NullCrew pillages Sony servers?

Senin, 03 September 2012

Hacktivist group NullCew have claimed it has seized control of eight of Sony's servers due to lax security measures. Through a message sent from the group's official Twitter account, the group claim that they have gained control of eight of Sony's servers, apparently related to the website Sonymobile.com.
"Sony, we are dearly dissapointed in your security. This is just one of eight sony servers that we hve control of. Maybe, just maybe considering IP addresses are avaliable. Maybe, just maybe it's the fact that not even your customers can trust you. Or maybe, just maybe the fact that you can not do anything correct technologically."

The release shows a list of usernames and passwords, which apparently were taken from one of the 'hijacked' servers as proof of the security breach. 441 usernames with additional email addresses, 24 usernames with hashed passwords, and 3 admin data sets are part of the data dump. According to the group, the attack was made possible through weak security credentials.

In addition, NullCrew stated on its Twitter feed that it has broken into a Cambodian airliner and military website -- now a target due to the arrest of The Pirate Bay's co-founder in Cambodia.  As part of "operation The Pirate Bay (#OpTPB)" the group have taken Cambodian payment transactions, plane component prices, and usernames. NullCrew state that "The founder of The Pirate Bay was arrested in Cambodia, so Cambodia is now a target."

This is not the first time Sony has borne the brunt of cyber attacks. Last week, a second alleged member of the LulzSec hacking group was arrested on charges over Sony's computer breach last year, which resulted in the theft of over a million user accounts on the Playstation network, and the closure of the service for over a month.

We have reached out to Sony and will update if we hear back.

SOCA, Cambodia National Bank & US Courts Attacked for #OpFreeAssange

Minggu, 02 September 2012

This weekend has been very eventful so far and it is looking that the following weeks may be to with a few new operations backed by anonymous and other hacktivist are picking up pace. The most recent attacks come from @0x00x00 who has been using exploits within the sites servers has been taking down a number of high profile sites

The most high profile site so far is the Serious Organised crime agency (www.soca.gov.uk) the other sites to be taken down so far as well are the Cambodian National Bank (nbc.org.kh) and a subdomain for the US court systems (mab.uscourts.gov).
These attacks have all been in the name of the Operation Dubbed #OpFreeAssange and at time of publishing the sites where back up and active. The attacks have not been long lasting but they have been fairly constant for up to an hour each.
#OpFreeAssange has also had other targets over the past weekend with a few websites being defaced and sites such as 2600.com and adrian.org.

Two Israeli Sites Hacked by #gsec_ for #OpFreePalestine

Two Israeli based websites have been attacked in the latest attacks for an Operation that has been on going for some time now and is called #OpFreePalestine, an operation by anonymous hacktivist to free Palestine.

The most recent attacks come from Grey Security or @gsec_ and was announced via twitter on the 31st of august and has been posted to pastebin.
The two websites that have been attacked are Connections Mag (connectionsmag.co.il) and Satec heating solutions (http://www.satec-heating.co.il) which proves solutions for water and home heating.

The leaked data was posted to pastebin in two separate files and contains the following message

The Satec leak contains minor database information as well as a list of emails from users of the site. At the end of the file is a link to full database listing of all user emails from the site, the database has been uploaded to axifile


http://ozdc.net/archives.php?aid=3185

http://pastebin.com/1VXiXWyz

http://pastebin.com/D07fc65y

Cambodian Government Sites Attacked for #OpTPB2

This week there has been a major turn in the fight against censorship with one of the worlds largest torrent sites being arrested and detained in Cambodia. As a result of this already hackers have started to attack Cambodian based government websites.

So far there has been 2 leaks and the attacks so far have come from Nullcrew aka @OfficialNull and they have targeted the tax office (http://www.tax.gov.kh/) , ministry of works and transport (http://www.mpwt.gov.kh) and the Institute of Standards of Cambodia (http://www.isc.gov.kh/) in the first attack and in the second the Cambodian army have been targeted.

The attacks have only resulted in very minor data being leaked but it does prove that the Cambodian government really needs to rethink their cyber security and they need to do this fast before something major happens.

Recently the co-founder of Piratebay was arrested in Cambodia, this seems like the megaupload case.
As long as the government attempts to censor, then there will be more of this; what happened to “Freedom.”
It is angering, whenever they won’t allow us the slightest bit of freedom on the internet, taking all we care for.
So that is why #OpTPB has come to be, they should have expected it when they did this.
Cambodia, we will not stop until you come to your sences.

And now, for the leaks!

part 1 http://pastebin.com/uMJzRyB9

part 2 http://pastebin.com/KRvybdL7

http://ozdc.net/archives.php?aid=3182

National Bank Limited & Standard Chartered Banks hacked by @0x00x00

Sabtu, 01 September 2012

A hacker using the handle @0x00x00 who has been leaking data all week has just released a load of data from two banks after they were hacked.
The hack is on National Bank Limited (nationalbanklimited.com) and Standard Chartered (standardchartered.com). The NAtional bank limited appears to be offline at time of publishing and this may have something do to with these hacks.
The hacker has also released two images from the hack which shows the banks back end.
The leaked data is 2 complete database dumps one from each bank. The leak was announced via twitter and posted to pastebin with 2 further links to dropbox for full database download here and here

Each leak contains a few administration account details as well as load of other information,

standardchartered.com

Nationalbanklimited.com

http://ozdc.net/archives.php?aid=3179

http://ozdc.net/archives.php?aid=3180

http://pastebin.com/8WbbWqYJ

Classmate of Lulzsec Hacker arrested and accused as another Lulzsec teammate

The two students accused of Sony Pictures hack participated in Cyber Defense Competition team exercises at the University of Advanced Technology in Arizona. US authorities have reportedly arrested a second suspected member of hacking group LulzSec on charges of taking part in an extensive computer breach of Sony Pictures Entertainment.

Raynaldo Rivera, 20, of Tempe, Arizona, surrendered to the FBI in Phoenix six days after a federal grand jury in Los Angeles returned an indictment charging him with conspiracy and unauthorised impairment of a protected computer.

In September 2011 charged Cody Kretsinger, then 23, with being Recursion. This week, meanwhile, the FBI announced the arrest of Raynaldo Rivera, 20, after he was recently indicted by a federal grand jury on charges of conspiracy and the unauthorized impairment of a protected computer.

Two men who've been arrested on charges that they hacked into the website of Sony Pictures Entertainment and posted stolen data studied together at the same university, and they also participated on the university's team for the Cyber Defense Competition held in March 2011.

According to court documents, the attackers used a VPN service in an attempt to mask their activities, and later boasted of having compromised the Sony website by using a single SQL-injection attack.

Kretsinger began pursuing a network-security degree at UAT in August 210, and in July 2011 was named as student of the month, saying that "a job with the NSA or Department of Defense is my ultimate dream."

Both men’s grand jury indictments charge them with conspiracy and unauthorized impairment of a protected computer to participate in the Sony breach, which authorities said cost the studio more than $600,000. Prosecutors say Rivera used a proxy server to conceal his IP address and location.

Anonymous Threatens New York Times, OpNYT Initiated

Jumat, 31 Agustus 2012

Anonymous once again turns its attention to the media. This time it’s the New York Times, its reporters being accused of trying to downplay the impact of the TrapWire mass surveillance project, whose existence was recently unearthed by WikiLeaks.

After WikiLeaks published the Stratfor files and the world learned of TrapWire, the Internet started buzzing. Protests have been planned, sites have been hacked, and many have started looking for the company that’s behind it.

Hacktivists and activists have concentrated their efforts on learning more about the project and the fact that someone called it “wildly exaggerated” isn’t seen too well.

“The New York Times put on the story some yahoo who declared fears to be ‘wildly exaggerated’ in part because two unnamed, titleless sources at the Department of Homeland Security told them they tried it and didn't like it,” they wrote in a statement.

“No indication is given as to whether or not this was proven to the reporter, or if he saw any evidence of it at all. At any rate, this reporter did not see fit to mention what was elsewhere being shouted by Anonymous, Telecomix, Wikileaks, ProjectPM, and independent researchers: that Cubic is in control of this capability, and that this was where the main problem lay.”

While they’re upset that the paper published the piece, they don’t seem to have planned anything related to cybercrime. Instead, they urge supporters to raise awareness by “spreading these and other failures of the New York Times by attaching the info to those deeds to come.”

Finally, Anonymous representatives claim that the Times has changed its administrator password recently, which they consider to be amusing, but “not in accordance with generally-accepted Anonymous tradition of non-aggression via hacking or DOS towards publications not run (officially) by the state.”

Anonymous Releases Simple Guide for Joining the Community

In a blog post entitled “How to join Anonymous” the hacktivists running AnonPR teach everyone, well, how to join Anonymous.

“Wanna lose your theet, have a talking parrot, fire big ass canons and plunder a lot of booty? Then you’re in the right place lad! Here’s what you need to do in order not to be a total [expletive],” they write.

 “Find yourself a new name that is completely unrelated to anything you know or have usedbefore. Leave everything you did, have or know behind – especially your e-mail address and pics of your girlfriend.”

They instruct their supporters to download an IRC client and join one of the many networks, depending on what they’re looking for.

There is AnonPR for the latest news, AnonNet – where the dragons are –, AnonOps, VoxAnon, and AnonPlus.

So far, the small “guide” has attracted the attention of hackers, activists, developers and even journalists. They all want to contribute to the movement.

Yes, for many internauts to be part of Anonymous is cool, but before joining the hacker-activist community, there are some things you should consider.

First of all, it’s not a bad thing to try and make your voice heard, especially if you have something to say. Protesting against things you consider to be unjust is also healthy. We have freedom of speech and we should use this right.

However, there are other ways to make your voice heard besides hacking websites and launching DDOS attacks. Such activities are illegal and, as we recently witnessed, they will likely land you behind bars or in never-ending extradition trials which cause grief to your family and friends.

In a recent interview we had with a former member of the TeaMp0isoN group, he sent out a message to all those who are thinking of becoming hackers.

“Only thing I have to say to people is that the life of a blackhat is not worth the trouble and that I hope this does send a clear message out to people that you are not anonymous online, nothing is secure anymore. Be ethical and do good with your skills instead of bad, or you could meet the fate like the rest of the other big fish,” the hacker said.

RasGas, new cyber attack against an energy company

A new strange attack has hit Qatar's natural gas pumper RasGas, like happened to Saudi Aramco company a virus has infected machines of its network.

RasGas is a joint venture between Qatar Petroleum and ExxonMobil operating in Qatar that has an annual export quote of 36.3 million tonnes of liquefied natural gas.

The attack has necessitated the isolation of the company systems from internet to avoid further damage to its infrastructures, according to local reports the office systems have been unusable since August 27th . Actually (Thursday August 30th 22:40 CET) RasGas website is still down, the company report.

"RasGas is presently experiencing technical issues with its office computer systems. We will inform you when our system is back up and running."

As occurred in the case of Saudi Aramco the malware was not affecting gas extraction and critical processing. An official RasGas spokesperson contacted by Pipeline editorial staff declared:

“Our IT department is facing technical difficulties, we have been affected by an 'unknown virus’, our operational systems onsite and offshore are secure and this does affect nor impact our production as a Ras Laffan Industrial City plant or scheduled cargoes,"

“In response to that we have a specialist RasGas IT team working in collaboration with ICT Qatar to resolve this issue as soon as possible,"

The web press announced that the company has experienced an unprecedented complete shutdown of its computer network due to a reported "unknown virus" attack.



Actually there are no info regarding the nature of malware and the motivation of the attack meanwhile in the case of Saudi Aramco the experts blamed the Shamoon malware recently discovered.

Who is behind of these attacks?

It's hard to provide an answer,  the stakes are high and the possible responsibles are too much.

In closing my last article on the case of company Saudi Aramco I had predicted that similar events could have been repeated soon. These companies are relatively easy targets for cyber attacks that can block their activities. Fortunately, to date there have been no serious accidents and serious damage to people and / or production plants, but it's just a fluke. The attacks will increase in frequency and complexity, and companies must be supported by their governments to put in place the appropriate defensive measures ... otherwise we will soon witness a catastrophe foretold.

Siemens and Fujitsu General Hacked, Data leaked for #OpColtan

Earlier we posted that another Philips website had been hacked not long after a large load of data was leaked from various other Philips sites. Well now another two electronics Giants have been hacked by Anonymous hacktivist in the name of OpColtan.

The two companys are Siemens Switzerland (siemens.ch) and Fujitsu General Brazil(.fujitsugeneral.com.br) and both have resulted in data from server databases being leaked via paste sites.

The attacks have been carried out by @OpGreenRights and the Siemens attack has been posted to private paste in two different parts while the Fujitsu leak was posted to pastebin in  a single paste.

The leaked data from the Siemens attack contains basic database information as well as other non critical information related to the site.

Message:

Our attention turns to you, unscrupulously and greedy multinationals. Behind your famous commercial images, fabricated and marked on an false Ethic, the most cruel barbarites are hidden. 

Coltan, the mineral that you use to produce capacitors of mobile phones, besides being harmful to health, is also the sick result of environmental rape and enslavement of underdeveloped populations. 

His gruesome traffic conceal the abuse of human rights and the dirty, imperialist war, which is the daughter of greed and contempt of life in all its meanings. We can not remain indifferent to greedy profiteers whose revenues are derived from the suffering of a colonized, oppressed and exploited people, forced to work in inhuman conditions and paid with meager wages. 

We also can not remain indifferent to the accomplices of environmental devastation. Your work is unworthy: if you break the Life, we violate your sites. Appeal to the Citizens of the World: while self-styled advertising campaigns boast the next technological item, thousands of children are deprived of their childhood, their bloody hands don’t know what a toy is, and they excavate constantly, searching for a mineral which is harmful to health. 

Thousands of fathers and mothers also work up to 72 hours without any protection, being enslaved and humiliated. Coltan is deleterious for human rights, for environment, and also for health. 

Do not be complicit in this mess, make your voice heard, read up, stand up, fight to restore dignity to those who are without because of the dirty work of “democratic” giants of marketing. 

“We must always take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented.” (Elie Wiesel)

part 1: http://privatepaste.com/2ef6d13062
part 2: http://privatepaste.com/938acfc3f2

http://ozdc.net/archives.php?aid=3163

http://ozdc.net/archives.php?aid=3164

The leak from Fujitsu contains a short message as well as the exploitable url a few administration accounts and assistant accounts as well. All passwords appear to be encrypted.

http://ozdc.net/archives.php?aid=3162

http://pastebin.com/1YMJPa8h
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Operation Indonesian - All Rights Reserved
Template Created by Creating Website Inspired by Sportapolis Shape5.com
Proudly powered by Blogger