Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

10 October 2024

Security Experts Have Been Warning About This Forever

It appears that the systems mandated by the US government to allow our state security apparatus to easily spy on people were hacked by the Chinese state security apparatus to spy on people.

Security experts have been saying that mandatory government back doors are a bad idea, because other people can use them as well.

QED

Chinese government hackers penetrated the networks of several large US-based Internet service providers and may have gained access to systems used for court-authorized wiretaps of communications networks, The Wall Street Journal reported Saturday. "People familiar with the matter" told the WSJ that hackers breached the networks of companies including Verizon, AT&T, and Lumen (also known as CenturyLink).

"A cyberattack tied to the Chinese government penetrated the networks of a swath of US broadband providers, potentially accessing information from systems the federal government uses for court-authorized network wiretapping requests," the WSJ wrote. "For months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful US requests for communications data, according to people familiar with the matter."

These "attackers also had access to other tranches of more generic Internet traffic," according to the WSJ's sources. The attack is being attributed to a Chinese hacking group called Salt Typhoon.

The Washington Post reported on the hacking campaign yesterday, describing it as "an audacious espionage operation likely aimed in part at discovering the Chinese targets of American surveillance." The Post report attributed the information to US government officials and said an investigation by the FBI, other intelligence agencies, and the Department of Homeland Security "is in its early stages."

The Post report said there are indications that China's Ministry of State Security is involved in the attacks.

Considering the possibilities, from Daesh to the Sinaloa Cartel to whatever is left of al Qaeda, the Chinese are probably the least worrisome group to penetrate these systems. 

This is why mandatory back doors are a bad idea.

12 July 2024

Gay Furry Hackers

We owe Gay Furry Hackers a debt of gratitude after they hacked the Heritage Foundation and revealed the internal discussions behind the now infamous Project 2025.

It ain't pretty stuff.  It's ugly people with ugly minds and ugly souls trying to make the world confirm to their own ugliness:

After claiming to break into a database belonging to The Heritage Foundation, and then leaking 2GB of files belonging to the ultra-conservative think tank, the hacktivist crew SiegedSec says it has disbanded.

According to a message on the group's Telegram channel, they had already planned to exit the scene this week. That missive continues:
Given the circumstances i believe its best we do so now. for our own mental health, the stress of mass publicity, and to avoid the eye of the FBI.

I've been considering quitting cybercrime lately, and the other members have agreed its time to let SiegedSec rest for good.

And while disavowing a life of crime, SiegedSec will remain "hackers and always fighting for the rights of others." 

………

The feud began on July 9 after SiegedSec said it obtained usernames, passwords, logs and "other juicy info" belonging to the Heritage Foundation, and then leaked that private data online in response to the org producing and promoting Project 2025. The information dump has now been taken offline.

Project 2025 is a lengthy and fairly detailed blueprint that outlines how a future conservative president – such as, say, Donald Trump should he win the election again – could overhaul the federal government and public policy to enact a far-Right agenda and give huge powers to the executive branch. Trump has claimed he knows "nothing" about it all though there clear links between Project 2025's advisory board, Team Trump, and the Republican National Committee.

The Christo-fascist wishlist includes, among many, many, many things, rolling back environmental protection rules [PDF], eliminating energy efficacy standards and programs, and ending the US government's "focus on climate change and green subsidies" [PDF]. It also includes eliminating [PDF] the US Department of Education. 

………

In a July 9 post on its Telegram channel, the cat-fanatics-slash-hacktivists noted: "Project 2025 threatens the rights of abortion healthcare and LGBTQ+ communities in particular. so of course, we won't stand for that! ^-^"

Here is hoping that Biden will use the new immunity given him by the supreme court to roll up a paddy wagon and send the Heritage Foundation rat-bastards to a very dark hole.

Full disclosure:  A friend of mine worked for the Heritage Foundation, but was fired for getting cancer, so it's a personal grudge for me.

18 November 2023

Well, This is New

One of the world's preeminent ransomware gangs, AlphV, hacked digital lender MeridianLink, something that has become rather commonplace lately.

What AlphV also did was report the lender to the Security and Exchange Commission for not reporting this hack.

This is actually kind of interesting.

Now, not only will they make your data inaccessible, they will rat you out to the authorities if you do not pay:

One of the world’s most active ransomware groups has taken an unusual—if not unprecedented—tactic to pressure one of its victims to pay up: reporting the victim to the US Securities and Exchange Commission.

The pressure tactic came to light in a post published on Wednesday on the dark web site run by AlphV, a ransomware crime syndicate that’s been in operation for two years. After first claiming to have breached the network of the publicly traded digital lending company MeridianLink, AlphV officials posted a screenshot of a complaint it said it filed with the SEC through the agency’s website. Under a recently adopted rule that goes into effect next month, publicly traded companies must file an SEC disclosure within four days of learning of a security incident that had a “material” impact on their business.

“We want to bring to your attention a concerning issue regarding MeridianLink's compliance with the recently adopted cybersecurity incident disclosure rules,” AlphV officials wrote in the complaint. “It has come to our attention that MeridianLink, in light of a significant breach compromising customer data and operational information, has failed to file the requisite disclosure under item 1.05 of form 8-K within the stipulated four business days, as mandated by the new SEC rules.”

As noted, the rule hasn’t yet gone into effect, so even if the breach meets the legal definition of a material event, it’s not likely MeridianLink would be in violation. That said, AlphV is likely capitalizing on the industry-wide anxiety caused by the SEC’s recent decision to sue the chief information security officer of SolarWinds. The SEC alleged the SolarWinds executive misled investors about the company’s cybersecurity practices before a 2020 cyberattack by Russian hackers who then went on to infect 18,000 SolarWinds customers with malware.

I guess it's another way that they can exert leverage against their victims, so this was inevitable.

Still, it's a bit ironic.

09 November 2023

Yeah, No Surprise

A study has shown that there there is no evidence of Iran and Hamas coordination cyber hacking activities during the run-up to October 7.

This is not a surprise.  If Hamas had coordinated with Iran in any way, it would have gotten back to Israel faster than if they had emailed it directly to David "Dadi" Barnea, (דוד "דדי" ברנע) head of the Mossad. 

Hamas understands operational security and practices it aggressively:

There’s no sign that Iranian hackers attacking Israeli targets have coordinated with Hamas in that war, new Microsoft research out today concludes. Instead, the Iranian attacks have been opportunistic in their approach, the researchers say.

Media outlets have focused some attention on whether Iran worked with Hamas in advance of its Oct. 7 attack, when Hamas militants killed 1,400 people and took around 240 other people hostage. But at least in cyberspace, among hackers connected to Iran’s Ministry of Intelligence and Security (MOIS) and Islamic Revolutionary Guard Corps (IRGC), the answer seems to be “no,” per Microsoft.

“Microsoft does not see any evidence suggesting Iranian groups (IRGC and MOIS) had coordinated, pre-planned cyberattacks aligned to Hamas’ plans and the start of the Israel-Hamas war on October 7,” according to a summary of the research that the company plans to present at the CYBERWARCON conference today. “Observations from Microsoft telemetry suggest that, at least in the cyber domain, Iranian operators have largely been reactive since the war began, exploiting opportunities to try and take advantage of events on the ground as they unfold.”

Unlike US clients, see the roll-up of CIA assets by China in the teens as a result of compromised electronic communications, Hamas takes this sh%$ seriously.

I really do hope that the cowboys at Langley are watching and trying to learn spycraft lessons from this, but they probably aren't.

14 March 2023

Today in Schadenfreude


I am very amused.

15 September 2022

For the Love of God, Do Not Google This

An app used for student teacher communications, Seesaw, was hacked, and and users were treated to pictures of Goatse. (For the love of God, if you do not know what Goatse is, Do Not Google It!!!)

This is not a surprise, Ed Tech is notoriously insecure, and it could have been worse, it could have been a hack into people's passwords and bank logins.  (OK, maybe that's not worse.  Let me repeat this, for the love of God, if you do not know what Goatse is, Do Not Google It!!!)

It should be noted that this is software that we are trusting out children to, and it's getting hacked by people who are using it to post decades old shock internet memes instead of actually hurting people. (For the love of God, if you do not know what Goatse is, Do Not Google It!!!)

There needs to be some regulation to prevent our tax money to go to half baked software:

[Update: Seesaw told Ars that "less than 0.5 percent of Seesaw users were affected. Seesaw blocked the attack swiftly to prevent the message from being distributed widely." Although it "can't discuss the specifics of additional steps" taken to enhance security so far, some of the "additional mitigation steps to prevent an attack from achieving this scale in the future" include "refinements to our rate limiting, alerting, blocking, content detection, and login systems."]

Original story: A popular parent-teacher messaging app called Seesaw was hacked this week, resulting in families across the US receiving a Bit.ly link displaying one of the most widely shared shock images to ever befoul the Internet.

Vice posted a blurred screenshot of the text message that some parents received, confirming that the inappropriate image shared through Seesaw was Goatse, an explicit closeup image of (For the love of God, if you do not know what Goatse is, Do Not Google It!!!). Vice noted that over the years, the image has mostly been scrubbed from the Internet. However, for parents preparing to tuck in their first graders this week, its sudden resurfacing revived its original shock value from the Internet’s earliest days.

In the screenshot, one parent’s response was just a stunned “Um ???”

Seesaw is used by 10 million teachers in the US, and so far, the company has declined to specify how many accounts were impacted, NBC News reported Wednesday. NBC and Vice reporting confirmed that the issue was widespread, though. Reports showed that the inappropriate image was sent to families in school districts in Illinois, New York, Oklahoma, Texas, Colorado, Kansas, Minnesota, Michigan, and South Dakota. Some schools were so concerned that they updated their websites with pop-up windows and alerts to notify parents, urging them to avoid using the app and instead email teachers until the issue could be resolved.

Let me finish by noting that for the love of God, if you do not know what Goatse is, Do Not Google It!!!

This cannot be stressed strongly enough. That which is seen cannot be unseen.

09 September 2022

Ain't That a Shame

The Christo-Fascist hate group the Liberty Counsel got hacked and 7 years of donor information is now public.

Thousands of donors will be revealed, and held up to ridicule and hostility.

I support their right to make these donations, but it's our right to condemn and mock them for doing so.

That is how free speech works:

Liberty Counsel, an evangelical Christian nonprofit that provided a brief cited by the Supreme Court in its decision to overturn Roe v. Wade, has been hacked, revealing a 25-gigabyte internal database that contains nearly seven years’ worth of donor records. The hacker, who identifies with the Anonymous movement, released the data on the hacktivist site Enlace Hacktivista, and the transparency collective Distributed Denial of Secrets is providing it to journalists who request access.

“Noticing a worrying trend of far-right and anti-abortion activists aligning themselves with the evangelical Christian movement, hiding their funding sources behind laws that allow church ministries to keep their donations secret,” the hacker wrote in a press release, “we decided to bring about some much-needed radical transparency.”

In addition to fighting abortion, Liberty Counsel — a Southern Poverty Law Center-designated hate group — has focused its legal efforts on challenging LGBTQ+ rights and vaccine mandates in the name of religious freedom. Because it is registered with the IRS as an “association of churches,” Liberty Counsel is not required to file a public tax return, meaning that its finances are largely shielded from the scrutiny applied to other tax-exempt organizations.

This kind of sh%$ is why churches should be required to file 1099s. 

I founded a 501(c)3, and I know how difficult it is to file a 1099, and the answer is, "Not at all."

The hacked data includes content from Liberty Counsel’s website, emails the group sent to its supporters, and documentation of about $12 million in donations from some 44,000 donors since 2015. These donations, limited to those tracked on Liberty Counsel’s digital platform, represent only a portion of those the organization receives.

The records show that 501(c)(3) nonprofit organizations controlled by Liberty Counsel encouraged supporters to vote for former President Donald Trump despite IRS rules that prohibit such entities from directly or indirectly endorsing candidates for political office. They also reveal how Liberty Counsel has skillfully employed misinformation and partisan polarization over election integrity and the Covid-19 pandemic to build its email list and raise millions of dollars in small contributions — and done so at a breakneck pace since November 2020.

………

In all, the data shows donations to the organizations totaling over $748 million from roughly 409,000 donors, the earliest dating to September 2015. It also includes private information like names, addresses, and phone numbers for about 1.3 million people.

It appears that the Liberty Counsel and about ⅓ of their fellow Christo-Fascists use software called Site Stacker which has a few problems with its security.

For some reason, the example of Little Bobby Drop Tables comes to mind:


Link

30 August 2022

Ha Ha!!!!!

Disgraced medical fraudster, and poster child for backpfeifengesicht, Martin Shkreli has claimed that he had been been hacked by a Trojan attached to pr0n that he downloaded.

I hope that this is true, because the alternative is that he conducted another scam on his investors, and that is WAY less expensive:

Martin Shkreli, one of the most notorious grifters of the 2010s, has already destroyed whatever goodwill he was trying to secure through the creation of Druglike, a web3 platform for pharmaceutical modeling. Not even a month removed from the venture’s announcement, Shkreli has been tied to an early token dump for the cryptocurrency that was supposedly powering the project.

As reported by Web3isgoinggreat, $MSI’s (short for Martin Shkreli Inu, which is in fact a real token) valuation dropped by 90 percent after a crypto wallet connected to Shkreli dumped its holdings in exchange for 239 ETH, or a little over $450,000.

………

BigTitsRoundAsses.exe — After YouTuber Muta Anas posted a video calling out Shkreli for being hacked, Shkreli himself reached out to Anas, the man behind a channel called SomeOrdinaryGamers, to offer an explanation for the dump. According to Shkreli, the suspicious token dump was the result of a hack stemming from malware inadvertently torrented while Shkreli tried to download some pornography.

………

Fool me twice — Shkreli is fresh out of a prison stint that was imposed for a series of financial crimes that were unrelated to his pharmaceutical price-gouging; he’s barely holding on, if at all, to any credibility. Given that, it would certainly be a choice to engage in traceable pump-and-dump crypto scheming this soon after re-entering society. Maybe he did get hacked after all? We can’t say for sure, but he’s provided at least some receipts owning to that fact.

Regardless of the exact reasoning for the sell-off, one thing is clear: Any venture headed by Shkreli, especially one that is pharmaceutical-adjacent, should probably be steered clear of.

Yeah.  He and Elizabeth Holmes should be banished to a deserted island.

They won't be but they should be.

23 August 2022

Tweet of the Day

Now this is a phishing attack:
I guess that he did this just for the halibut.

21 August 2022

Why am I not Surprised

It appears that the criminal enterprise formerly known as Facebook™ has a solution to Apple's decision to restrict the ability of advertisers to track users across the web, it will just insert malicious tracking code into websites in its iOS apps:

Meta's Instagram and Facebook apps on iOS devices have been injecting JavaScript code into third-party websites from their custom in-app browser, gaining access to data that would be unavailable were those pages loaded in a stand-alone, WebKit-based iOS browser.

In-app browsers – implemented in native Android and iOS code using a component called a WebView – allow native app users to interact with websites without leaving their apps and opening free-standing browser applications. For this purpose, iOS offers WKWebView, part of the WebKit framework, and the more recent (and more privacy protecting) SFSafariViewController, part of the SafariServices framework.

Meta's apps rely on WKWebView, the more capable and customizable of the two options, both of which represent alternatives to opening web links in the iOS version of Safari.

"This causes various risks for the user, with the host app being able to track every single interaction with external websites, from all form inputs like passwords and addresses, to every single tap," explained developer Felix Krause, founder of fastlane.tools, in a blog post exploring the privacy implications of Meta's apps.

………

"The code in question allows us to respect people's privacy choices by helping aggregate events (such as making a purchase online) from pixels already on websites, before those events are used for advertising or measurement purposes," said Andy Stone, communications director at Meta, via Twitter.

Yeah, Andy, we believe you.  You are protecting people's privacy, just like you have claimed, and have been shown to have lied, every other time.

This sort of sh%$ will continue until Mark Zuckerberg is frog-marched out of Facebook headquarters in handcuffs.

07 July 2022

Good

It appears that the leak of gun owner data in California was far broader than previously thought.

Anything that makes the lives of the ammosexual community more difficult is a good thing:

The California department of justice admitted it had exposed the personal information of as many as hundreds of thousands of gun owners in the state, in a controversial data breach that appears of a far broader scale than the agency first reported.

The data breach temporarily made public the names, birthdates, gender, race, driver’s license numbers, addresses and criminal histories of people who were granted or denied permits to carry concealed weapons between 2011 and 2021. The state’s Assault Weapon Registry, Handguns Certified for Sale, Dealer Record of Sale, Firearm Certificate Safety and Gun Violence Restraining Order dashboards were also affected, the department said.

………

The news surfaced on Wednesday when the Fresno county sheriff’s office said that it had been informed of the data breach. It was initially reported that the exposure had affected every person with a concealed carry permit, rather than every person who was granted or denied a permit.

………

“It is infuriating that people who have been complying with the law have been put at risk by this breach,” said the Butte county sheriff, Kory Honea, the president of the California State Sheriffs’ Association, adding that sheriffs were concerned about potential risks to permit holders.

Gun fetishists own our polity, and our courts.

Even if this hack was not intended to strike fear into the hearts of gun owners, I am not broken up about the fact that this will make their life difficult.

My apologies to the decent folks who are collateral damage as a result.

 

12 June 2022

For the Love of God, Do Not Google “Goatse”

It appears that a disgruntled game developer has added "Goatse" to a Half Life 2 game mod.

If you know what "Goatse" is, you have my condolences, if you don't, you do not want to know.  That which is unseen cannot be unseen.

I will not be posting the image, (that image is NOT Goatse) and I will be expunging and descriptions from the report below: 

One of the reasons why Half-Life 2 is one of the most endearing games of all time is that it is goddamn Half-Life 2, another one is all the glorious fan content it gave birth to. No game deserves more thanks for bringing Half-Life 2 to the memestream than Garry's Mod,  an awesome open sandbox that allows players to use all models from Valve properties and create their own Source engine games. Trolls seem to have argued that Garry's Mod is too good, in fact, and so they've decided to fill it up with booby traps that are sure to traumatize anyone playing the game. Yeah, remember Goatse? We're sorry for reminding those who do, and we're even more sorry for the readers who don't know of it and are inevitably going to open google to search for something that will change their lives forever (for the worse). Goatse is a relatively ancient meme of great evil from a time when the Internet was an absolute free for all. It's a picture of ………
The horror………

22 January 2022

My Heart Bleeds Borscht

The neo-Nazi group Patriot Front got owned by some leet haxors who released their sensitive internal files to the public.

While I do not personally endorse violating computer intrusion laws, if someone chooses to do so, you could not find a more deserving group than this group of bigots:

Chat messages, images, and videos leaked from the server of a white supremacist group called the Patriot Front purport to show its leader and rank-and-file members conspiring in hate crimes, despite their claims that they were a legitimate political organization.

Patriot Front, or PF, formed in the aftermath of the 2017 Unite the Right rally, a demonstration in Charlottesville, Virginia, where one of the attendees rammed his car into a crowd of counter-protesters, killing one and injuring 35 others. PF founder Thomas Rousseau started the group after an image posted online showed the now-convicted killer, James Alex Fields, Jr., posing with members of white supremacist group Vanguard America shortly before the attack. Vanguard America soon dissolved, and Rousseau rebranded it as PF with the goal of hiding any involvement in violent acts.

Since then, PF has strived to present itself as a group of patriots who are aligned with the ideals and values of the founders who defeated the tyranny of the British in the 18th century and paved the way for the United States to be born. In announcing the formation of PF in 2017, Rousseau wrote:

………

But a published report and leaked data the report is based on present a starkly different picture. The chat messages, images, and videos purport to show Rousseau and other PF members discussing the defacing of numerous murals and monuments promoting Black Lives Matter, LGBTQ groups, and other social justice causes.

………

Friday’s published report said that the leak comprised about 400 GB of data and came from a self-hosted instance of RocketChat, an open source chat server that’s similar to Slack and Discord. It’s only the latest example of a hate group being hacked and its private discussions being dumped online. In 2019, the breach of the Iron March website revealed, among other things, that many of its members were members of the US Marines, Navy, Army, and military reserves.

File this under, "This is what you get for fist-f%$#ing a cobra."

02 December 2021

Was Benjamin Netanyahu (יִמַּח שְׁמו) Involved?

It's been known for years that the Israeli hacking firm NSO has been hacking good people on behalf of some profoundly bad actors for years, which makes me wonder why Israel has finally moved to rein in the company.

Certainly, recent revelations have made the firm toxic:

Well, it's been yet another hilarious couple of days for Israel's NSO Group. I mean, not so much for NSO, which is currently sitting at the center of a raging dumpster fire of its own creation. But just because NSO isn't laughing doesn't mean it's not funny.

For years, it sold spyware to whoever wanted it. Those customers used the powerful phone exploits to target journalists, activists, dissidents, and high-ranking government officials.

Some of this had already been exposed by security researchers like Canada's Citizen Lab before the bombshell dropped: a list of 50,000 alleged NSO malware targets. NSO denied having anything to do with the list, but report after report tied its spyware to abuse by government agencies and quasi-political leaders like kings and princes in the United Arab Emirates, one who used the malware to hack the phone of his ex-wife and her lawyer.

France's President, Emmanuel Macron, was one of those on the target list obtained by journalists. This prompted the President (and other French government officials) to acquire new phones. Because of this, the French government has decided it won't be requiring the services of NSO in the future.

………

That takes one customer off the list for NSO. The Israeli government -- after years of ignoring NSO's sales to human rights violators -- has further limited the company's market base, removing nearly two-thirds of the countries on its approved purchasers list.

………

The same can be said for the Israeli government, which has been aware of these troubling allegations about NSO for just as long, but instead chose to urge on sales to human rights abusers, rather than discourage NSO from pursuing business relationships with governments that were always going to end up abusing the powerful malware. Due to this close relationship, NSO's problems are also Israel's problems, which is likely why even the Israeli government is trying to distance itself from the country's most toxic asset.

My theory is that they kept the heat off during the Benjamin Netanyahu (יִמַּח שְׁמו) era because there was some sort quid pro quo between him and the spyware firm, which led to Israeli authorities looking the other way.

I have no evidence at all to support this, but it smells right to me.

Today in Awesome



Some people manning the cash registers are getting anti-work messages on their register tapes because people or persons hacked into those devices:

Someone or multiple people are blasting “antiwork” manifestos to receipt printers at businesses around the world, according to people who claim to have seen the printed manifesto, dozens of posts on Reddit, and a cybersecurity company that is analyzing network traffic to insecure printers.

“ARE YOU BEING UNDERPAID?” one of the manifestos read, according to several screenshots posted on Reddit and Twitter. “You have a protected LEGAL RIGHT to discuss your pay with your coworkers. [...] POVERTY WAGES only exist because people are ‘willing’ to work for them.”

On Tuesday, a Reddit user wrote in a post that the manifesto was getting randomly printed at his job.

“Which one of you is doing this because it’s hilarious,” the user wrote. “Me and my co-workers need answers.”

There are countless similar posts on the r/Antiwork subreddit, some of which have this same manifesto. Others have different messages with the same sentiment of worker empowerment. All of them suggest that the reader of the message check out the r/antiwork subreddit, which has exploded in size and influence over the last several months as workers begin to demand their worth and organize against abusive workplaces. 

“Stop using my receipt printer dudes. Although hilarious, I’d like it to stop,” one Reddit post read. Another one read: “I’ve received about 4 different messages at random times over the last week at work. Very inspiring, encouraging, and fun to see my bosses face when he has to rip them off the printer.”

If I did Reddit, I'd be on  r/antiwork.

This is funny as hell.

21 November 2021

Ha Ha!

A truly rightious bloke in Australia has download all of the NFTs on Ethereum and Solana, and uploaded the files to BitTorrent.

Needless to say, as one who considers NFTs to be a transparently obvious vehicle for fraud, I find this intensely amusing.

A 17.96 terabyte archive containing the screenshots of every single non-fungible token (NFT) minted on top of Ethereum and Solana has appeared on torrent site PirateBay.

Geoffrey Huntley, the software developer from South Australia behind the prank, says that he had to rent a bare-metal server to pull this off, adding that it was "worth it."



The final boss of "right-clickers" says that the gigantic collection of NFT screenshots is meant for others to study "this generation's tulip mania."

It is a rather elegant way to demonstrate the absurdity of the current NFT craze.

03 November 2021

About F%$#ing Time

The US Commerce department has NSO Group over it's aggressively hawking its spying software to every despot in the world.

What took them so long?

The United States on Wednesday added the Israeli spyware company NSO Group to its “entity list,” a federal blacklist prohibiting the company from receiving American technologies, after determining that its phone-hacking tools had been used by foreign governments to “maliciously target” government officials, activists, journalists, academics and embassy workers around the world.

The move is a significant sanction against a company spotlighted in July in an investigation by the global Pegasus Project consortium, which includes The Washington Post and 16 other news organizations worldwide. The consortium published dozens of articles detailing how NSO customers had misused its powerful spyware, Pegasus.

The move could also raise tensions between the United States and Israel, where NSO is a prized technological powerhouse. Exports of NSO’s software are regulated by Israel’s Ministry of Defense, which must approve them as it would any weapons sale.

………

The Commerce Department said in a statement that the action is part of the Biden administration’s “efforts to put human rights at the center of U.S. foreign policy, including by working to stem the proliferation of digital tools used for repression.”

………

The company has consistently denied the findings of the Pegasus Project, which found that some of NSO’s dozens of law enforcement, military and intelligence customers in more than 40 countries target journalists, politicians and human rights workers on a routine basis with Pegasus, which can hack into cellphones. NSO has acknowledged problems with certain customers in the past.

The entity list designation prohibits export from the United States to NSO of any type of hardware or software, severing the company from a vital source of technology. It could also hinder future business arrangements and challenge the firm’s ability to work as an international company.

“The impact is broader than just the legal prohibition,” said Kevin Wolf, an international trade lawyer at the Akin Gump law firm who previously ran the entity list process. “It’s a huge red flag.”

It should be a huge red flag.

NSO helped the House of Saud assassinate Jamal Kashoggi, and aggressively markets itself to repressive governments throughout the world.

They should have a big scarlet "S" (for sanctioned) on their chest.  (It's a Hawthorne reference, not a Siegel and Shuster reference, you Philistines.)

21 May 2021

The Colonial Pipeline Was Unaffected by the Ransomeware Attack

It turns out that the systems controlling the pipeline continued to function as intended, it was only the billing systems were hit, which means that the decision to shut down the pipeline, which threw much of the East Coast of the US into a panic, was not about safety, and critical infrastructure was not impacted, it was just that collecting payments from customers became more inconvenient.

The technical term for what Colonial did was irresponsible, and possibly negligent.

Why am I not surprised that Koch Industries, aka, the Koch Brothers, are a major shareholder?

This, "F%$# you, pay me," attitude is integral to their warped souls:

The cyber attack that shutdown the Colonial pipeline causing a gas panic and stoking fears of gasoline shortages, didn’t actually shut down the pipeline. It impacted the billing system at the Colonial Pipeline Co., which shut it down because they were worried about how they’d collect payments. 

Yes, the fuel-carrying pipeline was shut down last week in order to prevent a company that is entrusted with what should be a public utility from enduring an accounting headache.

I really hope that someone, I'm looking at you Katie Porter, to whip out the old white board, and cut the executives running a new asshole at hearings.

For the problem described, they could have set up a paper system, and faxes, (or scanners and Gmail) to handle billing temporarily in perhaps 48 hours.

28 February 2021

Ha Ha!

Right wing hate site Gab just got hacked, big time.

DDOSecrets, who previously had leaked racist and Islamophobic police training materials got almost everything, public posts, private posts, user info, passwords, etc.

These guys really do have spectacularly poor IT skills don't they?

It's the revenge of Bobby Droptables all over again

On the bright side, it save lots of aviation fuel.

Black helicopters are notorious fuel guzzlers: 

When Twitter banned Donald Trump and a slew of other far-right users in January, many of them became digital refugees, migrating to sites like Parler and Gab to find a home that wouldn't moderate their hate speech and disinformation. Days later, Parler was hacked, and then it was dropped by Amazon web hosting, knocking the site offline. Now Gab, which inherited some of Parler's displaced users, has been badly hacked too. An enormous trove of its contents has been stolen—including what appears to be passwords and private communications.

On Sunday night the WikiLeaks-style group Distributed Denial of Secrets is revealing what it calls GabLeaks, a collection of more than 70 gigabytes of Gab data representing more than 40 million posts. DDoSecrets says a hacktivist who self-identifies as "JaXpArO and My Little Anonymous Revival Project" siphoned that data out of Gab's backend databases in an effort to expose the platform's largely right-wing users. Those Gab patrons, whose numbers have swelled after Parler went offline, include large numbers of Qanon conspiracy theorists, white nationalists, and promoters of former president Donald Trump's election-stealing conspiracies that resulted in the January 6 riot on Capitol Hill.

DDoSecrets cofounder Emma Best says that the hacked data includes not only all of Gab's public posts and profiles—with the exception of any photos or videos uploaded to the site—but also private group and private individual account posts and messages, as well as user passwords and group passwords. "It contains pretty much everything on Gab, including user data and private posts, everything someone needs to run a nearly complete analysis on Gab users and content," Best wrote in a text message interview with WIRED. "It's another gold mine of research for people looking at militias, neo-Nazis, the far right, QAnon, and everything surrounding January 6."

DDoSecrets says it's not publicly releasing the data due to its sensitivity and the vast amounts of private information it contains. Instead the group says it will selectively share it with journalists, social scientists, and researchers. WIRED viewed a sample of the data, and it does appear to contain Gab users' individual and group profiles—their descriptions and privacy settings—public and private posts, and passwords. Gab CEO Andrew Torba acknowledged the breach in a brief statement Sunday.

………

According to DDoSecrets' Best, the hacker says that they pulled out Gab's data via a SQL injection vulnerability in the site—a common web bug in which a text field on a site doesn't differentiate between a user's input and commands in the site's code, allowing a hacker to reach in and meddle with its backend SQL database. Despite the hacker's reference to an "Anonymous Revival Project," they're not associated with the loose hacker collective Anonymous, they told Best, but do "want to represent the nameless struggling masses against capitalists and fascists."

It's reassuring that all the Nazis so far seem to be Colonel Klink, but we cannot rely on that forever.

05 August 2020

As Zathras Would Say, "At Least There is Symmetry."

There was a court hearing for the Florida teen who allegedly hacked dozens of celerity Twitter accounts today, and someone posted porn clips to the Zoom meeting.

Needless to say, this is now in my list as a perfect moment in the history of hacking:

Clearly, Mr. Clark has no F%$#s left to give
Perhaps fittingly, a Web-streamed court hearing for the 17-year-old alleged mastermind of the July 15 mass hack against Twitter was cut short this morning after mischief makers injected a pornographic video clip into the proceeding.

The incident occurred at a bond hearing held via the videoconferencing service Zoom by the Hillsborough County, Fla. criminal court in the case of Graham Clark. The 17-year-old from Tampa was arrested earlier this month on suspicion of social engineering his way into Twitter’s internal computer systems and tweeting out a bitcoin scam through the accounts of high-profile Twitter users.

………


Notice of the hearing was available via public records filed with the Florida state attorney’s office. The notice specified the Zoom meeting time and ID number, essentially allowing anyone to participate in the proceeding.



All worth it for Florida DA Andrew Warren's reaction
Even before the hearing officially began it was clear that the event would likely be “zoom bombed.” That’s because while participants were muted by default, they were free to unmute their microphones and transmit their own video streams to the channel.

………

What transpired a minute later was almost inevitable given the permissive settings of this particular Zoom conference call: Someone streamed a graphic video clip from Pornhub for approximately 15 seconds before Judge Nash abruptly terminated the broadcast.
I am very amused by this.

So say we all.