Attacks/Breaches
3/18/2013
12:25 PM
50%
50%

Anonymous Investigators Probe Reuters Reporter, Sabu

Feds indict Reuters social media editor for allegedly helping hacktivist group Anonymous -- and LulzSec leader Sabu -- deface the Los Angeles Times website.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Reuters employee Matthew Keys, 26, was indicted Thursday by a federal grand jury for allegedly enabling the hacktivist group Anonymous to hack into the computers of Tribune Co.

According to the indictment, Keys, formerly a Web producer for Tribune Co.-owned television station KTXL Fox 40 in Sacramento, Calif., shared a username and password with members of Anonymous, which enabled them to log onto Tribune's content management system (CMS) and change a Los Angeles Times news story.

But Keys' attorney, Jay Leiderman, told The Huffington Post that his client was working undercover while reporting a story. "This is sort of an undercover-type, investigative journalism thing, and I know undercover -- I'm using that term loosely," he said. "This is a guy who went where he needed to go to get the story. He went into the sort of dark corners of the Internet. He's being prosecuted for that, for going to get the story."

[ Who hacked Michelle Obama? Read Celeb Data Breach Traced To Credit Reporting Site. ]

Prosecutors, however, alleged that Keys' actions went beyond reporting, and charged him with three criminal accounts: conspiracy to damage a protected computer, transmission of malicious code -- or information that could be used for such a purpose -- and attempted transmission of malicious code. The three charges together carry a maximum penalty of 25 years imprisonment and $750,000 in fines.

According to chat logs cited in the indictment, someone using the nickname "AESCracked" in December 2010 told participants in the #InternetFeds IRC channel -- Internet Feds was a precursor to LulzSec and Anonymous, and members of those groups as well as AntiSec and Gnosis frequented the channel -- who had expressed a desire to access a Fox website, that he was a former Tribune employee. He later shared a working username ("anon1234") and password with members of the IRC channel, then told them to "go [expletive] some [expletive] up."

When told that the Los Angeles Times had been defaced, AESCracked replied, "nice," according to a Department of Justice statement.

After Tribune canceled the anon1234 account -- less than a half hour after it was used -- a user nicknamed "sharpie" asked AESCracked via the #InternetFeds IRC channel for more usernames and passwords, to continue the defacement campaign. "Let me see if I can find some other users/pass I created while there," said AESCracked. "It takes a while to grant one username permission to every site. I'm doing that now," he said, apparently referring to Tribune using the same content management system for both the Los Angeles Times and Fox 40.

The indictment alleged that Keys was AESCracked. Sharpie, meanwhile, turned out to be one of the nicknames used by Hector Xavier Monsegur, a.k.a. LulzSec leader Sabu, who was arrested by the FBI in June 2012 and turned informer.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4692
Published: 2015-07-27
The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.

CVE-2015-1840
Published: 2015-07-26
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space cha...

CVE-2015-1872
Published: 2015-07-26
The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via craft...

CVE-2015-2847
Published: 2015-07-26
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.

CVE-2015-2848
Published: 2015-07-26
Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!