Attacks/Breaches
10/29/2013
09:30 AM
50%
50%

Syrian Hackers Attack Obama's Website

Pro-Syrian regime hackers gain ability to redirect Twitter and Facebook short links because staff failed to use Google two-factor authentication.

The Syrian Electronic Army: 9 Things We Know
(click image for larger view)
The Syrian Electronic Army: 9 Things We Know
The Syrian Electronic Army (SEA) has struck again, this time targeting the BarackObama.com website and related social media accounts.

Rather than being able to directly hack the website, which was used by President Obama for his 2008 and 2012 election campaigns -- and which now supports his presidential agenda -- the Syrian hackers appear to have gained access to a control panel for the ShortSwitch link-shortening service used by the site.

The hackers, who back the regime of Syrian President Bashar al-Assad, altered all of the short links used by Obama's website and social media accounts, redirecting them to a "Syria Facing Terrorism" video on YouTube, which has since been removed. In other words, anyone who clicked on a link in Obama's Twitter feed, which counts 39 million followers, or Facebook page, which has been "liked" 37 million times, would have been redirected to pro-Assad propaganda.

[ Two-factor security can help, but it can pose problems also. Read Twitter Two-Factor Lockout: One User's Horror Story. ]

In keeping with the terrorism theme, the hackers tweeted from the @Official_SEA16 Twitter account Monday: "We accessed many Obama campaign emails accounts to assess his terrorism capabilities. They are quite high." They added: "Obama doesn't have any ethical issues with spying on the world, so we took it upon ourselves to return the favor."

The SEA apparently gained access to the ShortSwitch account tied to Obama's site by first hacking into multiple Gmail accounts used by Organizing for Action (OFA), a nonprofit that advocates for Obama's agenda and also maintains the BarackObama.com website. The Gmail hacking victims included the OFA's Suzanne Snurpus, who's the site administrator.

A self-proclaimed SEA spokesman confirmed Monday that the hackers obtained the ShortLink account credentials from OFA staff members' Gmail accounts. "As you might expect all the necessary information was in their emails," he told Mashable. "They didn't even enabled [sic] two-step verification." That's a reference to Google's two-factor authentication system, which would have blocked the attackers from hijacking the victims' Gmail accounts.

The OFA's Snurpus confirmed to Quartz that her Google account -- together with "lots" of her fellow volunteers -- had been compromised, but said they had regained control of their accounts. "We've all changed our passwords and added an extra layer of login security," she said.

OFA officials have said that the SEA never had direct access to Obama's Facebook page or Twitter feeds.

The SEA's hack of the Obama website and social media accounts recalls its takedown of satirical news site The Onion. In that case, the SEA sent emails containing links to purported news stories, but which really lead to a fake site that requested the viewer's Google Apps credentials to log in. Falling for the ruse, however, simply gifted related access credentials to the SEA, which ultimately seized control of The Onion's Twitter feed and posted hoax messages.

Security experts said that in both cases, the moral of the story is to always activate Google's two-factor authentication, which is free. "Two-factor authentication for email is an important security feature that should be enabled," according to a blog post from Symantec. "Two-factor authentication would have helped the staff members of OFA mitigate an attempt by hackers to obtain access to the Obama campaign's Google Apps email account." It added that "Google Apps administrators also have the option to 'enforce' two-factor authentication, making it mandatory for all users of that domain."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1449
Published: 2014-12-25
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.

CVE-2014-2217
Published: 2014-12-25
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

CVE-2014-3971
Published: 2014-12-25
The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote attackers to cause a denial of service (daemon crash) by attempting authentication with an invalid X.509 client certificate.

CVE-2014-7193
Published: 2014-12-25
The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site ...

CVE-2014-7300
Published: 2014-12-25
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.