Vulnerabilities / Threats
2/28/2013
10:16 AM
50%
50%

Anonymous: 10 Things We've Learned In 2013

The Anonymous hacker group continues to seek equal measures of revenge, justice and reform -- preferably through chaotic means -- for perceived wrongdoings.
Previous
4 of 10
Next


Largely, however, Anonymous stays on the offensive. Indeed, this week, Anonymous also announced that it had discovered a hacker-profiling operation being run by Bank of America (BoA).

"Has mummy ever said dont play with Anonymous???" read a subsequent release from Anonymous of what the group said was 320 MB of data amassed by Allegio Group subsidiary TEKsystems. In short order, Anonymous then released, via the Par:anoia website, what it said was "a total of 14 GB [of] data, code and software that is related to Bank of America, Bloomberg, Thomson Reuters, TEKSystems and ClearForest."

"It shows that Bank of America and others are contracting other companies to spy and collect information on private citizens," according to an overview published on that site.

"Looking at the data it becomes clear that Bank of America, TEKSystems and others ... gathered information on Anonymous and other activists' movement on various social media platforms and public Internet Relay Chat (IRC) channels," it said.

Despite the data dox, an Anonymous channel on Twitter promised that the attack was centered on revenge, rather than compromising customer data or committing identity theft. "No Bank of America customer information was viewed or published at any time," it said.

Photo courtesy of Flickr user Todd Blaisdell.

RECOMMENDED READING:

Anonymous Plays Games With U.S. Sites

Hacking, Privacy Laws: Time To Reboot

Anonymous Claims Wall Street Data Dump

Anonymous Takes On State Department, More Banks

Anonymous Says DDoS Attacks Like Free Speech

U.S. Bank Hack Attack Techniques Identified

Bank Attacker Iran Ties Questioned By Security Pros

Anonymous DDoS Attackers In Britain Sentenced

Previous
4 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:38:40 PM
re: Anonymous: 10 Things We've Learned In 2013
eslamp 248
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:38:29 PM
re: Anonymous: 10 Things We've Learned In 2013
top covere pix
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:38:11 PM
re: Anonymous: 10 Things We've Learned In 2013
my friends
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:36:39 PM
re: Anonymous: 10 Things We've Learned In 2013
eslampop785
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:36:30 PM
re: Anonymous: 10 Things We've Learned In 2013
eslampop
EslamP248
50%
50%
EslamP248,
User Rank: Apprentice
8/15/2013 | 10:14:14 PM
re: Anonymous: 10 Things We've Learned In 2013
facebook
majenkins
50%
50%
majenkins,
User Rank: Apprentice
4/24/2013 | 5:10:14 PM
re: Anonymous: 10 Things We've Learned In 2013
Revenge yes, justice only their own eyes, and reform only to remake the world to comform their ideas.
PJS880
50%
50%
PJS880,
User Rank: Ninja
3/14/2013 | 11:12:35 PM
re: Anonymous: 10 Things We've Learned In 2013
Great article but I have to agree with Leo, I dislike reading these articles for that reason alone. All though the topics are of interest, I donGÇÖt have the patience. I also have to disagree with Jonathan on his views on people and their awareness about their online security. I believe because of all the attacks and breeches and the general publicGÇÖs knowledge is constantly increasing, which was the exact opposite in the past.

Paul Sprague
InformationWeek Contributor
Jonathan_Camhi
50%
50%
Jonathan_Camhi,
User Rank: Apprentice
3/5/2013 | 9:47:33 PM
re: Anonymous: 10 Things We've Learned In 2013
I hadn't heard of this Rustle League incident before. Hackers hacking hackers. I wonder if all of the news surrounding hacking and cybercrime lately could put a big enough dent in people's trust in the internet to actually change people's behavior. Will people start taking their individual online security more seriously? Personally, I doubt it. I feel like we have already developed a sort of blind trust in the internet because it makes our lives so convenient that we don't even want to consider what would happen if our online credentials were compromised.
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
3/3/2013 | 8:54:42 PM
re: Anonymous: 10 Things We've Learned In 2013
Information Week only had one important New Year's Resolution this year. '"No Slide Show Articles with out a prominent 'View-as-one-page' link." How's that working out for you so far?
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.