Hacking Team Hacked, Attackers Grab 400GB of Internal Data
Several readers sent word that notorious surveillance company Hacking Team has itself been hacked. Attackers made off with 400GB worth of emails, documents, and source code. The company is known for providing interception tools to government and law enforcement agencies. According to the leaked files, Hacking Team has customers in Egypt, South Korea, Kazakhstan, Saudi Arabia, Oman, Lebanon, Mongolia, Russia, Germany, Sudan, and the United States — to name a few. It has been labeled an enemy of the internet by Reporters Without Borders. "Clients have had their passwords exposed as well, as several documents related to contracts and configurations have been circulating online." Nobody knows yet who perpetrated the hack.
Someone started uploading all the HackingTeam source code to GitHub: https://github.com/hackedteam?...
There are also some signing keys for kernel drivers in here.
That's a bad day for Hacking Team and a good day for everyone else.
*What's good for the goose...*
Schadenfreude...
“He’s not deformed, he’s just drunk!”
Serves those maggots well.
It's 2015, I just finished competing in BattleBots, and this is front page news. 12 year old me would be very happy about how things are going.
Liberty - Security - Laziness - Pick any two.
whoopsie!
(Brass) Yaku: It was hacked... by aliens!
(Brass) *gasp* They're invading the channel now!
(Yaku) are they the dick sucking kinda aliens?
(Yaku) or the brain eating ones?
(Brass) Yaku: Either way, I don't think you have anything to fear.
- http://bash.org/?81858
We apologize for corporate and govt data breeches. Those responsible have been
hacked.
---
We apologise again for the data breeches. Those responsible for hacking
the people who have just been hacked,
have been hacked.
Seems unlikely. There's going to be a lot of... binary data in there, surely.
Ydco co
Not anybody knows what really happened. It's an excuse to bandy around meaningless but scary-sounding terms yet once more. Any excuse will do.
Clearly Hacking Team is not worth their salt. I'll never do business with them.
You could not have made my day any brighter.
Clearly this never would have appened if Hacking Team was Apping App and apped apps instead of writing Luddite software!
Apps!
Can someone please explain the significance and consequences of publishing this:
GeoTrust_SigningCertificateExported_2011.pfx
https://github.com/hackedteam/...
-- I was raised on the command line, bitch
It's a lame attempt at coolness, like "Black Asphalt" as a code for stealing random drivers' money during traffic stops. The name "Hacking Team" does not make it an actual hacking team.
Yea, and they are going to say somebody else did it....
We all know who did it.. Got caught running the IIS exploit scripts again eh guys?
https://twitter.com/FredericJa...
Subject: UID=DE9J4B8GTF, CN=iPhone Distribution: HT srl, OU=DE9J4B8GTF, O=HT srl, C=IT
Oh ya, we're fucked.
A moose once bit my sister
ob: it's not 1997 anymore slashdot, you ruined a perfectly good joke with you shoddy unimacode support
magnet
Kevin Mitnick's twitter has this update:
https://twitter.com/kevinmitni...
"Stratigraphically the origin of agriculture and thermonuclear destruction will appear essentially simultaneous" -- Lee
From first link: "Hacking Team's Christian Pozzi was personally exposed by the incident, as the security engineer's [poor quality, easily guessed] password store from Firefox was published as part of the massive data dump. The websites indexed include social media (Live, Facebook, LinkedIn), financial (banks, PayPal), and network related (routers with default credentials)."
What kind of security conscious person uses Firefox for storing important passwords, let alone someone calling themselves a security engineer? I hope the hackers had fun accessing his bank accounts. :-)
http://dilbert.com/strip/2013-...
... will this help bona fide security researchers with their work on fighting exploits on all platforms ... ?
I wonder if this will also help people trying to write open software for closed devices? Signing keys, driver sources with spyware installed, ... Not only does it expose the malware bypassing the user's security, it may also expose the internal details of how the devices are driven and/or how to compromise the malware's and devices' anti-user "security".
(I have often wondered how many of the closed-driver devices have the code closed just for business reasons and how many are closed because that's where the spyware has been installed and they can't let the source out - even sanitized - because that would lead to the spyware's exposure.)
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Someone started uploading all the HackingTeam source code to GitHub ... There are also some signing keys for kernel drivers in here.
IMHO:
Anyone with a project hosted on git hub should pull a backup copy NOW!
Hosting this leak on git hub could lead to moves by authorities to contain it - which could have the side effect of making GitHub and/or some projects on it unavailable - temporarily or permanently.
Better safe than sorry.
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Looks like some interesting stuff in there for Android, but none of it will now qualify for the Android Security Rewards Program: "Bugs initially disclosed publicly, or to a third-party for purposes other than fixing the bug, will typically not qualify for a reward." Source: http://www.google.com/about/ap...
Oh! The irony! Etc... Etc...