Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

LulzSec's Top 3 Hacking Tools Deconstructed

Analysis suggests LulzSec was most effective using a relatively unknown vulnerability to launch large-scale, botnet-driven attacks against everyone from Sony to the Senate.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
In its 50-day hacking spree, how did the hacking group known as LulzSec manage to break into so many websites?

All told, the group appears to have relied heavily on three attack techniques: using remote file include (RFI), SQL injections, and cross-site scripting. That's according to an analysis conducted by data security vendor Imperva, which studied the leaked LulzSec IRC chat logs recently published by the Guardian.

Interestingly, according to the Open Web Application Security Project's list of the top 10 biggest application security risks, injection attacks and cross-site scripting, respectively, placed first and second. These vulnerabilities, furthermore, have been extensively analyzed and detailed by security experts.

But RFI--a "not widely discussed" type of attack, according to Imperva--is a different story. According to the leaked chat logs, LulzSec member Kayla said that he or she "used to load about 8,000 RFI with usp flooder crushed most server."

"Remember that [it's] Kayla who brought a bot army to Lulsec's toolbox," said Rob Rachwald, director of security strategy at Imperva, in a blog post. "In other words, Lulzsec used an often overlooked vulnerability to help ambush their targets."

What's an RFI attack? "An RFI attack inserts some nasty code into a Web application server," he said. "What does the code do? Usually, RFI is used to take over the Web application and steal data. In the case of Lulzsec, they used it to conduct DDoS attacks."

Based on the chat logs, Kayla had 8,000 infected servers at his or her disposal. "That's pretty sizable," said Rachwald. Furthermore, just one infected server, given its relatively large throughput, can equal about 3,000 bot-infected PCs, meaning that Kayla's botnet could have equaled the power of one with about 24 million PCs. Notably, this was the botnet used to launch the DDoS attack against the CIA's public website.

Regardless of the techniques used by LulzSec, the companies and organizations it hacked--ranging from Sony to the U.S. Senate--faced a similar end result. Namely, LulzSec gained access to their servers, then published sensitive information. But had those organizations taken better security precautions, LulzSec may have moved on to easier pickings.

Last month, a message on the official LulzSec Twitter feed announced that after a 50-day hacking spree, its members were moving on. But understanding how its attacks succeeded is useful information for avoiding similar attacks in the future.

Notably, the #AntiSec effort to publish sensitive business and government secrets, launched by the Anonymous hacking collective and LulzSec (which sprang from Anonymous), has carried on. In fact, #AntiSec recently claimed responsibility for publishing information it obtained in separate attacks against Viacom, Vivendi SA's Universal Music Group, as well as the Arizona Department of Public Safety.

Security monitoring, incident response, and forensics are essential, even in the cloud. But the cloud by definition implies relinquishing at least some control, which can make these practices problematic. In this report, we identify the challenges of detecting and responding to security issues in the cloud and discuss the most effective ways to address them. Download our report now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RWISELY520
50%
50%
RWISELY520,
User Rank: Apprentice
3/17/2012 | 2:37:47 PM
re: LulzSec's Top 3 Hacking Tools Deconstructed
So true. More hacking tools: www.ubers.org
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...
CVE-2020-25791
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with unit().
CVE-2020-25792
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with pair().
CVE-2020-25793
PUBLISHED: 2020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with From<InlineArray<A, T>>.