Live data from Hacker News

CIA.gov Possibly Down, LulzSec Claims Responsibility

readwriteweb.com

131–134 of 134 posts

Re: CIA.gov Possibly Down, LulzSec Claims Responsibility

#131

scratches head I can load cia.gov just fine. It doesn't even appear to be slow. I opened up the CIA World Factbook then checked their press section & what's new on cia.gov and there was nothing about it going down. Also, kudos to the CIA for flipping to HTTPS by default.

Interesting to me that they don't use a wildcard cert though.

Well they have the EV cert and as far as I know, you can't get one for wildcard domains.

Re: CIA.gov Possibly Down, LulzSec Claims Responsibility

#132
post #82

I read for most of their hacks they used SQL injection. Any know how that works exactly?

Input isn't properly sanitized by the server thus allowing an attacker to run code through the database. Fairly easy to test for.

It's pretty embarrassing that none of these big corporations (PBS, Sony) can't even take some time to test for security flaws considering that SQL injection like you mentioned is easy to test for.

Re: CIA.gov Possibly Down, LulzSec Claims Responsibility

#133

Earlier quoted context omitted.

I hear this concern, but I'm not quite sure what the government can even do to "civilize". What would it mean exactly? Tighter regulation of domains, criminalization of encryption, tracking down and harshly sentencing crackers, forcing an "Internet ID", registering hardware? Any of these measures seems extraordinarily expensive. Maybe doable if the CIA drums up a War on Hacking, shifting attention away from the War o…

> I'm not quite sure what the government can even do to "civilize" Nothing that would make anything better, and everything that would mean they have more powers.

This is exactly the kind of qualitative fear mongering I was referring to.

Re: CIA.gov Possibly Down, LulzSec Claims Responsibility

#134
post #59

Works for me. It puts me on edge that these idiots would pick such media-friendly targets to strafe with their clueless bandwidth wastage; not looking forward to the next round of "cyber security" laws one bit. "Hey dad, tell me just one more time about how when you were a kid you used to be able to make TCP connections freely and without the connection first being authorized by the NSA." "Go to sleep, son."

I'm wondering if LulzSec is a false flag operation very well engineered.

OK, why's this almost a 100% sure a false flag op? Because they're using a giant botnet ("Lulz Cannon"), and not something like LOIC (Low Orbit Ion Cannon, what Anonymous used). Who uses botnets? ScriptKiddies? Maybe if they've got access to rich Daddy's gold credit card to buy these botnet minutes from the web crime pros in russia; but for sure they can't build a powerful botnet like this. The "good guys" Anonymous apparently had some very skilled people; the chance that the "idiot ScriptKiddies" LulzSec has even more of them is very small. And on the other hand: What would a false flag op use? LOIC on their own PCs at home? Or in the agencies? LOL, for sure... No, they'd use a giant botnet; what else...

And lastly: Always ask the question "Cui bono?" (Latin for "who's gonna profit from it?"). In the Anon case it was clear; they were activists trying to express their support for wikileaks and their anger on organizations that ceased support for wikileaks. But who's profiting from what LulzSec does? They themselves? Think again!

Post reply on HN