5 ms·
Seems like a real stretch to me. HBGary like _targeted_intrusions_ with corresponding broad private information disclosures might have a bit of claim to that th
by trotsky 15y ago
Seems like a real stretch to me. HBGary like _targeted_intrusions_ with corresponding broad private information disclosures might have a bit of claim to that theory.
But as far as I can tell you just saw a couple of script kiddies run automated scans against whoever & whatever, happen to see a flaw at BAH, get in a dump a SQL database and then brag about how awesome they are. Big fucking deal?
Disclosing password hashes isn't going to bring down shit. It's like the hacker equivalent of the special olympics.
- travem 15y agoWith the password hashes being unsalted MD5 and estimates of password reuse averaging from 12% this is valuable information that could be used to gain access to more sensitive systems. Sure it may be as simple as running an automated scan, but if a script kiddie could do that and get this information it's likely this information may well have been compromised before now, we just haven't heard of it. [1] "A large-scale study of web password habits" http://portal.acm.org/citation.cfm?id=1242572.1242661 http://portal.acm.org/citation.cfm?id=1242572.1242661 via http://www.lightbluetouchpaper.org/2011/02/09/measuring-password-re-use-empirically/ http://www.lightbluetouchpaper.org/2011/02/09/measuring-pass...
- DanHulton 15y agoFor what it's worth, I just started a service based on the high password reuse you mentioned: http://www.emailambush.com http://www.emailambush.com I figure finding out the moment your email account is compromised is worth investing in, especially in these most recent days of hackers running wild.
- trotsky 15y agobut if a script kiddie could do that and get this information it's likely this information may well have been compromised before now, we just haven't heard of it. Hi. This happens all the time. There is evidence of far more significant data breeches nearly every day in the press - Byzantine Hades, RSA, Aurora, Night dragon, the list goes on and on. Probably the best argument for why this specific sql database with web app passwords hasn't been compromised in the past is that it's of very questionable value. The people holding up convenience stores aren't revolutionaries. And that's true even if you try to spin a yarn where removing the funds from a tax paying business might lead to an eventual budget shortfall.
- jimmyjim 15y agoI'm not sure why so many people jump to calling members of these groups "script kiddies" -- perhaps because it's in the vogue and makes one feel more important than others? It's been shown that a few of the 0days these guys are using are from their own findings. A handful of members of different groups (of Antisec fame and some not) seem to take great interest in cryptography, reverse engineering, etc. As immature as their ways may be, as misguided as their goals may seem to you, they're not certainly not script kiddies and they're certainly pretty clever if they've managed to not get caught yet.
- trotsky 15y agoLol, wait what? Which 0-days has it been shown they're using, let alone ones they developed themselves? I think the phrase here is citation needed. If you're using private zero days to break into systems you're almost assuredly not telling anyone about them - and the flip side is probably true as well.