Live data from Hacker News

Anonymous Pledges to Take Down Facebook

news.cnet.com

71–80 of 102 posts

Re: Anonymous Pledges to Take Down Facebook

#71
post #34
post #16

Earlier quoted context omitted.

Like I said, this is not Anon. Think about it. Anon aren't stupid. And going up against Facebook is stupid.

Isn't "Anonymous" anyone who claims to be it?

You must work for congress, quick, lets make being anonymous illegal. That'll stop this!

Re: Anonymous Pledges to Take Down Facebook

#73
post #67

Hi anonymous, I work at facebook. If you manage to hack us and grab our data, perhaps you'd like to apply for a job? It's not trivial getting the data even with full access, so you could really help our team! Plus the free lunches are pretty good.

[deleted]

Re: Anonymous Pledges to Take Down Facebook

#75
post #67

Hi anonymous, I work at facebook. If you manage to hack us and grab our data, perhaps you'd like to apply for a job? It's not trivial getting the data even with full access, so you could really help our team! Plus the free lunches are pretty good.

I don't think they're (if they're, because it looks like a fake) aiming for the data.

If I were them and wanted the data I'd hack a big Facebook application' account and since most of them are very intrusive with their permissions I'd get a lot of data that way.

I bet from the backend it'd be very hard to do it, and the data might be encrypted using a key that only a Facebook user has (the user might have multiple keys and share them with friends... etc etc), anyways, I'm thinking too much about this, it's too late already :).

Re: Anonymous Pledges to Take Down Facebook

#76
post #67

Hi anonymous, I work at facebook. If you manage to hack us and grab our data, perhaps you'd like to apply for a job? It's not trivial getting the data even with full access, so you could really help our team! Plus the free lunches are pretty good.

If you work at Facebook, mind posting your FB profile?

Re: Anonymous Pledges to Take Down Facebook

#77
post #68
post #67

Hi anonymous, I work at facebook. If you manage to hack us and grab our data, perhaps you'd like to apply for a job? It's not trivial getting the data even with full access, so you could really help our team! Plus the free lunches are pretty good.

Apparently it's a fake: https://twitter.com/#!/anonops/status/101152229087657984

I thought Anonymous is an unstructured "organization" and that anybody can do anything under their flag without authorization from a central body. How is it that there is apparently a central Twitter account?

Re: Anonymous Pledges to Take Down Facebook

#78
post #77
post #68

Earlier quoted context omitted.

Apparently it's a fake: https://twitter.com/#!/anonops/status/101152229087657984

I thought Anonymous is an unstructured "organization" and that anybody can do anything under their flag without authorization from a central body. How is it that there is apparently a central Twitter account?

Maybe it's a bit of a meritocracy? It seems some Twitter accounts are somewhat "official" in the sense that they are followed by most of the people involved in the Anonymous movement.

Re: Anonymous Pledges to Take Down Facebook

#79
post #47
post #36

Earlier quoted context omitted.

Taking something apart is vastly easier than putting it together. Just because Anon is small doesn't mean they can't find an exploit.

they just haven't even done anything novel. Why should we expect them to now? Facebook is very unlikely to have the usual slough of easy sql injections. I am quite sure that someone good could find attacks against facebook. I am dubious that anonymous can.

Easily said, but do you know what 'attack surface' means in infosec?

Facebook's is vast.

Re: Anonymous Pledges to Take Down Facebook

#80
post #63
post #37

Earlier quoted context omitted.

So if we assume these people have any idea what they're talking about, it's some kind of SQLi attack... presumably mySQL? I wonder at what point it'll occur to them that Facebook mostly serves data from memcached. Uh... did I get something wrong here? A correction or something would be nice.

"RefRef is a revolutionary DoS java site. Basically, by using an SQL and .js vulnerability, you can send a page request packet from your home computer with embedded .js file, because of the vulnerability in the SQL/Javascript engine on MOST websites, the site actually TEMPs the .js file on its own server. So now the .js is in place on the host of the site. Next since you still have the request, it picks up the .js fi…

I'm disinclined to trust any source that doesn't know the difference between Java and Javascript
Post reply on HN