Attacks/Breaches
2/6/2012
12:17 PM
Connect Directly
RSS
E-Mail
50%
50%

Who Is Anonymous: 10 Key Facts

Anonymous 'hacktivists' aim to expose what they call government and establishment hypocrisy. Take a closer look at the group, its offshoots, and its infamous attacks.
Previous
3 of 10
Next


One of the most fascinating chapters in Anonymous history concerned Aaron Barr, the CEO of HBGary Federal, who'd bragged about how he'd infiltrated Anonymous, and was set to reveal the identities of its key leaders. Anonymous responded by hacking into HBGary's email server less than 24 hours later, and claimed that a 16-year-old girl had socially engineered the social-media-friendly Barr. Anonymous (including future LulzSec leader Sabu, the rumor goes) then released a slew of emails claiming that HBGary had been retained by Bank of America--on the recommendation of the Department of Justice--to help it wage an anti-WikiLeaks campaign, after the whistle-blowing website claimed to have damning emails about the bank's practices. Other emails, meanwhile, detailed secret cyber-warfare tool-building programs, as well as legally questionable activities. Barr, meanwhile, cancelled his appearance on a DefCon July 2011 panel titled "Whoever Fights Monsters: Aaron Barr, Anonymous, and Ourselves."

Photo: Day 9 Occupy Wall Street September 25 2011 by David Shankbone, Flickr. Used with permission via a Creative Commons license.

RECOMMENDED READING

Black Hat Pwnies Nominate LulzSec, Anonymous

LulzSec Hackers Retire: Time To Rethink Risk

Cracking Bin Laden's Hard Drives

14 Enterprise Security Tips From Anonymous Hacker

Twitter Must Turn Over Records In Wikileaks Case

Previous
3 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
rjones2818
50%
50%
rjones2818,
User Rank: Moderator
5/22/2012 | 7:05:52 PM
re: Who Is Anonymous: 10 Key Facts
Interesting article. The Guy Fawkes mask idea is from the graphic novel for 'V for Vendetta' by Alan Moore and David Lloyd.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.