Threat Intelligence

2/9/2017
10:30 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

When Hackers Hack Hackers

Notable cases of internecine cyber squabbles.
Previous
1 of 9
Next

Image Source: Adobe Stock

Image Source: Adobe Stock

While most cybercriminals tend to set their sights on siphoning valuable data from poorly protected enterprises, there's no limit to the kinds of targets they'll seek out. There's no honor among thieves, so it shouldn't be a surprise that with the right kind of motivation, malicious hackers will happily attack other black hat and grey hat hackers.

Sometimes the attacks are purely mercenary: rivals know they can hit pay dirt very quickly if they find an easy way to tap into data stores of already vetted stolen identities or financial information. Similarly, certain kinds of cyber skirmishes are initiated to take competitors out. And then there are the attacks that are a little more personal: to show someone up, settle a score, or otherwise make a philosophical stand.

Regardless of the motives, these kind of squabbles offer up a satisfying dose of schadenfreude for cybersecurity pros beleaguered by the bad guys. It's nice to watch them fight amongst themselves every once in a while. So, pull up a chair, grab some popcorn and read on. 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
mikeroch
100%
0%
mikeroch,
User Rank: Apprentice
2/15/2017 | 8:13:56 AM
Re: More Interesting than a Standard Exploit 192.168.1.1
Hello sir, I am absolutely agree with your saying, it is the stuff that shows human tendency, the rivalry between hackers and a piece of show off can also lead to such happenings, where hackers hack hackers.
alphaa10
100%
0%
alphaa10,
User Rank: Strategist
2/11/2017 | 6:48:41 AM
More Interesting than a Standard Exploit Story
As expected, hacker warfare demonstrates only the human tendency for turf-building and defense. What should be great consolation to civilians already hit by hackers is realization even the worst criminal operators are vulnerable, at some point, to some degree. All it takes is a persistent probe, and the rest is literally to worm through the defense perimenter.

The security story of the decade is the massive array of national resources around the world now devoted to state actor exploits-- both leading them and defending against them. By no accident, the NSA just expanded facilities with an architectural antitheis to its inscrutably dark monolith of a building in DC. The new NSA complex, located in the Utah desert, and entirely reflective white, is a virtual black hole for the world's data.

This article is a fresh perspective, but its tedious slide show format should be outlawed. When we readers see the tell-tale slide navigation controls, we already have been negatively conditioned by other slide shows. The fact we read the story, anyway, means your actual reader interest might double with a normal, single "page" article. (Yes, of course, we promise to read and click each ad-- just set them aside for us in a corner.)

Appreciate the links-- that saves us rediscovery, and a lot of time. Besides, DR sometimes offers a unique, gem of a link to richer material-- which is actually likely, since there is simply too much of the stuff to read with the same depth of attention.
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19790
PUBLISHED: 2018-12-18
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restricti...
CVE-2018-19829
PUBLISHED: 2018-12-18
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.
CVE-2018-16884
PUBLISHED: 2018-12-18
A flaw was found in the Linux kernel in the NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel id and cause a use-after-free. Thus a malicious container user can cause a host kernel memory corruption and a system ...
CVE-2018-17777
PUBLISHED: 2018-12-18
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. The attacker will have acc...
CVE-2018-18921
PUBLISHED: 2018-12-18
PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.