Pirates, Hackers…They’re Always Willing To Expose ‘The Scene’ In Return For A Bit Of Money

Centropy member Matthew Thompson is sharing with TorrentFreak readers an excerpt from his forthcoming book, This is the Scene.

Things were great for me as a pirate; I had access to whatever I wanted and was a member of some of the biggest groups that have ever existed. Then Operation Fastlink happened.

Operation Fastlink was a multi-year, joint-operation run by the United States Department of Justice and the Computer Crimes and Intellectual Property Section of INTERPOL designed to take out the groups Fairlight, Kalisto, Echelon, ProjectX, and Class.

Matthew is currently running a Kickstarter campaign to raise funding to continue work on his book.

The campaign page and accompanying video are available here.

Much more:
http://torrentfreak.com/i-was-a-member-of-centropy-the-worlds-leading-movie-piracy-group-120526/

Raised Fist Was Right After All: Infamous international hacking group LulzSec brought down by own leader

Law enforcement agents on two continents swooped in on top members of the infamous computer hacking group LulzSec early this morning, and acting largely on evidence gathered by the organization’s brazen leader — who sources say has been secretly working for the government for months — arrested three and charged two more with conspiracy.

Charges against four of the five were based on a conspiracy case filed in New York federal court, FoxNews.com has learned. An indictment charging the suspects, who include two men from Great Britain, two from Ireland and an American in Chicago, is expected to be unsealed Tuesday morning in the Southern District of New York.

“This is devastating to the organization,” said an FBI official involved with the investigation. “We’re chopping off the head of LulzSec.”

The offshoot of the loose network of hackers, Anonymous, believed to have caused billions of dollars in damage to governments, international banks and corporations, was allegedly led by a shadowy figure FoxNews.com has identified as Hector Xavier Monsegur. Working under the Internet alias “Sabu,” the unemployed, 28-year-old father of two allegedly commanded a loosely organized, international team of perhaps thousands of hackers from his nerve center in a public housing project on New York’s Lower East Side. After the FBI unmasked Monsegur last June, he became a cooperating witness, sources told FoxNews.com.

“They caught him and he was secretly arrested and now works for the FBI,” a source close to Sabu told FoxNews.com.

Monsegur pleaded guilty Aug. 15 to 12 hacking-related charges and information documenting his admissions is expected to be unsealed in Southern District Court on Tuesday.

As a result of Monsegur’s cooperation, which was confirmed by numerous senior-level officials, the remaining top-ranking members of LulzSec were arrested or hit with additional charges Tuesday morning. The five charged in the LulzSec conspiracy indictment expected to be unsealed were identified by sources as: Ryan Ackroyd, aka “Kayla” and Jake Davis, aka “Topiary,” both of London; Darren Martyn, aka “pwnsauce” and Donncha O’Cearrbhail, aka “palladium,” both of Ireland; and Jeremy Hammond aka “Anarchaos,” of Chicago.

Hammond was arrested on access device fraud and hacking charges and is believed to have been the main person behind the devastating December hack on U.S. security company Stratfor. Millions of emails were stolen and then published on Wikileaks; credit card numbers and other confidential information were also stolen, law enforcement sources told FoxNews.com.

The sources said Hammond will be charged in a separate indictment, and they described him as a member of Anonymous.

The others are all suspected members of LulzSec, the group that has wreaked havoc on U.S. and foreign government agencies, including the CIA and FBI, numerous defense contractors, financial and governmental entities and corporations including Fox and Sony.

Ackroyd, who is suspected of using the online handle “Kayla,” is alleged to be Monsegur’s top deputy. Among other things, Kayla identified vulnerabilities in the U.S. Senate’s computer systems and passed the information on to Sabu. Kayla was expected to be taken into custody on Tuesday.

A spokeswoman for the Southern District and U.S. Attorney Preet Bharara declined comment.

Monsegur’s attorney did not return FoxNews.com’s repeated requests for comment.

http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/

SUMMARY

Hector Xavier Monsegur, aka “Sabu,” pleaded guilty to the following charges on Aug. 15, 2011:

COUNT ONE: Conspiracy to Engage in Computer Hacking—Anonymous
COUNT TWO: Conspiracy to Engage in Computer Hacking—Internet Feds
COUNT THREE: Conspiracy to Engage in Computer Hacking—LulzSec
COUNT FOUR: Computer Hacking—Hack of HBGary
COUNT FIVE: Computer Hacking—Hack of Fox
COUNT SIX: Computer hacking—Hack of Sony Pictures
COUNT SEVEN: Computer Hacking—Hack of PBS
COUNT EIGHT: Computer Hacking—Hack of Infraguard-Atlanta
COUNT NINE: Computer Hacking in Furtherance of Fraud
COUNT TEN: Conspiracy to Commit Access Device Fraud
COUNT ELEVEN: Conspiracy to Commit Bank Fraud
COUNT TWELVE: Aggravated Identity Theft

Previously:

Attack Of The Smurfs Part 2 – The Pirate Bay Promoting “Raised Fist”

http://vrritti.com/2012/03/03/attack-of-the-smurfs-part-2-the-pirate-bay-promoting-raised-fist/

US Intellectual Property Rights Coordination Center Welcomes Europol As Its 20th Partner Agency

IPR Center Director Lev Kubiak and Europol Operations Department Assistant Director Troels Oerting signed an agreement, outlining the collaborative investigative efforts and cooperation protocols.

“I’m excited about this new partnership with Europol, which greatly enhances cooperation and leverages greater resources, skills and authorities,” said Kubiak. “We will continue to work closely with our international and domestic law enforcement partners to facilitate global investigations and continue to crack down on transnational IP theft.”

“I very much welcome this closer and improved link with the ICE IPR Coordination Center,” said Europol Director Rob Wainwright. “Intellectual property theft is a rapidly growing and evolving area of criminal activity, with a massive economic cost to business and society, which we must work hard to minimize. By sharing intelligence and best practices, the cooperation between our two agencies will inevitably lead to future operational successes.”

Founded in 2000, the IPR Center is one of the U.S. government’s key weapons in the fight against criminal counterfeiting and piracy. The center uses the expertise of its 20 member agencies to share information, develop initiatives, coordinate enforcement actions, and conduct investigations related to IP theft. Through this strategic interagency partnership, the IPR Center protects the public’s health and safety, the U.S. economy and the war fighters.

Europol is the European law enforcement agency whose mission is to support the European Union (EU) Member States in preventing and combating all forms of serious transnational crime and terrorism. Europol received the mandate to work on intellectual property-related crime in 2002. For years now, Europol has improved operational expertise and networking facilities in EU Member States and beyond. In 2010, for example, a key operation was coordinated by Europol and the EU’s Judicial Cooperation Unit, covering 10 different EU countries, and led to the dismantling of an organized criminal network linked to the Camorra in Naples, Italy.

The center employs a true task force model to optimize the roles and enforcement efforts of member agencies, while enhancing government-industry partnerships to support ongoing IPR enforcement initiatives. Europol is the fourth international partner agency and joins the center’s other 19 partner agencies, which include:

  • U.S. Immigration and Customs Enforcement’s Homeland Security Investigations
  • U.S. Customs and Border Protection
  • Federal Bureau of Investigation
  • U.S. Postal Inspection Service
  • Food and Drug Administration, Office of Criminal Investigations
  • Department of Commerce, International Trade Administration
  • Naval Criminal Investigative Service
  • Defense Criminal Investigative Service
  • U.S. Army Criminal Investigative Command, Major Procurement Fraud Unit
  • Defense Logistics Agency, Office of Inspector General
  • Air Force Office of Special Investigations
  • U.S. Patent and Trademark Office
  • General Services Administration, Office of Inspector General
  • Consumer Product Safety Commission
  • National Aeronautics and Space Administration, Office of Inspector General
  • U.S. Department of State, Office of International Intellectual Property Enforcement
  • International Criminal Police Organization
  • Mexican Revenue Service
  • Royal Canadian Mounted Police

To report IP theft or to learn more about the IPR Center, visit http://www.iprcenter.gov/

http://www.iprcenter.gov/partners/ice/news-releases/ipr-center-welcomes-europol-as-its-20th-partner-agency

MegaUpload’s Kim Dotcom Linked To Notorious German-Led International Cigarette Smuggling Scheme Involving Son of Saddam Hussein?

MegaUpload’s Kim Tim Jim Vestor (aka Kim Schmitz aka Kim Dotcom) appears to be a shareholder of Ruyan Group (Holdings) Limited aka Dragonite International
http://www.dragonite.com.hk/upload/news/1276268729_EW0329ANN1.pdf

Dragonite International Limited (Stock Code: 0329) has been listed on the Main Board of the Stock Exchange of Hong Kong Limited since April 2001, fomerly known as ‘Ruyan Group (Holdings) Limited’.  On June 2007, the Group has acquired entire shareholding of Best Partners Worldwide Limited (currently known as “SBT Investment (Holdings) Limited”), which engaged in the manufacturing and sales of electronic atomizing cigarettes.
http://www.dragonite.com.hk/epage.php?frameid=6000&pageid=7

Dragonite has previously appointed Mr. Manfred A. Haussler as a non-executive director of the Company. Mr. Haussler has over 25 years’ experience as an executive in the consumer products and tobacco industries. He was the Chief Operation Officer and President of international operations and member of the board of directors of Reemtsma Cigarettenfabriken GmbH (the 4th largest global cigarette manufacturer).
http://en.prnasia.com/pr/2011/01/14/110010312.shtml

Previously:

The Board of Imperial Tobacco Group PLC announces that three new appointments will be made to the Group Board with effect from August 1st 2002. Manfred A Häussler will join the Board as an Executive Director. Operationally, he was recently appointed Imperial Tobacco’s Sales and Marketing Director following the Company’s acquisition of Reemtsma Cigarettenfabriken GmbH.
http://www.imperial-tobacco.co.uk/index.asp?page=78&newsid=25&year=archive

On Tuesday, German customs officials searched the offices of Imperial Tobacco’s Reemtsma subsidiary in Hamburg, as part of an investigation into cigarette smuggling into Iraq and Germany. Imperial said on Tuesday that a number of Reemtsma managers, including sales & marketing director Manfred Haussler, had been charged in connection with an investigation of alleged foreign trading and related violations. The German investigation centres on the suggestion that non-taxed cigarettes were exported then smuggled back into Germany and that Reemtsma broke UN sanctions by exporting cigarettes to Iraq. Officials believe up to 17 million cigarettes, worth about $270,000 (£170,000), were smuggled illegally into Iraq in 2000, breaking international embargoes.
http://news.bbc.co.uk/1/hi/business/2659397.stm

IT is being described as the biggest anti-Mafia raid in Europe. A thousand customs officials and armed border police stormed the Hamburg headquarters of Imperial Tobacco’s German subsidiary, Reemtsma, this month as part of Operation Tarot. They uncovered evidence involving allegations of massive cigarette smuggling. Elsewhere, arising from the same operation, but not connected to Reemtsma, they claim to have uncovered a money-laundering network with links to arms dealing and prostitution. Seven directors, including Imperial board member Manfred Haussler, were questioned on suspicion of working with the Russian Mafia to set up front companies to smuggle millions of cigarettes in a network that stretched from Dover to the Russian steppes. None was arrested and all are believed to have denied the accusations. They were released without charge pending further inquiries. Police also claim the executives masterminded the sale of 17m cigarettes to Iraq in 2000, contrary to UN trade sanctions, a charge Imperial vigorously denies.

If charged and convicted, the executives could be jailed for seven years while Imperial faces fines that could top £1bn. It is all very embarrassing for Imperial and its chain-smoking chief executive Gareth Davis, who bought Reemtsma for £3.5bn just eight months ago. The City hailed the deal as the perfect fit between Britain’s leading tobacco giant, which markets the best-selling Lambert & Butler, Regal and Superkings brands, and the Continent’s second-biggest tobacco company. Davis will need the allowance of 200 free cigarettes a month that all Imperial directors receive if he is to calm his nerves. Imperial states that even as it bought Reemtsma – its West brand is the most smuggled cigarette in Europe – no one on the board was aware of the extent of the undercover operation and they were kept in the dark by German managers.

Operation Tarot was carried out with utmost secrecy after the failure of a raid in 2001, thought to have been scuppered by a tip-off. The vital clues came from a Russian Mafia godfather turned supergrass, dubbed Andreas N. In exchange for freedom from prosecution, he revealed how the smuggling network he ran for more than a decade made him a fortune with homes in Germany and Spain and a collection of Porsches and Harley-Davidson motorcycles.

Andreas N. lived in the leafy Harburg district of Hamburg in a luxury house surrounded by a 7ft fence topped with heat-sensitive security cameras. His wife is a former Lithuanian beauty queen. The couple were the toast of Hamburg’s high society and frequent guests at jet-set parties thrown under the banner of Reemtsma’s West brand on the North Sea island of Sylt. He first came under suspicion three years ago. His address book was a Who’s Who of the Russian government and the heads of other former Soviet satellites in eastern Europe. His business interests extended to the Far East.

German police investigator Burkhard Vonnahme said: ‘He has given us a number of statements, all of them detailed. Now comes the task of checking what he claims against the evidence we have.’ Police sources say that the Mafia boss’s confessions will help them unravel what is thought to be Europe’s biggest criminal network.

So far they have staged a series of raids throughout western Germany on sex clubs suspected of being fronts for laundered Mafia money. One, frequented by bankers from nearby Frankfurt, boasts 80 call girls, tennis courts, a fitness room, saunas and swimming pools. But as for the raid on Reemtsma, not even the Hamburg police were told what was about to happen. The 1,000-strong Operation Tarot team was secretly billeted at an army barracks outside the city.

Over three days, a fleet of removal vans was used to take away more than 300 large boxes of files, computer hard drives and private notes and diaries.

Eckhard Bobeth, the public prosecutor, said: ‘It could take us four months to go through everything. No charges will be considered against the company or individuals until we have gone through the evidence carefully.’

But sources within the investigation have claimed that documents point to something between 20% and 30% of Reemtsma’s production ending up in the hands of smugglers. This colossal figure, if proved, could mean punitive fines and prison sentences.

‘We are looking at a fine in the realms of not millions of euros but a billion or two, and tough prison sentences to match,’ claimed one investigator. Imperial’s cost-cutting at Reemtsma, in which 800 of the 10,000 workers were sacked, helped the investigation – disgruntled staff are thought to have passed information to the Tarot investigators.

Andreas N.’s lucrative connection-with Reemtsma began before the fall of Communism when it sold cigarettes to the 350,000 soldiers of the Russian army stationed in East Germany. The Russians sold them on the street, making huge profits. By the time they left, an extraordinary network had been created.

In 1995, 1.2 million Davidoff cigarettes were exported to Mongolia where hardly anyone smoked the brand. Similar spectacular exports of millions of cigarettes were made to Kaliningrad on the Baltic coast, a city of no more than 420,000. By the mid-Nineties, Reemtsma’s foreign ‘sales’ had risen 400%.

An Imperial spokeswoman said: ‘We are totally surprised by the action of the German customs and police both in terms of its size and the scale of the allegations. We are co-operating with the authorities.’

She said Imperial, which undertook seven months of due diligence before it bought Reemtsma, was unaware that West was Europe’s leading smuggled brand.


CUSTOMS officers raided Imperial Tobacco’s offices in Hamburg and arrested its sales director following a massive probe into the alleged smuggling of cigarettes into Iraq. 
Saddam Hussein’s son Uday is believed to be a major figure in the trade.

Dissident members of the internet hacktivist group Anonymous, tired of what they call the mob’s ‘unpatriotic’ ways, have provided law enforcement with chat logs of the group’s leadership planning crimes, as well as what they say are key members’ identities

Now Gawker is running what it says are chat logs covering “several days in February immediately after the group hacked into internet security firm HBGary’s e-mail accounts”

http://www.p2pnet.net/story/49806

The EU’s cyber security Agency, ENISA, wants a re-think of how we measure the size and potency of botnets, networks of malware-infected PCs that are now the mainstay of spam distribution, identity theft and DDoS (distributed denial of service) attacks

Two parallel studies by ENISA, both due to be published at a security conference in Cologne on Wednesday, collectively evaluate the botnet threat while assessing the effectiveness of possible countermeasures and making recommendations to EU governments

http://www.theregister.co.uk/2011/03/08/enisa_botnet_study/

Dutch Cell of ‘Conspiracy Cells of Fire’ claims attacks on RABO bank online and offline

“The fascists from rabobank where investing in the arms industry(the arms that they are investing is also going to the police, military in the Netherlands, Egypt, Greece, Israel, Libya, Algeria and other country’s).
Rabobank calls this justifies action, and we also get Shell, ING, ABN-Amro, Randstad. All these mentioned fascists company’s of the system are paramount in their view that they justify the action.

The attacks on Rabobank justify what we call action! Future attacks on Shell, ING, ABN-Amro, Randstad these companies accountable!

In Egypt, Tunisia, Algeria, Libya, the above mentioned companies and / or subsidiaries that have been attacked by splinter cells called the Fire. A truth that is not released by the representatives of the syteem. This shows our strong international solidarity.

Attacks we are claiming:

• June 2010- setting the tower in fire in Utrecht(Netherlands)
• October 2010- setting the tower in fire in Utrecht(Netherlands)
• February 2011-setting the tower in fire and attacks on the website of Rabobank in Utrecht(Netherlands)”

More: http://www.indymedia.nl/nl/2011/02/74035.shtml

Previously:

Dutch RABO bank to file criminal complaint having suffered cyber attack, Dutch National Cyber Security Center coming up and call to address problems caused by data encryption
http://vrritti.com/2011/02/22/dutch-rabo-bank-to-file-criminal-complaint-having-suffered-cyber-attack-dutch-national-cyber-security-center-coming-up-and-call-to-address-problems-caused-by-data-encryption/

Dutch RABO bank to file criminal complaint having suffered cyber attack, Dutch National Cyber Security Center coming up and call to address problems caused by data encryption

Dutch media are reporting that last weekend, the RABO bank suffered from system failure rendering its online banking facilities inaccessible for several hours. Today it turns out that the cause had been a Denial of Service (DOS) attack. The bank will now go and file a criminal complaint with Dutch law enforcement authorities.

On the same day the Dutch Minister for Security and Justice Mr. Ivo Opstelten announces the birth of a National Cyber Security Center as well as the expansion of the Dutch Team High Tech Crime to remedy the cyber threat.

The Dutch Police Union (ACP) made public that legal encryption tools pose a big threat to enforcement activities both on a national and international level. It wants the developers of encryption software to cooperate with enforcement authorities and calls for international regulatory measures as well.

Dutch language news articles:
http://www.nu.nl/algemeen/2453108/rabobank-doet-aangifte-cyberaanval.html

http://www.nu.nl/internet/2452974/nationaal-centrum-cyberaanvallen.html

http://www.nu.nl/internet/2453115/gecodeerde-info-groot-probleem-in-opsporing.html

Miscreants have created a banking trojan that keeps victims’ accounts open to plundering even after their marks log out of their accounts

The memorably named OddJob Trojan hijacks customers’ online banking sessions in real time using their session ID tokens. By keeping accounts open even after victims think they have quit, the malware creates a window for fraudsters to loot compromised accounts and commit fraud

More: http://www.theregister.co.uk/2011/02/22/oddjob_banking_trojan/

Europol: Successful police operation disrupts international card skimming network

Romanian law enforcement authorities, in close cooperation with Europol, have successfully disrupted an international organised crime group responsible for payment card fraud. The criminal group was active in many EU countries including Poland, Romania, Sweden and the UK. The main focus of their criminal activities was the skimming and counterfeiting of payment cards, and illegal cash withdrawals all over the European Union. The criminal activities and illegal card transactions led to substantial financial losses for the card holders and issuers in the EU.

Five members of the international criminal structure were arrested in Romania. Additionally, during 14 house searches conducted in several Romanian cities, including Pitesti, Galati and Vaslui, police officers seized large amounts of cash (EUR 50 000, USD 50 000 and GBP 15 000), as well as goods illegally purchased by the suspects.

More: http://www.europol.europa.eu/index.asp?page=news&news=pr110216.htm

Advanced Zeus Trojan Hits Polish ING Customers

A version of the Zeus malware that intercepts one-time passcodes sent by SMS (Short Message Service) is targeting customers of the financial institution ING in Poland.

Zeus has changed its tactics, since some banks are now using one-time passcodes sent by SMS to authorize transactions performed on a desktop machine. First, attackers infect a person’s desktop or laptop. Then, when that person logs into a financial institution such as ING, it injects HTML fields into the legitimate Web page.

Those fields ask for a person’s mobile phone number and the model of their phone. When that information is entered, the attacker sends an SMS leading to a website that will install a mobile application that intercepts SMSes and forwards messages to another number controlled by the attackers. The Zeus mobile component will work on some Symbian and Blackberry devices.

Once that setup is complete, the attacker can simply do a transfer whenever it is convenient, such as when an account has just received a deposit. An attacker can log onto the account, receive the SMS code and begin transferring money.

More: http://www.pcworld.com/businesscenter/article/220223/advanced_zeus_trojan_hits_polish_ing_customers.html

Anonymous is the first internet-based superconsciousness. Anonymous is a group, in the sense that a flock of birds is a group. How do you know they’re a group? Because they’re travelling in the same direction. At any given moment, more birds could join, leave, peel off in another direction entirely

http://www.p2pnet.net/story/49177

The Internet was designed to survive a nuclear war, but researchers claim they’ve found a way to take down the Internet

In a report from New Scientist, Max Schuchard a computer science graduate student and his buddies claim they’ve found a way to launch DDoS attacks on Border Gateway Protocol (BGP) network routers that could crash the Internet.

Much more: http://www.zdnet.com/blog/networking/how-to-crash-the-internet/680

Starting in November 2009, covert cyberattacks were launched against several global oil, energy, and petrochemical companies. The attackers targeted proprietary operations and project-financing information on oil and gas field bids and operations. This information is highly sensitive and can make or break multibillion dollar deals in this extremely competitive industry

“Night Dragon”

http://blogs.mcafee.com/corporate/cto/global-energy-industry-hit-in-night-dragon-attacks

How one man tracked down Anonymous—and paid a heavy price

Aaron Barr, CEO of security firm HBGary Federal, spent a month tracking down the real identities of the hacker collective Anonymous. But when he prepared to go to the FBI, Barr and his company were viciously attacked—in part by a 16-year old girl. Leaked e-mails reveal exactly how it happened.

The situation got so bad for the security company that HBGary, the company which partially owns HBGary Federal, sent its president Penny Leavy into the Anonymous IRC chat rooms to swim with the sharks—and to beg them to leave her company alone.

Anonymous doesn’t like to let up. Barr’s Twitter account remains compromised, sprinkled with profane taunts. The HBGary websites remain down. The e-mails of three key players were leaked via BitTorrent, stuffed as they were with nondisclosure agreements, confidential documents, salary numbers, and other sensitive data that had nothing to do with Anonymous.

And they have more information—such as the e-mails of Greg Hoglund, Leavy’s husband and the operator of rootkit.org (which was also taken down by the group).

When Leavy showed up to plead her case, asking Anonymous to at least stop distributing the e-mails, the hivemind reveled in its power over Leavy and her company, resorting eventually to tough demands against Barr.

The attackers are quintessentially Anonymous: young, technically sophisticated, brash, and crassly juvenile, all at the same time. And it’s getting ever more difficult to dismiss Anonymous’ hacker activity as the harmless result of a few mask-wearing buffoons.

Much more: http://arstechnica.com/tech-policy/news/2011/02/how-one-security-firm-tracked-anonymousand-paid-a-heavy-price.ars

Cyber-attacks on government and corporate websites are now elements of resistance and a threat to elite powers. Throughout history and today we see acts of social protest through non-violent civil disobedience as a means of seeking change

Digital, non-violent civil disobedience has emerged as a term known as “hackitivism” that proves the approach to social movements and political change is ever-developing. The word hackitivism has developed from various actions of website hacking that have been claimed by hackers to be politically motivated.

More: http://www.statepress.com/2011/02/08/civil-disobedience-gone-digital/

Beginning Feb. 10, a federal grand jury in San Jose, Calif., will be presented with evidence collected by the FBI about Anonymous, the loosely based hacking group that in December launched mass denial-of-service attacks against PayPal, MasterCard, ebay and Visa in retaliation for those companies’ refusal to process payments to WikiLeaks

http://www.securitynewsdaily.com/grand-jury-to-collect-fbi-evidence-about-anonymous-0501/

Anonymous takes over security firm in vengeful hack

Hoglund said he first learned of the attack after attempting to login to his work email after spending much of Sunday afternoon doing work in his garage, purposely avoiding being around his computer.

“I have a ridiculously long password, so I thought I mistyped it,” a noticeably distraught Hoglund recalled in a telephone interview. When it didn’t work after a couple of tries, “That’s when I realized there was a problem.”

Anonymous also was able to hijack a web server for rootkit.com, a domain owned by Hoglund that provides a forum to discuss rootkits, he said.

Hoglund said the timing of the incident couldn’t be worse, considering the RSA Conference in San Francisco is taking place next week, and HBGary was planning a major product release at the show.

“They are causing me a great deal of pain right now,” he said. “What they’re doing right now is not hacktivism, it’s terrorism. They’ve really crossed a line here. I’ve worked so many years on HBGary, and I don’t deserve this. I never did anything to those people. They completely overreacted to [the Financial Times article]. Why did they need to do that?”

Much more: http://www.scmagazineus.com/anonymous-takes-over-security-firm-in-vengeful-hack/article/195837/

Previously:

Right now you can download a 4.7 gigabyte file full of about 50,000 emails stolen from a computer security expert named Aaron Barr. That’s what happens when you cross the hacking collective Anonymous
http://vrritti.com/2011/02/07/right-now-you-can-download-a-4-7-gigabyte-file-full-of-about-50000-emails-stolen-from-a-computer-security-expert-named-aaron-barr-thats-what-happens-when-you-cross-the-hacking-collective-anonymous/

Anonymous attacks US security company – HBGary chief Aaron Barr’s Twitter account hijacked and personal details leaked in revenge for infiltration of hacking collective
http://vrritti.com/2011/02/07/anonymous-attacks-us-security-company-hbgary-chief-aaron-barrs-twitter-account-hijacked-and-personal-details-leaked-in-revenge-for-infiltration-of-hacking-collective/

An international investigation into cyberactivists who attacked businesses hostile to WikiLeaks is likely to yield arrests of senior members of the group after they left clues to their real identities on Facebook and in other electronic communications, it is claimed
http://vrritti.com/2011/02/06/an-international-investigation-into-cyberactivists-who-attacked-businesses-hostile-to-wikileaks-is-likely-to-yield-arrests-of-senior-members-of-the-group-after-they-left-clues-to-their-real-identities/

Anti-Berlusconi hackers block Italy government website

Access to the website www.governo.it appeared to be blocked briefly during the afternoon, although it was working normally by evening.

The hackers, calling themselves Anonymous Italy, criticised a number of Italian government policies and said they were responding to a cable leaked by anti-secrecy group WikiLeaks from the U.S. embassy in Rome.

http://af.reuters.com/article/worldNews/idAFTRE7151XS20110206

Smart servers spot and block botnet attacks

Combating a DDoS attack is tricky because it is hard to distinguish botnet activity from that of ordinary users. “The most challenging issue is how to detect an attack that involves a large number of attacking hosts,” says Jaydip Sen of Tata Consultancy Services in Kolkata, India. So he has developed a set of tests that aim to do precisely that. Sen devised algorithms that measure how much data the server is receiving, and from which computers. The figures are then compared with levels of traffic these computers send on an average day. Hosts with an unusual burst of activity are put through another level of complex statistical analysis to identify exactly which ones are launching the attacks.

Once a server running Sen’s software has worked out where the attack is coming from, it can block traffic from the culpable IP addresses until the threat subsides. Announcing the work earlier this month at the First International Conference on Computer Science and Technology in Bangalore, India, Sen claimed the technique is so good that it has not made a mistake yet.

More: http://www.newscientist.com/article/mg20927975.200-smart-servers-spot-and-block-botnet-attacks.html

Distributed denial of service attacks topped 100Gbps for the first time last year, during which attempts to flood websites with junk traffic went mainstream

Major incidents in 2010 included DDoS attacks associated with pro- and anti-WikiLeaks hackers and militias as well as hacking attacks linked to political turmoil in Burma and Sri Lanka, according to the latest annual study by DDoS mitigation experts Arbor Networks.

http://www.theregister.co.uk/2011/02/02/arbor_botnet_ddos_insurgency/

The flaw in Anonymous’s argument is that when one elects to take part in a demonstration, one accepts the legal consequences. If the demonstration is a perfectly legal street march, no consequences (should) ensue. But if it’s a sit-in that disrupts a business or traffic, one is liable to being physically handled or arrested. Plainly DDOS attacks are closer to the latter than the former

This is the basic social contract around the rule of law for protestors: individuals don’t get to pick and choose which laws they are bound by and which they aren’t, even if their goal is to change the law or expose injustice. Whether someone who participated in a DDOS attack knew they were exposing themselves to arrest or not (bearing in mind the most widely-used DDOS tool, Low Orbit Ion Cannon, does nothing to hide your IP address), they face the consequences of that social contract: DDOSing is illegal.

Much more: http://blogs.crikey.com.au/thestump/2011/01/30/anonymous-arrests-shine-a-light-on-some-much-bigger-issues/

FBI executes search warrants on 40 ‘anonymous’ WikiLeaks defenders

The FBI announced today that they executed more than 40 search warrants in conjunction with the UK’s Metropolitan Police against participants in the DDoS’ing of WikiLeaks “enemies”.

Unlike the Met Police, the FBI did not release many details as to who they may executed the warrants against, or specifically what they were looking for. It is likely they were intending on seizing the computers used during the attacks to look for logs related to the planning and execution of the attacks.

The FBI’s press release implies that the attackers created the tools to attack Mastercard, Visa and others.

More: http://nakedsecurity.sophos.com/2011/01/28/fbi-executes-search-warrants-on-40-anonymous-wikileaks-defenders/