Showing posts with label Anonymous. Show all posts
Showing posts with label Anonymous. Show all posts

Sunday, 30 March 2014

99 Israeli Websites 0wn3d bY AnonGhost

99 Israeli Websites 0wn3d bY AnonGhost.

According to hackers, this was just a warning attack. The real attack on Israeli cyber space will be after 3 days(7 Apr 2014). Whole server is massively defaced and hackers message is displaying on each hacked site. This kind of attacks rise many questions for security experts that how much hackers become powerful and there is not enough knowledge security experts have.



Deface Page Say's:
"Hi Israel !
We always here to Punish you as we did on the last Operation 7 April and we back again to celebrate it
Because We are the voice of Palestine and we will not remain silent!!

Muslims are everywhere - We will enter to Palestine soon :) remember this :D 

Alkhilafah is Coming soon Insha'Allah"

Hacked Sites:

http://fpisrael.co.il/index.htm 
http://fanpagepro.co.il/ 
http://opticcenter.co.il/ 
http://intersurf.co.il/index.htm 
http://master-market.co.il/index.htm 
http://elit.org.il/index.asp 
http://mtns.co.il/ghost.htm 
http://melach-haaretz.co.il/index.htm 
http://elicohen.org.il/index.htm 
http://elazraki.org.il/index.htm 
http://burgerville.co.il/ 
http://komunityproject.co.il/index.htm 
http://coolshoe.co.il/index.htm 
http://aclimatic.co.il/index.htm 
http://www.agr-non.co.il/index.htm 
http://animalhouse.co.il/index.htm 
http://harel.co.il/index.htm 
http://ibca.org.il/index.htm 
http://colorless-carotenoids.com/index.htm 
http://dormins-technology.com/index.htm 
http://phyto-flu-ene.com/index.htm 
http://phytoene-phytofluene.com/index.htm 
http://ibrlogin.com/index.htm 
http://antiaging-dormins.com/index.htm 
http://skincarotenoids.com/index.htm 
http://skin-youth.com/index.htm 
http://prophyderm.com/index.htm 
http://phytoeneandphytofluene.com/index.htm 
http://ariel-weltsch.com/index.htm 
http://arnongolani.co.il/index.htm 
http://bizbazz.co.il/index.htm 
http://bootnest.com/index.htm 
http://buna.co.il/index.htm 
http://www.classico-group.com/index.htm 
http://classigan-ltd.co.il/index.htm 
http://dan-viro.co.il/index.htm 
http://elazraki.org/index.htm 
http://en-levant.com/index.htm 
http://eyal-cpa.co.il/index.htm 
http://fineschmeckers.com/index.htm 
http://golanplastic.com/index.htm 
http://gvahim-ltd.co.il/index.htm 
http://www.gvahim.com/index.htm 
http://handsontraining.co.il/index.htm 
http://handson-training.com/index.htm 
http://hatraklin.co.il/index.htm 
http://haygroup-web.com/index.htm 
http://hummer2rent.co.il/index.htm 
http://ibrweb.com/index.htm 
http://idc-diamond-deal.com/index.htm 
http://moriah-collection.com/index.htm 
http://iicc.org.il/index.htm 
http://josephbau.com/index.htm 
http://josephbau.org/index.htm 
http://kakkoii-fashion.com/ghost.htm 
http://levant.co.il/ghost.htm 
http://limelect.com/ghost.htm 
http://mbegood.co.il/index.htm 
http://memorex.co.il/index.htm 
http://mhasharon.co.il/ghost.htm 
http://miriambenhaim.com/ghost.htm 
http://mirshamim.co.il/index.htm 
http://mobisoft.co.il/ghost.htm 
http://monplatin.co.il/index.htm 
http://mor-logistics.co.il/index.htm 
http://moraz-pregnancy.com/index.htm 
http://mottichef.co.il/index.htm 
http://navy-raoul.com/index.htm 
http://kachol-atlit.co.il/index.htm 
http://neve-yam.co.il/index.htm 
http://nevemarom.co.il/index.htm 
http://www.nirugroup.com/index.htm 
http://nofim.net/index.htm 
http://nordic-dog-club.co.il/index.htm 
http://oig.co.il/index.htm 
http://opticjunior.co.il/index.htm 
http://rain-line.com/index.htm 
http://samarkand.co.il/index.htm 
http://www.sandwich-factory.co.il/ghost.htm 
http://sh-m.co.il/index.htm 
http://shay-cb.co.il/ghost.htm 
http://shay-cb.com/ghost.htm 
http://shtechs.com/ghost.htm 
http://www.sivan-digital.com/index.htm 
http://www.sivan-group.net/ghost.htm 
http://steinmetz-foundation.co.il/ghost.htm 
http://www.supercom.com/index.htm 
http://talyam.co.il/index.htm 
http://www.tavlit.co.il/ghost.htm 
http://terminator.co.il/index.htm 
http://www.the7d.co.il/index.htm 
http://www.the7d.com/index.htm 
http://www.ti-group.co.il/ghost.htm 
http://indoor-outdoor.co.il/index.htm 
http://transelectric.co.il/index.htm 
http://w2pcardpack.com/ghost.htm 
http://werubel.co.il/index.htm 
http://x-pens.com/index.htm 
http://yehudalight.co.il/index.htm



author

About Author:

Muhammad Usman - Designer, Security Expert, Blogger and Programmer.
Muhammad Usman is a Professional Geek. Follow him on Facebook, Twitter, Google+, LinkedinPinterest and Soundcloud.

Friday, 10 January 2014

Israel Project Website Hacked and defaced by AnonGhost

The Israel Project website has been defaced by AnonGhost

AnonGhost has hacked The Israel Project website, they have left the website defaced as you can view here. AnonGhost has actively been hacking Israeli websites for the last years. The AnonGhost team emerged from the TeamPoison hacking crew that has been disbanded.


What is TIP

Founded in 2003, The Israel Project (TIP) is a non-partisan American educational organization dedicated to informing the media and public conversation about Israel and the Middle East.

A one-stop source for detailed and accurate information, TIP provides facts to press, policy makers and the public on issues affecting Israel and the Middle East, the Jewish people and America’s interests in the Middle East.

TIP does not lobby and is not connected to any government. TIP informs, providing facts, access to experts and keen analysis. It offers real-time background information, images, maps, audio, video, graphics and direct access to newsmakers. TIP organizes press briefings and speaker tours, conference calls and educational trips, supports non-profit journalism, conducts public affairs research and adheres to the highest possible standards of accuracy and reliability.

Working in multiple languages, the TIP team collectively has decades of experience in media, government, policy institutes, research, academia and the military.

TIP has an extensive Arabic media program. More than 1.2 million Arabic-speaking social media subscribers already follow content on TIP Arabic’s Facebook page Israel Uncensored.

Saturday, 10 November 2012

Hacker ‘Cosmo the God’ Sentenced and Banned from Internet for Six Years

Hacker ‘Cosmo the God’ Sentenced and Banned from Internet for Six Years.



A 15-year-old UG Nazi hacker going by the name of Cosmo or Cosmo the God was sentenced in juvenile court on Wednesday with terms for six years without any computers or Internet, until his 21st birthday. During these 6 years, he'll need approval from his parole officer to access the internet. Wired report that hacker resides in Long Beach, California, and began as a politicized.

Wednesday, 12 September 2012

DHS Looking Outside the Box for Hackers, Feds Warm Up to the Cloud, and More


DHS Looking Outside the Box for Hackers, Feds Warm Up to the Cloud, and More



Here is today’s federal cybersecurity and information technology news:
  • As many security experts suspected, the Apple device ID’s that Anonymous claimed came from a Federal Bureau of Investigation agent’s hacked laptop actually came from the hack of an application development company. More here.
  • A new survey finds that although much of federal information technology has not yet moved to the cloud, agencies seem to be gaining confidence in moving more critical systems to the cloud. More here.
  • The Executive Office of the President is seeking a unified system for managing thousands of internship applications. More here.
  • Secretary of the Department of Homeland Security Janet Napolitano called for guidelines to facilitate public-private cybersecurity information sharing at a recent conference. More here.
  • In an attempt to bolster their cybersecurity workforce, the Department of Homeland Security is encouraging qualified hackers to apply even if they don’t have a college degree or don’t intend to stay at the position indefinitely. More here.

Cosmo the God Hacker



Cosmo is huge — 6 foot 7 and 220 pounds the last time he was weighed, at a detention facility in Long Beach, California on June 26. And yet he’s getting bigger, because Cosmo — also known as Cosmo the God, the social-engineering mastermind who weaseled his way past security systems at Amazon, Apple, AT&T, PayPal, AOL, Netflix, Network Solutions, and Microsoft — is just 15 years old.
He turns 16 next March, and he may very well do so inside a prison cell.
Cosmo was arrested along with dozens of others in a recent multi-state FBI sting targeting credit cardfraud. It is the day before his court date, but he doesn’t know which task force is investigating him or the name of his public defender. He doesn’t even know what he’s been charged with. It’s tough to narrow it down; he freely admits to participation in a wide array of crimes.
With his group, UGNazi (short for “underground nazi” and pronounced “you-gee” not “uhg”), Cosmo took part in some of the most notorious hacks of the year. Throughout the winter and spring, they DDoS’ed all manner of government and financial sites, including NASDAQ, ca.gov, and CIA.gov, which they took down for a matter of hours in April. They bypassed Google two step, hijacked 4chan’s DNS and redirected it to their own Twitter feed, and repeatedly posted Mayor Michael Bloomberg’s address and Social Security number online. After breaking into one billing agency using social-engineering techniques this past May, they proceeded to dump some 500,000 credit card numbers online. Cosmo was the social engineer for the crew, a specialist in talking his way past security barriers. His arsenal of tricks held clever-yet-idiot-proof ways of getting into accounts on Amazon, Apple, AOL, PayPal, Best Buy, Buy.com, Live.com (think: Hotmail, Outlook, Xbox) and more. He can hijack phone numbers from AT&T, Sprint, T-Mobile and your local telco.
“UGNazi was a big deal,” Mikko Hypponen, the chief security researcher at F-Secure, told Wired via email. “The Cloudflare hack was a big deal. They could have done much more with that technique.”
So, yes, he is Cosmo the God. But before he was Cosmo, he was Derek*. And while Cosmo may be a god, Derek is just a kid. A high school dropout. A liar, fraud, vandal and thief. But ultimately a kid, without much adult supervision or guidance.
I met Cosmo by accident and opportunity, after hackers used social-engineering techniques to circumvent Apple’s and Amazon’s security mechanisms and break into my accounts. They wrought enormous damage, wiping my computer, phone and tablet, deleting my Google account, and hijacking my Twitter account.
After it happened I fell into their world and began communicating regularly with the very hacker who jacked me, a kid named Phobia. He introduced me to Cosmo, who wanted to tell me about all manner of other account vulnerabilities. And last month, I flew down to Long Beach to talk to him face to face.
*Editor’s note: Because he is a minor, Wired is not disclosing Cosmo’s real name.

The suburban Southern California neighborhood that Cosmo calls home. Photo: Sandra Garcia/Wired

Becoming Cosmo

Cosmo squirms in his chair as we sit in his grandmother’s living room. Her small apartment, with dark brown carpeting, is directly downstairs from his own. The front door is open to let the breeze blow. It’s hot, even sitting next to a fan. There is a picture of Jesus on a table. Cosmo’s family has lived in Long Beach for four generations; in fact, his great grandfather poured the foundation on the very property where we now sit.
Cosmo lives upstairs with his mother, who he says typically works six days a week as an insurance claims adjuster. She gets home late in the evening. He doesn’t speak to his father. They live just south of State Route One in Long Beach. When I look up their address on CrimeReports, it is right on the border of a zone where crime is extremely frequent and violent. But Derek doesn’t get involved with any of that, says his grandmother.
“Derek is always, always home. He don’t go anywhere,” says his grandmother. “He’s a good kid. He’s a very good kid.”
That may be, but it turns out this wasn’t his first tangle with the law. He describes previous run-ins as he sits cramped, legs and head akimbo, in the passenger seat of my rental car, while we drive around looking for a quiet place to talk. The year before, he’d been arrested after getting caught smoking pot in a bathroom at school. I ask if that was the only other time. He says it was. Then he pauses.
“Oh! And I also got, I guess you could say arrested, in October 2011. Someone called in a bomb threat to my school. They did it every day of the school week, and on the fifth day they said my name. The fifth day they called in and said I had a gun. It was other hackers.”
Cosmo’s name and address — his documents, or “dox” as hackers know them — have long been published online. And it’s meant he’s been a target for both vengeance and lulz — just, you know, because he’s Cosmo the God and one of the more notorious social engineers around.
“Someone also swatted my house,” he tells me, smiling. “It happens a lot to me. Well, the SWAT team was only once at my house, but lots of time with the local police department.” Swatting is a vicious prank where a hacker uses an internet call system to report a hostage situation, which scrambles local law enforcement to the victim’s doorstep.
“Through AOL, you can use AT&T Relay to call the SWAT. It’s for handicapped people. You have to sign up, but it’s easy to sign up. You just instant message the username AT&T Relay and then 911. They ask what’s your location, the emergency. That’s what they did to me. That’s what they did to my school too, because there’s less ways of getting caught.”
Cosmo shrugs at this, like it’s all perfectly normal stuff for a teenage boy. And the thing is, in 2012, it is perfectly normal for a bored teenage boy on the edge of delinquency. Instead of egging cars and swinging bats at mailboxes, he’s breaking into e-mail accounts.
Cosmo got into hacking via online gaming. He grew up on Xbox, and played others online competitively. One day, he was knocked offline mid-match, forfeiting the game. He discovered that this was done via a simple trick, where one gamer turns a script on his opponent’s IP address. He began using this same tactic himself. It was easy and required nothing more than off-the-shelf programs, like Cain and Able. It was a veil lifted.
Xbox gamers know each other by their gamertags. And among young gamers it’s a lot cooler to have a simple gamertag like “Fred” than, say, “Fred1988Ohio.” Before Microsoft beefed up its security, getting a password-reset form on Windows Live (and thus hijacking a gamer tag) required only the name on the account and the last four digits and expiration date of the credit card on file. Derek discovered that the person who owned the “Cosmo” gamer tag also had a Netflix account. And that’s how he became Cosmo.
“I called Netflix and it was so easy,” he chuckles. “They said, ‘What’s your name?’ and I said, ‘Todd [Redacted],’ gave them his e-mail, and they said, ‘Alright your password is 12345,’ and I was signed in. I saw the last four digits of his credit card. That’s when I filled out the Windows Live password-reset form, which just required the first name and last name of the credit card holder, the last four digits, and the expiration date.”
This method still works. When Wired called Netflix, all we had to provide was the name and e-mail address on the account, and we were given the same password reset.
Cosmo says he did not know with certainty Netflix had the information he wanted prior to the call. But his success was an ah-ha moment.
“I figured that if Netflix could score, so could any big provider. Back then, Amazon was easier. And then it got a little bit more security. They made it where you needed the last four of the credit card to reset [a password]. That’s when I figured out you just have to go to fakenamegenerator.com to get a credit card number. So, I would just add the card, hang up, call back, give them the last four and they’d reset it.”
This Amazon method, the same one other hackers used to break into my accounts, was one of Cosmo’s innovations. (Although other hackers also claim to have discovered it independently.) I ask him how he figured out he could pull it off, because it’s as clever as it is devious. He shrugs. “It just came to me.”

Photo: Sandra Garcia/Wired

Enter UGNazi

Cosmo was soon finding all manner of sources for getting information: Hulu, Buy.com, BestBuy, PayPal, Apple and AOL all offered avenues into others’ accounts, where he could peep in at credit card numbers, addresses and emails.  He learned new social-engineering techniques online and likewise passed along what he knew to others. There is a constant information trade back and forth online. IRC and AIM are the user manuals to every back-end customer service system in corporate America.
Meanwhile, he had more time than ever to devote to his particular brand of hacking, also known as socialing. After the bomb threats, he was asked to leave Woodrow Wilson High School in October. He started taking classes at an adult continuing education program where he could complete his degree. But he found it boring. And he had to walk there and back, three miles each way. So in December, he quit.
This meant he was now home all the time, bored. The next month, an online friend of his approached him about joining a new hacking team. The friend was Josh the God, and he was putting together a hacktivist group called UGNazi, with the intention of using their combined skills to protest SOPA and CISPA. Far from being intimidated by the proposed anti-piracy legislation, they were motivated by it. They wanted to attack it and those who supported it. Cosmo’s job was to socially engineer companies that could provide data about their targets.
One of their initial targets was UFC.com–the website of the Ultimate Fighting Championship–in retaliation for its support of SOPA. (They did the same to Coach.com.) Once Cosmo gathered the necessary background information on UFC’s president, Dana White, they were able to get into the company’s account with Network Solutions. Via Network Solutions, they redirected the DNS to one they controlled. Bang.
SOPA, of course, died. But UGNazi lived on. They took down the websites for the states of California and Washington and the cities of New York and Washington D.C. They took out Papa John’s website after itfailed to deliver a pizza in a timely manner. They hacked into MyBB.com, the back-end that many websites use to power forums, and then hijacked its domain. They were pure mayhem.
“UGNazi was also remarkable in how they apparently had no limits on who to attack–the U.S. government, CIA, Wounded Warrior etc.” says Hypponen, “and no apparent [sense of] self preservation, which led to their demise. In this regard, UG and Lulzsec were similar.”
The group’s last big takedown was 4Chan. “Josh thought everyone on 4chan was a child molester,” Cosmo explained. But there was more than likely another motivation as well: Lulz. Not to mention huge traffic. If they could redirect 4chan to their own Twitter feed, even for a minute, they would achieve instant notoriety.
Their avenue to jack 4chan was a web services company called CloudFlare that was providing 4chan’s DNS services. (Ironically, UGNazi.com was also a CloudFlare customer.)
The original idea was to take CloudFlare via Network Solutions, something UGNazi done many times before with other companies. They had gotten CloudFlare CEO Matthew Prince’s dox and had all the information they typically needed to hijack a NetSol account. But they hit a snag: Prince had a two-step security mechanism on his account. They needed a device-specific PIN code that they couldn’t get. But they had been able to ascertain that Prince’s phone number was on AT&T, which meant they had another avenue of attack: his Google email, which used that AT&T number as an account recovery option.
Security is only as strong as its weakest link. And in this case, the weak link was AT&T. If UG Nazi could get to Prince’s phone, which was his backup mechanism, they could get to his Google account. And to get to his phone, they just needed his Social Security number. That sounds like it’s a tough thing to get. It’s not.
Social Security numbers are freely bought and sold online, not on hidden Tor sites or via some dark back alley, but on the open Web in broad daylight. The cost to buy a Social Security number and date of birth on one Russian site Cosmo referred us to, for example, is $3.80, payable via an alternative currency favored by carders called Liberty Reserve.
Once they had Prince’s Social Security number, it was time to manipulate AT&T’s customer service.
“First we called AT&T to forward [Prince’s] cell phone number to Google Voice. We did that, and the lady said ‘alright what’s your name?’ And Josh said ‘Matthew Prince.’ And the lady said, ‘what’s the last four digits of your SSN?’ And Josh gave the full SSN anyway. And she was like ‘alright what’s the phone number you want to forward it to?’
“He gave her the Google Voice number, and it was forwarded.”
Cosmo initially said UGNazi used text message forwarding, which both Google and Prince say is not the case. Furthermore, while Wired was able to set up a forwarding number in the manner Cosmo described, we were not able to forward text messages to Google Voice from AT&T. Voice yes, text no. It’s the one glaring inconsistency in everything Cosmo reported. When I asked him about it again, via AIM, he replied “maybe it’s just voice for them then.”
As Prince described the attack to Wired, his personal Gmail address was the backup address for his corporate Google Apps email. Although he had two step on the corporate account, he did not have it on the personal one. Furthermore, his phone number was the account-recovery option on that personal address. So UGNazi sent an account recovery request to his phone, which was forwarded to their number, and then used it to take over his personal Gmail.
“Once they were in that, they used it to get into my corporate email by doing an account recovery, which was sent to my personal email,” says Prince. “Even though I had two-factor authentication on, for this one account-recovery procedure, Google didn’t verify any out-of-band system. They just sent the email to my personal Gmail and then, once they were in that, they were able to get into my personal email.”
Google says this type of attack is no longer possible. A Google spokesperson gave Wired a statement noting “We fixed a flaw that existed in the account recovery process for Google Apps for Business customers under very specific conditions. If an administrator account that was configured to send password reset instructions to a registered secondary email address was successfully recovered, 2-step verification would have been disabled in the process. This could have led to abuse if their secondary email account was compromised through some other means. We swiftly resolved the issue to prevent further abuse.”
Ultimately, the end result was that UG Nazi was able to bypass the Google two factor and gain access to Prince’s CloudFlare’s email and then admin tools. They were then able to redirect 4Chan’s DNS to point to their own Twitter account. The hack lasted mere minutes, but given 4chan’s traffic volume, it was enough. It was extremely high profile, and UG Nazi was now basically the most notorious hacking crew of 2012.

People Are The Key to Every Lock

As he did with Prince and CloudFlare, Cosmo accomplished many of his feats by going after individuals associated with organizations UG Nazi was targeting. He would gather little bits of information here and there, collecting dox data from various online services, like addresses and credit card numbers, until he had what he needed to launch an attack. Often, he did that by calling a company’s tech support system and pretending to be a worker in another department. Sometimes he was able to pull that off by learning intimate details of a company’s back-end systems.
“I had a friend who installed a remote access tool on a Netflix computer. When [the Netflix employee] was AFK–not at the computer–he could use that computer. From there he took a bunch of screenshots, and saw the [support] tool was called Obiwan.”
Cosmo couldn’t actually use Obiwan himself because he didn’t have a Netflix IP address. But that didn’t matter. He just needed to know what the back end looked like.
“You have to impersonate a Netflix agent. So you call up and say ‘Hey, my name is Derek. I’m from Netflix Canada and I’m having a technical difficulty with Obiwan. Can you look something up for me?’ Then you say the email, the name, the billing, and then you ask for the last four. Then you just call back and reset their password.”
And that’s the secret. When Cosmo calls a company pretending to be an employee, he doesn’t wait for them to ask for details. He tells them all the person’s data he has up front. If he knows three pieces of a puzzle and just needs the fourth, he gives them those first without waiting to be asked for them. That way he demonstrates a knowledge of the system, disarming the person on the other end of the line and making them less likely to question his authenticity.
Cosmo sometimes even provides details that he knows tech support doesn’t need. For example, if a tech support requires only the zip code on file, he’ll provide the full address anyway. It makes him appear more knowledgeable and less likely to be questioned. That’s classic social engineering.
“You can pretty much do it at any company–impersonate an agent,” he shrugs and smiles. “Most people will fall for it unless they’ve been trained not to. But most companies aren’t doing that.”
Some of his techniques are incredibly complicated and involve multiple levels of social engineering, like the method he developed for getting into PayPal.
The inside of a PayPal account is a trove of information for social engineers. Once logged in, you can see the last four digits of someone’s credit cards and bank accounts, and their current billing address. That information can, in turn, be used to obtain password resets on all sorts of other sites. More nefariously, once inside someone’s PayPal account, you can flat out rob them.
Cosmo explained exactly how it is done.
“You have to add a bank account. You can make a virtual bank account on eTrade.com with info from FakeNameGenerator.com.”
Wired verified that it’s possible to create online bank accounts with automatically generated information–although we were also required to enter a driver’s license number, which we got via a second site, using the information from FakeNameGenerator.
“You call PayPal, and you have to have the last four of a payment method. You can get that from Amazon or you can impersonate a PayPal agent. They access your account from the last four. You tell them you want to add a phone number, and you add a Google Voice number. And then you say, I also want to add a new bank account I just got. And they add that for you.
“Then you hang up, go to PayPal.com, and go to Reset My PayPal Account. It says send to a phone number and shows the last digits. You pick your Google Voice number, and then it [calls] your phone. You enter that, and you go to a new page of verification that says please enter your full bank account with routing number. You just add the bank account number you made with E-Trade. And once you click next, it prompts you to create a new password.”
Wired was able to replicate this method and receive PayPal password resets. After we disclosed the issue to PayPal, the company closed this security hole. PayPal’s director of communications, Anuj Nayar, told Wired this was a temporary issue caused by product testing that was accidentally left open and had now been closed.
Wired’s subsequent tests found this to be the case, although we could still add a phone number to an account, PayPal would no longer send a password reset to it until it had been verified by logging in.

Busted

Cosmo was still sleeping when the police arrived at his apartment. Officers and a detective with the Long Beach Police Department searched his home and seized three of his netbooks and his iPod Touch. They put him in handcuffs and refused to let him change clothes out of the shorts and t-shirt he’d been sleeping in the night before. Then they took him to the Los Padrinos Juvenile Hall, where he spent the next two days.
They raided his grandmother’s home, too.
“I was in the bathroom and I heard some guys talking,” she says. “When I opened up the bathroom door there was this cop standing right at the door. He stood right inside this door and it startled me. He took me by my arm and told me to come in and sit down. I sat down and the three cops were standing over there and they just stood there. I was startled and some cops walked by with Derek, and he was handcuffed.”
Cosmo suspects the raid was tied to UGNazi’s participation in the WHMCS credit card dump, when they dropped a half million credit card numbers on the open Web, and not the CloudFlare hack that ultimately landed UGNazi on the FBI’s hit list. Still, he expressed remorse for what had gone down with Prince and for people who were still having accounts compromised via methods he pioneered.
“I called Matthew Prince the night before [the hack],” Cosmo told me. “I was going to tell him about it. I called through AT&T relay and he hung up on me. I was just going to let him know, ‘Your site’s about to get hacked.’ Josh was going to do it anyway, but…”
Did Cosmo really try to warn Prince? Prince confirms that he did get several calls via an AT&T relay the night before. And while a warning may seem far fetched, it would not be completely out of character.
For example, I was hacked long after Cosmo was arrested and had lost his ability to do any more damage. Yet he managed to learn about how it was done and attempted to relay that information to me via Mikko Hypponen, whom we both follow on Twitter. It was too late, but, still, he made the effort.
And then there’s the question of why he’s speaking to me at all. Why he’s essentially incriminating himself before he goes to trial. He ultimately reached me via Phobia, the guy who hacked me. Phobia said Cosmo wanted to tell me about a specific AOL account hack that they wanted closed. From my first interaction with Cosmo, weeks ago, through today, he has maintained this was his motivation for talking.
The method Cosmo described for taking an AOL account away from its owner is distressingly simple. Worse, multiple hackers described the AOL exploit as ancient and well known. In short, it takes nothing more than someone’s name and address to take over their AOL email.
To get a password reset on a free AOL email or chat account, all one needs to give the over-the-phone tech-support worker is the first and last name and zip code on the account. For a paid account, AOL asks for either the address or the last four digits of the credit card on file.
Cosmo tells me this casually, while drinking water from a plastic bottle. I stare at him.
“Yeah…. that’s all you need to do.”
Wired was able to confirm this and received password resets on both paid and free accounts, despite being being unable to answer account security questions. In some cases, we even deliberately provided incorrect answers. After we informed AOL, it quickly halted issuing password resets over the phone.
“We looked into the matter and found that there was, in fact, a gap in our phone support processes,” AOL’s Senior Vice President for Mail and Mobile David Tempkin informed Wired via email. “We addressed the problem immediately, and as of today, AOL users are better protected — it’s no longer possible to hack into an account via a phone-based password reset.”
As a direct result of Cosmo coming forward, PayPal and Aol changed their account security procedures. For me, this only adds to his enigma.
I wonder how much of everything else Cosmo has told me is true. The only thing I am certain of is that online security is an illusion. But I think he is being honest now. I think he’s genuinely remorseful and just wants all these gaping account holes, many of which he found or helped publicize, closed at last before anyone else has their identity stolen, or the SWAT team sent to their door. That’s what I believe, at least.
But then, he’s a very, very good liar.

GoDaddy hacked by Anonymous? Not likely

GoDaddy hacked by Anonymous? Not likely




Yesterday the massive Internet registrar/lowbrow advertiser GoDaddy went down, taking millions of web sites offline with it. Breaking news reports attributed the trouble to a hack by Anonymous. Later, these items were corrected to say that the hack was not the work of Anonymous as a whole, but that Twitter user @AnonymousOwn3r was claiming responsibility. Mashable called @AnonymousOwn3r ”the security leader of Anonymous,” which must be true because @AnonymousOwn3r calls themself “the security leader of Anonymous” on his or her Twitter profile (and an “official member” to boot).  CNN went with the more measured description of @AnonymousOwn3r as “a person affiliated with Anonymous.”

All of this is very silly. Anonymous isn’t an organized group of any kind and has no office or officer to make anything official. It has no leaders of security or of anything else, but I guess it does have affiliates. You become one by being anonymous on the Internet. Are you logged in to Macleans.ca right now as you read this? If not, you are a person affiliated with Anonymous.

Whoever @AnonymousOwn3r is, they’ve gained notoriety and thousands of new followers in the last 24 hours and are likely having a laugh at the media right now. It might be a big laugh, because @AnonymousOwn3r might have had nothing to do with GoDaddy’s troubles.

GoDaddy is claiming today that they were not, in fact, hacked at all. CEO Scott Wagner said in a statment today that the outage had nothing to do with a hack or with a denial of service attack, Anonymous’ brute force method of pushing sites offline. Instead, it was “due to a series of internal network events that corrupted router data tables” (which is totally what I thought it was from the start).

Could Wagner’s statement be face-saving bluster? Possibly, but if so, he would be playing a very risky game. Hackers are usually all too happy to provide technical proof of their deeds, and if necessary, demonstrate their “ownage” of a site by smacking it offline again. @AnonymousOwn3r is assuring doubters that he or she is the real deal and linking to GitHub text purportedly documenting GoDaddy’s vulnerabilities.

As security experts analyze this, we’ll find out who is lying: CEO Scott Wagner or @AnonymousOwn3r.

My best guess? GoDaddy went dark due to some internal technical glitch, some random indvidual took credit, the media ran with it, and “lulz” ensued.

Tuesday, 11 September 2012

Hackers Stole Apple Data From US Company, Not FBI

Hackers Stole Apple Data From US Company, Not FBI

Hacked ... Apple product identification data was posted online.


A US company says that its files - not an FBI agent's laptop - were hacked by a renegade group that released Apple product identification data it claimed to have obtained through a breach of the law enforcement agency.
"We want to apologise, announce what happened and set the record straight," said Paul DeHart, chief executive of software company BlueToad.
FBI spokesman Paul Bresson confirmed that "it certainly does appear that BlueToad was where the information was actually compromised."
BlueToad hosts more than 5,000 worldwide publications including consumer magazines and business documents, and creates apps for its clients. DeHart said the company experiences about 1,000 unsuccessful break-in attempts a day.

DeHart said his company realised it had been hacked soon after the group "AntiSec," an affiliate of Anonymous, posted a file on the internet with the identification numbers for what it claimed were 12 million Apple devices on September 3.
Anonymous is one of several loosely affiliated hacking groups that take credit for breaking into government security agencies and major corporations worldwide.
"A third party reached out to us who was examining the list that was on the internet and said, 'Hey, we see some connections to you guys,'" DeHart said.
He said his company is cooperating fully with the FBI. For security reasons, he declined to provide details of how they confirmed the data file came from his company.
"We haven't tied it to a person at least as of yet ... but we were able to figure out essentially what happened, tied to a lot of things and we've passed that information on (to the FBI)," DeHart said.
He said fewer than two million device IDs were obtained by the hackers rather than the 12 million the group claimed. He said his company, which does not collect private information such as Social Security numbers or credit card information, plugged the hole in its security system and has hired a national security firm to perform a complete security analysis.
"The attack that we got was pretty sophisticated, pretty determined," he said.
DeHart said his company hosts time-embargoed and time-sensitive content that could make it a target of hackers. He also speculated that whoever posted the data on the internet might have been acting out of a grudge against a hosted publisher, or might be trying to establish their bona fides among the well-known hacking groups.
The Apple ID numbers, called unique device identifiers or UDIDs, are a sequence of letters and numbers assigned to Apple products, such as iPhones or iPads. Many web-based mobile applications and gaming networks use UDIDs to identify users.
Marc Maiffret, chief technology officer of security firm BeyondTrust, said the data dump itself, while serious, would not prove to be very damaging to consumer privacy, and would not allow hackers to break into peoples' iPhones.


Monday, 10 September 2012

GoDaddy goes down, Anonymous claims responsibility

GoDaddy goes down, Anonymous claims responsibility


CBS News) GoDaddy, the domain registrar and Web hosting company, is down, perhaps taking millions of websites down as a result.
"Status Alert: Hey, all. We're aware of the trouble people are having with our site. We're working on it," @GoDaddy tweeted Monday.
A quick call to the company's customer service line resulted in this voice message:
"If you are having a problem with your email, we are aware of the problem."
GoDaddy email addresses are down, as well. The blog suggests customers concerned with that their site has been affected can check online status at Down For Everyone Or Just Me.
Twitter accounts claiming to be associated with the hacking group Anonymous claimed responsibility for the attack.
"Basically, every GoDaddy site on the planet just crashed," @TibitXimer tweeted.
"#TangoDown - godaddy.com," @AnonOpsLegion tweeted Monday, claiming that the Twitter account @AnonymousOwn3r was responsible for the breach. "TangoDown" is the term that Anonymous generally uses to signify that a website is down. 
"By using / supporting Godaddy, you are supporting censorship of the Internet," @AnonOpsLegion tweeted again later. 
GoDaddy was the target of protests after it was discovered that the company supported unpopular bills the Stop Online Piracy Act (SOPA) and Protect IP Act (PIPA).
GoDaddy did not immediately respond to CBS News' request for comment.

Tuesday, 4 September 2012

What Apple UDID’s? FBI Denies Being Hacked By AntiSec

What Apple UDID’s? FBI denies being hacked by AntiSec

Washington: The FBI on Tuesday disputed a computer hacker group’s claim that it stole personal identification data on millions of Apple device owners from an FBI agent’s laptop.

FBI officials said the bureau never asked for and never possessed the database that the group, which calls itself AntiSec, is posting on a website.
The group has released a link to a database of more than 1 million unique identification numbers for Apple devices, which could include iPhones and iPads. AntiSec said the data is just a piece of the more than 12 million unique identification numbers and personal information on the device owners that it got from a laptop used by an FBI agent.
The FBI denied that it ever had that information. But officials there said they could not verify the validity of the data that AntiSec released. Federal officials also warned that computer users should be careful when clicking on such links because they sometimes may contain malware that can infect computers.
FBI says it never had access to the Apple info. Reuters
Joe Stewart, a security researcher with Atlanta-based Dell SecureWorks, said, however, that he tested the link and did not find any connection to malware.
Apple did not respond to repeated requests for comment Tuesday.
Apple assigns unique device identification numbers (UDIDs) — a string of numbers and letters — to all of its devices. The numbers let iTunes and application developers know which device is running which apps. As an example, the numbers allow game developers to keep track of users’ high scores.
Besides the identification numbers, the information posted by AntiSec has the name that a person chooses to name their device and a description of whether the device is an iPhone, iPad or iPod Touch.
If linked with other information such as a name or address, the numbers could be used as a way to get at other more sensitive data. But knowing the number doesn’t enable the FBI to track or eavesdrop on people.
In its posting, AntiSec said it got the file by hacking into the laptop of an agent who was on one of the bureau’s cyber action teams. And it said part of the file’s name on the laptop was “NCFTA,” referring to the National Cyber-Forensics & Training Alliance. The NCFTA is a nonprofit group made up of experts from the public and private sectors to share information on cyber threats.
In the Internet post, it said the FBI was “using your device info for a tracking people project.”
A group known as Anonymous and its offshoot Lulz Security have been linked to a number of high profile computer attacks and crimes, including many that were meant to embarrass governments, federal agencies and corporate giants. They have been connected to attacks that took data from FBI partner organization InfraGard and they’ve jammed websites of the CIA and the Public Broadcasting Service.
Earlier this year, FBI agents arrested several hackers tied to the group, and in the process revealed that LulzSec’s reputed leader, known as Sabu, was an FBI informant.
Law enforcement officials said that linking the Apple data theft to an FBI agent may have been done, in part, as retribution for the arrests.