PDA

View Full Version : LuLzsec (Hacker group that hacked Sony Pictures) Just Hacked a FBI affliliate site



IronMaxipad
06-03-2011, 08:54 PM
Updated OP:

Timeline of Events:

Latest News

22/06/11
19 year old Ryan Cleary charged with offences under Computer Misuse Act
(From Sky News twitter and BBC News twitter)

Lulzsec takes down Brazilian government website (http://techie-buzz.com/tech-news/lulzec-brazil-takes-down-brazilian-government-portal.html).

A LulzSec Member's Site is Hacked (http://zone-h.org/mirror/id/14233017). More member details to be released soon.


TeaMp0isoN Issue 2 is coming out VERY soon exposing lulzsec members (pictures, addresses, passwords, ips, phone numbers etc). . . . not so anonymous anymore are you? lets hope that you can swim because the lulzboat just got titanic'd

Watch out, LulzSec – the CIA is adept at wiping lulz off faces (http://www.guardian.co.uk/commentisfree/cifamerica/2011/jun/22/lulzsec-hackers-cia)

Events Timeline

1. A group of hackers that go by the name anonymous existed with no clear structure
2. Some of the anon members decided to create a splinter group called Lulz Security to go after higher risk targets and for money
3. Soon after the PSN is hacked by an unrelated group, LulzSec decides to carry on attacking Sony and releases tens of thousands of user accounts from Sony Pictures
4. A lot of publicity follows and they decide to attack other sites and leak even more user information. They also start taking down websites using DDoS attacks
5. They piss of a lot of people and get the FBI and numerous agencies after them
6. They take down the CIA website and this enrages another hacker who goes by the handle 'The Jester'
7. The Jester is very patriotic and has a history of attacking Islamic sites. He is also hated by many for being arrogant. He decides that LulzSec has taken things too far and goes on a mission to out them
8. The Jester starts slowly trickling some information out about them. He outs a member called 'Akomis' (possibly not linked to LulzSec but somehow involved)
9. After this, a group who go by the name 'Web Ninjas' show up with a blog. They identify themselves as opponents to LulzSec and vow to out them all
10. They post a lot of information about the main members of LulzSec and send it to the FBI
11. LulzSec meanwhile slows down. Rumours have it that the owner of their twitter account switched with someone else as the tone of the tweets changes
12. LulzSec decideds to go back to join Anonymous and set up an anti government movement called 'AntiSec'
13. A 19 year old boy from Essex (UK) is arrested for running the anonymous IRC channel
14. The FBI seize some servers that have a supposed link to LulzSec (http://bits.blogs.nytimes.com/2011/06/21/f-b-i-seizes-web-servers-knocking-sites-offline/)
15. Another group enters the mix. This one is called 'Team Poison' and is also a hacker group. They get angry with LulzSec and join others on a mission to take them down. They attack the personal site of a LulzSec member and leak his information
16. There's a lot of publicity on AntiSec and the site for the Brazilian gov is taken down. LulzSec say they have a lot of info ready to release
17. Ryan Cleary is charged (http://www.bbc.co.uk/news/technology-13879678?utm_source=twitterfeed&utm_medium=twitter) over alleged website hacks (including SOCA)

Groups Involved

Anonymous = A large group of people from the site 4chan who go by the name 'anonymous'. Many of them consider themselves hackers

LulzSec = A splinter group originating from Anonymous. Consists of a few people who have been attacking sites for fun. Twitter (http://twitter.com/#!/LulzSec).

The Jester = A lone patriotic hacker on a mission to take down LulzSec. Twitter (http://twitter.com/#!/th3j35t3r). Site (http://th3j35t3r.wordpress.com/).

Web Ninjas = A group of unidentified people. Possibly 'double hackers' who are part of another group. They are also on a mission to take down LulzSec. Site (http://lulzsecexposed.blogspot.com/).

Team Poison = A group of hackers also wanting to take down LulzSec. Twitter 1 (http://twitter.com/#!/TeaMp0ison_) and Twitter 2 (http://twitter.com/_TeaMp0ison_).

LulzSec Members

Main:
Sabu (leader) - id supposedly found
Topiary - identified
Kayla - identified
tFlow

Secondary:
Joepie91 - identified
Nakomis - identified
Barret Brown (Good publicity. He is a journalist) - identified
Neuron - identified
Redacted - identified
Avunit
TrollPoll
Storm
Pwnsauce
voodoo
devrandom

More info here (http://lulzsecexposed.blogspot.com/p/team-lulzsec.html).

Sites/Groups Attacked (not in correct order)

Fox (http://linearfix.wordpress.com/2011/05/13/lulzsec-targets-fox-data-again-for-third-phase/)
UK ATMs (http://www.thehackernews.com/2011/05/lulzsec-hack-leak-pointless-atm.html)
PBS (http://www.thetechherald.com/article.php/201122/7215/PBS-LulzSec-attack-an-attempt-to-chill-journalism)
Sony Pictures (http://www.pcmag.com/article2/0,2817,2386362,00.asp)
InfraGard (http://www.trustedreviews.com/news/lulzsec-attack-nintendo-and-fbi-affiliate)
NHS (http://www.techradar.com/news/internet/lulzsec-reveals-nhs-web-security-holes-964323)
US Senate (https://www.infosecisland.com/blogview/14412-LulzSec-Claims-US-Senate-Network-Hack.html)
CIA (http://www.bbc.co.uk/news/technology-13787229)
Nintendo (http://www.trustedreviews.com/news/lulzsec-attack-nintendo-and-fbi-affiliate)
Eve Online (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
Minecraft (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
Bethesda (Brink) (http://www.zdnet.co.uk/news/security-threats/2011/06/14/lulzsec-targets-bethesda-softworks-game-maker-40093100/)
Pron (pron.com and numerous other porn sites) (http://blogs.forbes.com/andygreenberg/2011/06/10/lulzsec-hackers-get-personal-dump-26000-porn-site-usernames-and-passwords/)
The Escapist (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
League of Legends (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
UK Serious Organised Crime Agency (http://www.product-reviews.net/2011/06/21/soca-latest-hack-victims-as-site-is-attacked/)

More info here (http://www.neogaf.com/forum/showpost.php?p=28774985&postcount=10).

FAQ

Why are they doing this?
They claim it's for the lulz and to help corporations improve their security. The truth is that they do it for the money.

OMG! WAS MY DATA STOLEN?
Click here (http://gizmodo.com/5812545/find-out-if-your-passwords-were-leaked-by-lulzsec-right-here) to find out. If your data was stolen, change all your account passwords.

How can I stay safe in the future?
Use a different password and username for each site you use. Also, enable two step authentication for any service that allows it. More info here (http://www.neogaf.com/forum/showthread.php?t=425417).

Other links
Team Poison Joins In (http://www.techieblogie.info/2011/06/team-poison-hacked-lulzsec.html)
19 Year Old Arrested (http://theeword.co.uk/seo-manchester/essex_teenager_arrested_in_hacking_probe.html)
AntiSec Video Overview (http://www.youtube.com/watch?v=3pY1DC9PmYU)
LulzSec Manifesto (http://arstechnica.com/tech-policy/news/2011/06/lulzsec-heres-why-we-hack-you-bitches.ars)
LulzSec Video Overview (http://www.youtube.com/watch?v=udcnlLXUh8E)

credit to Enco from GAF














Dear Internets,

It has come to our unfortunate attention that NATO and our good friend Barrack
Osama-Llama 24th-century Obama have recently upped the stakes with regard to hacking.
They now treat hacking as an act of war. So, we just hacked an FBI affiliated website
(Infragard, specifically the Atlanta chapter) and leaked its user base. We also took
complete control over the site and defaced it, check it out if it's still up: http://infragardatlanta.org/

While not very many logins (around 180), we'd like to take the time to point out that all
of them are affiliated with the FBI in some way. Most of them reuse their passwords in other places,
which is heavily frowned upon in the FBI/Infragard handbook and generally everywhere else too.

One of them, Karim Hijazi, used his Infragard password for his personal gmail, and the gmail of
the company he owns. "Unveillance", a whitehat company that specializes in data breaches and botnets,
was compromised because of Karim's incompetence. We stole all of his personal emails and his company
emails. We also briefly took over, among other things, their servers and their botnet control panel.

After doing so, we contacted Karim and told him what we did. After a few discussions, he offered to
pay us to eliminate his competitors through illegal hacking means in return for our silence. Karim,
a member of an FBI-related website, was willing to give us money and inside info in order to destroy
his opponents in the whitehat world. We even discussed plans for him to give us insider botnet information.

Naturally we were just stringing him along to further expose the corruption of whitehats.
Please find enclosed Karim's full contact details and a log of him talking to us through IRC.
Also, enjoy 924 of his internal company emails - we have his personal gmail too, unreleased.

We call upon journalists and other writers to delve through the emails carefully, as we have
uncovered an operation orchestrated by Unveillance and others to control and assess Libyan
cyberspace through malicious means: the U.S. government is funding the CSFI to attack Libya's
cyber infrastructure. You will find the emails of all 23 people involved in the emails.

Unveillance was also involved in a scheme where they paid an Indian registrar $2000 to
receive 100 domains a month that may be deemed as botnet C&Cs. Shameful ploys by supposed "whitehats".

We accept your threats, NATO. Game on, losers.

Now we are all sons of bitches,

Lulz Security

http://pastebin.com/MQG0a130

lol sony

Creepn
06-04-2011, 09:16 PM
Very talented group of guys/gals no doubt.

ElNono
06-04-2011, 10:58 PM
They're either too young, too naive or both...

IronMaxipad
06-04-2011, 11:14 PM
Apparently they hacked Nintendo now.

http://twitter.com/#!/LulzSec/status/76782021116051457

IronMaxipad
06-05-2011, 12:17 AM
:lol

Trainwreck2100
06-05-2011, 09:26 PM
nintendo and pbs? wtf fuck is wrong with those two companies that they deserve to get hacked?

ElNono
06-06-2011, 05:18 PM
They're either too young, too naive or both...


One member of the group, Robert Cavanaugh, was apprehended and taken into custody by the FBI after an apparent counter hack, according to an internal chat log from their private IRC server, posted through SecList, a network mapper website.

link (http://www.theepochtimes.com/n2/technology/lulzsec-member-arrested-group-leaks-sony-database-57296.html)

smh

Creepn
06-06-2011, 09:03 PM
If you read the article, they don't confirm of catching one of the guys.

The whole war started when Sony sued a guy for jailbreaking his PS3. Does the guy have the right to do whatever he wants to his property? Is Sony right in suing this guy?

Nathan Explosion
06-07-2011, 04:02 PM
If you read the article, they don't confirm of catching one of the guys.

The whole war started when Sony sued a guy for jailbreaking his PS3. Does the guy have the right to do whatever he wants to his property? Is Sony right in suing this guy?

A PS3 is not necessarily his property though. I'm not a lawyer, so I could be totally wrong, but I thought you were buying a license to use a PS3 per se, and not actually buying the property. While you'll own the hardware, you can't access the PSN with modded hardware as per the license agreement.

So Sony isn't in the wrong. While suing may be out of line (depends on who you ask), you can't be angry with the stance that Sony is taking in that he can't expect to what he wants with technology they developed and be okay with it.

As for hacking the FBI networks, if you're bringing NATO into this and possible "missions" in Libya, I would think you're now fucking with national security. That also means you're fucking the the NSA and possibly the CIA. I'm not so sure I'd be so cocky about that, but that's just me.

IronMaxipad
06-11-2011, 12:40 PM
55 Porn Sites Hacked (26,000 emails/passwords compromised)

After high profile takedowns of PBS and Sony, the anarchic hacker group LulzSec now seems determined to maximize its exploits’ embarrassment factor.

On Friday afternoon the group announced that it had stolen and posted administrative emails and passwords for 55 porn sites, along with another 26,000 emails and passwords for users of the sex site Pron.com.

“Hi! We like porn (sometimes), so these are email/password combinations from pron.com which we plundered for the lulz,” reads a statement posted to the group’s website Lulzsecurity.com.

Those email addresses can’t be used to access users’ accounts on Pron.com without an additional username. But the posted data violates those users’ privacy on a more basic level, exposing them as visitors to the highly not-safe-for-work site. The group took special pleasure in pointing out that six of those users had signed up for the site using their government or military .gov and .mil email accounts.

LulzSec, a which has ties to the hacker collective Anonymous, has become one of the least predictable forces in the world of cybersecurity since it emerged just two weeks ago. After defacing the website of PBS and exposing many of its employees’ personal information in retaliation for a negative documentary program on WikiLeaks, it proceeded to target Sony, compromising one million passwords and leaking the source code for the Sony Computer Entertainment Developer Network.

In just the last 24 hours, LulzSec seemed to temporarily adopt more “whitehat” hacker practices, notifying the British National Health Service to password vulnerabilities on its network and taking down a Muslim extremist website. But the latest porn hack shows just how wildly the group is varying its targets. “We have no direct plans for targets today, but we’ll think of something,” LulzSec wrote on its Twitter feed just hours earlier. “Improvisation is a required Lulz Boat skill!”

http://blogs.forbes.com/andygreenberg/2011/06/10/lulzsec-hackers-get-personal-dump-26000-porn-site-usernames-and-passwords/

LulzSec strikes again

http://cdn.gossipgamers.com/wp-content/uploads/2011/06/Lulzsec-hackers-590x340.jpg

MaNuMaNiAc
06-11-2011, 02:15 PM
From the way they talk and carry themselves, these jackasses seem to be nothing more that a bunch of immature brats with just enough knowledge of hacking to be nothing more than a nuisance. I swear, the whole hacking scene is populated by idiots who think too highly of the stupid shit they pull.

velik_m
06-12-2011, 12:03 AM
From the way they talk and carry themselves, these jackasses seem to be nothing more that a bunch of immature brats with just enough knowledge of hacking to be nothing more than a nuisance. I swear, the whole hacking scene is populated by idiots who think too highly of the stupid shit they pull.

That's why it's so sad, this sites are getting hacked by a bunch of idiots...

BlackSwordsMan
06-12-2011, 01:11 AM
lol stringing along a paki and then face fucking him
lul indeed

BlackSwordsMan
06-12-2011, 01:12 AM
Can they hack trannysurprise.com? They banned my account because my views were too
''out there''.

IronMaxipad
06-16-2011, 01:45 PM
They DDoS cia.gov yesterday.

If anyone needs a recap:

udcnlLXUh8E

IronMaxipad
06-16-2011, 01:46 PM
Sites they hacked:

13/06/11
Senate.gov internal data | http
Bethesda internal data press release | http | torrent
Bethesda internal data | http | torrent

10/06/11
Pron.com user database | http
06/06/11
Sownage™ 2 press release | http | torrent
Scedev.net source code | http | torrent
Sony BMG internal network maps | http | torrent

03/06/11
Fuck FBI Friday™ press release | http | torrent
Infragard Atlanta users database | http | torrent
Karim dox | http | torrent
Karim IRC log | http | torrent
Karim emails | torrent
Nintendo.com webserver configuration | http
Unveillance secret conference | http

02/06/11
Sownage™ press release | http | torrent
Sownage™ summary | http | torrent
Sonypictures.com AutoTrader users database | http | torrent
Sonypictures.com Summer of Restless Beauty users database | http | torrent
Sonypictures.com Sony Wonder coupons database | http | torrent
Sonypictures.com Sony Wonder music codes database | http | torrent
Sonypictures.com Seinfeld Del Boca Vista database | http | torrent
Sonypictures.com database tables | http | torrent
Sonybmg.nl partners & admins database, + layout | http | torrent
Sonybmg.be users database | http | torrent

30/05/11
PBS.org defacement (pbs.org/lulz) snapshot | http
PBS.org defacement (fake Tupac article) snapshot | http
PBS.org internal hosts | http
PBS.org database list | http
PBS.org staffers database | http
PBS.org authors database | http
PBS.org pressroom users database | http
PBS.org stations database | http
PBS.org MySQL users database | http

23/05/11
Sonymusic.co.jp database | http
15/05/11
UK ATM database | http

10/05/11
Fox.com innerworkings | http
Fox.com/sales database (SQL) | http
Fox.com/sales database (txt) | http
Fox.com/sales database cracked passwords | http

07/05/11
X Factor contestants database (SQL) | http | torrent
X Factor contestants database (txt) | http | torrent

http://lulzsecurity.com/releases/

IronMaxipad
06-16-2011, 01:49 PM
And Another hacker (th3j35t3r) has declared war on Lulzsec :lmao

Follow them on twitter sons good stuff :lol
http://twitter.com/#!/th3j35t3r
http://twitter.com/#!/LulzSec

Trainwreck2100
06-16-2011, 02:19 PM
lulzsec flying real close to the sun with their hacking, expect them to get nice cushy nsa jobs when they get caught

symple19
06-16-2011, 06:03 PM
Edit: fail

IronMaxipad
06-16-2011, 06:31 PM
^ I just posted that like 2 post above bruh :lol

They just leaked 62,000 Emails and logins http://www.pcpro.co.uk/news/368122/lulzsec-hackers-leak-62-000-email-logins

Here's the list if you want to make sure they don't have your info:
http://www.mediafire.com/?zo7i6d8e4ydsy9a

symple19
06-16-2011, 06:35 PM
I failed

That's what I get for not reading farther up

IronMaxipad
06-17-2011, 07:47 PM
^ I just posted that like 2 post above bruh :lol

They just leaked 62,000 Emails and logins http://www.pcpro.co.uk/news/368122/lulzsec-hackers-leak-62-000-email-logins

Here's the list if you want to make sure they don't have your info:
http://www.mediafire.com/?zo7i6d8e4ydsy9a

Sons if i where you guys i would make sure your email is not on that list. Apperantly it contains xbox live info paypal accounts and facebook.


LulzSec Reportedly Targets Xbox Live Account Info

Hacker group LulzSec has reportedly released a file containing Xbox Live user information in combination with logins for other services such as Facebook, Twitter and Paypal. The exact amount of information compromised is not known at this time but the hacking group isn’t picking targets – casual gamers, long time live players and even government official’s information may have been compromised.

The group uploaded a large file containing usernames and passwords for the various services including Xbox Live last night. The file has since been removed but not before LulzSec could claim that the file had been viewed thousands of times.

The leak was first exposed through LulSec’s twitter account. There they wrote about abusing the breached information and messing with compromised Facebook and Social Networking accounts.

"Envelope yourself in the sickening realization that you secretly love f--king someone's Facebook life beyond repair." - Quote from LulzSec Twitter Account

We’ve reached out to Xbox Live’s community team for comment regarding the possible breach of Xbox Live Accounts. Should any further information break regarding this possible security risk we will make sure to bring it to you. For now the best advice would be to check your Xbox Live account and make sure that your password still works and that no unauthorized purchases have been made on the Marketplace under your account.

http://news.teamxbox.com/xbox/24144/LulzSec-Reportedly-Targets-Xbox-Live-Account-Info/

lol sony

Creepn
06-17-2011, 08:31 PM
That removed the file in that link. Do you know another location?

IronMaxipad
06-17-2011, 08:42 PM
That removed the file in that link. Do you know another location?

http://lulzsecurity.com/releases/62000_random_logins.txt

Trainwreck2100
06-17-2011, 08:54 PM
i checked last night, i'm clear thankfully

Creepn
06-17-2011, 10:22 PM
http://lulzsecurity.com/releases/62000_random_logins.txt


I appreciate it, thanks.

BlackSwordsMan
06-18-2011, 01:29 PM
So shitty.

symple19
06-21-2011, 10:20 AM
http://www.rockpapershotgun.com/2011/06/21/lulzsec-arrested/

http://www.develop-online.net/news/38083/LulzSec-suspect-to-be-examined-for-Sony-data

MannyIsGod
06-21-2011, 11:10 AM
3pY1DC9PmYU

LOOOOOOOOOOOOOL The Lulz boat.

IronMaxipad
06-21-2011, 11:46 AM
lulz

th3j35t3r and WebNinjas have been exposing their identities this past week.

http://lulzsecexposed.blogspot.com/
http://th3j35t3r.wordpress.com/2011/06/16/quick-n-dirty-just-for-clarification/

symple19
06-21-2011, 12:21 PM
lulz

th3j35t3r and WebNinjas have been exposing their identities this past week.

http://lulzsecexposed.blogspot.com/
http://th3j35t3r.wordpress.com/2011/06/16/quick-n-dirty-just-for-clarification/

:lmao

it's a fuckin soap opera

symple19
06-21-2011, 01:26 PM
check this out, a supposed interview with a lulzsec guy from cali

http://www.presstorm.com/2011/06/investigative-exclusive-interview-lulzsec-california/

IronMaxipad
06-21-2011, 03:26 PM
Read his tweets http://twitter.com/#!/th3j35t3r

good shit :lol

symple19
06-22-2011, 12:02 AM
lulzstep

7YoDt-MxhHg

IronMaxipad
06-22-2011, 12:47 AM
http://i.imgur.com/oo6zO.jpg

"Anti-Sec" group spreads message through graffiti in Mission Beach

SAN DIEGO (CBS 8) - Mysterious graffiti appearing on the Mission Beach boardwalk belongs to a group protesting computer security practices.

People living near Mission Beach say the unusual "Anti-Sec" graffiti first appeared last week on the boardwalk. It was quickly painted over, but the stenciled words were back Monday morning.

A computer security expert who spoke with News 8 says "Anti-Sec" stands for "Anti-Security Revolution". The organization claims it recently shut down several gamer sites, as well as websites for the CIA and FBI.

According to the group's mission statement, it believes the security industry uses full disclosure to profit and develop scare tactics to manipulate consumers into buying firewalls, then overcharges for products.

The group says it believes in spreading its message through mayhem.

VIDEO:
http://www.cbs8.com/story/14941495/anti-sec-group-spreads-message-through-graffiti-in-mission-beach?redirected=true

wow :lmao:lmao

IronMaxipad
06-22-2011, 01:23 AM
now they took down main Brazilian .gov sites.

Anyone speak Portuguese?

aIsTd9WIRKU

wtf :lmao

Fernando TD21
06-22-2011, 06:55 AM
now they took down main Brazilian .gov sites.

Anyone speak Portuguese?

aIsTd9WIRKU

wtf :lmao
They are just saying that our government is corrupt and the people should stand against them. And they're threatening the government saying that if they keep lying to the people, they (anonymous) are going to expose their secrets.

symple19
06-22-2011, 08:02 AM
you can't make shit like this up. FBI's bungling while searching for intel on lulzsec brings down legit sites

http://www.thinq.co.uk/2011/6/22/fbi-takes-down-legit-sites-search-lulzsec9/

:lmao

hater
06-22-2011, 08:14 AM
"In their efforts they seem to be causing as much mayhem as the hackers themselves."

:lmao that's pretty funny

reminds me of that Hackers movie with Angelina Jolie

ElNono
06-22-2011, 08:20 AM
Not so funny for the companies caught in the middle that had nothing to do with the search...

symple19
06-22-2011, 08:27 AM
Not so funny for the companies caught in the middle that had nothing to do with the search...

I agree, but this has become such a bizarre saga that I can't help but laugh. It's probably the most entertaining thing I've ever followed on Twitter

symple19
06-22-2011, 08:35 AM
So, besides thejester and the web ninjas, there's now a group called teamPoison (http://twitter.com/#!/TeaMp0isoN_ / http://twitter.com/#!/_TeaMp0isoN_ ) after them too.

http://www.abc.net.au/technology/images/general/anonymous/Vi3Ii.png

Article below

http://www.abc.net.au/technology/images/general/anonymous/Vi3Ii.png

lulz

cheguevara
06-22-2011, 08:46 AM
cybergang wars. it has started

symple19
06-22-2011, 08:54 AM
I had never heard of this either. Apparently there's an online currency called "Bitcoin" that has its own exchange:


A rogue member of hacker group LulzSec is suspected to have been responsible for a hack last weekend which resulted in the theft of $9m worth of online currency.

The hack focussed around a "currency exchange" called MtGox, which provides a method for swapping Bitcoins – an untraceable, cryptographically-created online-only currency favoured by online activists and hackers – for real US dollars.


http://www.guardian.co.uk/technology/2011/jun/22/lulzsec-rogue-suspected-of-bitcoin-hack?INTCMP=ILCNETTXT3487

leemajors
06-22-2011, 09:33 AM
yeah gawker plastered bitcoin and silk road all over the internets a few weeks ago and ruined it.

MannyIsGod
06-22-2011, 10:12 AM
lol no more internet drug buying?

IronMaxipad
06-22-2011, 12:17 PM
Timeline of Events:

Latest News

22/06/11
19 year old Ryan Cleary charged with offences under Computer Misuse Act
(From Sky News twitter and BBC News twitter)

Lulzsec takes down Brazilian government website (http://techie-buzz.com/tech-news/lulzec-brazil-takes-down-brazilian-government-portal.html).

A LulzSec Member's Site is Hacked (http://zone-h.org/mirror/id/14233017). More member details to be released soon.


TeaMp0isoN Issue 2 is coming out VERY soon exposing lulzsec members (pictures, addresses, passwords, ips, phone numbers etc). . . . not so anonymous anymore are you? lets hope that you can swim because the lulzboat just got titanic'd

Watch out, LulzSec – the CIA is adept at wiping lulz off faces (http://www.guardian.co.uk/commentisfree/cifamerica/2011/jun/22/lulzsec-hackers-cia)

Events Timeline

1. A group of hackers that go by the name anonymous existed with no clear structure
2. Some of the anon members decided to create a splinter group called Lulz Security to go after higher risk targets and for money
3. Soon after the PSN is hacked by an unrelated group, LulzSec decides to carry on attacking Sony and releases tens of thousands of user accounts from Sony Pictures
4. A lot of publicity follows and they decide to attack other sites and leak even more user information. They also start taking down websites using DDoS attacks
5. They piss of a lot of people and get the FBI and numerous agencies after them
6. They take down the CIA website and this enrages another hacker who goes by the handle 'The Jester'
7. The Jester is very patriotic and has a history of attacking Islamic sites. He is also hated by many for being arrogant. He decides that LulzSec has taken things too far and goes on a mission to out them
8. The Jester starts slowly trickling some information out about them. He outs a member called 'Akomis' (possibly not linked to LulzSec but somehow involved)
9. After this, a group who go by the name 'Web Ninjas' show up with a blog. They identify themselves as opponents to LulzSec and vow to out them all
10. They post a lot of information about the main members of LulzSec and send it to the FBI
11. LulzSec meanwhile slows down. Rumours have it that the owner of their twitter account switched with someone else as the tone of the tweets changes
12. LulzSec decideds to go back to join Anonymous and set up an anti government movement called 'AntiSec'
13. A 19 year old boy from Essex (UK) is arrested for running the anonymous IRC channel
14. The FBI seize some servers that have a supposed link to LulzSec (http://bits.blogs.nytimes.com/2011/06/21/f-b-i-seizes-web-servers-knocking-sites-offline/)
15. Another group enters the mix. This one is called 'Team Poison' and is also a hacker group. They get angry with LulzSec and join others on a mission to take them down. They attack the personal site of a LulzSec member and leak his information
16. There's a lot of publicity on AntiSec and the site for the Brazilian gov is taken down. LulzSec say they have a lot of info ready to release
17. Ryan Cleary is charged (http://www.bbc.co.uk/news/technology-13879678?utm_source=twitterfeed&utm_medium=twitter) over alleged website hacks (including SOCA)

Groups Involved

Anonymous = A large group of people from the site 4chan who go by the name 'anonymous'. Many of them consider themselves hackers

LulzSec = A splinter group originating from Anonymous. Consists of a few people who have been attacking sites for fun. Twitter (http://twitter.com/#!/LulzSec).

The Jester = A lone patriotic hacker on a mission to take down LulzSec. Twitter (http://twitter.com/#!/th3j35t3r). Site (http://th3j35t3r.wordpress.com/).

Web Ninjas = A group of unidentified people. Possibly 'double hackers' who are part of another group. They are also on a mission to take down LulzSec. Site (http://lulzsecexposed.blogspot.com/).

Team Poison = A group of hackers also wanting to take down LulzSec. Twitter 1 (http://twitter.com/#!/TeaMp0ison_) and Twitter 2 (http://twitter.com/_TeaMp0ison_).

LulzSec Members

Main:
Sabu (leader) - id supposedly found
Topiary - identified
Kayla - identified
tFlow

Secondary:
Joepie91 - identified
Nakomis - identified
Barret Brown (Good publicity. He is a journalist) - identified
Neuron - identified
Redacted - identified
Avunit
TrollPoll
Storm
Pwnsauce
voodoo
devrandom

More info here (http://lulzsecexposed.blogspot.com/p/team-lulzsec.html).

Sites/Groups Attacked (not in correct order)

Fox (http://linearfix.wordpress.com/2011/05/13/lulzsec-targets-fox-data-again-for-third-phase/)
UK ATMs (http://www.thehackernews.com/2011/05/lulzsec-hack-leak-pointless-atm.html)
PBS (http://www.thetechherald.com/article.php/201122/7215/PBS-LulzSec-attack-an-attempt-to-chill-journalism)
Sony Pictures (http://www.pcmag.com/article2/0,2817,2386362,00.asp)
InfraGard (http://www.trustedreviews.com/news/lulzsec-attack-nintendo-and-fbi-affiliate)
NHS (http://www.techradar.com/news/internet/lulzsec-reveals-nhs-web-security-holes-964323)
US Senate (https://www.infosecisland.com/blogview/14412-LulzSec-Claims-US-Senate-Network-Hack.html)
CIA (http://www.bbc.co.uk/news/technology-13787229)
Nintendo (http://www.trustedreviews.com/news/lulzsec-attack-nintendo-and-fbi-affiliate)
Eve Online (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
Minecraft (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
Bethesda (Brink) (http://www.zdnet.co.uk/news/security-threats/2011/06/14/lulzsec-targets-bethesda-softworks-game-maker-40093100/)
Pron (pron.com and numerous other porn sites) (http://blogs.forbes.com/andygreenberg/2011/06/10/lulzsec-hackers-get-personal-dump-26000-porn-site-usernames-and-passwords/)
The Escapist (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
League of Legends (http://www.joystiq.com/2011/06/14/lulzsec-attacks-escapist-magazine-eve-online-and-minecraft/)
UK Serious Organised Crime Agency (http://www.product-reviews.net/2011/06/21/soca-latest-hack-victims-as-site-is-attacked/)

More info here (http://www.neogaf.com/forum/showpost.php?p=28774985&postcount=10).

FAQ

Why are they doing this?
They claim it's for the lulz and to help corporations improve their security. The truth is that they do it for the money.

OMG! WAS MY DATA STOLEN?
Click here (http://gizmodo.com/5812545/find-out-if-your-passwords-were-leaked-by-lulzsec-right-here) to find out. If your data was stolen, change all your account passwords.

How can I stay safe in the future?
Use a different password and username for each site you use. Also, enable two step authentication for any service that allows it. More info here (http://www.neogaf.com/forum/showthread.php?t=425417).

Other links
Team Poison Joins In (http://www.techieblogie.info/2011/06/team-poison-hacked-lulzsec.html)
19 Year Old Arrested (http://theeword.co.uk/seo-manchester/essex_teenager_arrested_in_hacking_probe.html)
AntiSec Video Overview (http://www.youtube.com/watch?v=3pY1DC9PmYU)
LulzSec Manifesto (http://arstechnica.com/tech-policy/news/2011/06/lulzsec-heres-why-we-hack-you-bitches.ars)
LulzSec Video Overview (http://www.youtube.com/watch?v=udcnlLXUh8E)

credit to Enco from GAF

leemajors
06-22-2011, 12:19 PM
lol no more internet drug buying?

a lot of people on the rogan board just started buying bitcoins to sell them off later since the value skyrocketed. Hope they got out in time.

symple19
06-22-2011, 12:28 PM
maxipad, you do that epic breakdown yourself or did you c/p?


credit to Enco from GAF link?

symple19
06-22-2011, 12:37 PM
anonymous have a "plan"

j_9T1SPJXRI

IronMaxipad
06-22-2011, 12:45 PM
maxipad, you do that epic breakdown yourself or did you c/p?

link?

Nope, c/p from another forum that i post at:
http://www.neogaf.com/forum/showthread.php?t=434859

that's why i put credit to Enco from gaf at the bottom.

symple19
06-22-2011, 12:53 PM
thanks

Creepn
06-23-2011, 03:35 AM
Damn, the Jeter is whooping that ass! That's cool that he makes it a mission to take down radical extremist recruiting sites. Props. :tu

So Lulsec was trying to start some global unified hacker revolt? If so, they fucked up when they started hacking Nintendo and releasing xboxlive information imho. Left a bad taste with that.

symple19
06-23-2011, 01:16 PM
https://www.infosecisland.com/blogview/14706-LulzSec-How-Not-to-Run-an-Insurgency.html#.TgNxjyifa2A.twitter

MannyIsGod
06-23-2011, 06:08 PM
They just released a lot of Arizona law enforcement docs.

LnGrrrR
06-23-2011, 09:57 PM
A PS3 is not necessarily his property though. I'm not a lawyer, so I could be totally wrong, but I thought you were buying a license to use a PS3 per se, and not actually buying the property. While you'll own the hardware, you can't access the PSN with modded hardware as per the license agreement.

So why doesn't Sony just kick them off the PlayStation Network?

I think the whole "You're not buying hardware, you're buying a license to use the hardware as intended" line is complete bullshit.

symple19
06-24-2011, 04:59 AM
Here's some video associated with the Lulzsec hack of AZDPS which was leaked. Don't watch it if you like cops. Very graphic

http://www.liveleak.com/view?i=459_1308898935

A few less doughnuts and he might have made it

lulz

symple19
06-24-2011, 05:07 AM
They just released a lot of Arizona law enforcement docs.

http://www.azcentral.com/news/articles/2011/06/23/20110623lulzsec-hacks-into-arizona-dps-system-abrk23-ON.html#ixzz1QAAc7nov

symple19
06-24-2011, 05:21 AM
Jester took down the lulzsec site this morning and released additional details, including the possible real name/location of Lulzsec leader Sabu

http://www.guardian.co.uk/technology/blog/2011/jun/24/lulzsec-site-down-hacker-jester

symple19
06-24-2011, 09:39 AM
A further breakdown (http://www.boingboing.net/2011/06/23/breaking-lulzsec-lea.html) of some of the leaked info from AZDPS, including tidbits like this:
One document is titled "shootout at a McDonalds," authored by "a California Sergeant."



"I was standing in line and oblivious (like all the other patrons) to the fact that an armed suspect had taken the manager hostage and was forcing her to open the safe in the restaurant's office. One of the cashiers had seen this and I overheard her telling another employee that the business was being robbed.
At that time, I had approximately 15 years of experience and was a SWAT team member and use-of-force/firearms instructor. ... As I was standing near the front counter trying to get some of the kitchen help to get out, the suspect came from the office area and began running in my direction.

I immediately noted the large semi-automatic pistol in his hand. The distance was about 15 to 20 yards. I drew my weapon, announced myself and took a kneeling position behind the counter. Unfortunately, the suspect raised his weapon at me and the gunfight erupted. The suspect fired a total of 2 rounds in my direction. I fired 11, striking him 10 times. ..."

I immediately noticed a small child lying behind me. I saw blood pooling under her head and knew at a glance she was dead. One of the bullets fired at me had struck this child.


"You cannot have the typical police mind-set in an off-duty situation," concludes the sergeant who so artfully avoided saying who fired first in a shootout in the presence of children. " ... I was really worried that one of my own guys might not recognize me. I was worried too that there might be some other off-duty copper around who would think I was the bad guy."

symple19
06-24-2011, 09:43 AM
^^^ so basically the guy was off-duty, in plain-clothes, and would have avoided a dead baby had he not pulled his gun. disgusting.

symple19
06-24-2011, 09:46 AM
fucking cops


A guide to social networking sites cautions officers not to boast about beating arrestees on Facebook, because that may be of use to defense attorneys:


One of the notable postings introduced to the jury was that the officer watched the movie "Training Day" (a motion picture that displayed corrupt police behavior and brutality) to brush up on "proper police procedure. One of his postings said, "If he wanted to tune him up some, he should have delayed cuffing him." In another he added, "If you were going to hit a cuffed suspect, at least get your money's worth 'cause now he's going to get disciplined for a relatively light punch."

Trainwreck2100
06-24-2011, 12:15 PM
^^^ so basically the guy was off-duty, in plain-clothes, and would have avoided a dead baby had he not pulled his gun. disgusting.

fuck that robbers don't get to go free cause there's babies around.

MannyIsGod
06-24-2011, 12:33 PM
fuck that robbers don't get to go free cause there's babies around.

Uh yeah - they do. No fucking child should die over 300 bucks and a big mac.

Trainwreck2100
06-24-2011, 12:46 PM
Uh yeah - they do. No fucking child should die over 300 bucks and a big mac.

cop didn't shoot the kid robber shot the kid.

MannyIsGod
06-24-2011, 12:55 PM
And? The cop made the situation worse. Cop keeps his gun in his holster and the kid is alive. Oh no a fucking junkie robber made off with 300 bucks and a couple of big macs. The kid is dead because the cop made the situation worse because he had to prove he was fucking Rambo. Did you read that he was worried about how he'd look? Fucking jack ass.

Trainwreck2100
06-24-2011, 01:10 PM
And? The cop made the situation worse. Cop keeps his gun in his holster and the kid is alive. Oh no a fucking junkie robber made off with 300 bucks and a couple of big macs. The kid is dead because the cop made the situation worse because he had to prove he was fucking Rambo. Did you read that he was worried about how he'd look? Fucking jack ass.

you mean he was afraid he'd look like a bad guy in front of another off duty cop who would probably not hesitate to shoot what he would have perceived as a kid killer? Yeah what a jackass

IronMaxipad
06-24-2011, 01:38 PM
wait wat? Moving to fast can't keep up with this shit. Will wait for the movie.

redzero
06-24-2011, 01:44 PM
wait wat? Moving to fast can't keep up with this shit. Will wait for the movie.

Cops got into a shootout at lulzsec's top secret compound. Many innocents were caught in the crossfire. :depressed

MannyIsGod
06-24-2011, 01:45 PM
you mean he was afraid he'd look like a bad guy in front of another off duty cop who would probably not hesitate to shoot what he would have perceived as a kid killer? Yeah what a jackass

Oh he was a kid killer before he killed the kid huh? You're fucking stupid if you think its worth it for a kid to die because a McDonalds is getting robbed.

symple19
06-24-2011, 01:51 PM
Cops got into a shootout at lulzsec's top secret compound. Many innocents were caught in the crossfire. :depressed

:lol

Trainwreck2100
06-24-2011, 01:52 PM
Oh he was a kid killer before he killed the kid huh? .

I have no idw as what you are talking about

symple19
06-24-2011, 03:27 PM
anyway, back on track

http://www.zdnet.com/blog/security/lulzsecs-leader-sabu-revealed/8905

symple19
06-25-2011, 05:24 AM
Lulzsec/Anonymous outs the names of 2800 Peruvian special police forces, called the "Black Eagles" http://www.itproportal.com/2011/06/24/latest-lulzsec-anonymous-leak-targets-peruvian-special-police-group/

Meanwhile, TeamPoison leaks info from Tony Blair acquired in 2010

http://news.cnet.com/8301-27080_3-20074224-245/hackers-leak-former-british-pm-tony-blair-data/?tag=mncol;posts

http://pastebin.com/raw.php?i=mn6Dhgcd

symple19
06-25-2011, 05:29 AM
Lulzsec's thoughts on Jester http://pastebin.com/XDXyQ5KQ


Jester responds http://pastebin.com/YnuwarHX

Creepn
06-25-2011, 04:18 PM
Jester took down the lulzsec site this morning and released additional details, including the possible real name/location of Lulzsec leader Sabu

http://www.guardian.co.uk/technology/blog/2011/jun/24/lulzsec-site-down-hacker-jester


Update: The Jester claims he did not take it down. It's another hacker called Oneiroi. Geez... Cyber World War I

This also looks like a gateway for other hackers to openly attack other sites and claim it was lulsec.

symple19
06-26-2011, 04:30 AM
Update: The Jester claims he did not take it down. It's another hacker called Oneiroi. Geez... Cyber World War I

This also looks like a gateway for other hackers to openly attack other sites and claim it was lulsec.

Thanks for clarifying. I noticed that too.

symple19
06-26-2011, 04:34 AM
Lulzsec retiring after 50 days of mayhem: http://pastebin.com/1znEGmHa

Despite their reasoning, I'm guessing it's more to do with other hackers/police agencies getting close.

Or, it could be another joke/attention grab/troll job. We'll see

symple19
06-26-2011, 04:40 AM
A-team does some serious ownage http://pastebin.com/raw.php?i=iVujX4TR


So we've been tracking and infiltrating these kids since the gawker hack. We have the D0x (as they call it)
on everyone except Sabu and Kayla. First we'll go with the kid who did the gawker hack: Uncommon.

the lulz group included a tranny (laurelai) :lmao

Looks like the above is what broke the camel's back. Good reading

symple19
06-26-2011, 04:53 AM
Kinda sad this may be over. Was hugely entertaining.

Anyway, their last leak is outlined here (http://www.rockpapershotgun.com/2011/06/26/lulzsec-over-release-battlefield-heroes-data/#more-63605).


LulzSec, the hacker group who have claimed responsibility for many of the high profile attacks on gaming companies, publishers, and even the CIA, have declared their work is done, their time is up, and they’re off. Apparently it was always intended to be a 50 day voyage aboard their Lulzboat, and it has come to an end. They believe they have revitalised the Antisec Movement, and entertained themselves along the way. Which they claim, albeit in hindsight, was always their goal. But whatever their reasons, their goodbye comes with perhaps their biggest release of data yet. It’s going to be messy. This one contains 550,000 Battlefield Heroes Beta users’ details, and the details of 50,000 users from “random gaming forums”.


Their final statement comes with a final release, and it’s not a happy one for many. It contains the following:

booty/AOL internal data.txt 63.6 KiB
booty/AT&T internal data.rar 314.59 MiB
booty/Battlefield Heroes Beta (550k users).csv 24.67 MiB
booty/FBI being silly.txt 3.82 KiB
booty/Hackforums.net (200k users).sql 111.2 MiB
booty/Nato-bookshop.org (12k users).csv 941.8 KiB
booty/Office networks of corporations.txt 3.87 KiB
booty/Private Investigator Emails.txt 2.52 KiB
booty/Random gaming forums (50k users).txt 6.08 MiB
booty/Silly routers.txt 67.7 KiB
booty/navy.mil owned.png

Here's the torrent link for their final releases: http://thepiratebay.org/torrent/6495523/50_Days_of_Lulz

Some pastebins of said releases

Silly routers:
http://pastebin.com/ennsYDM5

Private Investigators:
http://pastebin.com/BPBAcTxp

FBI Being Silly:
http://pastebin.com/hCnvTy0z

AOL Internal Data:
http://pastebin.com/08zJHQeA

60k of the Battlefield Hero Hashes Cracked
http://pastebin.com/vdYNFWP4
http://pastebin.com/cmjKGfE1
http://pastebin.com/HuiY03WC

10k hackforum hashes cracked
http://pastebin.com/7T9MTUMY

symple19
06-26-2011, 05:46 AM
(Supposedly) A few of the "random gaming sites" from which they harvested user info:

http://www.egamingsupply.com/
http://www.yougamers.com/
http://www.sigames.com/
http://forum.vces.net/

symple19
06-26-2011, 06:00 AM
Here is another resource to check the integrity of your email/password:

https://shouldichangemypassword.com/


ShouldIChangeMyPassword.com has been created to help the average person check if their password(s) may have been compromised and need to be changed.

This site uses a number of databases that have been released by hackers to the public. No passwords are stored in the ShouldIChangeMyPassword.com database.

ElNono
06-26-2011, 11:03 AM
Here is another resource to check the integrity of your email/password:

https://shouldichangemypassword.com/

You're not this dumb, are you?

If you are, please send me all your passwords in a private message. I swear no password will be stored, kthx

symple19
06-26-2011, 12:20 PM
You're not this dumb, are you?

If you are, please send me all your passwords in a private message. I swear no password will be stored, kthx

you don't have to give them your password, genius :lol

symple19
06-26-2011, 12:25 PM
http://webbeat.tv/website-of-the-day-should-i-change-my-password/

you don't give them your password, you just enter your e-mail and it cross references it against databases that have been released by hackers

symple19
06-26-2011, 12:27 PM
http://www.healthypasswords.com/content.How_to_find_out_of_your_password_was_stole n.html

symple19
06-26-2011, 12:35 PM
And here's an article from the NYtimes which also recommends it http://gadgetwise.blogs.nytimes.com/2011/06/23/how-to-know-if-youve-been-hacked/. kthnxbai

MannyIsGod
06-26-2011, 02:20 PM
This shit has just been retarded.

ElNono
06-27-2011, 12:46 AM
http://webbeat.tv/website-of-the-day-should-i-change-my-password/

you don't give them your password, you just enter your e-mail and it cross references it against databases that have been released by hackers

An conveniently adds it to a few select mailing lists :lol