Showing posts with label Lulzsec. Show all posts
Showing posts with label Lulzsec. Show all posts

Thursday, 29 August 2013

FBI used Anonymous to attack foreign government systems, claims jailed hacker Hammond

Sentencing for former LulzSec leader Hector Xavier Monsegur, better known as "Sabu" , has again been delayed. Monsegur pleaded guilty to a dozen criminal counts two years prior and stands to face more a maximum sentence of more than 124 years.
Another Lulzsec Hacker Jeremy Hammond has claimed that the FBI used Sabu to coordinate attacks against foreign governments, by Anonymous hackers and Others.
The delays indicate that the FBI is not extracting information from Monsegur and this could mean that the hacker may be helping FBI with other covert operations as Jeremy Hammond claims.
Jeremy Hammond, released a statement on Thursday accusing the US government of asking Monsegur to encourage fellow hacktivists to infiltrate foreign government entities.
What many do not know is that Sabu was also used by his handlers to facilitate the hacking of the targets of the government’s choosing including numerous websites belonging to foreign governments”, Hammond said.
What the United States could not accomplish legally, it used Sabu, and by extension, me and my co-defendants, to accomplish illegally”, Hammond added.
"Why was the US using us to infiltrate the private networks of foreign governments? What are they doing with the information we stole? And will anyone in our government ever be held accountable for these crimes?"
Hammond pleaded guilty in May to hacking private intelligence firm Stratfor to expose millions of revelatory emails. The Illinois native faces up to 10 years in prison when he is sentenced, scheduled for 15th November.

Tuesday, 11 September 2012

LulzSec hacker arrested over Sony attack

A second member of the LulzSec hacking was arrested by US authorities in connection with attacks on Sony Pictures Europe .
US police was arrested Raynaldo Rivera, 20, a member of the hacking group LulzSec, on charges that he took part in breach of the computer systems belonging to Sony Pictures Europe.

The indictment, which was unsealed on Tuesday, accuses Rivera and co-conspirators of stealing information from Sony Pictures Europe's computer systems in May and June 2011 using an SQL injection attack – which exploits flaws in the handing of data input for databases to take control of a system – against the studio's website.SQL injection, or SQLi, is an increasingly common technique used by hackers to break into systems.

The attack, which may have leaked credit card details for millions of users, has never been traced to any group – although Sony suggested not long afterwards that Anonymous might have been involved.Since then it has given no further details about who it suspects of carrying out the attack, and no data from the attack has ever been posted publicly.

"From a single injection we accessed EVERYTHING," the hackers said in a statement at the time. "Why do you put such faith in a company that allows itself to become open to these simple attacks?"

Authorities have said the Sony breach ultimately cost the company more than $600,000 (£378,000).
An accused British hacker, Ryan Cleary, 20, was indicted by a US grand jury in June on charges related to LulzSec attacks on several media companies, including Sony Pictures.

The rise of LulzSec saw a burst of similar "crews" aiming to hack sites, but since then Anonymous has focussed on providing an outlet for documents released by WikiLeaks.

Friday, 8 June 2012

Hacker Looking For US Military Documents Finds VMWare Source Code

Members from the hacktivist group “LulzSec” are at it again, as source code from VMWare’s ESX hypervisor technology has been leaked to a website used to anonymously host hacked files. According to a company blog, VMWare has said a “single file” from their ESX source code had been leaked and posted to Pastebin. The company also went on to say the source code is 8-9 years old.

Lain Mulholland, director of VMware’s security response center said the source code was publicly posted on Monday and said more code could be posted in the future.

“The fact that the source code may have been publicly shared does not necessarily mean that there is any increased risk to VMWare customers,” Mulholland noted in the company’s blog.

“VMWare proactively shares its source code and interfaces with other industry participants to enable the broad virtualization ecosystem today.”

VMWare is pointing the finger at LulzSec hacker “Hardcore Charlie” as the culprit of the source code leak. It appears Charlie wasn’t looking for the code specifically, however. In March, Charlie had attacked a Chinese import-export company, the China National Electronics Import-Export Corporation (CEIEC). During these attacks, Charlie had copied a terabyte of data from the CEIC’s database. According to The Guardian, anti-virus company Kaspersky Lab had engaged in an IRC chat with Charlie, wherein the hacker claimed to have 300 MB of VMWare’s source code.

This chain of events suggests that the CEIEC had the source code originally. Other documents have leaked online which show what appear to be internal VMWare documents on CEIEC letterhead.

When asked why he was trying to hack into the CEIEC database, Charlie said he was trying to find information about the US involvement in Afghanistan. According to The Guardian, Charlie claims to not have strong political affiliations, but was concerned the CEIEC had access to internal documents about the US involvement.

Charlie told Kaspersky he was able to break into the CEIEC after targeting email hosting firm Sina.com. Once he and his partner, known as YamaTough, stole hundreds of thousands of credentials, they were able to crack specific accounts which they found interesting. Some of these accounts belonged to workers at the CEIEC. With this information, Charlie and Tough were able to steal a terabyte worth of data.