Hackers Dump Millions of Records From Banks, Politicians
hypnosec writes "TeamGhostShell, a team linked with the infamous group Anonymous, is claiming that they have hacked some major U.S. institutions, including major banking institutions and accounts of politicians, and has posted those details online. The dumps, comprised of millions of accounts, have been let loose on the web by the hacking collective. The motivation behind the hack, the group claims, is to protest against banks, politicians and the hackers who have been captured by law enforcement agencies."
Yes let's ruin millions of innocent lives to protest the arrest of criminals!
To offset political mods, replace Flamebait with Insightful.
Banks got billions in bailout but apparently put none of it into security. Like the bailouts the Banks and politicians win and the consumers lose.
Chief Thinker www.devotedskeptic.com
The powers-that-be, which includes banks, corporations and lawmakers, have been driving all of us "ordinarylings" towards a future where we are increasingly under 24/7 surveillance, whether we like it or not. They have been building a "surveillance grid" that becomes more sophisticated every day, and that knows everything from what we are buying/consuming, to what we are reading, to where we surf on the net when we get up in the morning, to where we park our cars, or go for an evening walk. ---- In a sense it is almost fair that the people who have been encouraging & bankrolling & constantly expanding this surveillance grid get their own digital lives hacked, and thrown online for everyone to scrutinize. ----- If we weren't surveilled digitally, 24/7, and so cruelly, I would say that these hackers have done "a bad thing". ------- Things being what they are - we are watched every more closely by the surveillance grid - its hard, morally speaking, to blame these hackers for their unorthodox actions and tactics.
Why did the chicken cross the road? Because Elon Musk put an AI chip in its head.
Score against banks - a bit of a headache, some minor bad P.R., a temporary drop in share price maybe. Don't worry, it'll come back up when the next scandal pushes this one off of people's memories.
Score against the people they're standing up for (the public) - millions of lives ruined as their credit goes to pot, countless hours and days of effort spent to try and recover, thousands of dollars of extra interest payments now their credit score has been dropped down, potential bankruptcies and divorces and split households from the stress...
What a bunch of jackasses. Maybe these people should think who they're really hurting once in a while.
What is the point of these efforts? It's generally accepted that systems can be compromised. You aren't helping the issue by making it more obvious to the general public through scare tactics. Why not just burn a bunch of houses to ground in protest? that should get some media coverage. So what if a few are occupied they should have invested in better smoke detector security.
It's all about the big picture.
With data like this--just emails tied to businesses--even the little guy can start making connections. Without those connections being apparent, Big Business can simply do what they've done for centuries--operate behind closed doors to the detriment of those that remain outside. Posting the information the way it has been, I can Google someone's email address, perhaps a potential business partner, and see what other businesses they have been interacting with and base my decisions on that.
The point is that governments, employers and corporations already do this with OUR data--it's high time we were given the power to do the same. Releases like this--that open the doors to back-room deals--serve to balance the scales between individual rights and everything else.
Yay for the little guy.
Seriously, has anyone actually looked at these so called "dumps"? Most of them are a single field from a table, with no relational data to associate the bits. I see email addresses with nothing else. I see [email] addresses with nothing else. I see First and Last names, but nothing else. Phone numbers... the same. Then there are loads of obvious blog style records that is used to populate their "news" and such sections (which are obviously on their front page anyway). Where is the damage?
"When life gives you lemons, don't make lemonade. Make life take the lemons back!" -- Cave Johnson
http://ciaservices.com/
unless it's just a really well concealed CIA front of course.
Money - the abstract representation of value intended to ease trade was never meant to be so manipulated with ever higher levels of abstraction as it has been. In essence its been turned into an abstract tool to transfer real value deceptively.
What other field do you find abstractions? How about the concept of religion/philosophy, Government/kingdoms, Intelligence/military, and of course Economy/financials.... but there is one other.... computer programming. So among other article currently on slashdot you have this one, the story about how damn much money is in the programming industry and one about spying and control of anything that has computer technology in it...
Abstraction abstractions, who got the next one or the meaning change file of double and triple speak?
Population drive change. Today we have over 7 billion people... and yeah.... we are going through a evolutionary change... and its not the first time.
But this time we are all getting tired of the liars and cheats.
Wasn't this a computer equivalent to a bank safe break in?
The motivation behind the hack, the group claims, is to protest against banks, politicians and the hackers who have been captured by law enforcement agencies.
(emphasis mine)
Yeah, I'd be protesting against those stupid hackers too. I mean, they got caught? Horrors!
Is no one proofreading these submissions?
Those who can, do. Those who can't, write technology blogs.
Seriously, has anyone actually looked at these so called "dumps"? Most of them are a single field from a table, with no relational data to associate the bits. I see email addresses with nothing else. I see [email] addresses with nothing else. I see First and Last names, but nothing else. Phone numbers... the same. Then there are loads of obvious blog style records that is used to populate their "news" and such sections (which are obviously on their front page anyway). Where is the damage?
I've looked at over 20 so far and all have been absolutely worthless. Even the ones that didn't hash their passwords (BookData? what site is that, can't even find their landing page and all the logins look to be JP e-mail addresses) I can't find where I'm supposed to log in. Furthermore, some of these look like some automated testing software when I see rows like:
Those two filled in columns are username and password by the way. So I'm going to say there's three possibilities:
1) these are completely fabricated tables mixed in with (like you noticed) front page public news items and HTML to make them look authentic.
2) these are legitimate but just plain crappy sites. How is it that they only get ~1200 user records from a site unless the site is so worthless that it only has 1200 users?
3) they have everything. They have sensitive stuff but what they've done is show the targets that they have been compromised by releasing only the sensitive data that won't hurt the small users. Since they are publishing the structure of the databases and the targeted entities know that if you have access to that structure, you have/had access to all of the many user information.
I can't believe Teenfad hashed their passwords but some of these other seemingly more sensitive sites didn't. Who the hell is storing plain text passwords in a database!? Well, I guess we have a list of worthless sites that do it now.
My work here is dung.
Working on it... See for yourself: http://par-anoia.net/midasbank/midas.rar It's 2MB, 21MB text.
Thank you, Edward Snowden.
"Arguments from authority are worthless." —Carl Sagan
Wait.. thats my account details... no no burn them in jail!
Yeah. bunch of morons who support this ONLY when it's not THEIR account.
TeamGhostShell, a team linked with the infamous group Anonymous
No.
This is the single most inflammatory and weaselly-worded sentence in the article, and it's the first frigging one.
Perhaps it's pedantic by this point, but I am tired of stupidity like this and I'm just irritable enough right now to attack some misinformation.
"Anonymous" is not a group. It's not a collective. It's not even an "it". Anonymous is synonymous with "the masses", with a specific connotation of anonymity and being on the internet. I'll grant that XxXTeamNameChosenByMiddleSchoolersXxX is a "member" of anonymous, but that's like saying that Barack Obama is a "member" of the human species, it doesn't mean anything useful.
Stop doing this.
You should turn signatures off.
"The motivation behind the hack, the group claims, is to protest against banks, politicians and the hackers who have been captured by law enforcement agencies."
Banks, politicians, and hackers were captured by law enforcement agencies?
As much as I'd like to claim same-shit-different-group on this one, what exactly are they protesting? Generally against banks because...you like to keep your money in the place place you stash your Playboy so mom doesn't find it?
... so let's not do that.
Security requires thoughtfulness, planning, good practices and a lot of things they just don't want to do. These are the consequences of bad security.
That there is dirty laundry or information which might be considered controversial or damaging is another matter.... also too bad for them. But if these targetted parties are learning anything at all, it is that tighter security is important so they don't get caught. They are not learing they shouldn't do things which might look bad if they are exposed.
... that ISN'T "linked to Anonymous"? I don't know who's the most retarded anymore: their stupid followers or the media.
Also, FYI, the correct term is "terrorists". Not hackers. Get your fucking facts straight or I'll come over and shit in your faces, you dumb nigger donkeys.
Apparently the slashmods missed the memo: "The Supreme Court ruled Wednesday that consumers can be bound by an arbitration clause in a cellphone deal or other contract even when state law permits a class-action lawsuit for claims arising from the deal."
Along with a lot of other people, for some reason, despite there being almost a dozen slashdot articles on it. Must be because I'm a troll. You know, one of those fact trolls. Damn you facts! DAAAAAMMMMMNNN YYYOOOOOOUUUU!!!
#fuckbeta #iamslashdot #dicemustdie
Sure, it's semi-random data from a bunch of semi-random databases.
There are e-mail addresses in there to be harvested. (I'd hesitate to say even that much, but I'm sure the spammers have already jumped all over those.)
There are passwords. Even though at least some are encoded, that still gives crackers something to run rainbow tables against.
I'd mention more, but I really don't want to give random wannabee social engineers too many clues. (Even dead simple ones.)
There are real security issues here, and pretty much every company on-line in the world had better be tightening up ship, asking users to change their passwords, and combing through that data to see what visible dangers there are.
Computer memory is just fancy paper, CPUs just fancy pens with fancy erasers; the 'net is just a fancy backyard fence.
While trying to link to the files (from TFA) on my independently hosted Wordpress-based website, I encountered a very peculiar situation where any attempt to include this link: http://pastebin.com/BuabHTvr -- resulted in a failed or deleted post. That link directs to the files mentioned in the story above. But any effort to include it in a post on Wordpress results in an error message.
I have created a video to document the experience here.
I'd really appreciate any insight as to WTF this is happening. And please pardon the quality in advance; I spent waaaay too much time trying to edit out the black-space, but either I don't get pitivi, or it sucks. Anyway, it must be watched in HD to see the text.
Forward! -- Emperor Norton, 2012
Some lazy assumptions in your analysis
Unreal. He at least took the time to actually look at the data. What did you do? You gave us "lazy assumptions" (that's being generous) like this: "Condemn Intel for insinuating their under-baked IP into all the pipes."
http://pastesite.com/42582
http://pastebin.ca/2198346
https://gist.github.com/3485740
http://pastie.org/4595347
http://dpaste.com/791953/
unescape('%23%21%2F%62%69%6E%2F%73%68%0A%0A%23%44%45%42%55%47%3D%31%0A%5B%20%2D%7A%20%24%44%45%42%55%47%20%5D%20%7C%7C%20%73%65%74%20%2D%78%0A%0A%4D%45%54%41%3D%4D%65%74%61%2E%74%78%74%0A%69%66%20%5B%20%21%20%2D%66%20%24%4D%45%54%41%20%5D%3B%20%74%68%65%6E%0A%09%77%67%65%74%20%2D%71%20%2D%4F%20%24%4D%45%54%41%2E%74%6D%70%20%68%74%74%70%73%3A%2F%2F%70%72%69%76%61%74%65%70%61%73%74%65%2E%63%6F%6D%2F%64%6F%77%6E%6C%6F%61%64%2F%34%35%30%63%32%65%33%35%64%65%20%2D%2D%6E%6F%2D%63%68%65%63%6B%2D%63%65%72%74%69%66%69%63%61%74%65%20%26%26%20%6D%76%20%24%4D%45%54%41%2E%74%6D%70%20%24%4D%45%54%41%20%7C%7C%20%72%6D%20%2D%66%20%24%4D%45%54%41%0A%66%69%0A%0A%69%66%20%5B%20%21%20%2D%66%20%24%4D%45%54%41%20%5D%3B%20%74%68%65%6E%0A%09%65%63%68%6F%20%22%55%6E%61%62%6C%65%20%74%6F%20%67%65%74%20%4C%69%73%74%2E%22%0A%09%65%78%69%74%20%2D%31%0A%66%69%0A%0A%63%61%74%20%24%4D%45%54%41%20%7C%20%67%72%65%70%20%67%69%74%68%75%62%20%2D%41%20%32%20%7C%20%77%68%69%6C%65%20%72%65%61%64%20%73%74%75%66%66%3B%20%64%6F%0A%09%74%69%74%6C%65%3D%60%65%63%68%6F%20%24%73%74%75%66%66%20%7C%20%63%75%74%20%2D%64%2D%20%2D%66%31%20%7C%20%74%72%20%22%20%22%20%5F%20%7C%20%73%65%64%20%73%2F%5F%24%2F%2F%67%60%0A%09%75%72%6C%3D%60%65%63%68%6F%20%24%73%74%75%66%66%20%7C%20%74%72%20%22%20%22%20%22%5C%6E%22%20%7C%20%67%72%65%70%20%67%69%74%68%75%62%20%7C%20%67%72%65%70%20%68%74%74%70%20%7C%20%73%65%64%20%27%73%2F%4D%69%72%72%6F%72%31%2F%2F%67%27%60%0A%09%66%69%6C%65%3D%22%24%74%69%74%6C%65%2E%74%78%74%22%0A%09%69%66%20%5B%20%21%20%2D%7A%20%22%24%75%72%6C%22%20%5D%20%3B%20%74%68%65%6E%0A%09%09%66%74%61%72%3D%0A%09%09%69%66%20%65%63%68%6F%20%24%75%72%6C%20%7C%20%67%72%65%70%20%2D%76%20%2E%74%78%74%20%7C%20%67%72%65%70%20%67%69%73%74%20%32%3E%26%31%20%3E%2F%64%65%76%2F%6E%75%6C%6C%20%3B%20%74%68%65%6E%0A%09%09%09%73%75%72%6C%3D%60%65%63%68%6F%20%24%75%72%6C%20%7C%20%73%65%64%20%27%73%2F%67%69%73%74%2E%67%69%74%68%75%62%2E%63%6F%6D%2F%67%69%73%74%2E%67%69%74%68%75%62%2E%63%6F%6D%5C%2F%67%69%73%74%73%2F%67%27%60%0A%09%09%09%75%72%6C%3D%24%73%75%72%6C%2F%64%6F%77%6E%6C%6F%61%64%0A%09%09%09%66%74%61%72%3D%24%66%69%6C%65%2E%74%61%72%0A%09%09%66%69%0A%09%09%69%66%20%5B%20%21%20%2D%66%20%22%24%66%69%6C%65%22%20%2D%61%20%21%20%2D%7A%20%22%24%66%74%61%72%22%20%5D%3B%20%74%68%65%6E%0A%09%09%09%69%66%20%5B%20%21%20%2D%66%20%22%24%66%74%61%72%22%20%5D%3B%20%74%68%65%6E%0A%09%09%09%09%65%63%68%6F%20%22%46%65%74%63%68%69%6E%67%3A%20%24%75%72%6C%20%2D%2D%20%24%74%69%74%6C%65%22%0A%09%09%09%09%77%67%65%74%20%2D%71%20%2D%4F%20%24%66%74%61%72%2E%74%6D%70%20%24%75%72%6C%20%2D%2D%6E%6F%2D%63%68%65%63%6B%2D%63%65%72%74%69%66%69%63%61%74%65%20%26%26%20%6D%76%20%24%66%74%61%72%2E%74%6D%70%20%24%66%74%61%72%20%7C%7C%20%72%6D%20%2D%66%20%24%66%74%61%72%2E%74%6D%70%0A%09%09%09%66%69%0A%09%09%09%69%66%20%5B%20%2D%66%20%22%24%66%74%61%72%22%20%5D%3B%20%74%68%65%6E%0A%09%09%09%09%66%69%6C%65%6E%65%77%3D%60%74%61%72%20%2D%74%66%20%24%66%74%61%72%20%7C%20%67%72%65%70%20%2E%74%78%74%60%0A%09%09%09%09%69%66%20%5B%20%21%20%2D%7A%20%24%66%69%6C%65%6E%65%77%20%5D%3B%20%74%68%65%6E%0A%09%09%09%09%09%74%61%72%20%2D%78%66%20%24%66%74%61%72%20%24%66%69%6C%65%6E%65%77%0A%09%09%09%09%09%6D%76%20%24%66%69%6C%65%6E%65%77%20%24%66%69%6C%65%0A%09%09%09%09%09%72%6D%64%69%72%20%60%64%69%72%6E%61%6D%65%20%24%66%69%6C%65%6E%65%77%60%0A%09%09%09%09%66%69%0A%09%09%09%66%69%09%0A%09%09%66%69%0A%09%09%69%66%20%5B%20%2D%66%20%22%24%66%74%61%72%22%20%5D%3B%20%74%68%65%6E%0A%09%09%09%72%6D%20%2D%66%20%22%24%66%74%61%72%22%0A%09%09%66%69%0A%09%09%69%66%20%5B%20%21%20%2D%66%20%22%24%66%69%6C%65%22%20%5D%20%3B%20%74%68%65%6E%0A%09%09%09%65%63%68%6F%20%22%46%65%74%63%68%69%6E%67%3A%20%24%75%72%6C%20%2D%2D%20%24%74%69%74%6C%65%22%0A%09%09%09%77%67%65%74%20%2D%71%20%2D%4F%20%24%66%69%6C%65%2E%74%6D%70%20%24%75%72%6C%20%2D%2D%6E%6F%2D%63%68%65%63%6B%2D%63%65%72%74%69%66%69%63%61%74%65%20%26%26%20%6D%76%20%24%66%69%6C%65%2E%74%6D%70%20%24%66%69%6C%65%20%7C%7C%20%72%6D%20%2D%66%20%24%66%69%6C%65%2E%74%6D%70%0A%09%09%65%6C%73%65%0A%09%09%09%65%63%68%6F%20%22%53%6B%69%70%70%69%6E%67%20%24%74%69%74%6C%65%22%0A%09%09%66%69%0A%09%66%69%0A%64%6F%6E%65%0A');
Well, if there weren't any damages, why would this be news?
I was promised a flying car. Where is my flying car?
They are famous, meaning "known", but not infamous in the sense of "sadly known". Very partial text, it sucks.
The free market itself is a myth.
I find your lack of faith in the invisible hand disturbing...
Sorry, I just couldn't let the image of Darth Adam Smith choking some scoffer with an invisible force hand alone...
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
I was just watching "Fight Club" and I realized that if Anonymous and TGS want to protest these banks and politicians, then why don't they just do what Project Mayhem did without all the destruction of property: alleviate everyone's outstanding credit card and other unsecured debt? If they really want to convince me that they're doing this to fight for the "little guy" then help out the little guy. Until then, they're only doing this for their own satisfaction.
These are both so bad, I had to step in :D
Lets try:
"The group claims that the motivation behind the hack was to protest against the figurative capture of banks and politicians [by government and large special interest groups] along with the physical detention of hackers by law enforcement agencies."
Is it starting to look like a comment that might have been made by someone with a bit of intelligence now?
I took time to dig into the data, before I posted that rant.
Did you?
Like I said, when I make random test addresses I do not bother going to the effort that would have been required if those lists of addresses were fabricated. Maybe someone did go to the trouble, but the data did not look that way to someone who thinks about what the data should look like.
Pointing too much out would be helping wannabee script kiddies, so that's about as far as I'm gonna say here. (It's bad enough to confirm to the spammers who lurk here that there are probably live addresses in those lists.)
I also took time to dig into Intel's, Microsoft's, and now Apple's non-efforts at security.
And I refrain from being more specific about that for similar reasons, but it is precisely because of the no-brainer holes that the market leaders leave in their security that more than half of that load of data was harvested. And it is the market leader wannabees in the Linux communities, trying to "be like the big boys", that have produced similar holes in many of the Free/Open systems available..
Now, who's unreal here?
Computer memory is just fancy paper, CPUs just fancy pens with fancy erasers; the 'net is just a fancy backyard fence.
Not that is is not possible but such statements are suspicious. Can you provide and actual link or is it too late to acquire the identity of a war victim, say? Though once I arrived to the corner and... WHERE IS THE BANK! Maybe it was them? I wonder... Basically if they can do it they are missing a nice business opportunity: to get the programming company or worker s contract for themselves! Then they would show them what it means to leave no backdoor trapdoor to milk cents from millions of accounts every day for the babies to grow nice and strong... :\
Thousands of top secret patents at the USPTO. Energy companies keeping world-changing technologies a secret. Military keeping advanced propulsion technologies a secret as well. All these could be benefit mankind! An appeal to hacker groups to refocus your efforts!