Slashdot Mirror


ImageShack Hacked, Security Groups Threatened

revjtanton writes "Last night a group calling themselves 'Anti-Sec' hacked ImageShack, one of the largest image hosting sites on the web, and replaced many of the site's hosted pictures with one of their own, which detailed their manifesto. The group's grievance is against full-disclosure of exploits, an issue that was debated recently after a presentation on an ATM exploit was canceled. Anti-Sec simply wants the practice within security circles to end, and they've promised to cause 'mayhem and destruction' if it doesn't. These people are taking direct aim against a sector of the IT industry that is already armed to fight the ... but they also already know that. It should be interesting to see how this plays out."

51 of 288 comments (clear)

  1. Their message is certainly ironic, by Anonymous Coward · · Score: 3, Insightful

    in a "shoot the innocent bystander while sounding all righteous about risk" sort of way.

  2. Is this considered full-disclosure ... by neilobremski · · Score: 3, Funny

    ... of their movement?

    --
    -- NeilO
    1. Re:Is this considered full-disclosure ... by ILuvRamen · · Score: 2, Funny

      well not exactly but wouldn't it be funny is someone did publish the exploit they used to hack imageshack? :-P

      --
      Google's Super Secret Search Algorithm: SELECT @search_results FROM internet WHERE @search_results = 'good'
  3. related to openssh rumors? by Anonymous Coward · · Score: 2, Interesting

    These are the same people who say they've found an exploit in some versions of openssh. Any connection?

    http://seclists.org/fulldisclosure/2009/Jul/0028.html

    http://news.ycombinator.com/item?id=692036

    http://lwn.net/Articles/340483/

  4. Astalavista by Spyware23 · · Score: 5, Informative

    For interested readers; these were the same people who killed astalavista. (Logs of that attack can be found all over the internet if you google).

    1. Re:Astalavista by Threni · · Score: 3, Interesting

      Hardly, given that they're anti-disclosure.

    2. Re:Astalavista by tomhudson · · Score: 4, Insightful

      Hardly, given that they're anti-disclosure.

      ... but they ARE in favour of people p0wning sites - which requires disclosure of vulnerabilities - something they're against. Kind of contradictory ...

      They're just a bunch of assholes, same as the punks who key cars.

    3. Re:Astalavista by tomhudson · · Score: 3, Insightful

      No, one of the reasons they cite for their anti-full disclosure sentiments is that it allows hordes of script kiddies to "p0wn" sites.

      ... in other words, they (Anti-Sec) don't want competition that will ruin the economic value of the 'sploit prematurely.

      Just follow the money ...

    4. Re:Astalavista by Monkey+Angst · · Score: 2

      ... but they ARE in favour of people p0wning sites - which requires disclosure of vulnerabilities - something they're against. Kind of contradictory ...

      Well, not if you look at it this way: They're not against finding and exploiting vulnerabilities. They're against sharing those vulnerabilities so that others can exploit them. Think of it like an anti-nuke treaty. The US has nukes and will not give them up, but we're dead against letting anyone else have them.

      They're just a bunch of assholes, same as the punks who key cars.

      Oh yeah, this too.

      --
      stripShow - Where WordPress meets webcomics
  5. Leave door open or we will rob you ? by abies · · Score: 4, Insightful

    From what I can understand from their manifest, they don't want full disclosure of exploits so
    1) Other script kiddies cannot use them too easily
    2) General public is not aware of the risks
    3) Security companies cannot prepare protection against them

    This is like... let's thing about proper, slashdot analogy... bunch of car thieves telling that they are against installing immobilizers in cars and warning they will steal cars of immobilizer producers and supporters till they stop distributing immobilizers. When they stop, thieves will come back to stealing random cars, with less effort.

    1. Re:Leave door open or we will rob you ? by binkzz · · Score: 4, Informative

      1) I think that's a good thing
      2) They don't want the world to not know about the exploits, they just don't want the world to know how to use those exploits
      3) These exploits would still be in the hands of the security companies so that they could prepare protection against them

      I'm not sure how you came to your conclusions, I don't believe they are correct.

      --
      'For we walk by faith, not by sight.' II Corinthians 5:7
    2. Re:Leave door open or we will rob you ? by Svartalf · · Score: 2, Funny

      Good analogy- so it's not in keeping with the "proper, slashdot analogy" thinking.

      You have to do a **BAD** car analogy for it to be that.

      --
      I am not merely a "consumer" or a "taxpayer". I am a Citizen of the State of Texas
    3. Re:Leave door open or we will rob you ? by whoever57 · · Score: 4, Insightful

      3) These exploits would still be in the hands of the security companies so that they could prepare protection against them

      Except that history has shown that many software companies won't actually fix problems until forced to do so by full disclosure.

      --
      The real "Libtards" are the Libertarians!
    4. Re:Leave door open or we will rob you ? by Tycho · · Score: 2, Informative

      OT: your sig "I am not merely a "consumer" or a "taxpayer". I am a Citizen of the State of Texas"

      I assume you aren't going to try to deny that you are also a citizen of the United States of America at this point. Other people, now in jail, have tried not to pay income taxes and other federal taxes by claiming that they had renounced their US citizenship and were now just a citizen of the State of X, but not a US citizen any longer. None of these individuals actually successfully argued in court that they were just a citizen of State X and not a US citizen, so they no longer had to pay income tax. Most idiots in this position would have found their lawyer unwilling to make that argument, or if acting as their own lawyer these idiots might have found themselves stopped as soon as they started and fined $5000 each time during trial for even trying. When one makes a frivolous argument that is not valid and that relates to income taxes in court, expect a bill. Obviously the lesson to take back in this argument and with others is to not parse words intentionally incorrectly, and that you will not find any valid loophole to avoid paying any income taxes. Just to suck it up and pay your income taxes like everyone else. If you are behind on filing a year or two, contact a tax lawyer and then negotiate with the IRS and do so before the IRS calls you, you will always end up better off that way.

      --
      Impersonating Tycho from Penny Arcade since before there was a PA.
    5. Re:Leave door open or we will rob you ? by Vellmont · · Score: 4, Insightful


      2) They don't want the world to not know about the exploits, they just don't want the world to know how to use those exploits

      There's at least a couple large-scale problems with this viewpoint.

      The most direct one is that knowing about the exploit, and knowing how to use the exploit aren't really as different as you try to make them out. How long do you think for "bad guys" to figure out the full picture if you released enough information for people to protect themselves? i.e. "disable function X of server product Y". Well shit, you just gave a HUGE clue to the "bad guys", but probably didn't really give ENOUGH information to enough of the "good guys". What about the guys relying on "function x of server y" who simply can't disable it?

      Exploits are often esoteric sounding enough that companies can just claim (and often have) "that vulnerability is entirely theoretical". It's often the case that the exploit is VERY exploitable, but the developers or companies are just being arrogant, don't understand, or don't care. In a perfect world where companies and developers had perfect knowledge of exactly how exploitable and dangerous a vulnerability was (and addressed the ones that needed to be addressed) your idea would work. The real world has proven otherwise.

      The third problem is simply that the companies/developers responsible for fixing the problem often don't suffer the costs (or a much lower cost) or people actually exploiting the vulnerability. i.e. Microsoft doesn't suffer enormous losses when the latest worm ravages the internet. Since they suffer a lot less pain, they'll devote a lot less resources to fixing it. If the exploit eventually will get out then company X will be a lot more likely to fix it rather than just ignoring it and hoping nobody else ever finds out.


      3) These exploits would still be in the hands of the security companies so that they could prepare protection against them

      Heh. Where does this view that there's always the mysterious people who are just going to fix everything come from? If you think "Security Companies" are going to save you, blah blah blah Bridge to sell.. blah blah blah swamp land in Florida.

      No, what needs to happen is if security is important it needs to be built into the product to begin with. Security isn't a product you "buy", it's something you are. This is nothing different than what people have been saying for 20 years.

      --
      AccountKiller
    6. Re:Leave door open or we will rob you ? by Ifni · · Score: 2, Insightful

      Because you are the only one (or member of a minority group) that apparently lacks the predominant knowledge of the statement's truth. If I state a fact that is common knowledge, I do not need to cite it. If you dispute that fact, it is your job to find corroborating evidence in defense of your stance, not mine.

      --

      Oh, was that my outside voice?

    7. Re:Leave door open or we will rob you ? by shish · · Score: 2, Insightful

      Both Gandhi and Martin Luther King, Jr. constantly broke the law with their peaceful protests.

      Peaceful protests may break the law, but they don't break many people's morals; destroying servers (if you read their site, you'll see a history of "rm -rf /"'s), even with the best of intentions, is much less morally sound.

      --
      I mod down anyone who says "I will be modded down for this", regardless of the rest of their comment
  6. Re:Wow by Kell+Bengal · · Score: 4, Insightful

    Wait, wait. How is messing with other people's stuff on the net from safely behind a computer 'gutsy'? Sounds like cowardice to me. I don't care what their message - if they're fucking with my, or other people's, stuff then whatever their argument is will go unheard. If their message is clear, concise and not disagreeable, why can't they convince us with a logical argument?

    --
    Scientists point out problems, engineers fix them
    altslashdot.org: The future of slashdot.
  7. HaCk ThE PlanET!!! by carn1fex · · Score: 4, Funny

    These punks dont know who theyre messin with!! Me and my posse are put on our roller blades, spike our hair and take them out with our camouflage thirty three point six bee pee ess moh demz.

    --

    ---------

    No matter how thin you slice it, its still baloney.

  8. wow what an awesome idea! by trybywrench · · Score: 4, Interesting

    What an effective way to distribute a message, hack one of the worlds most popular image hosting sites and replace all the images with your manifesto! Every site with an image linked back to imageshack would be displaying your message. Instant.global.audience. I'm not justifying what they did and I'm all for the feds handing out a beat down, afterall, the law is the law but man, what a good idea.

    --
    I came to the datacenter drunk with a fake ID, don't you want to be just like me?
    1. Re:wow what an awesome idea! by Pyrion · · Score: 4, Informative

      Except they haven't replaced all of the images. I just looked in my account and only one of my images (a horribly outdated tf2 screenshot, of all things) was replaced.

      --
      "There is much pleasure to be gained from useless knowledge." - Bertrand Russell.
  9. Re:Wow by jombeewoof · · Score: 3, Insightful

    ...If their message is clear, concise and not disagreeable, why can't they convince us with a logical argument?

    Because logic doesn't always work. Logic in the hands of those who count the beans is usually twisted into some diseased, desecrated version of it's former elf.

    --
    Linux Zealots: Smarter than Mac Zealots, but still zealots.
  10. Re:Wow by Anonymous Coward · · Score: 5, Funny

    ...If their message is clear, concise and not disagreeable, why can't they convince us with a logical argument?

    Because logic doesn't always work. Logic in the hands of those who count the beans is usually twisted into some diseased, desecrated version of it's former elf.

    And trust me, the dwarves are not happy about that.

  11. Best pro full-disclosure advert ever by AmiMoJo · · Score: 3, Insightful

    This hack demonstrates exactly why we need full disclosure. If I used ImageShack to host important images for (e.g. a lot of people use it for blog images or forums) and someone figured out a way to hack in, I'd want to know about it so I can take steps to protect myself. What if someone uploaded child porn and it appeared on my forum?

    It's always better to know than to stay ignorant. It might harm the companies behind affected products, but if it was a safety issue (e.g. your car can occasionally explode while filling it with petrol, which actually happened) there would be no question that full disclosure would be a good thing.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  12. Easy to identify ? by sugarmotor · · Score: 2, Insightful

    Their language and style sounds rather distinct. If other writings of them are available on the web, they should be easy to identify.
    There's also quite a lot of text.

    Stephan

    --
    http://stephan.sugarmotor.org
  13. Re:Help for the unfamiliar by klui · · Score: 5, Interesting

    It doesn't show the details but their website gives a summary. http://romeo.copyandpaste.info/txt/imageshack-pwned.txt How accurate, who knows.

  14. Re:Wow by sqlrob · · Score: 5, Insightful

    If it's free speech, mind if I come and write graffiti on the side of your house? If you stop me, you're censoring my speech.

  15. So rash by UnixUnix · · Score: 2, Funny

    They didn't even bother to Ask Slashdot :(

  16. Re:I was a victim... by Niris · · Score: 3, Funny

    Thankfully you're a /. user, so the goatse.cx picture was probably better.

  17. I'm not sure I get it by sjames · · Score: 3, Insightful

    In order to put an end to security consultants and companies spreading fear of being hacked in order to sell security oriented products and services, they will go on a reign of terror hacking everything that isn't secured to the nines? Uhmmmmmm. I'm not sure how that works.

    1. Re:I'm not sure I get it by maxume · · Score: 4, Insightful

      It probably makes more sense if you are 15.

      --
      Nerd rage is the funniest rage.
    2. Re:I'm not sure I get it by Bigjeff5 · · Score: 3, Insightful

      You may need to go younger, ever seen a toddler when mommy or daddy tells them "no"? They tend to pitch a fit, and try to break stuff.

      These guys may be smart as hell, but they are little more than toddlers who can hack. They are definitely NOT worth paying attention to beyond what is necessary to track them down and put them in jail.

      BTW, do you know what happens to guys like these when they get caught? After jail time, they are generally banned from computers. I.e. more jail time if they are caught using one. That's got to be a virtual death sentance for a hacker.

      I'm not sure these guys thought this thing through, they are definitely public enough to be traceable. I hope they don't like where they live very much!

      --
      Security is mostly a superstition... Avoiding danger is no safer in the long run than outright exposure. - Helen Keller
  18. Re:Wow by NickFortune · · Score: 4, Insightful

    Why stop at the outside? Break into the place and scrawl all over his wallpaper. That's effectively what anti-sec did here.

    --
    Don't let THEM immanentize the Eschaton!
  19. I'm hoping.. by slashkitty · · Score: 2, Insightful
    that this is just some sort of reverse logic... because now, anyone wanting to hide details of sec exploits are thrown into the group of these "nasty hackers"..

    I mean, it's mostly only big corps that are for "non-disclosure".. the rest of the free world wants to know!

    --
    -- these are only opinions and they might not be mine.
  20. Some observations by rs79 · · Score: 2, Informative

    1) The text was syntactically and grammatically near perfect. You don't often see that in these sorts of things.

    2) The cadence and style was sort of familiar. I was always able on usenet to identify forgeries not by the path, but by the way they were written. Any idiot can put words where they're not supposed to be, but very few people can wrote like somebody else.

    3) I posit that if they weren't good intentioned they'd have hacked DHS.

    It would not surprise me if this turned out to be a bunch of CS/security professors or the like, or their minions doing their work.

    From the message, I'm absolutey certain they're in America, and had either a very rigorous or British schooling.

    --
    Need Mercedes parts ?
    1. Re:Some observations by maxume · · Score: 2, Funny

      I no get rigorous or Brit schooling and I are good grammer.

      What I mean is, that is quite a statement to make, there are plenty of people who learned to write by reading, not in school.

      --
      Nerd rage is the funniest rage.
    2. Re:Some observations by TheRaven64 · · Score: 2, Informative

      You have an odd definition of perfect grammar. Their writing style isn't bad, but they had run-on sentences and incorrect hyphenation in a few places early on and then deteriorates completely towards the end into something barely coherent.

      --
      I am TheRaven on Soylent News
  21. Re:so, they'd rather? by MaskedSlacker · · Score: 2, Insightful

    Not only is the exact opposite of the OSS mindset, I'd be willing to be that it is motivated by exactly what you describe. These are not people concerned about security, these are people who want exploits kept secret so they can sell them and use them--the morons posting here in support of this don't get it. These people are not your friends.

    There are a number of well-documented cases of vendors being notified well in advance of publication, and those vendors doing nothing until after publication (in some cases the publication was only made because the vendor refused to do anything). Full disclosure forces lazy, cost-cutting corporations to improve their products when they would otherwise have no motivation to do so. The only people who benefit from non-disclosure are black hat criminals.

  22. Re:Making the world a better place. by billcopc · · Score: 5, Insightful

    They want to discourage full disclosure, because it means they won't get to abuse undisclosed vulnerabilities as freely as they currently do.

    Let me put it to you in more immediate terms: If the BH presentation on ATM exploits goes through, it will trigger a much more rapid response to patch the problem, which means the true exploiters have less time to plunder. Now this is just one example... There are hundreds of high-risk exploits discovered every day, some of which were obviously used to hack into ImageShack. These kiddies are scared that full disclosure will take away their "toys".

    --
    -Billco, Fnarg.com
  23. Re:Wow by GeorgeS · · Score: 3, Funny

    They did a LOT more than that!
    They came inside the house. Sat down at the TV and ordered PPV and drank all the beer!

    Bastards!

    --
    "I'd rather have a bottle in front of me than have to have a frontal lobotomy."
  24. Re:Judging by the thought process behind this by smoker2 · · Score: 2, Funny

    Are we talking about /. now ?
    Oh sorry that's mental age.

  25. Re:Making the world a better place. by aristotle-dude · · Score: 2, Informative

    They want to discourage full disclosure, because it means they won't get to abuse undisclosed vulnerabilities as freely as they currently do.

    Let me put it to you in more immediate terms: If the BH presentation on ATM exploits goes through, it will trigger a much more rapid response to patch the problem, which means the true exploiters have less time to plunder. Now this is just one example... There are hundreds of high-risk exploits discovered every day, some of which were obviously used to hack into ImageShack. These kiddies are scared that full disclosure will take away their "toys".

    Wow. I don't think you understand what full disclosure is and what they are allegedly advocating. It seems like they are not advocating to not disclose the vulnerability to the vendor but rather to not disclose not only the existence of vulnerability but also an example exploit to the world. This full disclosure is precisely what results in "script kiddies" getting their toys because they don't have to be part of any particular hacking group or hack significant "skillz". It creates a mad rush for the vendor to get the patch out there before it can be exploited by lamerz using a script they either downloaded off a website or a script that they copied from the the disclosure with some minor changes.

    Providing the public with a warning that a vulnerability exists is not unethical and neither is providing information to the vendor but providing full exploit information is not only unethical but completely useless to the end user and places them at additional risk.

    --
    Jesus was a compassionate social conservative who called individuals to sin no more.
  26. Re:Wow by Nautical+Insanity · · Score: 2, Insightful

    True, they're exercising free speech in the text of their manifesto. They have their right to that. However, while you're entitled to say what you want, how you say it is quite naturally under some limitations. For example, you are free to say that you like flowers. But if you said that by lighting houses on fire so that from the air, the flames could be read, then you'd get arrested for massive arson. Hacking into the site is clearly illegal and this group should get busted for that.

  27. Example of a virus from Image Shack. by afxgrin · · Score: 2, Informative

    A friend of mine had her machine infected with one of the imageshack exploits. It was basically a double extension EXE, labelled like Aphoto.jpg__________________.exe

    She wasn't paying much attention and had hit OK when prompted to run the program. So her computer had started sending me MSN links to similar images hosted on ImageShack.

    Here's the EXE that I got sent.

    Someone I was chatting with in a technology IRC chatroom had run the virus in a VM, and it apparently has code to detect the presence of a VM, rapes your registry, spreads itself to multiple EXEs across your system, and a bunch of other weird things. The code is apparently run through one of those code masher programs to prevent decompilers.

  28. Re:Making the world a better place. by Thiez · · Score: 4, Insightful

    I think full disclosure is a good motivation for companies to fix their stuff. Notify them you found a problem, what the problem is, and that you will make the exploit public after a certain (reasonable) period of time, whether they fix it or not.

  29. My best guess is... by bXTr · · Score: 3, Funny
    • This is a legitimate threat, and they're truly against full disclosure.
    • Or they're using reverse psychology and are for full disclosure.
    • Unless they're using reverse-reverse psychology and are really against full disclosure.
    • But maybe they're using reverse-reverse-reverse psychology and are really for full disclosure.
    • ...
    • Or they're just a bunch of script kiddies trying demonstrating their "l33t 5k1lz".
    --
    It's a very dark ride.
  30. Re:Making the world a better place. by UncleTogie · · Score: 3, Insightful

    I think l0pht's home page back in the day had it right when they quoted Microsoft as saying:

    "That vulnerability is theoretical." -Microsoft

    ...which is one of my arguments for releasing POC code. Some folks need to be hit with a bigger clue-stick than others.

    --
    Don't tell me to get a life. I'm a gamer; I have LOTS of lives!
  31. Re:What is their motivation? by fictionpuss · · Score: 2, Interesting

    If you discover another zero-day root exploit in the Linux kernel on your own, and you have the means to sell it to the highest bidder for a nice pile of cash, then neither you nor the winner have a motivation to pass on that secret to the underground.

    If there are fewer active vulnerabilities floating in the underground - accounting for accidental or the occasional intentional leak - then how is that more chaotic than what we have now?

    I'm curious - I'm not an expert in this stuff by any means.

    Oh wait, this reminds me a little of the Linux-development policy change with regards no longer enumerating the fixes and vulnerabilities which comprise each release version -- do you similarly believe that policy will lead to more chaos?

  32. Re:Making the world a better place. by Jah-Wren+Ryel · · Score: 5, Insightful

    Wow. I don't think you understand what full disclosure is and what they are allegedly advocating.

    Nope. He has it right, you have it 100% wrong. The ATM issue is a perfect example. That vulnerability was disclosed to the vendor eight months ago and they haven't done jack shit. Now the threat of full disclosure - to the entire world - has caused the vendor to get an injunction to prevent disclosure. Where is the fix? I still don't see a fix. Under your theory of "full disclosure is just another word for limited disclosure" the vendor would have fixed the problem long ago.

    It rarely ever works like that and we have 30+ years of history to prove it - the security industry used to work the way you wish and the results were the same, vendors didn't do shit. The only time a fix comes is when the vendor knows that the only way to stop the script kiddies and all the serious blackhats is to actually fix the problem instead of sitting on it. Without at least the threat of true full disclosure vendors won't fix their problems, they don't have enough of an economic incentive to do so.

    Providing the public with a warning that a vulnerability exists is not unethical and neither is providing information to the vendor but providing full exploit information is not only unethical but completely useless to the end user and places them at additional risk.

    Without the threat of true full disclosure, nothing ever comes of limited disclosure.

    --
    When information is power, privacy is freedom.
  33. Re:What is their motivation? by Bert64 · · Score: 2, Interesting

    What would happen, is that the prevalence of unskilled script kiddies would massively decrease, and the background scans taking place constantly would decrease... Because the perceived threats would have abated, people wouldn't bother installing updates or taking any measures to protect themselves. Also without public disclosure and/or active exploitation, software vendors would downplay the seriousness of their vulnerabilities and delay providing patches for them.

    The end result of this, is that the smaller number of people who can acquire exploits, and this includes paid criminal gangs, would have a lot more power because they would no longer have to compete against the script kiddies for control of drone systems.

    Incidentally, i am also against the *free* disclosure of vulnerabilities in non free software... Commercial vendors charge you a lot of money for their software, and can often be hostile or uncommunicative towards people who find bugs in their software... These people finding bugs are effectively doing their jobs for them and get nothing but grief in return, so it's no wonder that so many bug hunters are now working for criminal gangs.
    A lot of these vendors want you to do their beta testing for them for free, and then report the bugs privately to them so they can silently fix them not even giving you credit for the find and often not disclosing any details to the public other than perhaps providing a black box patch.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  34. Excellent use of irony by gr8dude · · Score: 2, Interesting

    I think they are pro full-disclosure, and this action is just a pun.

    The message they are trying to get across is: "If you close your eyes, the world doesn't disappear. Here's an example of a hack, just to show you that vulnerabilities will continue to exist even if you don't make them public. Not only that, but there will also be people who will find them and use them, regardless of your will to make them public or not".

    The message is worded well, others noticed it too; I think the author is too intelligent to be so ignorant of the truth.