Live data from Hacker News

Syrian Electronic Army hijacks Microsoft blog and Twitter account

theverge.com

1–10 of 17 posts

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#2
They have a long history of doing these kind of things. My question is, how do these blog/twitter hackings really help them? I doubt people are gonna stop using Microsoft email. Maybe they're just trying to publicize, but I feel like these antics are getting a bit old and losing their efficacy.

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#4
post #2

They have a long history of doing these kind of things. My question is, how do these blog/twitter hackings really help them? I doubt people are gonna stop using Microsoft email. Maybe they're just trying to publicize, but I feel like these antics are getting a bit old and losing their efficacy.

SEA claims that defacing Microsoft's blog/Twitter is just a distraction. A possible goal could be to leak a huge volume of internal email? They already captured and released one exchange.

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#5

are these just mercenaries or are they all syrian? how do they 'hack', what type of coding skills do they have that can do this? brute force? genius algos?

AFAIK, they're just Syria's nationalist version of Anonymous, but not necessarily all based in Syria. http://en.wikipedia.org/wiki/Syrian_Electronic_Army

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#6
post #2

They have a long history of doing these kind of things. My question is, how do these blog/twitter hackings really help them? I doubt people are gonna stop using Microsoft email. Maybe they're just trying to publicize, but I feel like these antics are getting a bit old and losing their efficacy.

I'm guessing DNS Hijacking. https://www.youtube.com/watch?v=7Pp72gUYx00&feature=youtube_...

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#7

are these just mercenaries or are they all syrian? how do they 'hack', what type of coding skills do they have that can do this? brute force? genius algos?

Web application cracking really isn't all that difficult in our current age, especially with sufficient dedication and manpower, as the SEA certainly has.

There's simply so many vectors to get in. Every layer of technology you add is a potential layer of vulnerability. The state of security is appalling and people have been repeating this for so many years, but few other people listen (or they simply pretend to listen and convincingly appear as if they've taken precautions).

I doubt most of them have any particularly good coding skills. Large-scale Middle Eastern hackers and website defacers are primarily script kiddies. It's just that they have a lot of willpower and time to run vast automated attacks.

Actually a lot of high-profile attacks like this don't even involve exploiting the actual web application. Rather, they hijack nameservers, socially engineer domain registrars or find some external avenue or service to get in by enumerating open ports, seeing what's juicy and searching for exploits. They also phish a lot.

Information security is a very complex and intriguing field, but when it comes to merely cracking web applications from a purely practical point of view, it's relatively easy and especially so now that any wannabe hacker can just burn Kali Linux on a CD and read some tutorials on using tools.

Re: Syrian Electronic Army hijacks Microsoft blog and Twitter account

#9

are these just mercenaries or are they all syrian? how do they 'hack', what type of coding skills do they have that can do this? brute force? genius algos?

I work for a major Arabic news channel and we had to deal with many incidents/attacks from the SEA. the amount of DDOS we had was really massive even the network firewall couldn't handle it.

Most ips were located in Russia, Ukraine, USA and a few other Arab countries. I highly suspect they are a small group of amateurs, right now we have moved to AWS with Dos-Arrest in front which seems to work well.

Post reply on HN