Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

41–50 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#41
post #39
post #16

Earlier quoted context omitted.

The Battlefield Heroes passwords are unsalted MD5. Way to go EA.

Hm, are you sure? I have a couple accounts there (and they are appearing in the dump) and they are not simply md5(password). Of course they were long, random passwords and I don't play this game anymore, but I'm curious. Where did you read that?

I didn't read it anywhere. I downloaded the database and checked all my friends against a known password database. They're plain md5(password).

Re: LulzSec: 50 Days of Lulz statement

#42
post #30

Earlier quoted context omitted.

I was being sarcastic :-)

And here I was, sparing you my snark. You've made me re-evaluate humanity, sir, and I'm not impressed with the results.

I appreciated your brief synopsis. I only know a little bit about LulzSec, and the added information helped. So your efforts were not entirely lost...

Re: LulzSec: 50 Days of Lulz statement

#43
post #16
post #2

The torrent appears to contain hacked personal data from: * EA (Battlefield Heroes) * Hackforums.net * Nato-bookshop.org * Misc other forums The first of these purports to be 200K+ users.

The Battlefield Heroes passwords are unsalted MD5. Way to go EA.

Some BF Heroes beta server was hacked over 2 years ago. I wonder if this could be the same hack.

Re: LulzSec: 50 Days of Lulz statement

#44
post #40
post #34

Earlier quoted context omitted.

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…

Ahhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?

Re: LulzSec: 50 Days of Lulz statement

#45
post #33

Earlier quoted context omitted.

Right, but then they'd be prosecuted, and the means would come out. You wouldn't be able to both put people in jail based upon evidence gained from compromising TOR, as well as keep secret the fact that TOR was compromised. Not for long, at any rate.

Pretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.

Just get someone to make an allegation against them (underage porn, etc), and their computers get seized.

Is that legal in the UK? Because in the US it'd be unconstitutional.

Re: LulzSec: 50 Days of Lulz statement

#46
post #26

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

Re: LulzSec: 50 Days of Lulz statement

#47
post #28

Earlier quoted context omitted.

Note that the press release was two days ago, after NATO was notified by police. AFAIK, this is the first that Lulzsec has disclosed that the NATO bookstore was hit, which means the police knew before we did. That can't be good for those behind the mask.

AFAIK, this is the first that Lulzsec has disclosed that the NATO bookstore was hit, which means the police knew before we did. That can't be good for those behind the mask. Maybe they were seeing how long it would take for the news to come out without their help.

My guess is that they spent a few days trying to see if they can access accounts of anyone important from the NATO dump. The passwords were in plaintext.

They would only release the data to the public once they are done using it.

Re: LulzSec: 50 Days of Lulz statement

#48
post #26

Earlier quoted context omitted.

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

Right, but then they'd be prosecuted, and the means would come out. You wouldn't be able to both put people in jail based upon evidence gained from compromising TOR, as well as keep secret the fact that TOR was compromised. Not for long, at any rate.

I'm pretty sure confidential informants are tailor made for covering up illegal or undisclosed investigation techniques. It's not like they haven't had a little practice trying to protect wiretaps.

Which isn't to say that I think the feebs have compromised TOR, because I think that's pretty unlikely.

Re: LulzSec: 50 Days of Lulz statement

#49
post #33

Earlier quoted context omitted.

Pretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.

Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. Is that legal in the UK? Because in the US it'd be unconstitutional.

I've seen news about child porn allegations in the UK that usually lead to nowhere in the latest years, mostly because of some credit card issues. I remember it happening with Pete Townshend (from The Who) and Robert Del Naja (from Massive Attack), plus some football player whose name I can't remember.

Re: LulzSec: 50 Days of Lulz statement

#50
post #40
post #34

Earlier quoted context omitted.

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…

This mirrors an idea that I had. TOR is a military project, and you know at least some of the exit nodes are controlled by the US gov't. Why not replicate TOR with a botnet? Bounce your communications around a plethora of average joes and you have yourself a more stable tor. If you spread the botnet without a CnC server and have the infected machines bounce random traffic around, it would be damned difficult to break. TOR is open source, so it shouldn't be too hard to modify it to work on a private network. The nice thing about it is that if you attract to much heat you can always ditch the network and start a new one.
Post reply on HN