Showing posts with label Hacker. Show all posts
Showing posts with label Hacker. Show all posts

Saturday, March 10, 2012

Symantec's Norton anti-virus 2006 source code Leaked by Anonymous

Security firm Symantec confirmed Friday that the hacker group Anonymous has just posted some of its product source code, but strongly downplays any risk, because it's old code from a 2006 version of Norton security software.


Anonymous claimed to have the information for a while but they finally published it on The website Pirate Bay. The information is a source code for the Symantec Norton Antivirus 2006 edition,which includes files that serve as a source code for software products like the corporate edition, the consumer version, and files for NetWare, Windows and Unix. The download file is 1.07GB. The file has a note that asks for the liberation of the LulzSec members that were arrested.


Symantec the anti-virus and Security Company previously stated that the breach will “not affect any current Norton product”. Then added: “The current version of Norton Utilities has been completely rebuilt and shares no common code with Norton Utilities 2006. The code that has been posted for the 2006 version poses no security threat to users of the current version of Norton Utilities.”


It is believed that the Indian authorities wanted access to the source code to ensure that the product was secure, But the source code was left to stagnate on a poorly-secured network which was then accessed by the hackers.

This week Anonymous attacked the Vatican’s website, they tried to attack it last year but failed. The attack came after one of their partners from LulzSec was arrested.

Source: THN

Thursday, December 29, 2011

20 Indian Website Hacked by Team Cyber Turk Hacking

This summary is not available. Please click here to view the post.

Tuesday, November 15, 2011

Noakhaliweb.net got Hacked by Sil3nt_hUnt3r

 Noakhaliweb.net got Hacked!



And they also added a post in there and after their message they added National Anthem of Bangladesh in the post.

Source: Admin

Tuesday, November 8, 2011

Molly Katchpole’s Victory Over Bank of America

undefined

22-year-old Molly Katchpole and 300,000 other petition signer’s victory over Bank of America may be part of a much larger trend — a consumer backlash against corporate America. “Every company is now sitting on electronic quicksand,” PR guru Howard Rubenstein tells USA Today. Katchpole’s online petition was signed by 300,000 consumers, and was one reason why Bank of America dropped its decision to impose monthly fees on debit card users. Some see the instant backlash against Netflix and Bank of America as the Occupy Wall Street of the no longer silent majority.

Let your bank know your taking back control! #OpCashBack

Anonymous Hackers hack neo-Nazis website & leak personal info of 16,000 Finns


Anonymous Hackers have successfully hacked the neo-Nazi website and published the database of its 16000 membership application database containing personal datas of some applicants from all around the country. The hack was motivated by an apparent desire to shame the Finnish government into improving data security.

In a Statement Anonymous says "We have no tolerance for any group based on racial, sexual and religion discrimination as well as for all the people belonging to them and sharing their ideologies, which is the reason why we decided to carry out last Monday's attack.". Authorities are investigating the security breaches, according to an online message attributed to Anonymous Finland.


According to the Helsingin Sanomat, the published information seems stolen from several sources: the Work Efficiency Institute, Student Alliance Osku, WinNova Länsirannikon koulutus Ltd, and Aducate - Centre for Training and Development at the University of Eastern Finland.

Mikko Hypponen, chief research officer of the Finnish internet security firm F-Secure, dubbed the attack 'irresponsible'.Israel recently rubbished claims that Anonymous had caused the failure of several governmental websites, putting the outage down to a server failure.

Source: The Hacker News

Monday, October 24, 2011

Phishing Site Hacked to Warn About Phishing Sites

Sometimes hackers aren't as big and bad as they're made out to be. Sometimes they just want to help make the Web a safer place for everyone. That benevolent spirit is on display on a phishing site that was recently hacked to teach gullible Internet users about the dangers of — you guessed it — phishing sites.
A hacker modified a phishing website to teach people about phishing scams. Credit: Dreamstime
Researchers at the security firm GFI Labs found an email used to lure people to a phishing site, www.canal-i.com. The message attempts to scare unsuspecting readers by telling them they have exceeded the storage limit on their inbox, and says, "You will not be able to send or receive new mail until you upgrade your email. Click below link and fill the form to upgrade your account." When clicked, that link directs users to a Web page that asks for their username, email address and password.

For one hacker — he or she has not been identified — this was not just an ordinary phishing scam, but also a chance to teach others. The white-hat hacker — "white hat" refers to hackers who exploit security bugs to improve security —  stripped the phishing page of its malicious content and replaced it with a stern educational message about the perils lurking in the online world.

"There is no such thing as a central Email service update," the website was manipulated to read. "A stupid criminal created this to steal your email account. I have modified it to educate you about online crime. He does not like that but that is too damn bad. You can submit this form to see a helpful video about phishing. Stop letting stupid criminals like this one hijack your account. Have a great day."

The altered phishing page included a "Submit Form" button at the bottom, the same way the original fraudulent page did, except this button redirected users to an instructional video about phishing scams. (The canal-i website currently shows an "under construction" message.)

As a general rule, any unsolicited emails that ask you to download software to fix a problem or restore any kind of service should not be trusted. Emails that appear to come from a bank or financial institution such as the Federal Deposit Insurance Corporation (FDIC) should also be handled with a heavy dose of skepticism; online crooks know that people are likely to fall for scams when they fear their personal finances may be in trouble. If you suspect such an email is out for your personal details, delete it and contact your bank directly. Running up-to-date anti-virus and anti-malware software on your computer will also help detect phishing sites and malicious emails as threats.

Source: Internet

Thursday, September 29, 2011

700,000 websites hacked in a single shot by TIGER-M@TE


The largest hack ever made in a single shot !!!!

TiGER-M@TE had hacked 700,000 websites hosted on InMotion Hosting network in a single shot

Tiger-M@TE had given some of the domain i.e. about 2,00,00 to Zone-h (http://zone-h.com/archive/notifier=TiGER-M%40TE)
He claim "I hack 700000 websites in one shot, this may be a new world Record. After submitting 200,000 domains,zone-h was going down again and again and became almost unresponsive in the end.so i was unable to submit all websites.so i've listed all domains in attachment. It was not just a server hack, actually whole data center got hacked."

 At InMotion website they gave an announcement saying:
" Dear Customer,

At around 4am EST, our system administration team identified a website defacement attack affecting a large number of customers. We are still investigating, but it appears that files named index.php have been defaced.

We are evaluating how this has occurred and our security team will have more information shortly.

11:30am EST Update

If you have a backup of your site, you may upload your index.php files to correct this. You may need to do this for each directory. If your site uses an index.html or index.htm, you will need to upload those files, then delete the index.php. For more help, please see How to Restore a File from your own Backup.

It is possible our automated restore system will also be working on correcting the issue while you are. If you see this happen, just upload again.

If you do not have a backup of your site, it is best to wait until our automated system has completed its attempt at restoring. At this point, we feel that should solve a majority of the defaced sites.

1pm EST Update

Systems has been successful in restoring a portion of the affect sites. They are refining their repair method now and should be able to begin deploying the update to additional sites shortly. Please bear with us for another 1 hour when we feel we will have more information to share.

Best Regards,
The InMotion Hosting Team "

Source: Internet

DMCA.com

Tuesday, May 31, 2011

Shahrukh Khan's upcoming Movie - Ra One Official Website hacked

Shahrukh Khan's upcoming Movie - Ra One Official Website hacked
undefined

A hacker with name "Seeker" today hacked into the Cpanel of Shahrukh Khan's upcoming Movie - Ra One Official Website and Deface the main page of site as shown below...

undefined


For original View Go here!

Source: The Hacker News

Friday, May 6, 2011

A Message To Viacom from Anonymous

undefined

Greetings, World. We are Anonymous.
For years we have had to endure Viacom's attempts to strip away the basic rights of the individual. We have been silenced persistently, and consequently the free flow of information has been limited.


Thousands of people have undergone the unfortunate experience of receiving falsely-claimed copyright infringements. For far too long have we shared an enraged commonality in helplessly witnessing totalitarian-like actions taking place. The logging of millions of IP addresses and personal information extends beyond the domain of acceptability. When one's capitalistic agenda interferes with, exploits, and profits through infringing upon an individual's freedom, we, Anonymous, endorse the people's rights and hereby demand a refund.


After Viacom lost their lawsuit against YouTube, they continued to exploit YouTube for money. Viacom's justification of "creator's rights" seems only to mean making money for the sake of money. Their hypocritical action of uploading fake videos to YouTube in order to furnish their own court case is transparent:


"For years, Viacom continuously and secretly uploaded its content to YouTube, even while publicly complaining about its presence there. It hired no fewer than 18 different marketing agencies to upload its content to the site. It deliberately 'roughed up' the videos to make them look stolen or leaked." ( http://news.bbc.co.uk/2/hi/8575666.stm )


"Viacom's request for all YouTube's records of log-in names and email and IP addresses was granted by a US district court in a preliminary hearing..." ( http://www.digitalspy.co.uk/broadcasting/news/a107404/youtube-user-logs-to-be-released-to-viacom.html )


Anonymous demands from Viacom a public press release to admit and apologize for the fraud and crimes that they have commited. Anonymous also demands that Viacom allows everyone thoughout the internet full rights to be able to express themselves. Lastly, we, the citizens of the world, demand that Viacom stops their attempts to gather personally identifying information such as IP's, which are of no relevance to them.


We are Anonymous.
We are Legion.
We do not forgive.
We do not forget.
Expect us.


Thursday, May 5, 2011

Anonymous launches Operation Blitzkrieg


Neo-Nazis,

Your incomprehensible actions, and your reluctance to accept the Freedom and Equality that every single human being possesses by right from birth, causes the birth to hatred and worldwide Racism.

After the first World War, your ideology plunged the world into chaos. You took over a plague, known as anti-Semitism, and made sure that racism was drilled into our collective consciousness, in order for humanity to accept this crude ideas as given, mostly without ever questioning them.

Your misdirected politics and your hate filled crusade against humanity have not only blurred your perception, but also affected countries worldwide.You have robbed irretrievable evidences of history as well as valuable art objects and architectural structures which belong to mankind, or were part of the cultural heritage of humanity. You were anxious to cause trouble between continents, which involved a collapse of political dialogues. The result, the cold war, lasted for years and its voice still echoes today. The holocaust against the Jewish, the sinti and the roma, your so called "euthanasia" imposed on disabled people, all of them are considered the cruel climax of the Second World War, to a cost of 6.000.000 innocent people's lifes.You have combined the ideals of industrialization with the abomination of mass murder, a circumstance that led to destruction of human life, in a scale never seen before.
All this are known fact,s and yet you are still following and spreading such ideals, in order to enhance the symbolism of this despicable hate further. You are still causing injuries and killing people, people who have that done nothing against you, and yet you do it partly out of disgust or simply for your own personal pleasure.

You intimidate people that go on the streets protest for their ideals, and attack your political opponents, thus you deny them the right of free speech. Yet you hypocriticaly demand this exact same right of free speech for yourself, and throw the dirt in the form of agitations and "art arround you ". You attack journalists and the media in general, you attack members of the opposing parties and equally you attack refugees and immigrants, who live and work in your "home country". This people simply had to leave their native countries because of suppression and misery.

This behaviour can no longer be tolerated. You have convicted yourself to many crimes against humanity.With this hypocritical attitude and your drive to become a mirror of your inspirational criminals, you have brought the attention of the collective known as Anonymous upon yourself.

In this case, this attention implies the taken of crucial actions against your actions.

We are Anonymous.
We are Legion.
We do not Forgive.
We do not Forget.

Expect Us.


Source: AnonOps

Thursday, April 14, 2011

WordPress.com Servers Site Source Code Exposed

undefinedWordPress.com has revealed that someone has gained root-access (“low-level,” as in deep) to several of its servers this morning and that VIP customers’ source code was accessible. WordPress.com VIP customers are all on “code red” and in the process of changing all the passwords/API keys they’ve left in the source code.

“Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.
We have been diligently reviewing logs and records about the break-in to determine the extent of the information exposed, and re-securing avenues used to gain access. We presume our source code was exposed and copied. While much of our code is Open Source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited.”

While Automattic is downplaying the leak, sites’ source code could include API keys and Twitter and Facebook passwords which can let interested parties gain access to sensitive information as well as shut people out of their Twitter and other vulnerable accounts.

Automattic says that the investigation “is ongoing.” I’ve contacted founder Matt Mullenweg for more information and will update this post when I hear back.

WordPress.com currently serves 18 million publishers, including VIPs like us, TED, CBS and is responsible for 10% of all websites in the world. WordPress.com itself sees about 300 million unique visits monthly.


Tuesday, March 8, 2011

Latest Problem occuring to Facebook users

From the GMT+6 Zone, Some of the Bangladeshi users are getting problem when they are using Facebook from their Opera Mini Browser. To ensure that problem When I wrote an Status about it we found that not only in this zone, but also Users who are using from other countries, they are also having that same problem! It is Showing May be the HTML version of Facebook, Only the Facebook Logo is Colorful on their but others are Totally Looks like Simple HTML work. But it is badly true that now it is making Problem for the Users. Some of the users are in fear that "Are they hacked or not"? But the Main problem is what we don't know. Some are thinking Hacked, Some are thinking New Layout problem, Some are thinking about the New Integration problem. But we are still haven't Find the Proper Cause!  

We know that Facebook is now became most Browsed or Searched website of the world. But Facebook should inform about this knid of problem what ever is occuring as huge and big problem. And from some months we are watching that Facebook is not anymore being User Friendly! Thay are blocking News Websites, isn't taking proper action against Sex Scam & Scam Application, Limited Friend Request Sending Systems etc. Their new Messaging systems is also occuring problem to users. And users are upset about that to. They are now not in Social Networking market Place, but they are moving to do business. We think Facebook should think about their users who are using from all over the world. If they provide good service to their users, then users also will support as much as they can.

Source: BAG Desk

Thursday, February 17, 2011

Anonymous speaks: the inside story of the HBGary hack



It has been an embarrassing week for security firm HBGary and its HBGary Federal offshoot. HBGary Federal CEO Aaron Barr thought he had unmasked the hacker hordes of Anonymous and was preparing to name and shame those responsible for co-ordinating the group's actions, including the denial-of-service attacks that hit MasterCard, Visa, and other perceived enemies of WikiLeaks late last year.
When Barr told one of those he believed to be an Anonymous ringleader about his forthcoming exposé, the Anonymous response was swift and humiliating. HBGary's servers were broken into, its e-mails pillaged and published to the world, its data destroyed, and its website defaced. As an added bonus, a second site owned and operated by Greg Hoglund, owner of HBGary, was taken offline and the user registration database published.
Over the last week, I've talked to some of those who participated in the HBGary hack to learn in detail how they penetrated HBGary's defenses and gave the company such a stunning black eye—and what the HBGary example means for the rest of us mere mortals who use the Internet.
Anonymous: more than kids

HBGary and HBGary Federal position themselves as experts in computer security. The companies offer both software and services to both the public and private sectors. On the software side, HBGary has a range of computer forensics and malware analysis tools to enable the detection, isolation, and analysis of worms, viruses, and trojans. On the services side, it offers expertise in implementing intrusion detection systems and secure networking, and performs vulnerability assessment and penetration testing of systems and software. A variety of three letter agencies, including the NSA, appeared to be in regular contact with the HBGary companies, as did Interpol, and HBGary also worked with well-known security firm McAfee. At one time, even Apple expressed an interest in the company's products or services.
Greg Hoglund's rootkit.com is a respected resource for discussion and analysis of rootkits (software that tampers with operating systems at a low level to evade detection) and related technology; over the years, his site has been targeted by disgruntled hackers aggrieved that their wares have been discussed, dissected, and often disparaged as badly written bits of code.
One might think that such an esteemed organization would prove an insurmountable challenge for a bunch of disaffected kids to hack. World-renowned, government-recognized experts against Anonymous? HBGary should be able to take their efforts in stride.
Unfortunately for HBGary, neither the characterization of Anonymous nor the assumption of competence on the security company's part are accurate, as the story of how HBGary was hacked will make clear.
Anonymous is a diverse bunch: though they tend to be younger rather than older, their age group spans decades. Some may still be in school, but many others are gainfully employed office-workers, software developers, or IT support technicians, among other things. With that diversity in age and experience comes a diversity of expertise and ability.
It's true that most of the operations performed under the Anonymous branding have been relatively unsophisticated, albeit effective: the attacks made on MasterCard and others were distributed denial-of-service attacks using a modified version of the Low Orbit Ion Cannon (LOIC) load-testing tool. The modified LOIC enables the creation of large botnets that each user opts into: the software can be configured to take its instructions from connections to Internet relay chat (IRC) chat servers, allowing attack organizers to remotely control hundreds of slave machines and hence control large-scale attacks that can readily knock websites offline.
According to the leaked e-mails, Aaron Barr believed that HBGary's website was itself subject to a denial-of-service attack shortly after he exposed himself to someone he believed to be a top Anonymous leader. But the person I spoke to about this denied any involvement in such an attack. Which is not to say that the attack didn't happen—simply that this person didn't know about or participate in it. In any case, the Anonymous plans were more advanced than a brute force DDoS.
Time for an injection

HBGary Federal's website, hbgaryfederal.com, was powered by a content management system (CMS). CMSes are a common component of content-driven sites; they make it easy to add and update content to the site without having to mess about with HTML and making sure everything gets linked up and so on and so forth. Rather than using an off-the-shelf CMS (of which there are many, used in the many blogs and news sites that exist on the Web), HBGary—for reasons best known to its staff—decided to commission a custom CMS system from a third-party developer.
Unfortunately for HBGary, this third-party CMS was poorly written. In fact, it had what can only be described as a pretty gaping bug in it. A standard, off-the-shelf CMS would be no panacea in this regard—security flaws crop up in all of them from time to time—but it would have the advantage of many thousands of users and regular bugfixes, resulting in a much lesser chance of extant security flaws.
The custom solution on HBGary's site, alas, appeared to lack this kind of support. And if HBGary conducted any kind of vulnerability assessment of the software—which is, after all, one of the services the company offers—then its assessment overlooked a substantial flaw.
The hbgaryfederal.com CMS was susceptible to a kind of attack called SQL injection. In common with other CMSes, the hbgaryfederal.com CMS stores its data in an SQL database, retrieving data from that database with suitable queries. Some queries are fixed—an integral part of the CMS application itself. Others, however, need parameters. For example, a query to retrieve an article from the CMS will generally need a parameter corresponding to the article ID number. These parameters are, in turn, generally passed from the Web front-end to the CMS.
SQL injection is possible when the code that deals with these parameters is faulty. Many applications join the parameters from the Web front-end with hard-coded queries, then pass the whole concatenated lot to the database. Often, they do this without verifying the validity of those parameters. This exposes the systems to SQL injection. Attackers can pass in specially crafted parameters that cause the database to execute queries of the attackers' own choosing.
The exact URL used to break into hbgaryfederal.com washttp://www.hbgaryfederal.com/pages.php?pageNav=2&page=27. The URL has two parameters named pageNav and page, set to the values 2 and 27, respectively. One or other or both of these was handled incorrectly by the CMS, allowing the hackers to retrieve data from the database that they shouldn't have been able to get.


Specifically, the attackers grabbed the user database from the CMS—the list of usernames, e-mail addresses, and password hashes for the HBGary employees authorized to make changes to the CMS. In spite of the rudimentary SQL injection flaw, the designers of the CMS system were not completely oblivious to security best practices; the user database did not store plain readable passwords. It stored only hashed passwords—passwords that have been mathematically processed with a hash function to yield a number from which the original password can't be deciphered.
The key part is that you can't go backwards—you can't take the hash value and convert it back into a password. With a hash algorithm, traditionally the only way to figure out the original password was to try every single possible password in turn, and see which one matched the hash value you have. So, one would try "a," then "b," then "c"... then "z," then "aa," "ab," and so on and so forth.
To make this more difficult, hash algorithms are often quite slow (deliberately), and users are encouraged to use long passwords which mix lower case, upper case, numbers, and symbols, so that these brute force attacks have to try even more potential passwords until they find the right one. Given the number of passwords to try, and the slowness of hash algorithms, this normally takes a very long time. Password cracking software to perform this kind of brute force attack has long been available, but its success at cracking complex passwords is low.
However, a technique first published in 2003 (itself a refinement of a technique described in 1980) gave password crackers an alternative approach. By pre-computing large sets of data and generating what are known as rainbow tables, the attackers can make a trade-off: they get much faster password cracks in return for using much more space. The rainbow table lets the password cracker pre-compute and store a large number of hash values and the passwords that generated them. An attacker can then look up the hash value that they are interested in and see if it's in the table. If it is, they can then read out the password.
To make cracking harder, good password hash implementations will use a couple of additional techniques. The first is iterative hashing: simply put, the output of the hash function is itself hashed with the hash function, and this process is repeated thousands of times. This makes the hashing process considerably slower, hindering both brute-force attacks and rainbow table generation.
The second technique is salting; a small amount of random data is added to the password before hashing it, greatly expanding the size of rainbow table that would be required to get the password.
In principle, any hash function can be used to generate rainbow tables. However, it takes more time to generate rainbow tables for slow hash functions than it does for fast ones, and hash functions that produce a short hash value require less storage than ones that produce long hash values. So in practice, only a few hash algorithms have widely available rainbow table software available. The best known and most widely supported of these is probably MD5, which is quick to compute and produces an output that is only 128 bits (16 bytes) per hash. These factors together make it particularly vulnerable to rainbow table attacks. A number of software projects exist that allow the generation or downloading of MD5 rainbow tables, and their subsequent use to crack passwords.
As luck would have it, the hbgaryfederal.com CMS used MD5. What's worse is that it used MD5 badly: there was no iterative hashing and no salting. The result was that the downloaded passwords were highly susceptible to rainbow table-based attacks, performed using a rainbow table-based password cracking website. And so this is precisely what the attackers did; they used a rainbow table cracking tool to crack the hbgaryfederal.com CMS passwords.
Even with the flawed usage of MD5, HBGary could have been safe thanks to a key limitation of rainbow tables: each table only spans a given "pattern" for the password. So for example, some tables may support "passwords of 1-8 characters made of a mix of lower case and numbers," while other can handle only "passwords of 1-12 characters using upper case only."
A password that uses the full range of the standard 95 typeable characters (upper and lower case letters, numbers, and the standard symbols found on a keyboard) and which is unusually long (say, 14 or more characters) is unlikely to be found in a rainbow table, because the rainbow table required for such passwords will be too big and take too long to generate.
Alas, two HBGary Federal employees—CEO Aaron Barr and COO Ted Vera—used passwords that were very simple; each was just six lower case letters and two numbers. Such simple combinations are likely to be found in any respectable rainbow table, and so it was that their passwords were trivially compromised.

For a security company to use a CMS that was so flawed is remarkable. Improper handling of passwords—iterative hashing, using salts and slow algorithms—and lack of protection against SQL injection attacks are basic errors. Their system did not fall prey to some subtle, complex issue: it was broken into with basic, well-known techniques. And though not all the passwords were retrieved through the rainbow tables, two were, because they were so poorly chosen.
HBGary owner Penny Leavy said in a later IRC chat with Anonymous that the company responsible for implementing the CMS has since been fired.
Password problems

Still, badly chosen passwords aren't such a big deal, are they? They might have allowed someone to deface the hbgaryfederal.com website—admittedly embarrassing—but since everybody knows that you shouldn't reuse passwords across different systems, that should have been the extent of the damage, surely?
Unfortunately for HBGary Federal, it was not. Neither Aaron nor Ted followed best practices. Instead, they used the same password in a whole bunch of different places, including e-mail, Twitter accounts, and LinkedIn. For both men, the passwords allowed retrieval of e-mail. However, that was not all they revealed. Let's start with Ted's password first.
Along with its webserver, HBGary had a Linux machine, support.hbgary.com, on which many HBGary employees had shell accounts with ssh access, each with a password used to authenticate the user. One of these employees was Ted Vera, and his ssh password was identical to the cracked password he used in the CMS. This gave the hackers immediate access to the support machine.
ssh doesn't have to use passwords for authentication. Passwords are certainly common, but they're also susceptible to this kind of problem (among others). To combat this, many organizations and users, particularly those with security concerns, do not use passwords for ssh authentication. Instead, they use public key cryptography: each user has a key made up of a private part and a public part. The public part is associated with their account, and the private part is kept, well, private. ssh then uses these two keys to authenticate the user.
Since these private keys are not as easily compromised as passwords—servers don't store them, and in fact they never leave the client machine—and aren't readily re-used (one set of keys might be used to authenticate with several servers, but they can't be used to log in to a website, say), they are a much more secure option. Had they been used for HBGary's server, it would have been safe. But they weren't, so it wasn't.
Although attackers could log on to this machine, the ability to look around and break stuff was curtailed: Ted was only a regular non-superuser. Being restricted to a user account can be enormously confining on a Linux machine. It spoils all your fun; you can't read other users' data, you can't delete files you don't own, you can't cover up the evidence of your own break-in. It's a total downer for hackers.
The only way they can have some fun is to elevate privileges through exploiting a privilege escalation vulnerability. These crop up from time to time and generally exploit flaws in the operating system kernel or its system libraries to trick it into giving the user more access to the system than should be allowed. By a stroke of luck, the HBGary system was vulnerable to just such a flaw. The error was published in October last year, conveniently with a full, working exploit. By November, most distributions had patches available, and there was no good reason to be running the exploitable code in February 2011.
Exploitation of this flaw gave the Anonymous attackers full access to HBGary's system. It was then that they discovered many gigabytes of backups and research data, which they duly purged from the system.
Aaron's password yielded even more fruit. HBGary used Google Apps for its e-mail services, and for both Aaron and Ted, the password cracking provided access to their mail. But Aaron was no mere user of Google Apps: his account was also the administrator of the company's mail. With his higher access, he could reset the passwords of any mailbox and hence gain access to all the company's mail—not just his own. It's this capability that yielded access to Greg Hoglund's mail.
And what was done with Greg's mail?
A little bit of social engineering, that's what.
A little help from my friends

Contained within Greg's mail were two bits of useful information. One: the root password to the machine running Greg's rootkit.com site was either "88j4bb3rw0cky88" or "88Scr3am3r88". Two: Jussi Jaakonaho, "Chief Security Specialist" at Nokia, had root access. Vandalizing the website stored on the machine was now within reach.
The attackers just needed a little bit more information: they needed a regular, non-root user account to log in with, because as a standard security procedure, direct ssh access with the root account is disabled. Armed with the two pieces of knowledge above, and with Greg's e-mail account in their control, the social engineers set about their task. The e-mail correspondence tells the whole story:

From: Greg
To: Jussi
eed to ssh into rootkit
im in eur
Subject:
nope and need to ssh into the server. can you drop open up
firewall and allow ssh through port 59022 or something vague?
and is our root password still 88j4bb3rw0cky88 or did we change to
88Scr3am3r88 ?
thanks
-------------------------------------
From: Jussi
To: Greg
Re: need to ssh into rootkit
hi, do y
Subject:
ou have public ip? or should i just drop fw?
lowed
and it is w0cky - tho no remote root access a
l
-------------------------------------
From: Greg
To: Jussi
e: need to ssh into rootkit
no i dont
Subject:
R have the public ip with me at the moment because im ready
for a small meeting and im in a rush.
changeme123 and give me public
ip and ill ssh in and reset my pw.
if anything just reset my password to
-------------------------------------
From: Jussi
To: Greg
Re: need to ssh into rootkit
ok,
it s
Subject:
hould now accept from anywhere to 47152 as ssh. i am doing
testing so that it works for sure.
online so just shoot me if y
your password is changeme123
i am
ou need something.

nd? :-)

in europe, but not in finl
-------------------------------------
From: Greg
To: Jussi
e: need to ssh into rootkit
if i can
Subject:
Rsqueeze out time maybe we can catch up.. ill be in germany
for a little bit.
into rootkit. you sure the ips still
65.74.181.141?

th
anyway I can't ssh
anks
-------------------------------------
From: Jussi
To: Greg
Re: need to ssh into rootkit
does it
Subject:
work now?
-------------------------------------
From: Greg
To: Jussi
e: need to ssh into rootkit
yes jussi
Subject:
R thanks

set the user greg or?
did you r
e
-------------------------------------
From: Jussi
To: Greg
Re: need to ssh into rootkit
nope. yo
Subject:
ur account is named as hoglund
-------------------------------------
From: Greg
To: Jussi
e: need to ssh into rootkit
yup im lo
Subject:
Rgged in thanks ill email you in a few, im backed up
hanks
t
Thanks indeed. To be fair to Jussi, the fake Greg appeared to know the root password and, well, the e-mails were coming from Greg's own e-mail address. But over the course of a few e-mails it was clear that "Greg" had forgotten both his username and his password. And Jussi handed them to him on a platter.
Later on, Jussi did appear to notice something was up:
From: Jussi
To: Greg
Re: need to ssh into rootkit
did you
Subject:
open something running on high port?
As with the HBGary machine, this could have been avoided if keys had been used instead of passwords. But they weren't. Rootkit.com was now compromised.

Standard practice

Once the username and password were known, defacing the site was easy. Log in as Greg, switch to root, and deface away! The attackers went one better than this, however: they dumped the user database for rootkit.com, listing the e-mail addresses and password hashes for everyone who'd ever registered on the site. And, as with the hbgaryfederal.com CMS system, the passwords were hashed with a single naive use of MD5, meaning that once again they were susceptible to rainbow table-based password cracking. So the crackable passwords were cracked, too.
So what do we have in total? A Web application with SQL injection flaws and insecure passwords. Passwords that were badly chosen. Passwords that were reused. Servers that allowed password-based authentication. Systems that weren't patched. And an astonishing willingness to hand out credentials over e-mail, even when the person being asked for them should have realized something was up.
The thing is, none of this is unusual. Quite the opposite. The Anonymous hack was not exceptional: the hackers used standard, widely known techniques to break into systems, find as much information as possible, and use that information to compromise further systems. They didn't have to, for example, use any non-public vulnerabilities or perform any carefully targeted social engineering. And because of their desire to cause significant public disruption, they did not have to go to any great lengths to hide their activity.
Nonetheless, their attack was highly effective, and it was well-executed. The desire was to cause trouble for HBGary, and that they did. Especially in the social engineering attack against Jussi, they used the right information in the right way to seem credible.
Most frustrating for HBGary must be the knowledge that they know what they did wrong, and they were perfectly aware of best practices; they just didn't actually use them. Everybody knows you don't use easy-to-crack passwords, but some employees did. Everybody knows you don't re-use passwords, but some of them did. Everybody knows that you should patch servers to keep them free of known security flaws, but they didn't.
And HBGary isn't alone. Analysis of the passwords leaked from rootkit.com and Gawker shows that password re-use is extremely widespread, with something like 30 percent of users re-using their passwords. HBGary won't be the last site to suffer from SQL injection, either, and people will continue to use password authentication for secure systems because it's so much more convenient than key-based authentication.
So there are clearly two lessons to be learned here. The first is that the standard advice is good advice. If all best practices had been followed then none of this would have happened. Even if the SQL injection error was still present, it wouldn't have caused the cascade of failures that followed.
The second lesson, however, is that the standard advice isn't good enough. Even recognized security experts who should know better won't follow it. What hope does that leave for the rest of us?
Source: Ars Technica