspection, and perhaps more information. However, 2.) They almost certainly are. I could see them saying how many people they actually had almost as a bluff, but more than likely they're just throwing out misinformation.
- alvivar 15y agoI guess is part of the concept... transparency, clarity...
- Mad_Dud 15y agoIt doesn't have to be true.
- tathagatadg 15y agoI was trying to search web cache on who used the words lulz and security together before Lulzsec ... and then this final release :|
- aklemm 15y agoWhat about analyzing their writing? They release quite a bit of text...somebody likes to write. Considering there are efforts to identify people by typing patterns, I wonder if this is how they'll get caught: http://petsymposium.org/2011/papers/hotpets11-final8Chairunnanda.pdf http://petsymposium.org/2011/papers/hotpets11-final8Chairunn...
- tsumnia 15y agoUnfortunately given the scope of that paper, it doesn't sound like typing patterns can be used just yet. A sample size of 36 participants doesn't handle the scale involved when going against 'The Internet'. Also, the paper collected timestamps of each keystroke, something that'd need to done on suspects; however, if they are already suspecting you, they probably have other ways to identify you. Finally, how in the world does a paper like this get away with having 'nowadays' in it? I know its a legit word, but, just seems awkward.
- wisty 15y agoWas it written by an ESL speaker? Sometimes non-English speakers feel insecure starting a point without "However", "Because of this", and other conjunctions. If you don't need a conjunctions, you can say "Nowadays", but you don't need it. It's like the "auto" keyword in C. Because ESL speakers cram a lot of grammar into a few years, rather than spending years making simple sentences, they often use advanced patterns when simpler ones would suffice.
- kristofferR 15y agoDamn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's available publicly here: http://www.ntia.doc.gov/osmhome/allochrt.pdf http://www.ntia.doc.gov/osmhome/allochrt.pdf
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- mkr-hn 15y agoHow would using a Mac prevent that?
- ender7 15y agoGiven the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.
- afterburner 15y agoBecause if they ever got caught the company would be sued out of existence (probably bought by competitors at that point). They have too much to lose in most cases.
- deleted 15y ago[deleted]
- count 15y agoBased on the HBGary leak, I'd say that they currently do.
- skeltoac 15y agoOdds that one of the crew is commenting on this thread?
- Zarathust 15y agoIt seems that there are better people out there that got angrier http://www.gamemarshal.com/features/20110622113313/lulzsec-hacked-by-rival-hackers.html http://www.gamemarshal.com/features/20110622113313/lulzsec-h...
- cantbecool 15y agoLooks like they were a getting a bit anxious that they were going to be outed, which will ultimately still happen anyway. Regardless, it was a fun reading their Pastebins and Twitter feeds every few days making a mockery of multiple corporations information security.
- Tichy 15y agoHow is it possible to register a .com domain in an anonymous way?
- trotsky 15y agoprepaid visa or just get someone who doesn't know you very well to do it