05/18/12

bitCoin Mining Scam

gAtO fOuNd -this in the (.onion network site) BlackMarket Reload (while looking into bitCoin mining. bitCoin mining is something that people are getting into and using customize scripts to use zombie computers to generate bitCoins. Using Trojan-Downloader.win32.Agent.bmzd as a starting point it is modified to give it’s own unique hash file whoch will sometimes be overlooked by virus scans.

Then the author will insert 2 miners for him and give you the rest. At least that’s what this ad tells us. Here is a clue what a scan is it say’s it does not draw CPU power and of course if you know anything about Mining bitCoins that’s how it hashes bitCoins. So I would think that it would slow down a windows machine quite a bit. Since it modeled as a legit bitCoin Miner they tell us it’s 100% undetectable, I question that part. I also see that they are using DeepBit guild instead of the BTC guild, BTC guild will give you a little higher hashes and faster.

 

GREED is the reason why this little scam will work. The old saying if it’s too good to be true it’s NOT true. As bitCoins become more popular we will se others come into the bitCoin mining, but think about it. You can now take over a machine and have it mine bitCoins. It’s pretty much undetectable because the zombie machine is not being use to DdOs someone or used as a spammer machine. These zombies will be noticed when the C2 (Control and Control) is caught but in this bitCoin scam the machines will not be noticed too much from the outside world just the user will have a slow ass Windows machine- let’s face it a slow Windows machine is normal, and since this is only marketed in the deepWeb not the clearWeb less people will notice- gAtO oUt

the Ad can be found in the deepWeb- http://4eiruntyxxbgfv7o.onion/paste/show.php?id=169a828090203b12

Hi! I’m androd2 and in this site http://5onwnspjvuk7cwvk.onion/index.php?p=view_listing&id=2851

(The WELL known BlackMarket Reloaded)  I sell this really.. REALLY cheap.

(you must sing up to enter… just do it as customer, enter nickname..

and you’re IN! .. then enter http://5onwnspjvuk7cwvk.onion/index.php?p=view_listing&id=2851 )

As you’ll see.. I have positive feedback.. i’m not a scamming newbie.. I just wanna spread and

get people to know what I sell!

What is it? {It’s EXTREMELY well described in the item description}

.. I will paste the item description below ;).. pelase at least visit it!

100% Coded By Myself, Undetectable, Customized… and STEALTH!

***************************************

Proof it is “undetectable”: https://www.virustotal.com/file/ef390fc5455a3a2ca07168eff05071d10bf7ed156d2455fb28e5b6eb045ddb7f/analysis/1335995324/

.. notice that the ONLY positive was from ByteHero ONLY.. and it is even a FALSE positive.. “Trojan-Downloader.win32.Agent.bmzd” because it doesn’t download anything. It passed ALL Antivirus.

***************************************

How does it work? Well…

I make a CUSTOMIZED and UNIQUE Stealth miner exe (configured with 2 worker sessions of yours), i send it to you, and you and make your victims execute it (I can disguise it as you wish just ASK… for example I spread mine in a forum. I embedded a legitimate Windows7 activator.. and while actually activating Windows7.. it , without popup of ANY kind,it generated some files.. and starts mining)

It draws a little of GPU Power form each machine, mining for you! I’ve spread mine, and in one month now I ‘ve already Passed the 2000Mhash/s!

Excellent for posting anywhere… just make me disguise the exe! , uploading to your BOT-NET, or infect with social engineering, or, if you want to, embed a useful EXE, disguise it, and while actually executing the legitimate EXE… also installing the Silent Miner.

It’s 100% made by me. It hides itself. Auto-start with windows… NO window opened. Doesn’t draw CPU power!

The victim will not notice! No strange windows, no console popup… NOTHING!

The best part: 100% Undetectable! It’s based on a modded and legitimate GPU Miner, so it can’t be detected as VIRUS!

IT DOESN’T AUTO SPREAD ITSELF… so the key is how many victims execute this… thinking a bit you’ll came with TONS of ways (ask me to change the icon, a fake screen error, embeding a legitimate binary.. ) Thanks to that,get almost 100% invisibility to Heuristics.

Once executed by the victim.. the victim can even delete the original file..because the files are already installed!

It’s simple. All you need to give me is the data of 2 workers (recomend BIG Public Mining Pools.. for anonimity.. and quick cashout.. I used Deepbit for example) (One is backup in case the first one’s mining pool is down). That is Miner address and password {the password of the miner, not session… ask if you don’t understand this.. it’s not dangerous, because it’s the pass of the worker}. And the things you want me to do … put a custom icon? embeding a some sort of file or binary? ASK for it!

IMPORTANT: Once made the program and shipped to you, the workers address can’t be changed by ANY MEANS, because it’s embedded to the code.

I sold the first for 0.35 now it is a bit higher … Check the feedback yourself! it works! Have your Own Miner Factory… without having to spend money on hardware. With this, is extremely EASY to make much more in a day, than the price I ask for it. You’ll get that money back in NO TIME.

The price is extremely low to the Next buyers just to get positive feedbak of the product.. I’m planing to sell it for more than 2BTC or something like that. (In matter of days I got 2BTC from mine…)

. Consider this discount as a EXTREMELY good opportunity to get a 100% anonymous, decentralized, and secure way to get BTC!

CUSTOM THINGS I MAY ADD IF YOU ASK FOR (Check “Shipping options”, some of these are free, others not… if you only want the free ones,select the option one, to complete the price of the offer :) ):

*Error Message – FREE {Once the victim machine executes it, you can chose it to do nothing -silent, no popup, no window, nothing-, or if you want it to be used with Social Engineering, show some sort of error message}

*Exe’s Icon – FREE {Change the icon of the file… useful for social engineering

*Embed File/Binary – 0.09BTC Extra {You can ask me to embed -you must provide it- a file, so the victim won’t suspect it’s something weird happening. For example, I embedded a USEFUL Windows 7 Activator, and made the spread SO easy… because it actually unlocked Windows7 while infecting with the miner, so they shared it to friends and leave positive feedback on the post}

*YOU can say whatever you need and I will try to adapt this to your needs!

I’m doing it with LOW price because i want positive feedback to this product in particular {because it’s made by myself}. Then I’ll set a HIGHER Price.

If you have any doubts, please ASK… don’t keep the doubts!

- BITCOIN Silent FUD GPU Miner,UNDETECTABLE,100%Custom.


Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
05/16/12

gAtOmAlO2 is @_th3j35t3r

gAtO iS _th3j35t3r – I as soon as a friend heard the news of the th3j35t3r and  @cubespherical were at each other I went on to twitter and pick up the name. Why? As a security researcher I wanted to see if people were dumb enough to be fooled by anyone. Call it a test of a fool for the fools. Well I was surprised that people started to follow me right away, not too many fell for it but a few were confused and that is why you should always “trust but verify” .

I really don’t care what this is all about I just wanted to Social Engineer it just a wee bit to play a game of thrones. Who would suspect – who will know, who really cares. Anyway I got work to do so I need to play this out and finally come clean so I don’t have to play this game for anyone else. A few friends that I told were smiling a bit and they know I’m a lOcO gAtO so now you have it my friends. I hope I didn’t hurt anyone by this little trick, I hope you all learned something, and I did not waste 24 hours I learned what fools of Tooks they all are and remember -This is all bullShit, get over it -gAtO oUt

#th3j35t3r #cubespherical

the game goes on and on - http://pastebin.com/fKFP0qJt

So, th3j35t3r is on the run. He’s rmed everything, he’s disappeared from the net. And it’s all the doing of this Smedley Manning/@cubespherical.

But who is this hero?! What manner of man is he?!

Let’s look over his brief history.

http://topsy.com/twitter/cubespherical?nohidden=1&offset=40&om=aaaa&page=5

If you go to topsy and look at his tweets, he was solidly pro-Jester until recently. Then suddenly, he remembered a bar fight back in 2002, and as the internets is serious business and he was owned so badly in that fight he was still feeling butthurt aftershock tremors a decade later, he decided to toss all that on the fire and DOX THE JESTER AND KILL HIM FOREVER.

Once people paid him 20K bitcoins.

Riiiiiight.

Good luck with that, Smedley.

I’ve already commented on him probably being th3j35t3r here http://pastebin.com/jwYt7Hyf. tl;dr: th3j35t3r appears to be running some kind of half-witted psyops gambit. They both using the same OS (but different browsers, dohoho), they both speak more or less the same, both use bitcoins, the Smedley Manning account acted like a sockpuppet prior to this, the truck he posted came from a car dealer’s website (http://www.beckhamsautos.com/web/vehicle_photos/1951320/#1).

Also, I don’t think anyone apart from th3j35t3r’s supporters (and a handful of Anons who were annoyed by him for 20 minutes) have ever actually taken him that seriously, to be honest. God forbid anyone would think his identity was worth 100K. He’s got enemies, sure, but most of the retaliation will consist of sending him hookers and pizzas; the Taliban and radical jihadists have bigger fish to fry. Taking down a website for 30 minutes and giving them free publicity by bragging about it probably isn’t going to put him on the INFIDELS WE’VE REALLY GOT TO CRUSH, WITH FIRE AND BOMBS, unless the US .gov reveal that they got Osama just before he finished recording his “th3j35t3r, NUMBER ONE ENEMY OF ISLAM” video.

Protip: They won’t.

Anyway. I don’t know what th3j35t3r is trying to accomplish with this little scheme. I strongly suspect it’s all about money, like those wristbands, and the adf.ly links on his blog that must have made him a tidy dollar every time the media reported on his latest drama. I could be wrong, of course. It’s happened once before.

[*] WHAT COMES NEXT

- From where I’m sitting, on top of my Keyboard Warrior throne, there are three likely outcomes for this, no matter what the original goal is, and I’d like to predict them right now, so that he can’t use any of them to weasel out of this.

1) He’ll reactivate his normal account and claim it was all a Psyops operation all along, and that he was tracking bitcoin usage by “bad guys”, trying to map them out and connect them to various twitter handles, or some variant of that story. It’ll be alright, though, because he’ll definitely have “donated all the money to the Wounded Warriors” project. Definitely. Totally legit. This, I suspect, may have been his original plan, but that’s just a suspicion based on his previous actions.

2) He’s going to make Smedley Manning look like a total villain, probably an Anon (like he’s doing now), and then pop up with his normal account, claim the dox was fake, and that he was gone dark in order to get enough time to notify this poor .mil dude that some crazy nemesis was after him, because he’s a hero like that. I figure this is now the mostly likely move.

3) He’s going to actually disappear. Whether it’s because he doesn’t want to disclose the truth about Saladin, whether it was all part of his plan all along, or whether he wants to run with the Smedley Manning coverstory, who knows. This is my favourite outcome.

Anyway, sit back, grab a beer, get some popcorn, and watch the Serious Business unfold. Brace for the oncoming shitstorm.

http://pastebin.com/fKFP0qJt

 

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
04/6/12

Supply Chain Cyber Attack

gATO rEaDiNg - 2012 Maindiant “An Evolving Threat” and Trend-Micro LuckyCat ReDux reports. Great reading for any security geek but most important it’s about the business side of the hack. Take the old smash and grab of financial information and split town, process the financial windfall and party like it’s 2999. Now it’s more beneficial for the criminals to stay inside the victims servers and collect intelligence and espionage. Ok let the gAtO break it down for you, not as a criminal that’s easy, as a state actor I would go after AeroSpace, Energy, Shipping, Military Research, Engineering, India  and Tibetan Activist… Wait a minute a India, a Tibetan Activist group, oh yeah you know it’s China but this is to be expected from China. Now the new spin is why would they go into a banks and use advanced persistent threats (APTs) hacks, well as gAtO understands it the Chinese have a shit load of MONEY— follow the money is not only an american thing it’s for every player in the world.

We have to look at the data through 3 different set of eye’s (magnifying glass with gAtO’s old EyE’s) but it’s still the same – Your data (ALL- your little company secrets) needs protection.

Here is the Score-Card your Business — versus – Competition, Government, Criminals, Hacktavist, Economic Espionage, Nuisance Hackers. On top of all this 94% of victims were notified by an external entity that they were hacked. If that doesn’t send chills down every board member in every company in the world, nothing does.

Here you are doing your business and let’s be frank some business well they walk a thin line sometimes like dumping medical and radioactive waste on a beach in New Jersey ( I know Snooki lives there) . IS your company maybe polluting the ground water for a 100 mile radius of the plant. This is not the information that they want hackers, or the press to get a hold of. “Remmember Rudolf Murdock News Hacking Empire- hey hack anyone for a buck”

Protect Customer Data yeah companies and governments want to protect it, but their little illegal/legal stuff companies do like hiding the report of the of shore oil well that just blew up and spilled all kinds of stuff all over the Gulf coast. These are the real thing that keep business people up at night worrying about hackers, it’s plain and simple cover your ass and let’s get that no bid government contract after we pay off the senator and we better encrypt that information…..

Hackers come in all flavors but if you look at the LuckyCat crewz these are very unique. Not only real computer scientist but marketing campaign and project management. They dual tier C&C (Command and Control), they use the victims supply chain to move laterally across trusted networks in order to be more invisible. Invisible takes a new trend here these hacker hide their code in plain site, they used older malware as insertion points sometimes and of course social engineering to gain access.

Bottom line these new hackers- they  are business-men, -they are governments, -they are commercial criminals, -they are hacktivist or -they are a lone wolf hacker. Companies are finally getting the message. Protect your data, not just your customer’s data, but all your little secrets because if your online– someone is watching you and these can be a 15 year old kid or a Dual Master degree in computer technology that is unemployed or works for a government. Trust but verify takes on a new meaning now -gAtO oUt

lab notes - The report, which is based on hundreds of advanced threat investigations conducted over the past year, includes analysis, statistics and case studies that highlight how advanced and motivated attackers are stealing sensitive intellectual property and financial assets.

Malware Only Tells Half of the Story Organizations’ investments in malware detection and antivirus capabilities, while effective in detecting characteristics associated with common worms, botnets, and drive-by downloads, do little to help defend against targeted intrusions.

The use of these publicly available tools has added some complexity to identifying threat actors because when organizations identify a piece of publicly available malware they often cleanse the file and — in the process — obscure what could be a larger incident.

It’s unclear why banks wouldn’t already be looking for unusual settlement activity and conducting daily monitoring, but there it is. At any rate,  “high-risk” merchants generally handle the dicey and vicey types of online commerce, such as Internet gaming, adult Web sites, rogue anti-virus software sales and online pharmacies. Might be a good idea to keep an extra close eye out for these types of unauthorized charges over the next few days

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
02/19/12

gAtO aLmOsT -got hacked

gAtO aLmOsT -got hacked WHY? after a nice kitty nap I woke up and found my site uscyberlabs.com was suspended. I could not get into my site or get any email so I called my hosting provider. We soon found out that someone was trying to do a brute force trying to get into my admin panel. (see logs—below) To top it off someone called my provider and tried to social engineer them into resetting my password. From my simple SEO plug-ins I could see that it was a ToR connection the IP 72.14.182.266 running a Python-urllib/2.7 script. You can see the timestamp and the delay’s give it away to a ToR connection. Of course my hosting Service is doing some research to see what they can find out but the IP as well as the phone call were non-traceable (or were they).

gAtOmAlO sAy's

Since gAto writes about Anonymous I assume at first that the FBI was going to kick down my door but that made no sense since everything I publish is available online Open-Source. I did notice a few days ago a tweet warning of a grayHat that needed a Dox – http://whatismyipaddress.com/ip/72.14.182.226 this is a little info about the IP address it shows Dallas, TX but my internal SEO places it in Newark, NJ.

Why is the question did I piss someone off, was I getting close. I HAVE a lot of information about Anonymous and the crew(z) that I do not publish, just because “gAtO is No SnItCh”. Maybe @MissRevolution_ got pissed because of her money problems or Xgirlfriend, in Chi-town I could go on and on but The OpCashBack Twitter of Banks that I published was to get the world out. Why so many banks have twitter I still find that interesting. Oh Well back to the SaltMines -

Ok so is GaTo’s words so powerful that  you want to hack his site…. gAtO feel so important —naw.. just messing.. -gAtO oUt 

http domain  72.14.182.226 Hostip (subject) more info

Country: UNITED STATES (US)

City: Newark, NJ

IP: 72.14.182.226

,

li45-226.members.linode.com

Python-urllib/2.7

February 19, 2012 15:06:44

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:43

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:42

/blog/?p=1915

February 19, 2012 15:06:40

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:39

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:38

/blog/?p=1915

February 19, 2012 15:06:34

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:33

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:06:32

/blog/?p=1915

February 19, 2012 15:02:53

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:53

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:51

/blog/?p=1915

February 19, 2012 15:02:50

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:49

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:48

/blog/?p=1915

February 19, 2012 15:02:45

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:43

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 15:02:42

/blog/?p=1915

February 19, 2012 14:59:44

/blog/2012/02/17/banks-twitter-opcashback/

February 19, 2012 14:59:44


Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
02/16/12

PennTest Threat Intelligence

PennTest Threat Intelligence - part-1

gAtO bEen ThInKiNg - In the hyper connected world we live in Pen-Testers have a lot on their hand, hardware, firmware, OS, web-apps. The facts are that a simple web-app upgrade, may open new holes that off-set the problem they had to begin with. A pen-test, is a method of evaluating the security of a computer system or network by simulating an attack from malicious outsiders. Who are the outsider? How do the outsiders pen-test your system? Non-state actors have played an important part in many international cyber conflicts in the past two years- game changers. With the Anonymous crew(z), China, Russia, India, Iran out in force in cyberspace a company needs to know if they are the target from a political, competition or worse yet a loneWolf or activist.

Many think that with BackTrack anyone can be a tester, but it’s different today. Companies need to understand the Geo-Political aspect of their company and who are their markets and how does it play out in the real world. Look at Sony, HBGrays these are two different companies but their reputation has been tarnish by what, a bunch of kids, naw, these boy’s and girls are the new breed, smart, educated and connected. These people are System Admin in their day job and Anonymous during off-hours. They know how to work in the box and also see out-of-the-box tips and tricks and have thousands that want to try their game and imitate them. Whatever you think these new boy’s and girls will multiply, it’s a fab, a movement but they all want to be a cool hackers and the next generation of hacktivist will make these people look like amateurs.

Who knew that a Low Orbit Ion Cannon (LOIC) used to test how many connection your server will handle, would be used by the attackers themselves. A long time ago in cyber years (2-3 years ago) only the geeks had the knowledge and skills to do some of the hacks that we see today. Today Anonymous is not only a social movement but it’s a cause celeb, people want to belong and these social 4chan outcast have started a revolution in cyberspace that governments and corporations now are worried about, and well they should be.

Break out Backtrack and do some pen-testing and yes you may find misconfigured servers like gAtO hAs -(SCADA systems to boot) and such but if you can see what your enemy is looking at, planning. Nothing is better than threat intelligence to guide you in mitigating your company as to future attacks.

Look at the RSA and Diginotar APT attacks, the bad guy’s went after the certificate authority how does a typical pen-test tools know that, they don’t if you don’t have your pulse on the game your in, you may be next.

Remember the technical aspect is one thing but if you have many, many hands trying new things on your site guess what, they will hack you if your connected to the Internet. Your company cannot live in a bubble and so must expose themselves to customers, vendors and business partners your company cannot control all those aspects. When a simple email attachment to the c-Suite boys just like with the Nortel hack they got you big time, in Nortel chase they were inside their network for 10 years. The reputation, the technical all this means nothing if you don’t have good solid threat intelligence to know what’s going on in the world.

If you don’t have a team to look at threat intelligence for your company, get some people fast. If your connected you can be hacked, learn and be silent – Can’t stop the signal. Everything goes somewhere, and I go everywhere…. -gAtO oUt

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
01/27/12

Predictive Behavioral Security Analysis part 1:

Predictive Behavioral Security Analysis part 1:

gAtO bEeN -watching a mouse hole called Twitter lately, it’s an OSINT Open Source Intelligence source that monitors real events in real time. OSINT – is a form of intelligence collection management that involves finding, selecting, and acquiring information from publicly available sources and analyzing it to produce actionable intelligence.

 

cool dashboard – internet Storm Center - http://isc.sans.edu/dashboard.html

gAtO bEeN -watching World Web War (WWW) hacktivismn has jumped started this new year, #OpMegaUpload upset lot’s of people and the organization structure of Anonymous is getting more refine. Things happened in #poland #ireland and during the middle of a DoS attack Anonymous told their warrior on twitter:

 

http://trendsmap.com/

@AnonyOps: #DDOS of European Parliament must stop NOW. They’re not the ones #ACTA

Later they tweeted this:@AnonyOps: europarl.europa.eu back up after #DDOS. Thanks for listening to logic #Anonymous.go persuade the MEPs:

http://www.msisac.org/apps/dashboard/

Command and Control in your face and people responded to this organized movement. Each new attack everyone get’s better more coordination Anonymous is growing up. Just look at the causes #SOPA #PIPA  #ACTA #OpMegaUpload #poland #Ireland #SOPAIreland #France #Belgium  #FreeTopiary. The Anonymous thingy has grown up it’s a social conscious mindset created, manipulated, organic, ???? leaderless ????. The evolution of this movement has spawned OWS the Occupy Wall Street political movement has it’s roots in Anonymous, but you can see the worldwide community support for this group that is anyone. This movement will grow and mature.

http://www.fsisac.com/

Think about it.

This Week gAtO Learned mUcHo-mUcHo, we have not only the technical means but now the social monitoring needs that can be used to gather information like no other time before. Of course our governments are getting in on the fun.

Homeland Security DHS- Human Factors/Behavioral Sciences Projects:

  • Actionable Indicators and Countermeasures Project
  • Biometric Detector Project
  • Community Perceptions of Technology Panel Project
  • Community Resilience Project
  • Enhancing Public Response and Community Resilience Project
  • Future Attribute Screening Technology (FAST) Project
  • Hostile Intent Detection – Automated Prototype Project
  • Hostile Intent Detection – Validation of Observable Indicators of Suspicious Behavior Project
  • Human Systems Engineering Project
  • Human Systems Research Project
  • Insider Threat Detection Project
  • Mobile Biometrics System Project
  • Multi-modal Biometrics Project
  • Passive Methods for Precision Behavioral Screening Project
  • Predictive Screening Project
  • Quantitative Psychosocial Impacts Index Project
  • Rapid DNA Project
  • Risk Prediction Project
  • Violent-Intent Modeling and Simulation Project

http://www.dhs.gov/files/programs/gc_1218480185439.shtm

http://k.root-servers.org/

And the CIA got into the fun[1] way before it was hip to monitor the web. We know the government has all kinds of databases of all kinds of things they collect remember echelon and carnivore the FBI first grab at data. Then we yell at the CHinese for doing the same thing we did, they learned from us about gathering information about people. Now cyberspace ties us in even tighter with SMS, streaming video, encrypted mobile chats for the masses. But as more is piled on more tools are developed. Recorded Future[2] was a little geek company sucking in the data and developing Analytical tools for Intelligence forecasting and the CIA loves them.

Predictive Behavioral Security Analysis is just monitoring choice which is freedom for it is predictive and can then be manipulated to plant an idea, a spark, a tweet. “Egypt can be free” this little spark is setting the fuel for the flames that will burn in Cairo by it’s people via Twitter, Facebook and any other social media. The Arab Awakening -Arab Spring was an simple idea, manipulated in cyberspace by protester, dissidents and governments in Tunisia, Bahrain, Syria and others, we will see Iraq’s move in March of this years with it’s election, they are closing down their Internet but will the idea of freedom explode anyway. We will be monitoring this – gAtO OuT

 

References:

[1] CIA Invest in ‘Future’ of Web Monitorin http://www.wired.com/dangerroom/2010/07/exclusive-google-cia/

[2] https://www.recordedfuture.com/

 

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
01/23/12

Underground Cyber War-TangoDown OpMegaupload

gAtO wItNeSs – LIVE International Underground Cyber War via  Twitter this weekend. #Anonymous #Megaupload #OpMegaupload #TangoDown …

If you haven’t heard, police in New Zealand raided MegaUpload.com took down the site and confiscated the servers and all the materials, copyrighted or original content. Remember SOPA protest last week this raid was a SOPA raid by the New Zealand government. They used (Low Orbit Ion Canon) and other tools plus  Twitter (Twitter follower could click on a link and that would launch a dDoS attack -live crowd-source enabled TangoDown attack.

http://pastebin.com/WEydcBVV

  1. Twitter – @AnonymousWiki - January 19th, 2012
  2. Popular file-sharing website megaupload.com gets shutdown by U.S Justice – FBI and charged its founder with violating piracy laws. Four Megaupload members were also arrested. The FBI released a press release on its website which you can view here:

    German Internet millionaire Kim Schmitz (Kim Dotcom) arrives for. a trial at a district court in Munich in these May 27, 2002 file photos. New Zealand police broke through electronic locks and cut their way into a mansion safe room to arrest the alleged kingpin of an international Internet copyright theft case and seize millions of dollars worth of cars, artwork and other goods. German national Schmitz, also known as Kim Dotcom, was one of four men arrested in Auckland on January 20, 2012, in an investigation of the Megaupload.com website led by the U.S. Federal Bureau of Investigation. Reuters

  3. http://www.fbi.gov/news/pressrel/press-releases/justice-department-charges-leaders-of-megaupload-with-widespread-online-copyright-infringement
  4. We Anonymous are launching our largest attack ever on government and music industry sites. Lulz. The FBI didn’t think they would get away with this did they? They should have expected us.

Anonymous Twitter feeds kept everyone informed, supporters retweeted it,  joined in the attack  and soon you could see the traffic increase 100% over the course of the event. The attack vector was dDoS but they manage to delete sites like cbs.com down to the bone. Another defiance stance from Anonymous and their crew(z) this weekend showing who has bad security. This is a way for Anonymous to be job creators (mEoW), because these companies need more security people fast…  

**- Will these companies try and hide these attacks? Will these organization disclose if any identifiable USER INFO was compromised? – Will we see unencrypted USER INFO (credit cards -mastercard.com was tango down)in the wild of cyberspace? -**

When gAtO saw Justice.gov and http://justinbieberweb.com/ got TangoDown gAtO kNeW they meant business. When the .gov took a hit you saw thing start to happened…like Anonymous.action-24.com is a fake forum created by the authorities (FBI).

“A security expert (name withheld -Tweeted)” *** Is the (fully unsecure) #AnonGroup social network really run by #AnonOps / #Antisec ?

gAtO sEe- conspiracy theory (FBI vs Anonymous) all around this, but if this was true, or maybe a plant to throw distress amongst the Anons or to capture participants IP address. \I see some links to news Items pop up in pasterBin all the time to a blank post, one way of seeing who is following the #OpMegaupload / I still haven’t found out but I’m sure people are looking into this. Trust in the crowd-sourcing communication and tracking tools coordinating attacks and status is something any dissident groups is concern about, but that the FBI and other’s took notice of these attacks thats for sure Dude:

GOV TANGO DOWN! #Megaupload. » anonops AnonOps. “The Internet Strikes Back” is TT! » anonops AnonOps. The Internet Strikes Back #Megaupload info

At the end of the day we see the power of the people in cyber space, a world wide movement like the SOPA, OWS support. Most people don’t have a clue what’s been happening in the underground cyber war to keep it FREE.  |gAtO is no judge as to the protesters wether it’s right or wrong first #SOPA blackout then this massive attack on some major companies -movers and skaters bAbY. I just want these companies to come clean and do the responsible thing, full Disclosure  what happened. Protect my data or else I will not do business with you. Hacktivismn has taken a new turn and people want to belong, they want to be empowered, some are hipsters but the majority are real protesters, the new breed of (hacktivist ) that comes after this one will blow our minds.

 **- 5:17 P.M. Update: RIAA.org is now down.

5:55 Update 3: Tweets indicate there may be more attacks to come this evening.

5:55 Update 3: Tweets indicate there may be more attacks to come this evening.

7:47 Update 4: Anonymous is reporting FBI.gov as down. Some people report being able to get through, but the site is clearly under a lot of stress.

8:19 Update 5: Now it’s definitely down. FBI.gov, that is. MPAA and RIAA sites are back now though

- **

 A masked hacker, part of the Anonymous group, hacks the French presidential Elysee Palace website on January 20, 2012 near the eastern city of Lyon. Anonymous, which briefly knocked the FBI and Justice Department websites offline in retaliation for the US shutdown of file-sharing site Megaupload, is a shadowy group of international hackers with no central hierarchy. On the left screen, an Occupy mask is seen. Getty

Expect Us! is their motto, we better be prepared - gAtO oUt

Until this mess is clear , I hope you saved copies and can upload them to alternative sites like megaupload.com like Putlocker.comFilebox.com or Depositfiles.com or one of the many other cyberlockers available so that people can continue to enjoy them while Megaupload is not working. 

References:

Universal, RIAA, FBI, MPAA and Department of Justice Sites Go Down, Anonymous Claims Responsibility -http://www.geekosystem.com/anon-justice-universal/

Anonymous deletes CBS: Operation Megaupload continues -http://www.examiner.com/anonymous-in-national/anonymous-deletes-cbs-operation-megaupload-continues?@anonymouspress

If Megaupload is not working what happens to the files? http://www.examiner.com/video-game-in-honolulu/if-megaupload-is-not-working-what-happens-to-the-files?@anonymouspress

Anonymous tricked people into joining Web site attacks - http://news.cnet.com/8301-27080_3-57363103-245/anonymous-tricked-people-into-joining-web-site-attacks/

MegaUpload Photo’s of the Bust  - http://cryptome.org/2012-info/megaupload/0051.htm

TangoDown 4 opMegaUpload -List

CBS.com

http://warnerbros.com

http://www.vivendi.com/

mastercard.com

fightprivacy.com

universalmusic.com

http://paidcontent.co.uk/

http://store.warnerbrosshop.com/

wando.com.br

Justice.gov

http://justinbieberweb.com/

http://www.europarl.europa.eu/

http://ms.gov.pl/ Poland

http://universalmusic.es/

http://www.brasilia.df.gov.br/

http://www.fbi.gov/

Department of Justice http://www.justice.gov/

http://www.riaa.com/

http://www.universalmusic.com/

http://www.wmg.com/

http://www.BMI.com/

http://www.mpaa.org/

Motion Picture Association of America (MPAA.org) Universal Music (UniversalMusic.com) Belgian Anti-Piracy Federation (Anti-piracy.be/nl/) Recording Industry Association of America (RIAA.org) Federal Bureau of Investigation (FBI.gov) HADOPI law site (HADOPI.fr) U.S. Copyright Office (Copyright.gov) Universal Music France (UniversalMusic.fr) Senator Christopher Dodd (ChrisDodd.com) Vivendi France (Vivendi.fr) The White House (Whitehouse.gov) BMI (BMI.com) Warner Music Group (WMG.com)

Brazil - MEGA TANGO DOWN

http://pastebin.com/H4NpqCDC -

Invadimos denovo : http://imgur.com/6bmFe. Havittaja – @Havittaja – www.twitter.com/Havittaja -The evilc0de – @theevilc0de – www.twitter.com/theevilc0de -Todos os servidores foram desligados -MEGA TANGO DOWN -(TODOS DEVEM ESTAR OFFLINE AGORA 22/01/2012 19:47)

?antigo.se.df.gov.br (OFFLINE)

?brasiliasustentavel.seduma.df.gov.br (OFFLINE)

?www.admjardimbotanico.df.gov.br (OFFLINE)

?www.agecom.df.gov.br (OFFLINE)

?www.agenciabrasilia.df.gov.br (OFFLINE)

?www.aguasclaras.df.gov.br (OFFLINE)

?www.arpdf.df.gov.br (OFFLINE)

?www.bandeirante.df.gov.br (OFFLINE)

www.brasilia.df.gov.br (OFFLINE)

www.brasiliatur.df.gov.br (OFFLINE)

www.brazlandia.df.gov.br (OFFLINE)

www.candangolandia.df.gov.br (OFFLINE)

www.capitaldigital.df.gov.br (OFFLINE)

www.carnaval.df.gov.br (OFFLINE)

www.cbhparanaiba.seduma.df.gov.br (OFFLINE)

www.ceasa.df.gov.br (OFFLINE)

www.ceilandia.df.gov.br (OFFLINE)

www.cepceilandia.df.gov.br (OFFLINE)

www.codeplan.df.gov.br (OFFLINE)

www.codhab.df.gov.br (OFFLINE)

www.coorsep.seg.df.gov.br (OFFLINE)

www.cruzeiro.df.gov.br (OFFLINE)

www.defensoria.df.gov.br (OFFLINE)

www.defesacivil.df.gov.br (OFFLINE)

www.der.df.gov.br (OFFLINE)

www.detran.df.gov.br (OFFLINE)

www.df.gov.br (OFFLINE)

www.dfdigital.df.gov.br (OFFLINE)

www.distritofederal.df.gov.br (OFFLINE)

www.educacaointegral.df.gov.br (OFFLINE)

www.emater.df.gov.br (OFFLINE)

www.escoladegoverno.seplag.df.gov.br (OFFLINE)

www.esporte.df.gov.br (OFFLINE)

www.etc.se.df.gov.br (OFFLINE)

www.etc.sect.df.gov.br (OFFLINE)

www.fap.df.gov.br (OFFLINE)

www.fhb.df.gov.br (OFFLINE)

www.gama.df.gov.br (OFFLINE)

www.gdf.df.gov.br (OFFLINE)

www.gdfdireto.df.gov.br (OFFLINE)

www.governo.df.gov.br (OFFLINE)

www.guara.df.gov.br (OFFLINE)

www.hbdf50anos.df.gov.br (OFFLINE)

www.ibram.df.gov.br (OFFLINE)

www.inas.df.gov.br (OFFLINE)

www.iprev.df.gov.br (OFFLINE)

www.itapoa.df.gov.br (OFFLINE)

www.jardimbotanico.df.gov.br (OFFLINE)

www.juventude.df.gov.br (OFFLINE)

www.lagonorte.df.gov.br (OFFLINE)

www.lagosul.df.gov.br (OFFLINE)

www.matricula.df.gov.br (OFFLINE)

www.metro.df.gov.br (OFFLINE)

www.nahora.df.gov.br (OFFLINE)

www.novacap.df.gov.br (OFFLINE)

www.orgaos.df.gov.br (OFFLINE)

www.ouvidoriageral.df.gov.br (OFFLINE)

www.paranoa.df.gov.br (OFFLINE)

www.parceirosdaescola.df.gov.br (OFFLINE)

www.parkway.df.gov.br (OFFLINE)

www.pedala.df.gov.br (OFFLINE)

www.pg.df.gov.br (OFFLINE)

www.planaltina.df.gov.br (OFFLINE)

www.prg.df.gov.br (OFFLINE)

www.procon.df.gov.br (OFFLINE)

www.protec.df.gov.br (OFFLINE)

www.recanto.df.gov.br (OFFLINE)

www.revista.seduma.df.gov.br (OFFLINE)

www.riachofundo.df.gov.br (OFFLINE)

www.riachofundoii.df.gov.br (OFFLINE)

www.sa.df.gov.br (OFFLINE)

www.samambaia.df.gov.br (OFFLINE)

www.santamaria.df.gov.br (OFFLINE)

www.saosebastiao.df.gov.br (OFFLINE)

www.saude.df.gov.br (OFFLINE)

www.scia.df.gov.br (OFFLINE)

www.scs.df.gov.br (OFFLINE)

www.sde.df.gov.br (OFFLINE)

www.sdet.df.gov.br (OFFLINE)

www.se.df.gov.br (OFFLINE)

www.seade.df.gov.br (OFFLINE)

www.seapa.df.gov.br (OFFLINE)

www.sect.df.gov.br (OFFLINE)

www.sedest.df.gov.br (OFFLINE)

www.seduma.df.gov.br (OFFLINE)

www.sehab.df.gov.br (OFFLINE)

www.sejus.df.gov.br (OFFLINE)

www.semarh.df.gov.br (OFFLINE)

www.seops.df.gov.br (OFFLINE)

www.seplag.df.gov.br (OFFLINE)

www.setur.df.gov.br (OFFLINE)

www.sga.df.gov.br (OFFLINE)

www.sia.df.gov.br (OFFLINE)

www.slu.df.gov.br (OFFLINE)

www.so.df.gov.br (OFFLINE)

www.sobradinho.df.gov.br (OFFLINE)

www.sobradinhoii.df.gov.br (OFFLINE)

www.ssp.df.gov.br (OFFLINE)

www.st.df.gov.br (OFFLINE)

www.sudoeste.df.gov.br (OFFLINE)

www.taguatinga.df.gov.br (OFFLINE)

www.tcb.df.gov.br (OFFLINE)

www.varjao.df.gov.br (OFFLINE)

www.vice.df.gov.br (OFFLINE)

www.visitbrasilia.df.gov.br (OFFLINE)

www.vlt.df.gov.br (OFFLINE)

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
12/27/11

Detectives Hunting Dead Girl -Rupert Murdoch Hacked the Phones

gAtO pIsSiRupert Murdoch and son James get away with not just hacking a dead girls cell phone but it appears that they also hacked the phones of the police investigators on the case. this all happened in 2002. Chief Constable Mark Rowley reported this and when passed to Scotland Yard about the phone hacking investigation in 2006 this part of the report was missing.

gAtO sAiD- funny ha ha how Rupert Murdoch can get Scotland Yard in your pocket and the local police in London.

So Rupert, Jimmy and let’s not forget Tom Mockridge as another scumbag at News International. These are the hackers that make me sick. Here was power and influence totally disregarding any decorum of a news organization. They went out and hired crackers the web 3.0 type and then these people had great meetings about all this information. They could of deleted messages and dummied some up. The personal violation that these people committed in cyberspace and then they talk about hackers.uscyberlabs - gatomalo_at_uscyberlabs_dot_com

The Murduch cyber crewz were the best. No problem if this is illegal we got a get out of jail card with he police and Scotland Yard this was a hackers dream. gAtO aDmIt - he would like to hack without strings one time sI-nO but unless I find a rich and powerful well connected type like the Kock brothers. gAtO sent in a rEsUmE it was a zenmap report of their site -gAtOmAlO sOmEtImE

Detectives hunting Milly Dowler’s killer had phones hacked, Leveson Inquiry hears

Police officers investigating the disappearance of the schoolgirl Milly Dowler had their mobile phones hacked during the inquiry, Surrey Police has revealed.

A lawyer for the force told the Leveson inquiry that “a number of Surrey Police officers themselves were victims” of phone hacking shortly after the investigation began in March 2002.

Previously it was known that journalists at the News of the World had hacked the mobile telephone of the missing 13-year-old.

But this is the first time that it has been confirmed that detectives working on the case were also victims of phone hacking.

John Beggs QC, counsel for Surrey Police, told Lord Justice Leveson: “My instructions are that it is very likely that a number of Surrey Police officers themselves, at the time of launching the Milly Dowler investigation in March nine years ago, were themselves victims of hacking.”

Earlier this month Surrey Police admitted that they learned that Milly Dowler’s phone was hacked by the Sunday tabloid in 2002 but did not act.

RELATED ARTICLES

Mr Beggs did not reveal whether the force also learned that their own officers had been hacked or whether this has since come to light during Operation Weeting, the Metropolitan Police’s investigation into phone hacking.

He was speaking as the Surrey Force made an application to become a core participant in the Leveson inquiry, which will look at the culture and ethics of the press.

Mr Beggs argued that the force should be allowed “core participant” status in light of the criticism the force has faced following their admission that they knew about Milly Dowler’s phone being hacked.

The force made the admission in a letter to the Home Affairs Select Committee.

The force’s then Chief Constable Mark Rowley said that officers became aware in April 2002 that someone from the News of the World had accessed the missing girl’s voicemail after someone on behalf of the Sunday newspaper phone the police operation room.

However Mr Rowley said that a formal investigation was not launched. He said: “At that time the focus and priority of the investigation was to find Milly who had then been missing for over three weeks.”

Mr Rowley’s letter said that an inquiry is looking into why no formal investigation was launched. He also revealed that the information that the News of the World had accessed Milly Dowler’s voicemail in 2002 was npot passed to the original Scotland yard phone hacking investigation in 2006. The reason for that is also being investigated.

http://www.telegraph.co.uk/news/uknews/phone-hacking/8860067/Detectives-hunting-Milly-Dowlers-killer-had-phones-hacked-Leveson-Inquiry-hears.html

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
10/27/11

Cyber Security LinkedIn Groups

Groups gAtOmAlO likes

 

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit
10/25/11

Cyber 911 For the Average Small Business Person | After the Tiger-Mate Hack -Project Notes

Project Notes

Who do you call when your web sites is hacked – “cyber 911 -may I help you”. The hosting service -no way, no they’re too busy fixing the attack, and what to say at a press release!

We hear a lot of politician talk about helping the small businessman. Well Sunday 9/25/2011 @(4am)  about 500,000 (half a million) small business were hacked. gAtO’s site was hacked too, we are still waiting to hear-  about declaring InMotion and it’s hacked site into a disaster area.  gAtO say – we have not heard a word about some cyber political person flying around InMotion and touring the 500k websites that were hacked by Tiger-M@te and his crew(z).

Tiger Mate has been tied to the Google Bangladesh cyber attack, this is a real hacker not the wanna be like, Anonymous and LulzSec. One shot 500k website, that’s “The Biggest Hack in the World” that we know of. Could this hack be a practice run for something worst. Could it be an intelligence gathering, the raw data of all the sites could be a gold mind for spam. Did the hack page effect anyone with a trojan. This is a great way to deliver a virus. One Hosting service, to many content providers and to their readers. One to Many Distribution Attack- One hack and it could potentially deliver hundred of thousand of zombie computers to a BotMaster. There is some talk the attack also infected the http_Access file. So far it only infected blog’s not static sites. Is there any Politician out there.. HeLLo …

gAtO has not seen it, but were was the cyber Community Emergency Response Teams (CERT). This is the kind of government programs that are needed in the new age in Cyberspace. How can we create a cyber team to help situations like this attack.

After I took care of my own site, I started to look around for others that were infected to see if I could help and was lucky to run into 2 great sites. The  Urban Cowboy and Leo Blanchette’s clipartillustration.com these two cyber heroes took the fight to the streets and showed leadership. People helping people.

What to do when your site’s been hacked. Some of the lessons learned from the recent Tiger-M@te attack on inMotion are right in front of our face. For the average website/blog content creator, we all have our special thing we do. But as we saw the provider’s blog (InMotion) was down, they had to shut down, save everything for forensics, evaluate and find the hack, then a plan for a sanitize re-boot and disinfect the hacked sites. The attacker Tiger-M@te set his target on “wordpress”. Why?

It’s a favorite amongst bloggers, and it has a wide distribution installation base, to get the most bang from your buck (attack)…Who do we call when our sites are down. I’m not sure. I would like to see our government get in and help us small business with the problems we have in cyberspace. New jobs for the new world – cyber-Police?.

Later,

My 2© cents – gatoMalo_at_uscyberlabs_dot_com

 ———lab Notes

InMotion  Forum about the Hack  –> http://forum.inmotionhosting.com/viewforum.php?f=57

Timeline -InMotion release -see below

http://www.webhostinghub.com/support/website/website-troubleshooting/status-of-september-tiger-mte-attack


http://www.citizencorps.gov/cert/
Community Emergency Response Teams (CERT)

Tiger Mate

The bangladeshian hacker “Tiger Mate” has been very active and has hacked some high profile websites in the past such as bangladesh airtel and local american express website.

We are in good company, check out the also-afflicted. http://zone-h.org/archive/notifier=TiGER-M@TE

 

Mass compromise at inmotionhosting.com

Mass compromise at inmotionhosting.com | Sucuri

According to zone-h, they defaced at least 1,000 sites, and a list of the attacked sites can be viewed here: http://zone-h.org/archive/notifier=TiGER-M@TE

*It seems that some of the compromised sites were also at webhostinghub.com (both owned by the same company)
**We are tracking more than 10k sites already defaced.
***Update from their in their Twitter account: “inmotionhosting InMotion Hosting
Security team members have traced this vulnerability to an authentication system and are working to patch this now. “

Comment for Sara @ PoliticalUSA

The largest hack ever made in a single shot !!!!

It was not just a server hack, actually whole data center got hacked.”

700,000 websites hacked in a single shot by TIGER-@MATE

Good Morning, PoliticusUSA; You’ve Been PWNed by TiGER-M@TE!

http://www.politicususa.com/en/politicususa-you’ve-pwned-tiger-mate

Good morning, PoliticusUSA; you’ve been PWNed by “TiGER-M@TE”! “PWN” This is called a “PWN” hack. Yeah, InMotion got PWNed.

I’m writing to you from a secure, non-disclosed location known as GOP Clown Show. Don’t ask, and I won’t tell.

This morning when I opened PoliticusUSA to share my colleagues’ morning stories, an ominous black page replaced my story from last night on Occupy Wall Street. This can’t be good, I thought. Then the page shrank down and began dancing all over my screen.

I chased it around for a few minutes, too sleepy to be alarmed.

Muttering under my breath (to say I am short tempered when it comes to technology is to put it mildly), I cursed the dancing box. I believe I may have called it the devil, but it’s all a blur now. I clicked and clicked and it ran and played.

Finally, I got it: “Server HackeD by TiGER-M@TE”

Ohhhhhhhhh………………

Our host tells us, “InMotion Hosting
Security team members have traced this vulnerability to an authentication system and are working to patch this now.”

Tiger mate hacking Immotion

http://josephtavern.com/?p=63

Apple Support

Sep 25, 2011 6:56 PM

En-route to ASC today I suffered a hack attack by tiger-m@ate …I say I suffered the attack, in fact it seems to have been an attack on either google.co.uk or apple.com. There is some insistence that it can’t be the latter.

New to ASC I started a discussion at:  https://discussions.apple.com/thread/3345813?start=0&tstart=0

…advised that it belongs here instead, it not being an attack on ASC (unconfirmed).

It seems that several hundred servers were attacked today and most likely these were XSS-attacks. My initial research leads me to believe that these attacks are based on the exploitation of server-side vulnerabilities rather than malware on the client-side but I’m no expert.

I’ve always assumed that as much as I try to protect my network against hacking and my computers from physical theft, there will always be a risk. For this reason I ensure my data is well protected: I use 1Password for log-in security, Knox for encrypting my documents and data (whilst retaining portability) and Espionage for securing application data. Nevertheless, it concerns me that my system may have been compromised.

Please contribute if you’ve had a similar experience or can offer advice on the extent of the risk involved.

Andrew

Your system was not compromised. This hackers seems like like to hack DNS servers and poorly secured web hosting providers. It is extremely rare for individual users to be hacked by an individual hacker. It has never happened to a Mac user. Nothing to worry about.

@etresoft  thanks for your response — it seemed to me when I revisted it, that the redirected page had no apparent functionality and appeared to be more of a calling-card …seemingly aimed at increasing the noteriety of tiger-m@te, than to launch any kind of malicious attack on the end-user.

Seeing a browser window shrink, dance around the screen like a sprite and then expand to reveal “hacked” across the screen was a little disconcerting ….and naturally ones immediate reaction is to quit, trash and cut the connection.

Thanks for your input, hopefully it will reassure others.

InMotion Hosting apologizes, says it “understands” method used by TiGER-M@TE

InMotion, in an email to users, said Sunday that the homepage defacement attack launched by the southeast Asian hacker TiGER-M@TE was not meant to do permanent or catestrophic damage to the hundreds of thousands of websites that were hit.

“We understand the method the attacker used to accomplished this and the main exploit path was through an internal management server that can control Cpanel on other servers. The management server was used to change passwords on the Cpanel servers then login with those passwords,” said Todd Robinson, president of the hosting company.

The defacement attacked worked by replacing index files in all public_html directories with the attacker’s own branded index.php. InMotion does not believe that any data was stolen or that any passwords were compromised.

“It does not appear that gaining passwords was a goal or was accomplished, just password changes were used. Access to the management server was gained from an exploited customer’s server that was within our network,” Robinson said. “Though our team moved quickly to disable the internal management server and limit the exposure of the servers to this attack when it began, it
was a very serious breach and could have been much worse if the hacker had intended to do more harm.”

This does fit the modus operandi of TiGER-M@TE, who often claims to hack for fun or just to prove that “it can be done.”

Blast Magazine’s network of websites were defaced during the attack on InMotion, as was the offical City of Providence website.

InMotion took responsibility for failing to prevent the damage. Some estimates have the attack hitting more than 500,000 websites, making it historic in its proportions if not in its level of damage.

“Please accept our apologies as we go through this process,” Robinson said. “We are very aware of our failure in this situation and we will provide more details when we have completed the work of recovery.”

http://blastmagazine.com/the-magazine/technology/tech-news/computers/inmotion-hosting-apologizes-says-it-understands-method-used-by-tiger-mte/

Timeline -InMotion release 

At around 4am EST, our system administration team identified a website defacement attack affecting a large number of customers.  We are still investigating, but it appears that files named index.php have been defaced.

We are evaluating how this has occurred and our security team will have more information shortly.

While we review this issue, cPanel and SSH access has been disabled on various platforms.  For additional security, we are rotating passwods on a number of accounts.  We will honor requests for password resets as they are needed but are attempting to limit the inconvenience to our customers as we’re able.  FTP is still operational should you wish to access your files at this time and correct any issues you see yourself.  We will be working diligently to make cPanel access available again as soon as possible.

If there is a defacement on your account, please know that our Systems team is working to get your site back online.  If your index.php was modified, they will be restoring it from the most recent backup and no further action is necessary on your part.  At this time, we do not have a definitive timeframe for resolution, but we will update this page as we gather more information.

We do apologize for this issue, let us know as you have further questions, we’ll be glad to answer them as we’re able.  Please understand it will take our security team some time to review this issue before we can have a full explanation available.

11:45 AM EST Update

If you have a backup of your site, you may upload your index.php files to correct this. You may need to do this for each directory. If your site uses an index.html or index.htm, you will need to upload those files, then delete the index.php. You can find more help at How to restore a backup file.

It is possible our automated restore system will also be working on correcting the issue while you are. If you see this happen, just upload again.

If you do not have a backup of your site, it is best to wait until our automated system has completed its attempt at restoring. At this point, we feel that should solve a majority of the defaced sites.

We will be updating this page every hour, please check back here versus calling or chatting. Our team is currently working very hard and we are bringing in additional people, but the volume is greater than our Sunday staff is able to handle quickly at this time.

1 PM EST Update

Systems has been successful in restoring a portion of the affect sites. They are refining their repair method now and should be able to begin deploying the update to additional sites shortly. Please bear with us for another 1 hour when we feel we will have more information to share.

4:00pm EST Update
Our system’s team is still working on the automated repairing. We have restored over 65% of the affected sites at this time and are continuing to do so via an automated process and with our technical support team.

For people who are fixing their sites themselves, we have a few additional suggestions. First, be sure to check all directories, the hacker targeted all directories within the public_html.

If you are not sure how to do this, once our system’s team has completed their automated restores of home pages and general review of the changes we have made, they will be running an additional cleanup process that will look in directories for the hacked files. If the hacked files are found, they will be saved to hacked_page in the same directory.

Second, we have additional advice if you do not have a backup on your computer of your index.html and you are now seeing a directory listing instead of your site when you visit your URL. This means our automated restore system could not find a suitable file to restore to your account. Please go here, Site Backup Restore Options, for a few options to deal with this.

Most users should not see defacement on their site. If you do, it may be cached in your browser. Please refresh your browser by restarting it or by pushing CTRL-F5 (usually works, restart is best though). If you still see defacement, please do contact us via support@webhostinghub.com immediately for priority handling.

If you are seeing an empty directory, our system has not been able to locate your index files yet. If you have a backup of your index files, please upload them via ftp now (index.php, index.html, index.htm, etc.)

For those who do not have the files or who are unable to upload, our team is working on an automated solution now. Please see this link, Site Backup Restore Options, for a solution that may work for you.

Currently, Cpanel is disabled on all platforms as we evaluate the situation and apply patches to the security problems that allowed this to occur.  We should be able to enable access later today after running our final checks.   FTP access is still available though.

Best Regards,
The Web Hosting Hub Team

Share on TwitterShare on TumblrSubmit to StumbleUponSave on DeliciousDigg ThisSubmit to reddit