The kid who apparently got caught was using Windows. http://89.248.164.63/dox/xyz/3.png
LulzSec Exposed
41–50 of 82 posts
Re: LulzSec Exposed
#42I'm glad they were doing it for the lulz. Some day someone's going to be doing it, not for the lulz, and the price we'll have to pay for this kind of massive developer/it-sec incompetence will be extremely high. Hopefully this has served as a wake-up call to people who weren't already aware how low the fruit has been hanging.
You say you are glad they were doing it for fun and wait for someone to do it not for fun? How do you know it's not already been done? A true hacker wouldn't expose their actions and would continue with the exploit. I think these kids have exposed the true lack of security around the world in general and it has raised some serious attention for other people to take a look at their own defence, which is good in some r…
And I'll remind everybody that we are dealing with SQL injections and plain-text passwords. And it's 2011.
Re: LulzSec Exposed
#43Not surprising since they are just a bunch of weekend warriors and kids. Any real smooth operator wouldn't be working out of his house, and especially not on a personal browsing machine. From the opposite perspective of that, the government hasn't seen diddly when it comes to digital terrorism. Just wait until the FBI can't track down the culprits from their broadband bill and drive over to their parents house and ma…
From what I observe, it just keeps getting progressively easier for the FBI to do that. Not harder.
Re: LulzSec Exposed
#44The kid who apparently got caught was using Windows. http://89.248.164.63/dox/xyz/3.png
Browsing around that site, there seems to be a lot of information... much of which i'm guessing probably shouldn't be on a public website?
Re: LulzSec Exposed
#45Earlier quoted context omitted.
Sure! starts off with telling everyone to get off this network, ED IRC (it could be a server in their own network, but if that were the case their network would already be breached) calls for a new operation (similar to how anon has various operations). Then admits to hiring a botnet to help them. chimes in, talking about an irc server exploit is basically killing his computer. asks for an exploit, says he has it, bu…
ED almost certainly refers to http://encyclopediadramatica.ch/Get_On_IRC_Fgt (usually semi-NSFW)
Re: LulzSec Exposed
#46whoops I guess you really are not anonymous on internet after all
Re: LulzSec Exposed
#47So they got exposed because they were acting like a bunch of children and taking no precautions? Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.
The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it.
The highest-risk category is true information warfare, targeted attacks by other governments and large entities. As the previous replier said, just look at Stuxnet. You don't have to be a government for this to be a real threat. Imagine if Nintendo had compromised Sony's servers, and somehow loaded corrupt firmware onto the Playstation update system...
These threats are real and constant, and anyone with sensitive data needs to be aware of them. Simply firing up iptables and disabling root SSH isn't sufficient - you need to be aware of the intricacies of your system on a day-to-day basis.
Re: LulzSec Exposed
#48Not surprising since they are just a bunch of weekend warriors and kids. Any real smooth operator wouldn't be working out of his house, and especially not on a personal browsing machine. From the opposite perspective of that, the government hasn't seen diddly when it comes to digital terrorism. Just wait until the FBI can't track down the culprits from their broadband bill and drive over to their parents house and ma…
Uh, when will that be? From what I observe, it just keeps getting progressively easier for the FBI to do that. Not harder.
The truly paranoid might like to rent a botnet and build their own tor network on top of it or something like that.
In short: the fundamental nature of TCP/IP is such that if you are sufficiently motivated, and dont mind horrible latency, even the FBI/tptacek cant identify you.
Re: LulzSec Exposed
#49I'm glad they were doing it for the lulz. Some day someone's going to be doing it, not for the lulz, and the price we'll have to pay for this kind of massive developer/it-sec incompetence will be extremely high. Hopefully this has served as a wake-up call to people who weren't already aware how low the fruit has been hanging.
You say you are glad they were doing it for fun and wait for someone to do it not for fun? How do you know it's not already been done? A true hacker wouldn't expose their actions and would continue with the exploit. I think these kids have exposed the true lack of security around the world in general and it has raised some serious attention for other people to take a look at their own defence, which is good in some r…
You said, the hackers "lowered people's trust in massive corporations [...] which is not good in any respect."
It seems pretty clear to me that Sony is most decidedly not deserving of consumer's trust - and without these public disclosures, we would have never known that.
Certainly - as I learned in the Gawker security breach - it sucks to have your login details broadcasted to the rest of the internets. But, after a few hours restting passwords across the internet, I was good to go. I expect the affected consumers in this case will have a similar experience.
And, that experience is a far better one than having your data stolen by a more malicious group of hackers, who use it for far more damaging means, without your knowledge.
So, I don't believe that this group of hackers are any kind of heroic. But even if their motivation is suspect, I do believe they're performing a type of public service. Teaching us all that it's the height of ludicrous to hand over your sensitive data to Sony, and expect them to keep it reasonably secure from basic script-kiddie tactics.