Contents of Leaked HBGary Emails Reveal Wrongdoing
chargersfan420 writes "Ars Technica has sifted through the contents of the HBGary emails leaked last week in the attack by Anonymous and posted an interesting story about some of the things they were up to (which include rootkit development, selling rootkits to the private sector, and an entire list of 0-day exploits in a variety of OSes and other software, among a variety of other devious plans). Today they are reporting a democratic push for a congressional investigation of HBGary Federal."
a democratic push for a congressional investigation of HBGary Federal
You're going to dig for info on their union-busting, but you're going to be very embarrassed if you find out that the Obama administration was in bed with these scumbags on some other sleazy project(s) that come up too. They were working for the banks, but some of these firms were (or at least had been) working for the government too. Might want to check with the White House before you start digging too deep.
SJW: Someone who has run out of real oppression, and has to fake it.
Who the hell is HBGary? Some schmuck from Huntington Beach? Is that his Slashdot handle?
The word Karma comes to mind...
eventually anonymous would become a V for vendetta mask behind which vigilantes would do things that needed to be done, like this. Where are the people who were foaming at the mouth against Anonymous just a few weeks ago huh ? Here is anonymous justice, packed up and ready to go. The justice which was in no way delivered by the normal means you were speaking about that people should follow.
of course good guys, indifferent guys, and bad guys will do things by hiding behind such a mask. but, that doesnt make the presence of that mask, something bad.
Read radical news here
1) Don't use Windows
2) Don't use Facebook
I am very small, utmostly microscopic.
So they were clearly and intentionally on the more shady end of ethical boundaries. They aren't a security firm, they're crackers for hire.
how is babby formed?
I suspect that what was meant was that there is a Democratic push (by big D Democrats) to investigate HBGary. I haven't heard of any sit-ins over the issue, at least as yet.
i told you that, going after anonymous would cause more hardcore circles, which are in constant rebellion to anything that is establishment, to take up the cause of the anonymous.
Anyone spending a few years in the early stages of internet, in which those underground circles were not so underground like today, would be able to know and tell the same. Its the rebel net culture. That underground is multitudes over the level of what the private lackey corps or govts. can afford to hire or educate. They are of a sort that grows/breeds on its own.
Despite their roads have diverged with most of us the early netizens like me, i indeed learned to develop a deep respect for their kind. For, even if they do a lot of shady stuff, they do have a very strong attachment to some principles. and that's something to be respected.
Anyway. see, what they have done. good luck to govt and their lackeys in finding who did it. they may even be inside hbgary itself. you'll never know. once a rebel, always a rebel.
Read radical news here
Talk about rats leaving a sinking ship...
ELOI, ELOI, LAMA SABACHTHANI!?
http://nakedsecurity.sophos.com/2011/02/16/lessons-to-learn-from-the-hbgary-federal-hack/
..... blah blah and stole proprietary and 'confidential' information which was STOLEN by us by using ROOTKITS and VIRUSES and 0 DAY EXPLOITS from private citizens' computers ....."
....
down below.
http://sophosnews.files.wordpress.com/2011/02/hbgary-rsa-sign.jpg?w=640
"A group of AGGRESSIVE hackers known as 'Anonymous' illegally broke into blah blah
corporate lack of shame. you produce rootkits, viruses, 0 day exploits, malware to spy on people, steal their confidential, legally private information to SELL them, and then you dub that information 'proprietary' information belonging to you
i wonder what will they say in their defense in front of senate committee. what's more, i wonder what will the senate committee say to them, in regard to their dealings with this filthy outfit.
whats the slogan of hbgary anyway ? "hey - we produce viruses, rootkits, 0 day exploits and malware to steal your private information to sell to corporations and government !!!" ?
Read radical news here
Quis custodiet ipsos custodes?
Where money and power is concerned there is no freedom and nothing is sacred; except money and power.
Did you ever wake up in the morning, with a Zombie Woof behind your eyes? -- FZ
Or not so amazing...
I note the comment from The Wild Norseman:
http://it.slashdot.org/comments.pl?sid=2017860&cid=35350670
No brain, no pain.
HBGary has also DMCA'd a security blogger over a post about "Malware DNA" as well.
This is the same blogger HBGary called 'nutty but smart' (I paraphrase) in their emails and then cited to his work as 'a good idea'
See: http://conanthedestroyer.net/2011/02/15/wherez-it-at-hbgary-response/
The problem I have with this is that I think its just noobs selling shit to boobs.The more this story develops I become more and more uncertain that HBGary had te technical know how to make working root kits, and 0-days for multiple OS's. I betcha these guys would just sit waiting for bugtraq to update and hurriedly package it, that i do believe they are capable of. Some of the things that were apparently willing to sell or selling require superior technical understanding, and if the twats at HBG had that, they wouldn't be so chock full of epic loss right now
sig loading.......
http://en.wikipedia.org/wiki/The_Yes_Men
The Yes Men often deploy a satirical approach: they pose as a powerful entity (typically a corporate or government representative or executive) and make ridiculous and shocking comments that caricature the ideological position of the organisation or person. Furthermore, they acknowledge the idea that many corporate or government entities manipulate their ideology using spin; in response, the Yes Men use this power of spin to their own advantage, and use media outlets to disseminate their personal interpretation of the situation. A sense of humor and shock value is usually employed to make these issues more palatable to the general public and to call greater media attention to stories of interest.[1] Some of these outrageous ideas include the possibility to sell one's vote or that the poor should consume recycled human waste. On most occasions, little to no shock or outrage is publicly evoked in response to their prank.
On occasion, the Yes Men's phony spokesperson will make announcements that represent fictitious scenarios for the anti-globalization movement or opponents of corporate crime. The result often heed false news reports which cover the demise of the World Trade Organization, or Dow Chemical paying compensation to the victims of the Bhopal disaster, which the Yes Men intend to provide publicity for problems concerning these organizations. One of the effects of apologizing and promising support on behalf of an organization is that the organization is then later forced to re-acknowledge the event in question and retract all of the proposed good will. This served to further publicize the negative event of the organization and sets-up the organization to look bad for taking back any support The Yes Men offered under the name of their organization.
--
There are people who attack corporations in this way, and are not investigated by the Democrats on anything like a regular basis.
memo to self: ask security firm if they know and read Bruce Schneiers blog
Are they gonna be investigated too?
I have left slashdot and am now on Soylent News. FUCK YOU DICE.
Why would Congress involve itself in an investigation of a simple criminal conspiracy?
"He who lives in glass house should not throw stones"
ok it's not attributed to him, but is attributed (in various slightly differing forms) to a wide variety of people, including Ben Franklin. Nothing quite as entertaining to see someone tasked with bending laws get bent over BY the laws, from their own pen.
I work for the Department of Redundancy Department.
Capitalization is important. Consider the sentence:
i helped my uncle jack off a horse
"I'd rather be a lightning rod than a seismometer." -Ken Kesey
I bet you their bosses at the NSA are already calling senators suggesting how Inconvenient it would be if Certain Things came to light and the whole matter will go poof inside of a week.
So why is Anonymous the good guys for hacking banks and the government is the bad guys for hacking...well the bad guys!?
Who is surprised at how unprofessional and childish some of these emails are? Forget about the questionable activities, I have never worked at a job where these emails would be considered acceptable communications, even internally.
"In America, first you get the sugar, then you get the power, then you get the women..." -H. Simpson
"Climategate"? You mean the made-up controversy by oil company shills?
The Lady of the Lake, her arm clad in the purest shimmering samite held aloft Excalibur from the bosom of the water, signifying by divine providence that I, Arthur, was to carry Excalibur.
Hail Eris, full of mischief...
E pluribus sanguinem
If you still believe climategate was anything other than a political beat up then you haven't even bothered to do your own investigation.
And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
They weren't even under investigation until the break in.
That kind of reminds me of something else I heard somewhere before...
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
the existence of personna management software makes you wonder about the useage of facebook and other social media in the revolutions in Tunisia, Egypt and Libya doesn't it...
Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
Folks,
This is US and EU. Businesses (DMCA, IPR, RIAA...) prove institutions' civil-rights exceed the individual rights of any citizen to any protection from attack, exploitation, legal threat. Themis is just another business committed to impacting "The USA Constitution," US, and EU people (nothing new).
Remember it is safer to accept than reject your masters. The politicians in the USA know that fact; So, never expect them to do anything about their betters.
Business is the government of governance. Parliaments, congresses, ministers, presidents... are the loyal servants of global-corporate elitist/plutocrats. IOW: National Governments are a propaganda façade for the dogma-swilling public.
Industry/banking... C*Os legally destroyed the economies, our governments provided corporate-welfare bailouts, many of "The People" lost everything, and some token-crooks went to jail. US and EU folks are really very fucked-up legally and economically. We lose our houses, retirements... and the C*Os, politicians... that committed the crimes get welfare (C*Os) or reelected (corporate loyal lobbyist).
CIOs/Politicians seldom to never go to jail for breaking laws or for fucking US or EU folks.
Unaccountable leaders are masters, and unrepresented people are slaves. How do US and EU fare?
thats quite well said actually. depending on the social composition of internet, anonymous will keep its identity and formation, because it comprises of voluntary, unattached groups having an attachment only to a principle ; "Anonymous"
Read radical news here
Isn't Blackwater called Xe now?
Once again, the DoJ is found to be involved in shady dealings involving software to track and correlate people.
http://www.wired.com/wired/archive/1.01/inslaw.html
The linked article mentions alleged wrongdoing by HBGary only very briefly - just one paragraph near the end. It also isn't immediately clear whether or not any of the actions this paragraph alleges would actually be illegal under US law. (For reference, the paragraph in question starts "When asked to investigate pro-union websites".)
The main focus of the article is on the sort of technology HBGary was developing. (Personally, I'm particularly intrigued by the use of direct access ports in attack technology, because this is a vulnerability I've been complaining about for years. Nobody I discussed it with would admit it was a security risk worth caring about.)
I still maintain that these jackwagons will just sell book and movie rights because of this amd make millions.
So. Hacking and computer security in the end made them rich. Not in the manner they intended... but I am sure they don't care.
I am very small, utmostly microscopic.
OK, so you've heard the term "chain of custody". You're not thinking this through like an investigator, though. Congress can subpoena the original records and establish that chain. They can even subpoena people who received the emails, and ISP who may have stored them on a server somewhere.
If you mod me down, I shall become more powerful than you could possibly imagine.
... for why abortion is necessary.
Lock n load. Kill'm All. A shoot'n gallery. Use Google Map & Street View for targetings.
-308
http://www.bradblog.com/?p=8351
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
As Thursday's show continued, I received confirmation that I, personally, along with members of my family, had been highlighted in Themis' proposed hit job, as ThinkProgress followed up with a second story, based on several other emails from HBGary's CEO Aaron Barr. The email focused on me included names, personal information, home addresses, etc. of myself, family members and a number of other members of VR. Naturally, I reported on the then-confirmed news in the second hour of that night's Malloy Show.
From page 5 of the Ars Technica article:
When asked to investigate pro-union websites and WikiLeaks, Barr turned immediately to his social media toolkit and was ready to deploy personas, Facebook scraping, link analysis, and fake websites; he also suggested computer attacks on WikiLeaks infrastructure and pressure be brought upon journalists like Glenn Greenwald.
His compatriots at Palantir and Berico showed, in their many e-mails, few if any qualms about turning their national security techniques upon private dissenting voices. Barr's ideas showed up in Palantir-branded PowerPoints and Berico-branded "scope of work" documents. "Reconnaissance cells" were proposed, network attacks were acceptable, "target dossiers" on "adversaries" would be compiled, and "complex information campaigns" involving fake personas were on the table.
Critics like Glenn Greenwald contend that this nexus of private and public security power is a dangerous mix. "The real issue highlighted by this episode is just how lawless and unrestrained is the unified axis of government and corporate power," he wrote last week.
Especially (though by no means only) in the worlds of the Surveillance and National Security State, the powers of the state have become largely privatized. There is very little separation between government power and corporate power. Those who wield the latter intrinsically wield the former.
The revolving door between the highest levels of government and corporate offices rotates so fast and continuously that it has basically flown off its track and no longer provides even the minimal barrier it once did. It's not merely that corporate power is unrestrained; it's worse than that: corporations actively exploit the power of the state to further entrench and enhance their power.
Even if you don't share this view, the e-mails provide a fascinating glimpse into the origins of government-controlled malware. Given the number of rootkits apparently being developed for government use, one wonders just how many machines around the globe could respond to orders from the US military. Or the Chinese military. Or the Russian military.
While hackers get most of the attention for their rootkits and botnets and malware, state actors use the same tools to play a different game—the Great Game—and it could be coming soon to a computer near you.
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
Aaron Barr just failed upward. Nepotism is one thing, but once I saw that W had failed upward all the way to the Presidency with Supreme Court jurists as his accomplices, I re-examined a lot of assumptions about ethics and competency in high places in this country.
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
I'm uncertain if it's been mentioned, but upon searching the exact file name mentioned on the first page brings up one hit: leaks.anonamegame.com
71,800 emails from FBGary, with some IP's and passwords, all in plain text, wikileaks style. (Can you feel the rushing torrent love?)
(I might be anonymous, but I assure you that I didn't do it.)
And all of them will be labeled Terrorist Organizations in a heart beat. And the majority of American Mouthbreathers will believe it in the same tick of time.
will never let a committee question HB Gary or any other corrupt company for that matter. Thanks, all-knowing, wise US voters.
The politician you have to feed to a tree chipper will have thousands of years worth of memories of how to be corrupt. Also, probably a wicked knowledge of swordfighting.
What is the most interesting to me, is how there was no direct damage done by Anonymous. They hacked into the servers, grabbed information, and published it. They did deface a web site to prove they'd been in, but that was minimal and easily fixed. They didn't destroy equipment or attack his family.
What they did was get in, grab the information, and publish it. Then they let the information stand on its own as to what it reveals about HBGary. This is the transparency corporations and governments should offer and which Wikileaks has been trying to offer. I really like where this is going.
If he explores all forms and substances Straight homeward to their symbol-essences; He shall not die.
I dunno, I see Anonymous as Chaotic Good, but with a problem much like a chess computer calculating a tricky move. What "is good to do" may be provisionally true, as a "fight censorship / fight the man / fight the corps" kind of thing. Per the other thread if more than one side is morally wrong, it becomes a mess to evaluate your own decision. HBGary would have been one more faceless semi-competent little gov agent of dubious morals. We wring our hands when the gov doesevil stuff, because "don't you know who they are? They're the Governaut, bitch!". But when citizens do it, look at the paid anonymous turfers trying to poison the discussion.
(What's a political astroturfer called? They're selling mercs, not merch.)
But yes, only Chaotic Good, because then they miscalc something and drift off into the lulz and lose the storybook ending for something messier.
Also Anonymous has a big weakness. Gov is trying to deliberatly apply the logical fallacy that "there is only one Anonymous and they must be stopped by draconian measures."
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine