Several weeks ago, I sent the following inquiry to Armatix, the makers of the "Smart System iP1", a "smart gun" secured by a RFID watch. Today I recieved an email stating that they will not be answering my questions because the information is "company confidential". My original letter and the resulting email string are as follows.
This Blog has Moved!
This blog is moving to
Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts
Closing Web Application Security Vunerabilities with Fortify
Recently I've started looking at the various source code vulnerability scanner programs.
Here is a great video demonstrating cross site scripting and SQL injection vulnerabilities in web applications. Take a look!
Here is a great video demonstrating cross site scripting and SQL injection vulnerabilities in web applications. Take a look!
Target Data Breach Outlines Need for Application Whitelisting, Flaws in PCI-DSS
As I find myself diving deeper down the rabbit hole of the recent Target data breach and the malware writers behind it, I can't help but keep asking "Why were no safeguards put in place to prevent this?"
For those who didn't hear, there has been an arrest of two Mexican citizens in Texas who were using stolen credit card numbers to purchase goods - and that the case possibly leads back to the Target data compromise.
Quite honestly, with today's computer security suites, there is almost no excuse for a static configured system such as a Point of Sale terminal to ever be infected by a virus. With proper implementation of application whitelisting a system can be protected from even unknown malware.
However, the Payment Card Industry Data Security Standard (PCI-DSS) only requires basic anti-virus coverage to protect against "known" malware, as well as a (network-based) firewall.
Target Customers' Credit Cards Now Available on Black Market
If you shopped at Target any time between November 27th and December 15th, cancel your card now. Target is giving very bad advice that you won't be held responsible for any fraudulent transactions. Even if caught, fraudulent transactions could quickly become a complete nightmare, resulting in the inability to pay bills or buy groceries.
As an update to my post Target Should Offer Free Credit Monitoring for Impacted Customers, customer credit cards have now been posted to the black market.
This is in complete contrast to statements previously made by Target claiming that there is no reason to cancel your credit cards.
Target is now claiming they will offer free credit monitoring services for everyone affected. If you shopped at Target during this time period with your credit or bank card, you should hold them to their word on this.
Target is also offering a 10% discount to customers who shop on the 20th and 21st. Personally I think this is a slap in the face to their customers, and many will have a hard time shopping and they probably won't have a credit card anymore, since they should cancel their card and have the bank issue a new one.
As an update to my post Target Should Offer Free Credit Monitoring for Impacted Customers, customer credit cards have now been posted to the black market.
This is in complete contrast to statements previously made by Target claiming that there is no reason to cancel your credit cards.
Target is now claiming they will offer free credit monitoring services for everyone affected. If you shopped at Target during this time period with your credit or bank card, you should hold them to their word on this.
Target Should Offer Free Credit Monitoring for Impacted Customers
In case you haven't heard, Target has been the victim of a massive network breach potentially impacting all credit card customers who shopped between November 27 and December 15 of this year, including Black Friday.
Normally when this happens, organizations try to make amends with their customers, often with free credit monitoring and identity theft protection for a year.
However, Target has chosen to take a potentially more damaging route (from a PR perspective), and simply direct customers to monitor their own accounts and request a free credit report.
Now it is understandable that Target is hesitant to do so, since credit monitoring services could potentially cost between $100 and $200 per person. Since 40 million customers are affected, this means Target would need to take a loss between $4 and $8 billion. According to MarketWatch Target's yearly profit has been approx. $20 billion. This would significantly impact their bottom line - but the potential loss of customers could be even more damaging.
Target - the ball is in your court. This could potentially make or break your company. Do you want to do the right thing and provide credit protection for customers? Or do you want to risk tarnishing the Target brand forever?
For historical reference, T.J. Maxx was forced to provide credit monitoring for customers.
Note: The blog author's family is most likely included in the list of affected customers.
Normally when this happens, organizations try to make amends with their customers, often with free credit monitoring and identity theft protection for a year.
However, Target has chosen to take a potentially more damaging route (from a PR perspective), and simply direct customers to monitor their own accounts and request a free credit report.
Now it is understandable that Target is hesitant to do so, since credit monitoring services could potentially cost between $100 and $200 per person. Since 40 million customers are affected, this means Target would need to take a loss between $4 and $8 billion. According to MarketWatch Target's yearly profit has been approx. $20 billion. This would significantly impact their bottom line - but the potential loss of customers could be even more damaging.
Target - the ball is in your court. This could potentially make or break your company. Do you want to do the right thing and provide credit protection for customers? Or do you want to risk tarnishing the Target brand forever?
For historical reference, T.J. Maxx was forced to provide credit monitoring for customers.
Note: The blog author's family is most likely included in the list of affected customers.
Hacker Academy and Pwnie Express Partner to Giveaway a Pwn Pad
The following is external content provided for readers' interest (because who doesn't like free stuff?). The blog editor is not responsible for its content.
The Hacker Academy is partnering with Pwnie Express to offer one lucky winner a Pwn Pad; a commercial grade penetration testing tablet, and a subscription to the Hacker Academy. So, how do you win?
Come up with something creative and catchy. Create something that demonstrates COMPLETE PWNAGE. Slogans, images, funny photos, hand-drawn pictures all are fair game.
Submit your entry. Use the form found here. The “Entry” field is where you put your masterpiece (submit images as links created through imgur.com).
Twiddle your thumbs. Sit and wait for the finalists to be announced and winners to be decided. follow the contest on Twitter with the #TrainYourPwnie hash tag and look for important updates and news via our blog at blog.hackeracademy.com andhttp://www.pwnieexpress.com/ blogs/pwnie.
Deadlines. Entries will be accepted until December 27, finalists announced January 6, with winner announced January 20.
The winning design will also be featured on the Hacker Academy's next t-shirt. Visit the contest website for more information and to enter.
The Hacker Academy is partnering with Pwnie Express to offer one lucky winner a Pwn Pad; a commercial grade penetration testing tablet, and a subscription to the Hacker Academy. So, how do you win?
Come up with something creative and catchy. Create something that demonstrates COMPLETE PWNAGE. Slogans, images, funny photos, hand-drawn pictures all are fair game.
Submit your entry. Use the form found here. The “Entry” field is where you put your masterpiece (submit images as links created through imgur.com).
Twiddle your thumbs. Sit and wait for the finalists to be announced and winners to be decided. follow the contest on Twitter with the #TrainYourPwnie hash tag and look for important updates and news via our blog at blog.hackeracademy.com andhttp://www.pwnieexpress.com/
Deadlines. Entries will be accepted until December 27, finalists announced January 6, with winner announced January 20.
The winning design will also be featured on the Hacker Academy's next t-shirt. Visit the contest website for more information and to enter.
Developing Intrusion Detection Systems Through Behavior Analysis
Recently at the Recorded Future User Network (RFUN) conference, I had the privilege of meeting Dr. Ben Shneiderman from the University of Maryland. Dr. Shneiderman is a Computer Science professor and founding director of the Human Computer Interaction Lab (HCIL) at University of Maryland.
Dr. Shneiderman demonstrated for us several amazing data analysis tools which have been developed at the HCIL, including LifeLines and EventFlow, two tools designed for temporal analysis and visualization of events. While these tools were designed to analyze medical events around patient care, I wondered if they could also be applied to analyze patterns used by attackers against my honeypots.
The first step was to take all of my honeypot logs and turn them into something EventFlow could understand. I imported the logs into Splunk, and started identifying fields. After careful consideration, the only fields I really care about for this analysis are the session number, source IP address, and the main commands being entered by the attacker, such as "who" "ls" "rm" etc. I combined the source IP and session number to create a session ID, so that EventFlow would treat each connection by each IP address separately.
Dr. Shneiderman demonstrated for us several amazing data analysis tools which have been developed at the HCIL, including LifeLines and EventFlow, two tools designed for temporal analysis and visualization of events. While these tools were designed to analyze medical events around patient care, I wondered if they could also be applied to analyze patterns used by attackers against my honeypots.
The first step was to take all of my honeypot logs and turn them into something EventFlow could understand. I imported the logs into Splunk, and started identifying fields. After careful consideration, the only fields I really care about for this analysis are the session number, source IP address, and the main commands being entered by the attacker, such as "who" "ls" "rm" etc. I combined the source IP and session number to create a session ID, so that EventFlow would treat each connection by each IP address separately.
Ingredients:
EventFlow,
Hacking,
Honeypots,
Intrusion Detection,
Security
Crowdfunding RFID Security Research
I've been thinking about doing some research on the security of RFID tags/access cards/etc.
This is the same topic which the Mythbusters have been banned from discussing by the Discovery Channel due toconcerns by the network's advertisers reasons unknown.
RFID is used by retailers for inventory control, building access control, livestock tracking, credit cards, passports, and even medical uses. And yet, there have been very few in-depth security studies of RFID technology.
Unfortunately, RFID equipment isn't cheap, and there are a lot of different RFID tags out there. So, I'm probably going to need to turn to crowdfunding to get the project going.
I've never used crowdfunding, and I'm aware there are a lot of different options. Any suggestions? I'm open to any helpful ideas.
This is the same topic which the Mythbusters have been banned from discussing by the Discovery Channel due to
RFID is used by retailers for inventory control, building access control, livestock tracking, credit cards, passports, and even medical uses. And yet, there have been very few in-depth security studies of RFID technology.
Unfortunately, RFID equipment isn't cheap, and there are a lot of different RFID tags out there. So, I'm probably going to need to turn to crowdfunding to get the project going.
I've never used crowdfunding, and I'm aware there are a lot of different options. Any suggestions? I'm open to any helpful ideas.
Guest Post: Steps to Take to Ensure Your Bank Accounts Can't Be Hacked
NOTE: The following is a guest post by Courtney Gordner. The blog maintainer is not responsible for its contents.
Allowing a bank to store all of your financial information is supposed to keep it safe, but that is not always the case. Although banks generally have the best anti-hacking software available and take extra precautions to keep this information secure, things do happens that can allow these documents to fall into the wrong hands. In many cases, it is not the bank's fault, as there are things that you should be doing to protect your bank account.
Ingredients:
Banking,
Guest Post,
Hacking,
Personal Security
Legacy Applications - The Swiss Cheese of Security
Almost every organization has them...
There's that one app which someone in your organization can't live without. It's probably from back in the 1990's, and the developer no longer supports it, if they're even in business anymore. Sometimes the app was never replaced simply due to lack of funding; other times a replacement simply doesn't exist.
To make matters worse, this app probably requires additional unsupported software, such as Java 1.4.2 or even Microsoft Java Virtual Machine. Bonus points if the app also requires an unsupported operating system, such as Windows 2000.
As a security practitioner, what can you do to help secure these applications which introduce gaping holes into your organization's network?
Why the Syrian Electronic Army Didn't Hack the NY Times
I'm just going to come out and say it. The Syrian Electronic Army (SEA) is a fraud. They didn't "hack" the New York Times, or any other high visibility websites today.
All SEA did today was an extremely old trick of domain hijacking. For those not familiar with it, here's a great writeup on how domain hijacking works.
All SEA did today was an extremely old trick of domain hijacking. For those not familiar with it, here's a great writeup on how domain hijacking works.
Now it's possible that SEA performed the domain hijacking through compromise of MelbourneIT, this in itself is also unlikely, based upon previous successful "attacks" using low-tech spearphishing (targeted social engineering) to obtain credentials of target organizations.
Previously, Syrian Electronic Army gained control of the Associated Press' Twitter account, The Onion's Twitter account, and the advertising service "Outbrain", all through spearphishing attacks.
Sensationalize their "hacking abilities" all you want. The Syrian Electronic Army has so far displayed very little technical skill, instead attacking "soft targets" and using social engineering. While these attacks have so far been effective, they only point out the lack of security awareness training in today's workforce, and not any serious software flaws.
Any organization which has been directly hit by SEA (and that excludes the victims of domain hijacking) should seriously reexamine their employee security awareness training, and possibly consider bringing in an outside consulting company to help identify deficiencies.
The weakest link in any network will always be uneducated users.
Anonymous #OpPetrol Most Epic #Fail Yet - Full Analysis Of Results
Looking at the "damage" (and I use that term very loosely) done as part of OpPetrol, Anonymous support by actual hackers is fading fast.
Let's take a look at the original target list of what was supposed to be attacked.
Hackers News Bulletin released a live list of all the damage done as part of OpPetrol, and it's a rather short list. Let's run through the list and look to see if Anonymous actually succeeded in their operation.
Better grab some popcorn, this is going to be quite entertaining.
Let's take a look at the original target list of what was supposed to be attacked.
United States, Canada, United Kingdom, Israel, Saudi Arabia (only Government), China, Italy, France, Germany, Kuwait (only government) and Qatar (only government)
Hackers News Bulletin released a live list of all the damage done as part of OpPetrol, and it's a rather short list. Let's run through the list and look to see if Anonymous actually succeeded in their operation.
Better grab some popcorn, this is going to be quite entertaining.
New PHP Malware Source Available for Analysis
After about a month of running my Glastopf honeypot, I've started getting some hits.
You can take a look at the files I've collected (including deobfuscated code) over at my malware analysis site.
One thing which stands out me in some of the malware is that it intentionally hides from being cached by search engines using the following code:
See something else worth discussing? Post it here!
You can take a look at the files I've collected (including deobfuscated code) over at my malware analysis site.
One thing which stands out me in some of the malware is that it intentionally hides from being cached by search engines using the following code:
if(!empty($_SERVER['HTTP_USER_AGENT'])) { $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler"); if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) { header('HTTP/1.0 404 Not Found'); exit; } }
See something else worth discussing? Post it here!
OpPetrol - It's Not About the Oil
I've posted a new Threat Watch bulletin for OpPetrol - a multi-target operation being run by Anonymous.
Updates to the bulletin can be read here.
Below is the bulletin posted in its entirety.
Target: United States, Canada, United Kingdom, Israel, Saudi Arabia (only Government), China, Italy, France, Germany, Kuwait (only government) and Qatar (only government)
Specific named targets:
Quote: “As petrol is sold with the dollar currency of the U S we find this not acceptable when the oil should be sold at the country of Origin, making petrol a lot less then what you the citizens is paying for it.”
Updates to the bulletin can be read here.
Below is the bulletin posted in its entirety.
INTEL BRIEF
First Release: 19MAY2013
Updated: 19MAY2013
Subject: Anonymous "OpPetrol"
Target: United States, Canada, United Kingdom, Israel, Saudi Arabia (only Government), China, Italy, France, Germany, Kuwait (only government) and Qatar (only government)
Specific named targets:
Saudi Arabia government emails (Most likely Phishing - http://pastebin.com/0Yr6kyWA)
Additional high probability targets:
Pending
Date: June 20, 2013
Attackers:
AnonGhost
AnonGhost
Others Pending
Attack types:
Distributed Denial of Service Attacks (DDoS)
Website Defacement
Possible leak of sensitive information
Details:
Original announcement on Pastebin: http://pastebin.com/Xsewfqvr
Second announcement on Pastebin: http://pastebin.com/38kvvD1S
Quote: “As petrol is sold with the dollar currency of the U S we find this not acceptable when the oil should be sold at the country of Origin, making petrol a lot less then what you the citizens is paying for it.”
Additional Analysis:
A look at the target list vs. top oil producers of the world (data from CIA World Factbook)
| Rank | Target List | Top Oil Producers | Amount Produced (BBL/Day) |
| 1 | No | Russia | 10,370,000 |
| 2 | Yes | Saudi Arabia | 10,000,000 |
| 3 | Yes | United States | 9,023,000 |
| 4 | No | Iran | 4,231,000 |
| 5 | Yes | China | 4,150,000 |
| 6 | Yes | Canada | 3,592,000 |
| 7 | No | United Arab Emirates | 3,087,000 |
| 8 | No | Mexico | 2,934,000 |
| 9 | No | Iraq | 2,900,000 |
| 10 | Yes | Kuwait | 2,682,000 |
| 11 | No | Brazil | 2,633,000 |
| 12 | No | Nigeria | 2,525,000 |
| 13 | No | Venezuela | 2,470,000 |
| 14 | No | Norway | 1,998,000 |
| 15 | No | Algeria | 1,885,000 |
| 16 | No | Angolia | 1,840,000 |
| 17 | No | Kazakhstan | 1,635,000 |
| 18 | Yes | Qatar | 1,631,000 |
| 19 | Yes | United Kingdom | 1,099,000 |
| ... | ... | ... | |
| 43 | Yes | Germany | 165,300 |
| 50 | Yes | Italy | 99,200 |
| 60 | Yes | France | 49,530 |
| 101 | Yes | Israel | 100 |
| 102 | No | Jordan | 20 |
| 103 | No | Slovenia (Last Place) | 5 |
Based upon the above target list, this attack has nothing to do with oil exports, especially since Israel only produces 100 BBL/Day and is third from the bottom.
Also of interesting note, the announcement speaks about Syria stealing your retirement and savings, but it was Cyprus, not Syria, that raided savings accounts when the country went bankrupt.
This operation appears to simply be an attempt at OpUSA and OpIsrael again, with a few extra countries thrown into the mix so that the operation can be declared a "success" even if only of the target countries is compromised. This operation is simply a publicity stunt, and not by any means a meaningful attempt to change anything.
Recommendations: Standard recommendations apply
Note: Based upon the past failures of OpIsrael and OpUSA, do not expect a large turnout for this operation either.
Prior to June 20 - In order for multiple sites to be defaced at the same time, malware infection or compromise of credentials must occur ahead of time. Change passwords, and perform full antivirus scans of systems. Monitor firewall logs for suspicious activity involving external IP addresses. Be vigilant, and warn employees of highly targeted phishing attacks.
On June 20 - Monitor network traffic, and coordinate with ISP should any signs of DDoS be seen.
After June 20 - Look for signs of compromise after DDoS attack. A common technique now being employed by multiple organizations is to mask hacking attacks with DDoS attacks.
Recorded Future Analysis: https://www.recordedfuture.com/live/sc/1L4n2d6OXDi8
Hacking to Setup a Free Counter Strike Server?
This week an attacker cracked my honeypot's root password "123456" and tried to install software I've never seen before.
The file was quite large for most malware packages, at over 20 MB. Curiously I uploaded the file to VirusTotal and was quite surprised that it came back completely clean.
Sure enough, more digging the more I verified the hacker had compromised my honeypot with the sole purpose of running a Counter Strike server.
I use the term hacker loosely because based upon the the attack, the person did not seem very knowledgeable outside of using his install scripts.
You can read the full attack logs on Google Drive.
This is the first time I've ever seen someone compromise a system to install a game server. I know there was a day when IRC chat bots were all the rage that people would compromise servers just to install them, but they're lightweight and don't generate a lot of traffic. A gaming server is going to generate a lot of traffic and CPU load, and surely would be noticed almost right away, right???
The file was quite large for most malware packages, at over 20 MB. Curiously I uploaded the file to VirusTotal and was quite surprised that it came back completely clean.
VirusTotal Analysis of csservers_redirecte_linux_hlds.zipAfter digging into the file further, I found that the file was actually a Counter Strike server?
Sure enough, more digging the more I verified the hacker had compromised my honeypot with the sole purpose of running a Counter Strike server.
I use the term hacker loosely because based upon the the attack, the person did not seem very knowledgeable outside of using his install scripts.
You can read the full attack logs on Google Drive.
This is the first time I've ever seen someone compromise a system to install a game server. I know there was a day when IRC chat bots were all the rage that people would compromise servers just to install them, but they're lightweight and don't generate a lot of traffic. A gaming server is going to generate a lot of traffic and CPU load, and surely would be noticed almost right away, right???
Ingredients:
Games,
Hacking,
Honeypots,
Project Picnic Basket
Identifying Hacker Group Locations Based Upon Temporal Signatures
What day and time an event occurs can sometimes be very helpful in determining the origin of that event.
Analysis Intelligence just posted an excellent article titled "Pattern of Life and Temporal Signatures of Hacker Organizations".
This article explores the possibilities of using the day/time of hacking activity to determine not only what part of the world the activity originated from, but also if they're a state sponsored group or not.
I highly encourage you to check out the article, and if applicable, apply it to your own research.
Analysis Intelligence just posted an excellent article titled "Pattern of Life and Temporal Signatures of Hacker Organizations".
This article explores the possibilities of using the day/time of hacking activity to determine not only what part of the world the activity originated from, but also if they're a state sponsored group or not.
I highly encourage you to check out the article, and if applicable, apply it to your own research.
OpUSA Failure Shows Anonymous is Past Their Prime
There have been indications of this for quite a while now, but I think it's time someone finally came out and said it.
Anonymous is losing steam, and quickly dying.
That's right, Anonymous is quickly becoming an obsolete part of a forgotten era of the Internet.
OpUSA promised to be a major cyber threat against the United States Government and major banks. Websites such as FBI.gov, Whitehouse.gov, and Bank of America were the key targets.
The actual damage? (per http://security.radware.com/Threats-Attacks/opusa/)
How much longer will Anonymous hacking groups last? Based upon current trends they may still be around for a while yet, but gone are the days where Anonymous should be considered a serious threat.
Instead, after the failure of OpUSA, they're now probably the laughing stock of the Internet.
If you're interested, you can pick up a #OpUSA #FAIL t-shirt from my CafePress shop.
Anonymous is losing steam, and quickly dying.
That's right, Anonymous is quickly becoming an obsolete part of a forgotten era of the Internet.
OpUSA promised to be a major cyber threat against the United States Government and major banks. Websites such as FBI.gov, Whitehouse.gov, and Bank of America were the key targets.
The actual damage? (per http://security.radware.com/Threats-Attacks/opusa/)
- An alert system which was being decomissioned by the Honolulu Police Department
- A Blood Bank
- Embassy of Cape Verde in the US
- ...and a handful of low-traffic websites which most people have never heard of.
How much longer will Anonymous hacking groups last? Based upon current trends they may still be around for a while yet, but gone are the days where Anonymous should be considered a serious threat.
Instead, after the failure of OpUSA, they're now probably the laughing stock of the Internet.
If you're interested, you can pick up a #OpUSA #FAIL t-shirt from my CafePress shop.
OpUSA Updated Target List Posted
I've managed to get a copy of the OpUSA target list. If you're at one of these organizations, be extra vigilant.
Additional targets are listed in the updated Threat Watch brief.
HIGH profile target listhttp://www.defense.gov/http://pentagontours.osd.mil/http://www.pentagonchannel.mil/http://www.archives.gov/http://www.whs.mil/http://www.nsa.gov/http://nsa.nato.inthttp://www.fbi.gov/http://www.whitehouse.gov/
Additional targets are listed in the updated Threat Watch brief.
Ingredients:
Government,
Hacking,
OpUSA,
Security
#OpUSA - So far an Epic Failure
In the early hours of #OpUSA, in the words of Anonymous "Op has failed to deliver!"
Anonymous et al. actually started their "hacking spree" on May 4...but no one really noticed. Probably because most of the websites were foreign hosted sites (you know, outside the target "USA"), or sites most people have never even heard of. Somewhere the SEO marketing gurus of jrzydevilmarketing.info and clearseo.net are quietly cursing, but if a tree falls on a SEO marketer's website, but no one ever visits it, does it still make a sound?
The attackers stepped up their game on May 5 and hacked even more websites. And by more, I mean more websites most people have never heard of in the USA.
May 6 - They HACKED BANK OF AMERICA. OMG!!!! No...wait...they hacked Blood Bank of America. Really guys? You hacked a blood bank? This speaks of fail on so many levels its not funny. That's like using your bat to call out a home run, then hitting a ground rule double. Sure, it just went out of the park, but it's nowhere near as effective.
Early hours of May 7 - A short list of websites was published (because these guys are clearly riding a "short bus"), and finally a target barely worth noting - the Honolulu Police Department alert system which isn't even used anymore.
So let's see - Anonymous and company planned to take down Whitehouse.gov, FBI, and Bank of America.
In fact, they even made this statement:
So...you've got less than 24 hours for "OpUSA" to be a "day to remember". So far it's been an epic failure which will be forgotten by Friday.
#TickTock
Anonymous et al. actually started their "hacking spree" on May 4...but no one really noticed. Probably because most of the websites were foreign hosted sites (you know, outside the target "USA"), or sites most people have never even heard of. Somewhere the SEO marketing gurus of jrzydevilmarketing.info and clearseo.net are quietly cursing, but if a tree falls on a SEO marketer's website, but no one ever visits it, does it still make a sound?
The attackers stepped up their game on May 5 and hacked even more websites. And by more, I mean more websites most people have never heard of in the USA.
Protip: Hacking Chinese, French, and Italian websites in the name of #OpUSA does not make a bit of difference to 99.999% of people in the USA.
May 6 - They HACKED BANK OF AMERICA. OMG!!!! No...wait...they hacked Blood Bank of America. Really guys? You hacked a blood bank? This speaks of fail on so many levels its not funny. That's like using your bat to call out a home run, then hitting a ground rule double. Sure, it just went out of the park, but it's nowhere near as effective.
Early hours of May 7 - A short list of websites was published (because these guys are clearly riding a "short bus"), and finally a target barely worth noting - the Honolulu Police Department alert system which isn't even used anymore.
“HPD Alerts was a pilot program (used) to provide breaking information to the public,” Yu said. “It was recently discontinued due to technical problems not associated with the cyberattack.”
So let's see - Anonymous and company planned to take down Whitehouse.gov, FBI, and Bank of America.
In fact, they even made this statement:
Anonymous will make sure that this May 7th will be a day to remember. On that day Anonymous will start phase one of operation USA. America you have committed multiple war crimes in Iraq, Afghanistan, Pakistan, and recently you have committed war crimes in your own country
So...you've got less than 24 hours for "OpUSA" to be a "day to remember". So far it's been an epic failure which will be forgotten by Friday.
#TickTock
OpUSA to Strike US Government and Banking Infrastructure May 7
Anonymous and several other hacking groups are planning to attack the US Government and Banking Infrastructure on May 7, 2013.
I added a threat briefing on OpUSA, what's being targeted, and by who, to my Threat Watch site.
Currently, the only named targets of this attack are Whitehouse.gov, FBI, and Bank of America. However, I'm sure other targets will be included.
If you work for a government agency, or in the banking agency, be vigilant, and be on the lookout for highly targeted phishing attacks.
You can read the full briefing at my Threat Watch site.
I added a threat briefing on OpUSA, what's being targeted, and by who, to my Threat Watch site.
Currently, the only named targets of this attack are Whitehouse.gov, FBI, and Bank of America. However, I'm sure other targets will be included.
If you work for a government agency, or in the banking agency, be vigilant, and be on the lookout for highly targeted phishing attacks.
You can read the full briefing at my Threat Watch site.
Ingredients:
Anonymous,
Banking,
Government,
Hacking,
OpUSA,
Threat Watch
Subscribe to:
Posts (Atom)




