Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Suspected Child Porn Hub Taken Offline
Newest First  |  Oldest First  |  Threaded View
RetiredUser
RetiredUser,
User Rank: Ninja
6/13/2014 | 3:28:38 PM
re: Suspected Child Porn Hub Taken Offline
@StygianAgenda

 I couldn't agree with you more.  And I also feel it is our responsibility as denizens of that "underground" to keep watch, to be our "brother's keeper".  Imagine how many hackers knew about the activities documented here, or had knowledge of the possibility of them, and yet did nothing to tip someone off about it.  As hacktivists, it is a duty to protect those who have no defense, and get rid of the bad fruit.  As I've noted before hacker culture often is more effective at dealing with issues like this than law enforcement or government agencies ever will be.  We simply need to ability to do it without fear of repercussions...
StygianAgenda
StygianAgenda,
User Rank: Strategist
4/16/2013 | 2:14:25 PM
re: Suspected Child Porn Hub Taken Offline
<quote>"Chances are the criminals will simply find move their operations elsewhere. But the shutdown is still a very positive step; anything we can do to disrupt the computer underground's activities has to be good for all of us."</quote>

While you're not wrong about the fact that criminals will simply move their ops elsewhere, and the shutdown of "Pricewert" *is* without a doubt a good thing, I take issue with your statement regarding "anything we can do to disrupt the computer underground's activities has to be good for all of us".-

I couldn't disagree more. -The so-called "computer underground", as you put it, is the epicenter of all cyber defense, as well as cyber offense. -Many of the most accomplished ethical hackers worldwide... those of us who make our careers by securing enterprise networks, got their start in the DarkNets, which is the core of the so-called "computer underground".

The DarkNets... or as you eloquently referred to them as the "computer underground", are populated by denizens ranging from hackers associated with Anonymous, LulzSec, as well as civilian law enforcement, military network security, and ethical hackers of many varying backgrounds. -As an ethical hacking student, there's no better place to get an education in 'what's really going on' than in the DarkNets. -So, your supposition that disrupting the "computer underground" is a good thing, is naive at best, and a heinous lie / misinformation at worst. -

With Tor, Freenet, I2P and several other DarkNet client/server-ware being open source, it's now impossible to stop this movement, especially in consideration of the fact that an instance of the Tor engine can be installed on several different embedded platforms (such as Raspberry Pi) and made into what is now referred to as a ShadowNet, which is basically an anonymized, encrypted DarkNet relay/entry-node/exit-node that can be combined with solar power and be-resilient-to being taken down, because these nodes can be attached to a telephone pole, ceiling tile, or any other place one can think of. -

What we have here is a "chicken or the egg" situation, where commodity hardware is being used for various, sometimes highly illegal purposes, to create a network that cannot be taken offline because the hardware cannot be located by anyone other than the person that has deployed it, or anyone that has been directly informed of the location. -Some of these nodes have been reported to be used to attach to unsecured WiFi, or hacked WiFi systems, and since all traffic to or from these nodes is randomly bouncing around the planet, it's (nearly) impossible to pin down exactly where one is deployed. -Without those of us that learn from the DarkNet security communities, there would be no real defense against these next generation threats whatsoever. -

Imagine for a moment that you went to work for an intelligence agency as a field operative. -How far do you think you would get using nothing but officially sanctioned training? -Not very far at all, I'd bet, because when you're dealing the world "as it really is", there's no manual, it's gritting, dirty, sometimes bloody, and yes... for a large part, underground. -To get an idea of the truth of this, read into both sides of "#OP-DarkNet", both from the perspective of Anonymous, and from the perspective of the pedo-site-OPs that have been their targets.... Anonymous has not been actually anywhere near as successful as they have claimed, and in many cases, the only way they've succeeded at all is not due to hacking techniques, or system-security weaknesses... it's most often due to the human element, and a bit of creative Open Source Intel Gathering techniques. -Successful or not, compare their record against, say.. the US-DOJ who have stated to the Senate Judiciary Committee that "The Silk Road" is impossible to take down, and it's easy to see where they've gotten a lot farther in less time... all thanks to ... ((insert drum roll))... -"The Computer Underground", as you called it.

Maybe I should be writing for DarkReading.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Improving Enterprise Cybersecurity With XDR
Enterprises are looking at eXtended Detection and Response technologies to improve their abilities to detect, and respond to, threats. While endpoint detection and response is not new to enterprise security, organizations have to improve network visibility, expand data collection and expand threat hunting capabilites if they want their XDR deployments to succeed. This issue of Tech Insights also includes: a market overview for XDR from Omdia, questions to ask before deploying XDR, and an XDR primer.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-2288
PUBLISHED: 2022-07-03
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
CVE-2022-2290
PUBLISHED: 2022-07-03
Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.
CVE-2022-2287
PUBLISHED: 2022-07-02
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVE-2022-34911
PUBLISHED: 2022-07-02
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to &quot;Welcome&quot; followed by the username, the usern...
CVE-2022-34912
PUBLISHED: 2022-07-02
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.