Attacks/Breaches
3/18/2013
12:25 PM
50%
50%

Anonymous Investigators Probe Reuters Reporter, Sabu

Feds indict Reuters social media editor for allegedly helping hacktivist group Anonymous -- and LulzSec leader Sabu -- deface the Los Angeles Times website.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Reuters employee Matthew Keys, 26, was indicted Thursday by a federal grand jury for allegedly enabling the hacktivist group Anonymous to hack into the computers of Tribune Co.

According to the indictment, Keys, formerly a Web producer for Tribune Co.-owned television station KTXL Fox 40 in Sacramento, Calif., shared a username and password with members of Anonymous, which enabled them to log onto Tribune's content management system (CMS) and change a Los Angeles Times news story.

But Keys' attorney, Jay Leiderman, told The Huffington Post that his client was working undercover while reporting a story. "This is sort of an undercover-type, investigative journalism thing, and I know undercover -- I'm using that term loosely," he said. "This is a guy who went where he needed to go to get the story. He went into the sort of dark corners of the Internet. He's being prosecuted for that, for going to get the story."

[ Who hacked Michelle Obama? Read Celeb Data Breach Traced To Credit Reporting Site. ]

Prosecutors, however, alleged that Keys' actions went beyond reporting, and charged him with three criminal accounts: conspiracy to damage a protected computer, transmission of malicious code -- or information that could be used for such a purpose -- and attempted transmission of malicious code. The three charges together carry a maximum penalty of 25 years imprisonment and $750,000 in fines.

According to chat logs cited in the indictment, someone using the nickname "AESCracked" in December 2010 told participants in the #InternetFeds IRC channel -- Internet Feds was a precursor to LulzSec and Anonymous, and members of those groups as well as AntiSec and Gnosis frequented the channel -- who had expressed a desire to access a Fox website, that he was a former Tribune employee. He later shared a working username ("anon1234") and password with members of the IRC channel, then told them to "go [expletive] some [expletive] up."

When told that the Los Angeles Times had been defaced, AESCracked replied, "nice," according to a Department of Justice statement.

After Tribune canceled the anon1234 account -- less than a half hour after it was used -- a user nicknamed "sharpie" asked AESCracked via the #InternetFeds IRC channel for more usernames and passwords, to continue the defacement campaign. "Let me see if I can find some other users/pass I created while there," said AESCracked. "It takes a while to grant one username permission to every site. I'm doing that now," he said, apparently referring to Tribune using the same content management system for both the Los Angeles Times and Fox 40.

The indictment alleged that Keys was AESCracked. Sharpie, meanwhile, turned out to be one of the nicknames used by Hector Xavier Monsegur, a.k.a. LulzSec leader Sabu, who was arrested by the FBI in June 2012 and turned informer.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.