Cyber Security Notebook

Cyber Security Notebook


  • Category Archives Black Hats
  • gAtO aLmOsT -got hacked

    gAtO aLmOsT -got hacked WHY? after a nice kitty nap I woke up and found my site uscyberlabs.com was suspended. I could not get into my site or get any email so I called my hosting provider. We soon found out that someone was trying to do a brute force trying to get into my admin panel. (see logs—below) To top it off someone called my provider and tried to social engineer them into resetting my password. From my simple SEO plug-ins I could see that it was a ToR connection the IP 72.14.182.266 running a Python-urllib/2.7 script. You can see the timestamp and the delay’s give it away to a ToR connection. Of course my hosting Service is doing some research to see what they can find out but the IP as well as the phone call were non-traceable (or were they).

    gAtOmAlO sAy's

    Since gAto writes about Anonymous I assume at first that the FBI was going to kick down my door but that made no sense since everything I publish is available online Open-Source. I did notice a few days ago a tweet warning of a grayHat that needed a Dox – http://whatismyipaddress.com/ip/72.14.182.226 this is a little info about the IP address it shows Dallas, TX but my internal SEO places it in Newark, NJ.

    Why is the question did I piss someone off, was I getting close. I HAVE a lot of information about Anonymous and the crew(z) that I do not publish, just because “gAtO is No SnItCh”. Maybe @MissRevolution_ got pissed because of her money problems or Xgirlfriend, in Chi-town I could go on and on but The OpCashBack Twitter of Banks that I published was to get the world out. Why so many banks have twitter I still find that interesting. Oh Well back to the SaltMines -

    Ok so is GaTo’s words so powerful that  you want to hack his site…. gAtO feel so important —naw.. just messing.. -gAtO oUt 

    http domain  72.14.182.226 Hostip (subject) more info

    Country: UNITED STATES (US)

    City: Newark, NJ

    IP: 72.14.182.226

    ,

    li45-226.members.linode.com

    Python-urllib/2.7

    February 19, 2012 15:06:44

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:43

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:42

    /blog/?p=1915

    February 19, 2012 15:06:40

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:39

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:38

    /blog/?p=1915

    February 19, 2012 15:06:34

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:33

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:06:32

    /blog/?p=1915

    February 19, 2012 15:02:53

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:53

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:51

    /blog/?p=1915

    February 19, 2012 15:02:50

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:49

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:48

    /blog/?p=1915

    February 19, 2012 15:02:45

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:43

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 15:02:42

    /blog/?p=1915

    February 19, 2012 14:59:44

    /blog/2012/02/17/banks-twitter-opcashback/

    February 19, 2012 14:59:44


    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • PennTest Threat Intelligence

    PennTest Threat Intelligence - part-1

    gAtO bEen ThInKiNg - In the hyper connected world we live in Pen-Testers have a lot on their hand, hardware, firmware, OS, web-apps. The facts are that a simple web-app upgrade, may open new holes that off-set the problem they had to begin with. A pen-test, is a method of evaluating the security of a computer system or network by simulating an attack from malicious outsiders. Who are the outsider? How do the outsiders pen-test your system? Non-state actors have played an important part in many international cyber conflicts in the past two years- game changers. With the Anonymous crew(z), China, Russia, India, Iran out in force in cyberspace a company needs to know if they are the target from a political, competition or worse yet a loneWolf or activist.

    Many think that with BackTrack anyone can be a tester, but it’s different today. Companies need to understand the Geo-Political aspect of their company and who are their markets and how does it play out in the real world. Look at Sony, HBGrays these are two different companies but their reputation has been tarnish by what, a bunch of kids, naw, these boy’s and girls are the new breed, smart, educated and connected. These people are System Admin in their day job and Anonymous during off-hours. They know how to work in the box and also see out-of-the-box tips and tricks and have thousands that want to try their game and imitate them. Whatever you think these new boy’s and girls will multiply, it’s a fab, a movement but they all want to be a cool hackers and the next generation of hacktivist will make these people look like amateurs.

    Who knew that a Low Orbit Ion Cannon (LOIC) used to test how many connection your server will handle, would be used by the attackers themselves. A long time ago in cyber years (2-3 years ago) only the geeks had the knowledge and skills to do some of the hacks that we see today. Today Anonymous is not only a social movement but it’s a cause celeb, people want to belong and these social 4chan outcast have started a revolution in cyberspace that governments and corporations now are worried about, and well they should be.

    Break out Backtrack and do some pen-testing and yes you may find misconfigured servers like gAtO hAs -(SCADA systems to boot) and such but if you can see what your enemy is looking at, planning. Nothing is better than threat intelligence to guide you in mitigating your company as to future attacks.

    Look at the RSA and Diginotar APT attacks, the bad guy’s went after the certificate authority how does a typical pen-test tools know that, they don’t if you don’t have your pulse on the game your in, you may be next.

    Remember the technical aspect is one thing but if you have many, many hands trying new things on your site guess what, they will hack you if your connected to the Internet. Your company cannot live in a bubble and so must expose themselves to customers, vendors and business partners your company cannot control all those aspects. When a simple email attachment to the c-Suite boys just like with the Nortel hack they got you big time, in Nortel chase they were inside their network for 10 years. The reputation, the technical all this means nothing if you don’t have good solid threat intelligence to know what’s going on in the world.

    If you don’t have a team to look at threat intelligence for your company, get some people fast. If your connected you can be hacked, learn and be silent – Can’t stop the signal. Everything goes somewhere, and I go everywhere…. -gAtO oUt

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Predictive Behavioral Security Analysis part 1:

    Predictive Behavioral Security Analysis part 1:

    gAtO bEeN -watching a mouse hole called Twitter lately, it’s an OSINT Open Source Intelligence source that monitors real events in real time. OSINT – is a form of intelligence collection management that involves finding, selecting, and acquiring information from publicly available sources and analyzing it to produce actionable intelligence.

     

    cool dashboard – internet Storm Center - http://isc.sans.edu/dashboard.html

    gAtO bEeN -watching World Web War (WWW) hacktivismn has jumped started this new year, #OpMegaUpload upset lot’s of people and the organization structure of Anonymous is getting more refine. Things happened in #poland #ireland and during the middle of a DoS attack Anonymous told their warrior on twitter:

     

    http://trendsmap.com/

    @AnonyOps: #DDOS of European Parliament must stop NOW. They’re not the ones #ACTA

    Later they tweeted this:@AnonyOps: europarl.europa.eu back up after #DDOS. Thanks for listening to logic #Anonymous.go persuade the MEPs:

    http://www.msisac.org/apps/dashboard/

    Command and Control in your face and people responded to this organized movement. Each new attack everyone get’s better more coordination Anonymous is growing up. Just look at the causes #SOPA #PIPA  #ACTA #OpMegaUpload #poland #Ireland #SOPAIreland #France #Belgium  #FreeTopiary. The Anonymous thingy has grown up it’s a social conscious mindset created, manipulated, organic, ???? leaderless ????. The evolution of this movement has spawned OWS the Occupy Wall Street political movement has it’s roots in Anonymous, but you can see the worldwide community support for this group that is anyone. This movement will grow and mature.

    http://www.fsisac.com/

    Think about it.

    This Week gAtO Learned mUcHo-mUcHo, we have not only the technical means but now the social monitoring needs that can be used to gather information like no other time before. Of course our governments are getting in on the fun.

    Homeland Security DHS- Human Factors/Behavioral Sciences Projects:

    • Actionable Indicators and Countermeasures Project
    • Biometric Detector Project
    • Community Perceptions of Technology Panel Project
    • Community Resilience Project
    • Enhancing Public Response and Community Resilience Project
    • Future Attribute Screening Technology (FAST) Project
    • Hostile Intent Detection – Automated Prototype Project
    • Hostile Intent Detection – Validation of Observable Indicators of Suspicious Behavior Project
    • Human Systems Engineering Project
    • Human Systems Research Project
    • Insider Threat Detection Project
    • Mobile Biometrics System Project
    • Multi-modal Biometrics Project
    • Passive Methods for Precision Behavioral Screening Project
    • Predictive Screening Project
    • Quantitative Psychosocial Impacts Index Project
    • Rapid DNA Project
    • Risk Prediction Project
    • Violent-Intent Modeling and Simulation Project

    http://www.dhs.gov/files/programs/gc_1218480185439.shtm

    http://k.root-servers.org/

    And the CIA got into the fun[1] way before it was hip to monitor the web. We know the government has all kinds of databases of all kinds of things they collect remember echelon and carnivore the FBI first grab at data. Then we yell at the CHinese for doing the same thing we did, they learned from us about gathering information about people. Now cyberspace ties us in even tighter with SMS, streaming video, encrypted mobile chats for the masses. But as more is piled on more tools are developed. Recorded Future[2] was a little geek company sucking in the data and developing Analytical tools for Intelligence forecasting and the CIA loves them.

    Predictive Behavioral Security Analysis is just monitoring choice which is freedom for it is predictive and can then be manipulated to plant an idea, a spark, a tweet. “Egypt can be free” this little spark is setting the fuel for the flames that will burn in Cairo by it’s people via Twitter, Facebook and any other social media. The Arab Awakening -Arab Spring was an simple idea, manipulated in cyberspace by protester, dissidents and governments in Tunisia, Bahrain, Syria and others, we will see Iraq’s move in March of this years with it’s election, they are closing down their Internet but will the idea of freedom explode anyway. We will be monitoring this – gAtO OuT

     

    References:

    [1] CIA Invest in ‘Future’ of Web Monitorin http://www.wired.com/dangerroom/2010/07/exclusive-google-cia/

    [2] https://www.recordedfuture.com/

     

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Underground Cyber War-TangoDown OpMegaupload

    gAtO wItNeSs – LIVE International Underground Cyber War via  Twitter this weekend. #Anonymous #Megaupload #OpMegaupload #TangoDown …

    If you haven’t heard, police in New Zealand raided MegaUpload.com took down the site and confiscated the servers and all the materials, copyrighted or original content. Remember SOPA protest last week this raid was a SOPA raid by the New Zealand government. They used (Low Orbit Ion Canon) and other tools plus  Twitter (Twitter follower could click on a link and that would launch a dDoS attack -live crowd-source enabled TangoDown attack.

    http://pastebin.com/WEydcBVV

    1. Twitter – @AnonymousWiki - January 19th, 2012
    2. Popular file-sharing website megaupload.com gets shutdown by U.S Justice – FBI and charged its founder with violating piracy laws. Four Megaupload members were also arrested. The FBI released a press release on its website which you can view here:

      German Internet millionaire Kim Schmitz (Kim Dotcom) arrives for. a trial at a district court in Munich in these May 27, 2002 file photos. New Zealand police broke through electronic locks and cut their way into a mansion safe room to arrest the alleged kingpin of an international Internet copyright theft case and seize millions of dollars worth of cars, artwork and other goods. German national Schmitz, also known as Kim Dotcom, was one of four men arrested in Auckland on January 20, 2012, in an investigation of the Megaupload.com website led by the U.S. Federal Bureau of Investigation. Reuters

    3. http://www.fbi.gov/news/pressrel/press-releases/justice-department-charges-leaders-of-megaupload-with-widespread-online-copyright-infringement
    4. We Anonymous are launching our largest attack ever on government and music industry sites. Lulz. The FBI didn’t think they would get away with this did they? They should have expected us.

    Anonymous Twitter feeds kept everyone informed, supporters retweeted it,  joined in the attack  and soon you could see the traffic increase 100% over the course of the event. The attack vector was dDoS but they manage to delete sites like cbs.com down to the bone. Another defiance stance from Anonymous and their crew(z) this weekend showing who has bad security. This is a way for Anonymous to be job creators (mEoW), because these companies need more security people fast…  

    **- Will these companies try and hide these attacks? Will these organization disclose if any identifiable USER INFO was compromised? – Will we see unencrypted USER INFO (credit cards -mastercard.com was tango down)in the wild of cyberspace? -**

    When gAtO saw Justice.gov and http://justinbieberweb.com/ got TangoDown gAtO kNeW they meant business. When the .gov took a hit you saw thing start to happened…like Anonymous.action-24.com is a fake forum created by the authorities (FBI).

    “A security expert (name withheld -Tweeted)” *** Is the (fully unsecure) #AnonGroup social network really run by #AnonOps / #Antisec ?

    gAtO sEe- conspiracy theory (FBI vs Anonymous) all around this, but if this was true, or maybe a plant to throw distress amongst the Anons or to capture participants IP address. \I see some links to news Items pop up in pasterBin all the time to a blank post, one way of seeing who is following the #OpMegaupload / I still haven’t found out but I’m sure people are looking into this. Trust in the crowd-sourcing communication and tracking tools coordinating attacks and status is something any dissident groups is concern about, but that the FBI and other’s took notice of these attacks thats for sure Dude:

    GOV TANGO DOWN! #Megaupload. » anonops AnonOps. “The Internet Strikes Back” is TT! » anonops AnonOps. The Internet Strikes Back #Megaupload info

    At the end of the day we see the power of the people in cyber space, a world wide movement like the SOPA, OWS support. Most people don’t have a clue what’s been happening in the underground cyber war to keep it FREE.  |gAtO is no judge as to the protesters wether it’s right or wrong first #SOPA blackout then this massive attack on some major companies -movers and skaters bAbY. I just want these companies to come clean and do the responsible thing, full Disclosure  what happened. Protect my data or else I will not do business with you. Hacktivismn has taken a new turn and people want to belong, they want to be empowered, some are hipsters but the majority are real protesters, the new breed of (hacktivist ) that comes after this one will blow our minds.

     **- 5:17 P.M. Update: RIAA.org is now down.

    5:55 Update 3: Tweets indicate there may be more attacks to come this evening.

    5:55 Update 3: Tweets indicate there may be more attacks to come this evening.

    7:47 Update 4: Anonymous is reporting FBI.gov as down. Some people report being able to get through, but the site is clearly under a lot of stress.

    8:19 Update 5: Now it’s definitely down. FBI.gov, that is. MPAA and RIAA sites are back now though

    - **

     A masked hacker, part of the Anonymous group, hacks the French presidential Elysee Palace website on January 20, 2012 near the eastern city of Lyon. Anonymous, which briefly knocked the FBI and Justice Department websites offline in retaliation for the US shutdown of file-sharing site Megaupload, is a shadowy group of international hackers with no central hierarchy. On the left screen, an Occupy mask is seen. Getty

    Expect Us! is their motto, we better be prepared - gAtO oUt

    Until this mess is clear , I hope you saved copies and can upload them to alternative sites like megaupload.com like Putlocker.comFilebox.com or Depositfiles.com or one of the many other cyberlockers available so that people can continue to enjoy them while Megaupload is not working. 

    References:

    Universal, RIAA, FBI, MPAA and Department of Justice Sites Go Down, Anonymous Claims Responsibility -http://www.geekosystem.com/anon-justice-universal/

    Anonymous deletes CBS: Operation Megaupload continues -http://www.examiner.com/anonymous-in-national/anonymous-deletes-cbs-operation-megaupload-continues?@anonymouspress

    If Megaupload is not working what happens to the files? http://www.examiner.com/video-game-in-honolulu/if-megaupload-is-not-working-what-happens-to-the-files?@anonymouspress

    Anonymous tricked people into joining Web site attacks - http://news.cnet.com/8301-27080_3-57363103-245/anonymous-tricked-people-into-joining-web-site-attacks/

    MegaUpload Photo’s of the Bust  - http://cryptome.org/2012-info/megaupload/0051.htm

    TangoDown 4 opMegaUpload -List

    CBS.com

    http://warnerbros.com

    http://www.vivendi.com/

    mastercard.com

    fightprivacy.com

    universalmusic.com

    http://paidcontent.co.uk/

    http://store.warnerbrosshop.com/

    wando.com.br

    Justice.gov

    http://justinbieberweb.com/

    http://www.europarl.europa.eu/

    http://ms.gov.pl/ Poland

    http://universalmusic.es/

    http://www.brasilia.df.gov.br/

    http://www.fbi.gov/

    Department of Justice http://www.justice.gov/

    http://www.riaa.com/

    http://www.universalmusic.com/

    http://www.wmg.com/

    http://www.BMI.com/

    http://www.mpaa.org/

    Motion Picture Association of America (MPAA.org) Universal Music (UniversalMusic.com) Belgian Anti-Piracy Federation (Anti-piracy.be/nl/) Recording Industry Association of America (RIAA.org) Federal Bureau of Investigation (FBI.gov) HADOPI law site (HADOPI.fr) U.S. Copyright Office (Copyright.gov) Universal Music France (UniversalMusic.fr) Senator Christopher Dodd (ChrisDodd.com) Vivendi France (Vivendi.fr) The White House (Whitehouse.gov) BMI (BMI.com) Warner Music Group (WMG.com)

    Brazil - MEGA TANGO DOWN

    http://pastebin.com/H4NpqCDC -

    Invadimos denovo : http://imgur.com/6bmFe. Havittaja – @Havittaja – www.twitter.com/Havittaja -The evilc0de – @theevilc0de – www.twitter.com/theevilc0de -Todos os servidores foram desligados -MEGA TANGO DOWN -(TODOS DEVEM ESTAR OFFLINE AGORA 22/01/2012 19:47)

    ?antigo.se.df.gov.br (OFFLINE)

    ?brasiliasustentavel.seduma.df.gov.br (OFFLINE)

    ?www.admjardimbotanico.df.gov.br (OFFLINE)

    ?www.agecom.df.gov.br (OFFLINE)

    ?www.agenciabrasilia.df.gov.br (OFFLINE)

    ?www.aguasclaras.df.gov.br (OFFLINE)

    ?www.arpdf.df.gov.br (OFFLINE)

    ?www.bandeirante.df.gov.br (OFFLINE)

    www.brasilia.df.gov.br (OFFLINE)

    www.brasiliatur.df.gov.br (OFFLINE)

    www.brazlandia.df.gov.br (OFFLINE)

    www.candangolandia.df.gov.br (OFFLINE)

    www.capitaldigital.df.gov.br (OFFLINE)

    www.carnaval.df.gov.br (OFFLINE)

    www.cbhparanaiba.seduma.df.gov.br (OFFLINE)

    www.ceasa.df.gov.br (OFFLINE)

    www.ceilandia.df.gov.br (OFFLINE)

    www.cepceilandia.df.gov.br (OFFLINE)

    www.codeplan.df.gov.br (OFFLINE)

    www.codhab.df.gov.br (OFFLINE)

    www.coorsep.seg.df.gov.br (OFFLINE)

    www.cruzeiro.df.gov.br (OFFLINE)

    www.defensoria.df.gov.br (OFFLINE)

    www.defesacivil.df.gov.br (OFFLINE)

    www.der.df.gov.br (OFFLINE)

    www.detran.df.gov.br (OFFLINE)

    www.df.gov.br (OFFLINE)

    www.dfdigital.df.gov.br (OFFLINE)

    www.distritofederal.df.gov.br (OFFLINE)

    www.educacaointegral.df.gov.br (OFFLINE)

    www.emater.df.gov.br (OFFLINE)

    www.escoladegoverno.seplag.df.gov.br (OFFLINE)

    www.esporte.df.gov.br (OFFLINE)

    www.etc.se.df.gov.br (OFFLINE)

    www.etc.sect.df.gov.br (OFFLINE)

    www.fap.df.gov.br (OFFLINE)

    www.fhb.df.gov.br (OFFLINE)

    www.gama.df.gov.br (OFFLINE)

    www.gdf.df.gov.br (OFFLINE)

    www.gdfdireto.df.gov.br (OFFLINE)

    www.governo.df.gov.br (OFFLINE)

    www.guara.df.gov.br (OFFLINE)

    www.hbdf50anos.df.gov.br (OFFLINE)

    www.ibram.df.gov.br (OFFLINE)

    www.inas.df.gov.br (OFFLINE)

    www.iprev.df.gov.br (OFFLINE)

    www.itapoa.df.gov.br (OFFLINE)

    www.jardimbotanico.df.gov.br (OFFLINE)

    www.juventude.df.gov.br (OFFLINE)

    www.lagonorte.df.gov.br (OFFLINE)

    www.lagosul.df.gov.br (OFFLINE)

    www.matricula.df.gov.br (OFFLINE)

    www.metro.df.gov.br (OFFLINE)

    www.nahora.df.gov.br (OFFLINE)

    www.novacap.df.gov.br (OFFLINE)

    www.orgaos.df.gov.br (OFFLINE)

    www.ouvidoriageral.df.gov.br (OFFLINE)

    www.paranoa.df.gov.br (OFFLINE)

    www.parceirosdaescola.df.gov.br (OFFLINE)

    www.parkway.df.gov.br (OFFLINE)

    www.pedala.df.gov.br (OFFLINE)

    www.pg.df.gov.br (OFFLINE)

    www.planaltina.df.gov.br (OFFLINE)

    www.prg.df.gov.br (OFFLINE)

    www.procon.df.gov.br (OFFLINE)

    www.protec.df.gov.br (OFFLINE)

    www.recanto.df.gov.br (OFFLINE)

    www.revista.seduma.df.gov.br (OFFLINE)

    www.riachofundo.df.gov.br (OFFLINE)

    www.riachofundoii.df.gov.br (OFFLINE)

    www.sa.df.gov.br (OFFLINE)

    www.samambaia.df.gov.br (OFFLINE)

    www.santamaria.df.gov.br (OFFLINE)

    www.saosebastiao.df.gov.br (OFFLINE)

    www.saude.df.gov.br (OFFLINE)

    www.scia.df.gov.br (OFFLINE)

    www.scs.df.gov.br (OFFLINE)

    www.sde.df.gov.br (OFFLINE)

    www.sdet.df.gov.br (OFFLINE)

    www.se.df.gov.br (OFFLINE)

    www.seade.df.gov.br (OFFLINE)

    www.seapa.df.gov.br (OFFLINE)

    www.sect.df.gov.br (OFFLINE)

    www.sedest.df.gov.br (OFFLINE)

    www.seduma.df.gov.br (OFFLINE)

    www.sehab.df.gov.br (OFFLINE)

    www.sejus.df.gov.br (OFFLINE)

    www.semarh.df.gov.br (OFFLINE)

    www.seops.df.gov.br (OFFLINE)

    www.seplag.df.gov.br (OFFLINE)

    www.setur.df.gov.br (OFFLINE)

    www.sga.df.gov.br (OFFLINE)

    www.sia.df.gov.br (OFFLINE)

    www.slu.df.gov.br (OFFLINE)

    www.so.df.gov.br (OFFLINE)

    www.sobradinho.df.gov.br (OFFLINE)

    www.sobradinhoii.df.gov.br (OFFLINE)

    www.ssp.df.gov.br (OFFLINE)

    www.st.df.gov.br (OFFLINE)

    www.sudoeste.df.gov.br (OFFLINE)

    www.taguatinga.df.gov.br (OFFLINE)

    www.tcb.df.gov.br (OFFLINE)

    www.varjao.df.gov.br (OFFLINE)

    www.vice.df.gov.br (OFFLINE)

    www.visitbrasilia.df.gov.br (OFFLINE)

    www.vlt.df.gov.br (OFFLINE)

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Detectives Hunting Dead Girl -Rupert Murdoch Hacked the Phones

    gAtO pIsSiRupert Murdoch and son James get away with not just hacking a dead girls cell phone but it appears that they also hacked the phones of the police investigators on the case. this all happened in 2002. Chief Constable Mark Rowley reported this and when passed to Scotland Yard about the phone hacking investigation in 2006 this part of the report was missing.

    gAtO sAiD- funny ha ha how Rupert Murdoch can get Scotland Yard in your pocket and the local police in London.

    So Rupert, Jimmy and let’s not forget Tom Mockridge as another scumbag at News International. These are the hackers that make me sick. Here was power and influence totally disregarding any decorum of a news organization. They went out and hired crackers the web 3.0 type and then these people had great meetings about all this information. They could of deleted messages and dummied some up. The personal violation that these people committed in cyberspace and then they talk about hackers.uscyberlabs - gatomalo_at_uscyberlabs_dot_com

    The Murduch cyber crewz were the best. No problem if this is illegal we got a get out of jail card with he police and Scotland Yard this was a hackers dream. gAtO aDmIt - he would like to hack without strings one time sI-nO but unless I find a rich and powerful well connected type like the Kock brothers. gAtO sent in a rEsUmE it was a zenmap report of their site -gAtOmAlO sOmEtImE

    Detectives hunting Milly Dowler’s killer had phones hacked, Leveson Inquiry hears

    Police officers investigating the disappearance of the schoolgirl Milly Dowler had their mobile phones hacked during the inquiry, Surrey Police has revealed.

    A lawyer for the force told the Leveson inquiry that “a number of Surrey Police officers themselves were victims” of phone hacking shortly after the investigation began in March 2002.

    Previously it was known that journalists at the News of the World had hacked the mobile telephone of the missing 13-year-old.

    But this is the first time that it has been confirmed that detectives working on the case were also victims of phone hacking.

    John Beggs QC, counsel for Surrey Police, told Lord Justice Leveson: “My instructions are that it is very likely that a number of Surrey Police officers themselves, at the time of launching the Milly Dowler investigation in March nine years ago, were themselves victims of hacking.”

    Earlier this month Surrey Police admitted that they learned that Milly Dowler’s phone was hacked by the Sunday tabloid in 2002 but did not act.

    RELATED ARTICLES

    Mr Beggs did not reveal whether the force also learned that their own officers had been hacked or whether this has since come to light during Operation Weeting, the Metropolitan Police’s investigation into phone hacking.

    He was speaking as the Surrey Force made an application to become a core participant in the Leveson inquiry, which will look at the culture and ethics of the press.

    Mr Beggs argued that the force should be allowed “core participant” status in light of the criticism the force has faced following their admission that they knew about Milly Dowler’s phone being hacked.

    The force made the admission in a letter to the Home Affairs Select Committee.

    The force’s then Chief Constable Mark Rowley said that officers became aware in April 2002 that someone from the News of the World had accessed the missing girl’s voicemail after someone on behalf of the Sunday newspaper phone the police operation room.

    However Mr Rowley said that a formal investigation was not launched. He said: “At that time the focus and priority of the investigation was to find Milly who had then been missing for over three weeks.”

    Mr Rowley’s letter said that an inquiry is looking into why no formal investigation was launched. He also revealed that the information that the News of the World had accessed Milly Dowler’s voicemail in 2002 was npot passed to the original Scotland yard phone hacking investigation in 2006. The reason for that is also being investigated.

    http://www.telegraph.co.uk/news/uknews/phone-hacking/8860067/Detectives-hunting-Milly-Dowlers-killer-had-phones-hacked-Leveson-Inquiry-hears.html

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Cyber Security LinkedIn Groups

    Groups gAtOmAlO likes

     

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Cyber 911 For the Average Small Business Person | After the Tiger-Mate Hack -Project Notes

    Project Notes

    Who do you call when your web sites is hacked – “cyber 911 -may I help you”. The hosting service -no way, no they’re too busy fixing the attack, and what to say at a press release!

    We hear a lot of politician talk about helping the small businessman. Well Sunday 9/25/2011 @(4am)  about 500,000 (half a million) small business were hacked. gAtO’s site was hacked too, we are still waiting to hear-  about declaring InMotion and it’s hacked site into a disaster area.  gAtO say – we have not heard a word about some cyber political person flying around InMotion and touring the 500k websites that were hacked by Tiger-M@te and his crew(z).

    Tiger Mate has been tied to the Google Bangladesh cyber attack, this is a real hacker not the wanna be like, Anonymous and LulzSec. One shot 500k website, that’s “The Biggest Hack in the World” that we know of. Could this hack be a practice run for something worst. Could it be an intelligence gathering, the raw data of all the sites could be a gold mind for spam. Did the hack page effect anyone with a trojan. This is a great way to deliver a virus. One Hosting service, to many content providers and to their readers. One to Many Distribution Attack- One hack and it could potentially deliver hundred of thousand of zombie computers to a BotMaster. There is some talk the attack also infected the http_Access file. So far it only infected blog’s not static sites. Is there any Politician out there.. HeLLo …

    gAtO has not seen it, but were was the cyber Community Emergency Response Teams (CERT). This is the kind of government programs that are needed in the new age in Cyberspace. How can we create a cyber team to help situations like this attack.

    After I took care of my own site, I started to look around for others that were infected to see if I could help and was lucky to run into 2 great sites. The  Urban Cowboy and Leo Blanchette’s clipartillustration.com these two cyber heroes took the fight to the streets and showed leadership. People helping people.

    What to do when your site’s been hacked. Some of the lessons learned from the recent Tiger-M@te attack on inMotion are right in front of our face. For the average website/blog content creator, we all have our special thing we do. But as we saw the provider’s blog (InMotion) was down, they had to shut down, save everything for forensics, evaluate and find the hack, then a plan for a sanitize re-boot and disinfect the hacked sites. The attacker Tiger-M@te set his target on “wordpress”. Why?

    It’s a favorite amongst bloggers, and it has a wide distribution installation base, to get the most bang from your buck (attack)…Who do we call when our sites are down. I’m not sure. I would like to see our government get in and help us small business with the problems we have in cyberspace. New jobs for the new world – cyber-Police?.

    Later,

    My 2© cents – gatoMalo_at_uscyberlabs_dot_com

     ———lab Notes

    InMotion  Forum about the Hack  –> http://forum.inmotionhosting.com/viewforum.php?f=57

    Timeline -InMotion release -see below

    http://www.webhostinghub.com/support/website/website-troubleshooting/status-of-september-tiger-mte-attack


    http://www.citizencorps.gov/cert/
    Community Emergency Response Teams (CERT)

    Tiger Mate

    The bangladeshian hacker “Tiger Mate” has been very active and has hacked some high profile websites in the past such as bangladesh airtel and local american express website.

    We are in good company, check out the also-afflicted. http://zone-h.org/archive/notifier=TiGER-M@TE

     

    Mass compromise at inmotionhosting.com

    Mass compromise at inmotionhosting.com | Sucuri

    According to zone-h, they defaced at least 1,000 sites, and a list of the attacked sites can be viewed here: http://zone-h.org/archive/notifier=TiGER-M@TE

    *It seems that some of the compromised sites were also at webhostinghub.com (both owned by the same company)
    **We are tracking more than 10k sites already defaced.
    ***Update from their in their Twitter account: “inmotionhosting InMotion Hosting
    Security team members have traced this vulnerability to an authentication system and are working to patch this now. “

    Comment for Sara @ PoliticalUSA

    The largest hack ever made in a single shot !!!!

    It was not just a server hack, actually whole data center got hacked.”

    700,000 websites hacked in a single shot by TIGER-@MATE

    Good Morning, PoliticusUSA; You’ve Been PWNed by TiGER-M@TE!

    http://www.politicususa.com/en/politicususa-you’ve-pwned-tiger-mate

    Good morning, PoliticusUSA; you’ve been PWNed by “TiGER-M@TE”! “PWN” This is called a “PWN” hack. Yeah, InMotion got PWNed.

    I’m writing to you from a secure, non-disclosed location known as GOP Clown Show. Don’t ask, and I won’t tell.

    This morning when I opened PoliticusUSA to share my colleagues’ morning stories, an ominous black page replaced my story from last night on Occupy Wall Street. This can’t be good, I thought. Then the page shrank down and began dancing all over my screen.

    I chased it around for a few minutes, too sleepy to be alarmed.

    Muttering under my breath (to say I am short tempered when it comes to technology is to put it mildly), I cursed the dancing box. I believe I may have called it the devil, but it’s all a blur now. I clicked and clicked and it ran and played.

    Finally, I got it: “Server HackeD by TiGER-M@TE”

    Ohhhhhhhhh………………

    Our host tells us, “InMotion Hosting
    Security team members have traced this vulnerability to an authentication system and are working to patch this now.”

    Tiger mate hacking Immotion

    http://josephtavern.com/?p=63

    Apple Support

    Sep 25, 2011 6:56 PM

    En-route to ASC today I suffered a hack attack by tiger-m@ate …I say I suffered the attack, in fact it seems to have been an attack on either google.co.uk or apple.com. There is some insistence that it can’t be the latter.

    New to ASC I started a discussion at:  https://discussions.apple.com/thread/3345813?start=0&tstart=0

    …advised that it belongs here instead, it not being an attack on ASC (unconfirmed).

    It seems that several hundred servers were attacked today and most likely these were XSS-attacks. My initial research leads me to believe that these attacks are based on the exploitation of server-side vulnerabilities rather than malware on the client-side but I’m no expert.

    I’ve always assumed that as much as I try to protect my network against hacking and my computers from physical theft, there will always be a risk. For this reason I ensure my data is well protected: I use 1Password for log-in security, Knox for encrypting my documents and data (whilst retaining portability) and Espionage for securing application data. Nevertheless, it concerns me that my system may have been compromised.

    Please contribute if you’ve had a similar experience or can offer advice on the extent of the risk involved.

    Andrew

    Your system was not compromised. This hackers seems like like to hack DNS servers and poorly secured web hosting providers. It is extremely rare for individual users to be hacked by an individual hacker. It has never happened to a Mac user. Nothing to worry about.

    @etresoft  thanks for your response — it seemed to me when I revisted it, that the redirected page had no apparent functionality and appeared to be more of a calling-card …seemingly aimed at increasing the noteriety of tiger-m@te, than to launch any kind of malicious attack on the end-user.

    Seeing a browser window shrink, dance around the screen like a sprite and then expand to reveal “hacked” across the screen was a little disconcerting ….and naturally ones immediate reaction is to quit, trash and cut the connection.

    Thanks for your input, hopefully it will reassure others.

    InMotion Hosting apologizes, says it “understands” method used by TiGER-M@TE

    InMotion, in an email to users, said Sunday that the homepage defacement attack launched by the southeast Asian hacker TiGER-M@TE was not meant to do permanent or catestrophic damage to the hundreds of thousands of websites that were hit.

    “We understand the method the attacker used to accomplished this and the main exploit path was through an internal management server that can control Cpanel on other servers. The management server was used to change passwords on the Cpanel servers then login with those passwords,” said Todd Robinson, president of the hosting company.

    The defacement attacked worked by replacing index files in all public_html directories with the attacker’s own branded index.php. InMotion does not believe that any data was stolen or that any passwords were compromised.

    “It does not appear that gaining passwords was a goal or was accomplished, just password changes were used. Access to the management server was gained from an exploited customer’s server that was within our network,” Robinson said. “Though our team moved quickly to disable the internal management server and limit the exposure of the servers to this attack when it began, it
    was a very serious breach and could have been much worse if the hacker had intended to do more harm.”

    This does fit the modus operandi of TiGER-M@TE, who often claims to hack for fun or just to prove that “it can be done.”

    Blast Magazine’s network of websites were defaced during the attack on InMotion, as was the offical City of Providence website.

    InMotion took responsibility for failing to prevent the damage. Some estimates have the attack hitting more than 500,000 websites, making it historic in its proportions if not in its level of damage.

    “Please accept our apologies as we go through this process,” Robinson said. “We are very aware of our failure in this situation and we will provide more details when we have completed the work of recovery.”

    http://blastmagazine.com/the-magazine/technology/tech-news/computers/inmotion-hosting-apologizes-says-it-understands-method-used-by-tiger-mte/

    Timeline -InMotion release 

    At around 4am EST, our system administration team identified a website defacement attack affecting a large number of customers.  We are still investigating, but it appears that files named index.php have been defaced.

    We are evaluating how this has occurred and our security team will have more information shortly.

    While we review this issue, cPanel and SSH access has been disabled on various platforms.  For additional security, we are rotating passwods on a number of accounts.  We will honor requests for password resets as they are needed but are attempting to limit the inconvenience to our customers as we’re able.  FTP is still operational should you wish to access your files at this time and correct any issues you see yourself.  We will be working diligently to make cPanel access available again as soon as possible.

    If there is a defacement on your account, please know that our Systems team is working to get your site back online.  If your index.php was modified, they will be restoring it from the most recent backup and no further action is necessary on your part.  At this time, we do not have a definitive timeframe for resolution, but we will update this page as we gather more information.

    We do apologize for this issue, let us know as you have further questions, we’ll be glad to answer them as we’re able.  Please understand it will take our security team some time to review this issue before we can have a full explanation available.

    11:45 AM EST Update

    If you have a backup of your site, you may upload your index.php files to correct this. You may need to do this for each directory. If your site uses an index.html or index.htm, you will need to upload those files, then delete the index.php. You can find more help at How to restore a backup file.

    It is possible our automated restore system will also be working on correcting the issue while you are. If you see this happen, just upload again.

    If you do not have a backup of your site, it is best to wait until our automated system has completed its attempt at restoring. At this point, we feel that should solve a majority of the defaced sites.

    We will be updating this page every hour, please check back here versus calling or chatting. Our team is currently working very hard and we are bringing in additional people, but the volume is greater than our Sunday staff is able to handle quickly at this time.

    1 PM EST Update

    Systems has been successful in restoring a portion of the affect sites. They are refining their repair method now and should be able to begin deploying the update to additional sites shortly. Please bear with us for another 1 hour when we feel we will have more information to share.

    4:00pm EST Update
    Our system’s team is still working on the automated repairing. We have restored over 65% of the affected sites at this time and are continuing to do so via an automated process and with our technical support team.

    For people who are fixing their sites themselves, we have a few additional suggestions. First, be sure to check all directories, the hacker targeted all directories within the public_html.

    If you are not sure how to do this, once our system’s team has completed their automated restores of home pages and general review of the changes we have made, they will be running an additional cleanup process that will look in directories for the hacked files. If the hacked files are found, they will be saved to hacked_page in the same directory.

    Second, we have additional advice if you do not have a backup on your computer of your index.html and you are now seeing a directory listing instead of your site when you visit your URL. This means our automated restore system could not find a suitable file to restore to your account. Please go here, Site Backup Restore Options, for a few options to deal with this.

    Most users should not see defacement on their site. If you do, it may be cached in your browser. Please refresh your browser by restarting it or by pushing CTRL-F5 (usually works, restart is best though). If you still see defacement, please do contact us via support@webhostinghub.com immediately for priority handling.

    If you are seeing an empty directory, our system has not been able to locate your index files yet. If you have a backup of your index files, please upload them via ftp now (index.php, index.html, index.htm, etc.)

    For those who do not have the files or who are unable to upload, our team is working on an automated solution now. Please see this link, Site Backup Restore Options, for a solution that may work for you.

    Currently, Cpanel is disabled on all platforms as we evaluate the situation and apply patches to the security problems that allowed this to occur.  We should be able to enable access later today after running our final checks.   FTP access is still available though.

    Best Regards,
    The Web Hosting Hub Team

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Security – Hacking Tools & Utilities – good tools to have in your collection

    Whatever colour hat you are – White – Gray – Black – these are some of the tools you will need for scuz-security work.

    Cyber Ricardo

    Cyber Ricardo - el GatoMalo - Cyber Hippy

     

    1. Nmap –  Get Nmap Here - nmap -v -sS -A xxx.xxx.xxx.xxx

    2. Nessus Remote Security Scanner - Get Nessus Here

    3. John the Ripper - Yes, JTR 1.7 was recently releasedYou can get JTR Here

    4. Nikto - Get Nikto Here

    5. SuperScan - Get SuperScan Here

    6. p0f - Get p0f Here

    7. Wireshark (Formely Ethereal) - Get Wireshark Here

    8. Yersinia - Get Yersinia Here

    9. Eraser - Get Eraser Here.

    10. PuTTY - Get PuTTY Here.

    11. LCP - Get LCP Here

    12. Cain and Abel - Get Cain and Abel Here

    13. Kismet - Get Kismet Here

    14. NetStumbler - Get NetStumbler Here

    15. hping - Get hping Here

    0.1 Metasploit – Backtrack – Paros – Proxy – Toufeeq – Pedro – BO2k – Optix – Beast – NetCat – LCP – Immunity Debbuger - 

     

     

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Hacker Cyber Crew (crewz) Diagram

    Hacker Moto:-be hidden, be silent, listen and don’t get DOX (documented-revealed). 

    Script Kiddies (also hackers) Moto:- Let’s do it, we won’t get caught, let’s tell the world what we done..yeh..me…me…me..me 

    New Hacker’s Dictionary, a hacker is “a person who enjoys exploring the details of programmable systems and how to stretch their capabilities” and one who is capable of “creatively overcoming or circumventing limitations”.

    These hackers know cyber space. There are some that are young and audacious. Look at Anonymous or AntiSec the authorities have arrested some hackers but they are only foot soldiers. Cyber Space is full of foot soldiers. These young hackers are very gifted and talented. There are “lone wolfs” and there are cyber crew. (Crewz)

    Org Chart of Hacker Crew -Groups

    uscyberlabs_cyber_crewz

    LulzSec Team 

    Sabu - Captain of the Ship, organizing the team and planning strategies.
    Topiary - Basically PR, updating Twitter and interviews with media.
    Kayla - Mostly focused on RFI / LFI / SQLi and coordinating with the rest.
    Tflow - Maintenance of LulzSec website and torrents.
    Storm  - DDOS and also involved in PBS hack.
    Pwnsauce - Coding required tools for the team and involved in Infragard hack.
    Neuron - Coding and also involved in Sownage.
    M_nerva - Deus Ex Game hack.
    TrollPoll - Involved in Fox hack and seems to be the most paranoid of all.
    JoePie - Updating the team with news related to LulzSec and other channels of interest.
    Avunit - Seems focused on XSS and SQLi
    Kl0ps, io, Palladium and Devrandom - Hackers supporting the team
    Bitcoin Donations handled by Tflow, Topiary and Joepie
    Team Strength - 13 or 15. It could be possible that some handles are used by same person.

    Who are these Hacker?

     

    Wake up these hackers are our sons and daughter. They are the focused ones the ones that could lock in with laser eyes what they wanted. Remember that nerd you picked on back in school well he just hacked the IMF. Now he has powers and she has friends that think alike and where treated alike, with their own slant on Peace and War and especially on what’s wrong and right. Guess what they are our future – were we good parents? That’s who these hackers are.

     

    They have tricked you! Mis/disinformation.

    • To hide in cyber space is simple get a VPN (virtual private network) look it up some are free. It hides you they can’t see your geo-location then get TOR this software hides you even more. With these 2 basic steps that are all free you can hide in cyberspace.
    • Do you think these hackers that hide behind more layers than the 2 above would use “Twitter” http://twitter.com/#!/search?q=%23AntiSec to communicate their plans -
    • How about on the public IRC relay channels. When your on the PUBLIC IRC channels like #AntiSec they know who you are. You don’t look like them. You don’t talk like them. You don’t act like them. They know who you are.
      http://search.mibbit.com/search/antisec
    • The News has interviews with these cyber hacker groups - Really? - LulzSec. If you do not know who they are how can you know they are real. -dis/information
    • How about their leader of the LulzSec cyber revolution http://twitter.com/#!/anonymouSabu Sabu the ring leader of LulzSec
    • How about the LulzSec Twitter – www.twitter.com/lulzsec

     

    These hackers know social media they grew up in this technology. Social Engineering it’s second nature, their bread and butter they are hackers. Here is a family picture of the latest Cyber Crew.

    US Cyber Labs dot com

    • See how many cyber crewz turned on LulzSec. Why did they dox them? Were they too good? Were they too arrogant? Why did their friends turn on them? Maybe they were forced to in order to not got to jail?
    • These guys are pissed about the flips and betrayal that’s why they are pissed at the world – it’s that simple.
      • We were young and invincible once too.
      • They use these PUBLIC tools to taunt us. To give us clues to put out but to divulge any real information – sometimes.
      • I do admit that they are young and brazen so they kind of show their metal and that’s when the clues really become clear. We can sometimes gleam information from there documentation -chatter.
    • Notes to Myself – mEoW - GatoMalo@uscyberlabs.com

     

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit

  • Hacker Family Tree 2011

    Hacker Family Tree 2011.

    US Cyber Labs dot com

    Notes to Myself - mEoW - GatoMalo@uscyberlabs.com

     

    Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit



©2012 US Cyber Labs - Blog Entries (RSS) and Comments (RSS)  Raindrops Theme  
gAtO had -15096 visitors