Attacks/Breaches
3/18/2013
12:25 PM
Connect Directly
RSS
E-Mail
50%
50%

Anonymous Investigators Probe Reuters Reporter, Sabu

Feds indict Reuters social media editor for allegedly helping hacktivist group Anonymous -- and LulzSec leader Sabu -- deface the Los Angeles Times website.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Reuters employee Matthew Keys, 26, was indicted Thursday by a federal grand jury for allegedly enabling the hacktivist group Anonymous to hack into the computers of Tribune Co.

According to the indictment, Keys, formerly a Web producer for Tribune Co.-owned television station KTXL Fox 40 in Sacramento, Calif., shared a username and password with members of Anonymous, which enabled them to log onto Tribune's content management system (CMS) and change a Los Angeles Times news story.

But Keys' attorney, Jay Leiderman, told The Huffington Post that his client was working undercover while reporting a story. "This is sort of an undercover-type, investigative journalism thing, and I know undercover -- I'm using that term loosely," he said. "This is a guy who went where he needed to go to get the story. He went into the sort of dark corners of the Internet. He's being prosecuted for that, for going to get the story."

[ Who hacked Michelle Obama? Read Celeb Data Breach Traced To Credit Reporting Site. ]

Prosecutors, however, alleged that Keys' actions went beyond reporting, and charged him with three criminal accounts: conspiracy to damage a protected computer, transmission of malicious code -- or information that could be used for such a purpose -- and attempted transmission of malicious code. The three charges together carry a maximum penalty of 25 years imprisonment and $750,000 in fines.

According to chat logs cited in the indictment, someone using the nickname "AESCracked" in December 2010 told participants in the #InternetFeds IRC channel -- Internet Feds was a precursor to LulzSec and Anonymous, and members of those groups as well as AntiSec and Gnosis frequented the channel -- who had expressed a desire to access a Fox website, that he was a former Tribune employee. He later shared a working username ("anon1234") and password with members of the IRC channel, then told them to "go [expletive] some [expletive] up."

When told that the Los Angeles Times had been defaced, AESCracked replied, "nice," according to a Department of Justice statement.

After Tribune canceled the anon1234 account -- less than a half hour after it was used -- a user nicknamed "sharpie" asked AESCracked via the #InternetFeds IRC channel for more usernames and passwords, to continue the defacement campaign. "Let me see if I can find some other users/pass I created while there," said AESCracked. "It takes a while to grant one username permission to every site. I'm doing that now," he said, apparently referring to Tribune using the same content management system for both the Los Angeles Times and Fox 40.

The indictment alleged that Keys was AESCracked. Sharpie, meanwhile, turned out to be one of the nicknames used by Hector Xavier Monsegur, a.k.a. LulzSec leader Sabu, who was arrested by the FBI in June 2012 and turned informer.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.