Damn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's avail…
Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.
LulzSec: 50 Days of Lulz statement
71–80 of 97 posts
Re: LulzSec: 50 Days of Lulz statement
#72Earlier quoted context omitted.
What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…
This mirrors an idea that I had. TOR is a military project, and you know at least some of the exit nodes are controlled by the US gov't. Why not replicate TOR with a botnet? Bounce your communications around a plethora of average joes and you have yourself a more stable tor. If you spread the botnet without a CnC server and have the infected machines bounce random traffic around, it would be damned difficult to break…
http://www.google.com/search?q=high+traffic+colluding+tor+ro...
Re: LulzSec: 50 Days of Lulz statement
#73Earlier quoted context omitted.
What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…
Ahhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?
Re: LulzSec: 50 Days of Lulz statement
#74Earlier quoted context omitted.
I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.
Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…
Re: LulzSec: 50 Days of Lulz statement
#75Re: LulzSec: 50 Days of Lulz statement
#76How is it possible to register a .com domain in an anonymous way?
Re: LulzSec: 50 Days of Lulz statement
#77Earlier quoted context omitted.
If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html
"P.S. I have a long bet that SELinux is an NSA backdoor. Any takers?" Really? Zed Shaw lost the credibility to talk about anything security related with that one sentence ...
Re: LulzSec: 50 Days of Lulz statement
#78Earlier quoted context omitted.
Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…
How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...
Re: LulzSec: 50 Days of Lulz statement
#79Earlier quoted context omitted.
Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.
Because if they ever got caught the company would be sued out of existence (probably bought by competitors at that point). They have too much to lose in most cases.
Re: LulzSec: 50 Days of Lulz statement
#80What about analyzing their writing? They release quite a bit of text...somebody likes to write. Considering there are efforts to identify people by typing patterns, I wonder if this is how they'll get caught: http://petsymposium.org/2011/papers/hotpets11-final8Chairunn...
Unfortunately given the scope of that paper, it doesn't sound like typing patterns can be used just yet. A sample size of 36 participants doesn't handle the scale involved when going against 'The Internet'. Also, the paper collected timestamps of each keystroke, something that'd need to done on suspects; however, if they are already suspecting you, they probably have other ways to identify you. Finally, how in the wo…