Attacks/Breaches
3/18/2013
12:25 PM
50%
50%

Anonymous Investigators Probe Reuters Reporter, Sabu

Feds indict Reuters social media editor for allegedly helping hacktivist group Anonymous -- and LulzSec leader Sabu -- deface the Los Angeles Times website.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Reuters employee Matthew Keys, 26, was indicted Thursday by a federal grand jury for allegedly enabling the hacktivist group Anonymous to hack into the computers of Tribune Co.

According to the indictment, Keys, formerly a Web producer for Tribune Co.-owned television station KTXL Fox 40 in Sacramento, Calif., shared a username and password with members of Anonymous, which enabled them to log onto Tribune's content management system (CMS) and change a Los Angeles Times news story.

But Keys' attorney, Jay Leiderman, told The Huffington Post that his client was working undercover while reporting a story. "This is sort of an undercover-type, investigative journalism thing, and I know undercover -- I'm using that term loosely," he said. "This is a guy who went where he needed to go to get the story. He went into the sort of dark corners of the Internet. He's being prosecuted for that, for going to get the story."

[ Who hacked Michelle Obama? Read Celeb Data Breach Traced To Credit Reporting Site. ]

Prosecutors, however, alleged that Keys' actions went beyond reporting, and charged him with three criminal accounts: conspiracy to damage a protected computer, transmission of malicious code -- or information that could be used for such a purpose -- and attempted transmission of malicious code. The three charges together carry a maximum penalty of 25 years imprisonment and $750,000 in fines.

According to chat logs cited in the indictment, someone using the nickname "AESCracked" in December 2010 told participants in the #InternetFeds IRC channel -- Internet Feds was a precursor to LulzSec and Anonymous, and members of those groups as well as AntiSec and Gnosis frequented the channel -- who had expressed a desire to access a Fox website, that he was a former Tribune employee. He later shared a working username ("anon1234") and password with members of the IRC channel, then told them to "go [expletive] some [expletive] up."

When told that the Los Angeles Times had been defaced, AESCracked replied, "nice," according to a Department of Justice statement.

After Tribune canceled the anon1234 account -- less than a half hour after it was used -- a user nicknamed "sharpie" asked AESCracked via the #InternetFeds IRC channel for more usernames and passwords, to continue the defacement campaign. "Let me see if I can find some other users/pass I created while there," said AESCracked. "It takes a while to grant one username permission to every site. I'm doing that now," he said, apparently referring to Tribune using the same content management system for both the Los Angeles Times and Fox 40.

The indictment alleged that Keys was AESCracked. Sharpie, meanwhile, turned out to be one of the nicknames used by Hector Xavier Monsegur, a.k.a. LulzSec leader Sabu, who was arrested by the FBI in June 2012 and turned informer.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVE-2014-9709
Published: 2015-03-30
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.