7 ms·
Saudi Arabian Hackers Leak Credit Card Details of 400,000 Israeli Citizens
- samstave 15y agoFaction warfare. EDIT: I got downvoted, without a reply. So, explain how doing this sort of thing is not faction warfare? The details of israeli credit is leaked by anons from the house of Saud. This is clearly a faction issue. It is not likely government sponsored (though likely condoned) and as a religious rift exists between jews and muslims, the word faction applies perfectly. Jews, muslims, christians; all factions within religious zealotry.
- jonhendry 15y agoI think the term is 'sectarian'.
- samstave 15y agoA sectarian word for factions. Tomato Potato --- Sectarian: of, relating to, or characteristic of a sect or sectarian limited in character or scope --- Faction a party or group (as within a government) that is often contentious or self-seeking : clique party spirit especially when marked by dissension --- You would be a fool to claim that sectarian skirmishes are not also political, given the widespread theocratic nature of governments under both muslim and jewish rule. In this case - this is an attack, while premised on the appearance of religion, is actually a theocratic/political-religious attack.
- hack_edu 15y agoCurious to see how the general consensus of Anonymous falls in line with this. Lets not forget the long history of black hats in Israel.
- theunixbeard 15y agoInteresting. I wonder, have there been other examples of religiously-motivated hacks on this scale?
- nostromo 15y agoReligious or political? I suppose in the Middle East the two are conflated.
- kingkilr 15y agoStay classy...
- darklajid 15y agoI have an israeli credit card. I'd have liked to understand where this was leaked from. And - well - make sure that mine is not among them. Unfortunately (or fortunately?) the file isn't available any more.
- Ohadr 15y agoI also have three of them... I think once that file was online even for a few minutes, the card numbers mentioned in it are not safe anymore. It will be leaked again. If it's not some kind of provocation (files with false data) then this is a pretty big crisis. I'm going to have to monitor my credit card logs closely in the next few weeks...
- gokhan 15y agoWhich one is more safe? Letting it go so media picks it up, forcing people to renew their cards with less damage to end users or covering it and let the underground community sit on it, using random cards time to time from an endless stash?
- Ohadr 15y agoAs a possible victim I prefer spreading the list as quickly as possible. All major commerce sites and payment companies will take note of this and stop accepting these card accounts. Obviously it will still be a huge hassle to reissue all those cards but it will minimize the financial damage.
- cabalamat 15y agoIf it is false data, won't the credit card companies say so loudly?
- krembo 15y agoSince i found my CC details over there I assume this is not false data. Can we call it a cyber terror attack?
- 15y ago
- gokhan 15y ago> We have posted this message in pastebin, but it seems they have deleted the file. That Stratfor dump with 75.000 card details is still on Pastebin. Why this one deleted and the other is still there? (I believe both should be deleted.)
- vsviridov 15y agoI thought Anonymous were against corrupt politicians et al, and not just general populace :(
- krembo 15y agoMy CC was in the list that the hackers published. Just canceled it... Does anyone have good arguments against leaving the files where they are now and not deleting them from pastebin/megaupload/...? Since the beast is already out of it's cage, there is no point in chasing it. It is even better to let the public d/l the file and try to find themselves if their card and other details like emails, passwords were stolen.
- darklajid 15y agoDo you have any idea where your card was leaked from? Can you share what card provider you used? I was already paranoid about credit cards before I came, now it's really affecting my blood pressure.. (nice username btw, learned the word here..)
- krembo 15y agoI'm not sure if they stole it directly from the sites (coupon site in my case) or from the clearance company. In any case it seems that the site who store the details broke the law by storing the CVV (not to mention that passwords were not encrypted..)
- yuvadam 15y agoI just gave a talk last week at 28C3 [1,2] about how all the personal details of Israeli citizens are up for grabs for anyone inclined enough to get them. I'm ashamed to see that we've learned nothing in the past 10 years. [1] - http://www.youtube.com/watch?v=ow7cvZOzp6w http://www.youtube.com/watch?v=ow7cvZOzp6w [2] - http://speakerdeck.com/u/yuvadm/p/28c3-data-mining-the-israeli-population-census http://speakerdeck.com/u/yuvadm/p/28c3-data-mining-the-israe... EDIT: Israeli media now claims that 400K is an exaggerated number, and the actual number of leaked CC is much smaller. EDIT2: I'm gonna go ahead and publish a mirror list [3] for the leaked data and for affected accounts by email [4]. I might be affected and I prefer to know if I am ASAP, even if this means the data leaks more, which it will anyway. [3] - http://pastebay.com/186092 http://pastebay.com/186092 [4] - http://pastebin.com/EnY7E0Hw http://pastebin.com/EnY7E0Hw
- maayank 15y agowhat's the password of the rar inside the rar? the page referenced in the "readme" file is unavailable
- yahelc 15y agoWhere can I access the raw Israeli Census registry? I'm an non-resident Israeli citizen; I'm curious as to what it has on me (and if I can de-anonymize myself.)
- tcas 15y agoDoes anybody know the legality of checking these lists? I'm always concerned that the access logs are sent to various authorities.
- justmememe 15y agowhooops... didn't know the wahhabi fanatics could code :> thought they were better at beating up their wifes and sisters :>
- justmememe 15y agooh oh being politically correct? :)
- deleted 15y ago[deleted]
- teyc 15y agoDon't VISA et al require some kind of PCI compliance for storing credit card details?
- jacquesm 15y agoPCI compliance is worth as much as the party that signs off on you being compliant, in most cases that is you. Audits are few and far between, lots of places have shoddy security but claim they are Fort Knox. PCI compliancy is quite meaningless unless the people that implement it take their job seriously. That's very frequently not the case, it is just seen as a small obstacle in the way of doing business.
- teyc 15y agoThanks. Odd that VISA would let the third party auditors get away with it, until they don't... which I'd hope so in this case. Related: http://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants http://serverfault.com/questions/293217/our-security-auditor...
- rdtsc 15y agoIt is mostly to cover their behinds not really to protect your data. When it comes to litigation they basically want to point to a piece of paper with your signature on it and say "see they agreed to be compliant" it is not our fault, we did all we could.
- teyc 15y agoI saw an Australian company offering tokenising solutions for credit card transactions. Glancing briefly, they talked about replacing credit card number with "tokens" that can be stored on the customer's premises, while the actual card numbers are securely stored on theirs. To me it seems to be a sensible approach to reducing the attack surface or auditable surface. Is this what Stripe does?
- waffle_ss 15y agoI have a very hard time resolving how this type of attack could fall under the umbrella of Anonymous. Saudis specifically attacking Israel implies a nationalistic attitude, given their history. They also affiliate their hacker group with Wahabbism, which is a strict branch of Islam that most would brand as fundamentalist (and sometimes extreme). I can't really see the ideals of Anonymous coexisting with nationalism and religious fundamentalism.
- pjscott 15y agoIt's inspired by the Anonymous style: find someone you dislike, attack their computers somehow (e.g. private information theft, DDoS, web site defacing), and brag about it online. The ideals are very different, but the method is pretty similar.
- noduerme 15y agoThe difference being that the people involved wouldn't be aware there was oil under their feet if our country hadn't invented the market for it, told them it was there and given them the equipment to drill it. Left to their own devices, the only thing they'd be hacking right now would be the back end of a camel. What do you think the chances are that their brute force method wasn't one of a million snippets written by someone in the west? Or in Israel, for that matter? How about the computers they used to get on the network they benefit from, but didn't create? Reckon the intel chips were made in Israel? After all the petty bullshit, Saudis like to party too. The problem is their government and society is repressive as hell, and they're so scared to confront it, they have to go into this whole make-believe world where they act as heroes by attacking Israeli servers. It's pretty funny. I'm sure Israelis will recover. The Saudis on the other hand still live in a medieval hellhole where women can't drive a car... and this really doesn't do much to change anything. Their time and energy would be better spent trying to bring civilization to their own wasteland. [Edit] I should add, the fact that if you did this in your own country, you'd probably have your hands cut off, is a powerful motivation to go after somebody with more liberal values.
- agilo 15y ago
- Ohadr 15y agoAnonymous just declared that they are not responsible for this: https://twitter.com/anonyops/status/153969476277248000 https://twitter.com/anonyops/status/153969476277248000 "We have no love for Israeli gov't but targeting 1000s for being Israeli? Sorry, you are not #Anonymous pastebay.com/148920"
- runn1ng 15y agoHeh. I like how Anonymous keep on repeating how are they "decentralized" and the only thing really needed to join is to call yourself Anonymous - and at the same time keep on telling trough semi-official twitter accounts, how this Wahhabi attack or that Stratfor attack was not official Anonymous and blah blah blah. Hypocrisy on hypocrisy.
- pdeuchler 15y agoI would argue that the purpose of allowing anyone to call themselves "Anonymous" places the group's identity on their actions, not who they say they are. It's kind of the whole point of calling themselves "Anonymous" and leads right into the "we are legion" bit. There is no individual, only the movement. However, by performing actions that are contrary to the Anonymous ideology the Saudi attackers distanced themselves farther from Anonymous than any name could
- jonhendry 15y agoBut what is "Anonymous' ideology" if anyone is part of Anonymous? Maybe Anonymous should have chosen a different name. Other groups could then remain anonymous, without being assumed to be Anonymous.
- runn1ng 15y agoWell, actually, Anonymous didn't really chose the name - it was a joke made on default "Anonymous" username on 4chan. And it really grew somehow organically into this point. That's what I don't like about people saying "You are not true Anonymous". First hackers under the name "Anonymous" posted other people MySpace passwords on 4chan and put blinking lights on epilepsy website. And the whole scientology movement was first meant as a joke, as a reaction to the leaked Tom Cruise video. Really, people calling other people "not true Anonymous" are hypocritical. I think.
- desireco42 15y agoJust because is easy, it doesn't mean you should do it. Stealing from ordinary people even from nation that you feel so much hostility to, still it is wrong.
- noduerme 15y agoFrom what I can see, the real Anonymous at least has the balls to go after their own government. Sure it's easy to hate on Israel, and these douchebags will no doubt get some props from fellow haters for their little hack, but if they had a pair of testicles between the lot of 'em, they'd start leaking info on the dictatorship they live in, rather than stealing credit cards from the democracy next door.
- pm90 15y agoAttacking the general (innocent) populace for the faults of their government/military? That's the definition of terrorism... and not activism.
- GiraffeNecktie 15y agoGood grief. Hassling the populace with a run of the mill credit card theft is not TERRORism. Terrorism is either violence or the threat of violence. Get a grip.
- rdtsc 15y ago> Attacking the general (innocent) populace for the faults of their government/military? Generally agree but with one exception -- in places were the government claims it represents the people and most people agree with that. Then everyone who votes basically shares the guilt of what the government does.
- dvirsky 15y agoMost democracies I know are usually divided between conservatives of some sort and liberals of some sort, who agree and nothing, and usually just over 50% of the voters if not less, agree with their government's policies. I totally disagree with the Israeli gov's policies and often protest them. Guess what? My personal info was inside those files (deprecated credit card and email though). Attacking citizens of democracies because they are inseparable from their government and responsible for its actions, is a common argument for terrorism, btw.
- rdtsc 15y agoDemocracies (or just "advertised" democracies) can't have it both ways. They get to tell the world about their superior system of government where citizens have a say in how their government runs (sometimes they even invade others to impose this "superior" system on them). And that's great. But then there is the other side of the coin when the said govt. screws up, then citizens should man up and take responsibility. I am responsible for US invading Iraq and Afghanistan. If I am in those countries and I would be afraid for my safety (and rightly so). I didn't vote for it, and I don't think realistically people have the power and the voice in most advertised democracies. But then, one can argue, they are also responsible for now changing the system (and therefor the 99% Occupy stuff is happening all over, it is not about economy it is about who has the power, control and responsability).
- billpg 15y agoI've set up a site to check if your card was on the list. Just go to my site and type in your card number...
- asjd 15y agoThis is the IP of the hacker: 188.75.86.66 (It's possible this is a bounce server, but geo locating it suggests against this.) I know because I was involved in cleaning up one of the hacks. (I have to stay anonymous, but my main account has more than 7000 karma.) In the one I dealt with they did not copy stored cards (because they couldn't), but rather added extra code that would email a copy of the details to the hacker as the order was placed. (So even with PCI compliance credit card numbers can still be stolen.)
- 3pt14159 15y agoRight now, right this second edit this post. Get right of the karma count and remove the rest of what you posted besides the IP of the hacker. Word frequency analysis + knowledge of your karma count will easily identify you.
- usaar333 15y agoWhen I went to Israel a few years back I could not believe my eyes when I noticed that my entire CC number was printed on every receipt. I don't imagine online CC security being much better..
- eliben 15y agoThat was mostly fixed, AFAIK. Now only the last 4 digits are printed on receipts.
- saljam 15y agoI find it odd they call themselves “Wahhabis.” For starters, that term isn't something a “Wahhabi” would call himself. I've never been able to trace when it was first used. However, it's often used by western scholars to refer to “the Saudi guys” when classifying Muslims. Does anyone know more about this group?
- shn 15y agotoo much fuss for something you can not verify. a)are they really valid identities. %100 of them? b) how do you know that these were done by Saudis?