Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

LulzSec Signs Off, But Attacks Don't -- And Won't -- Stop

Anonymous dumps new round of passwords, corporate network IP addresses

Jun 27, 2011 | 04:49 PM | 

By Kelly Jackson Higgins
Dark Reading
The LulzSec hacker group signed off over the weekend after 50 days of publicly wreaking havoc on a wide range of victims, from Sony to the CIA. But the attacks are far from over.

Anonymous -- the group from which LuzSec spun off -- late today dumped what appeared to be close to 90 stolen internal corporate network IP address blocks onto Pastebin, including those of Disney, Viacom, and Sony, as well as pilfered usernames, email addresses, and password hashes of more than 500 users. The group also warned that it will announce an even bigger hack later today.

Meanwhile, LulzSec's announcement that it shut down might not mean much in the long run. Anonymous today was basically picking up where the splinter group had left off, with an active Twitter feed via its AnonymousIRC account. "We like to clarify again: All LulzSec members are accounted for, nobody is hiding. Only a name was abandoned for the greater glory #AntiSec."

Security experts speculated that individuals associated with LulzSec were facing exposure or potential arrest in the wake of the arrest of Ryan Cleary, the U.K. teenager who allegedly ran an IRC channel used by LulzSec members, and the high-profile targets they had hit recently -- the CIA, Infragard, and Arizona police. Another theory: They are just moving their efforts under the AntiSec or Anonymous banners and taking on a lower profile. Or it could all be a hoax meant to grab media attention, expert say.

Karim Hijazi, founder at Unveillance, whose company was targeted by LulzSec last month, says whatever the reason for the LulzSec departure, even if the announcement is just a hoax, the group has left an impression. "I still think that they have created a substantial impact on the public and have them thinking that they can hack behind some popped proxies, a few free VPNs, and get away unscathed. Well, at least for the moment," Hijazi says.

Researchers at Imperva, who have been closely studying and profiling LulzSec membership, today said that LulzSec's demise was "inevitable." "During this week they tried to cover up themselves in order to avoid arrest by: regrouping with anonymous; creating the ‘antisec’ operation; and falsely claiming the UK census was hacked as a “red herring," blogged Imperva's Rob Rachwald.

Joshua Perrymon, a researcher and CEO of PacketFocus, says LulzSec initially broke off from Anonymous so its attacks wouldn't appear to be coming from Anonymous. He expects more splinter groups to help keep Anonymous going: "But it’s the same guys, and they just made up Lulz. What we will see is them making up new group names, then doing a bunch of hacks, then shutting down. But they are all still a part of Anonymous groups as a whole," Perrymon says.

When LulzSec attracted too much attention and law enforcement heat, they just folded back into Anonymous and AntiSec, he says.

LulzSec's farewell message over the weekend urged others to keep up the attacks. "We hope, wish, even beg, that the movement manifests itself into a revolution that can continue on without us. The support we've gathered for it in such a short space of time is truly overwhelming, and not to mention humbling. Please don't stop. Together, united, we can stomp down our common oppressors and imbue ourselves with the power and freedom we deserve," the post said.

LulzSec also reiterated its intent to "entertain" with its disclosures: "For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could. All to selflessly entertain others - vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. The raw, uninterrupted, chaotic thrill of entertainment and anarchy," the group's posting said.

One of LulzSec's final acts was the breach of more than 11,000 users and passwords on the North Atlantic Treaty Organization (NATO) e-bookstore.

In an interview earlier this month, Marcus Ranum, CTO at Tenable Security, said there appears to be a trend of these hactivist hacker groups popping up. "I find it fascinating," Ranum says. "I'm a little bit of an anti-government [person]. With the activity that I watch surrounding Anonymous, I honestly wonder if this is the early stages of backlash against government powers intruding further into cyberspace."

LulzSec had an anti-authoritarian ideology, but it wasn't well-articulated, he says. And going after the FBI's Infragard site might have been a bit too bold: "Tweaking the FBI's nose is probably asking for an over-the-top response," he says. Even so, the takeaway from the LulzSec and Anonymous hacks is that it should be a wake-up call for any business only "doing PCI stuff."

"If someone really talented goes after you, they will burn through your security," Ranum says.

Whether law enforcement is able to catch LulzSec or Anonymous members is the question, and experts say their copycat and splinter groups will keep emerging. The bottom line is that Anonymous has been and will continue to be a moving target as its membership ebbs and flows, depending on its latest target. A tweet earlier today from the AnonymousIRC account basically said as much: "Dear Media: This account is NOT Anonymous as a whole. That is impossible. We are merely an observer who reports current events. Please note."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Database Security Reports

report Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.

report Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.

report Stop SQL Injection: Don't Let Thieves in Through Your Web Apps
Think your corporate website isn't vulnerable to a SQL injection attack? Start rethinking. SQL injection is among the most prevalent -- and most dangerous -- techniques for exploiting Web applications and attacking back-end databases that house critical business information at companies of every size. And it persists despite relatively simple and effective countermeasures. Here, we explain how SQL injection works, and how to secure your Web apps and databases against it.

Other reports from the Database Security Tech Center:

Related Content

Data security and privacy: A holistic approach
This paper examines the complex data security and privacy threat landscape; compliance and regulatory requirements; and, the IBM InfoSphere portfolio of integrated solutions designed to help you stay focused on meeting your organization's business goals, achieving compliance and reducing risk. IBM InfoSphere solutions for data security and privacy support a holistic approach ensuring the protection and integrity of your data.

Ten Database Activities Enterprises Need to Monitor
Enterprises are paying too little attention to security risks associated with their databases. Auditors, security/risk professionals and data owners need to watch for behaviors that may indicate database security problems. Learn the 10 critical database activities & behaviors enterprises should audit now.

The Forrester Wave: Database Auditing And Real-Time Protection
Database auditing has become critical as enterprises deal with regulatory compliance and security requirements. Learn why Forrester Research named IBM InfoSphere Guardium a Leader with #1 scores in all 3 top-level categories: Current Offering, Strategy and Market Presence.

Look Beyond Native Database Auditing to Improve Database Security
This Forrester Consulting study provides real-world findings from in-depth interviews with enterprises that have implemented database auditing and real-time protection solutions to ensure comprehensive auditing, real-time monitoring and protection of critical database and enterprise applications from internal and external attacks.

HOWTO Safeguard Against the Latest Cyber-Threats
2010 saw 27% rise in new vulnerabilities with the largest category being Web Application vulnerabilities. Tom Cross discusses these security events from the "IBM X-Force 10 Trend and Risk Report." Learn more about APTs, virtualization and cloud security threats.