• We should now be fully online following an overnight outage. Apologies for any inconvenience, we do not expect there to be any further issues.

Anonymous rapes "security" firm investigating them for WikiLeaks related DDoSing

Page 6 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
@aaronbarr: Please do not infer anything from my username and vocal support of "Anonymous". I was Anonymouse before "Anonymous" was formed.
 

silverpig

Lifer
Jul 29, 2001
27,703
12
81
Here's the whole irc chat log between the president of HBGary and Anonymous:

http://pastebin.com/x69Akp5L

ROFL

[04:14] <@blergh> Penny: in all seriousness, i would really like it if your employee or someone residing on your network stopped trying to attack one of my servers
[04:14] <Eddy> maybe it's that guy again
[04:14] <@blergh> Penny: I have log-files/proof of a host residing on your network attacking one of my boxes
04[04:14] <url> penny, you need to email your contacts list before we do
[04:14] #ophbgary You need voice (+v) (#ophbgary)
[04:14] <+heyguise> ssshhh blergh
[04:14] <@blergh> ;)
[04:14] <+Penny> Hey guys, I'm at home on my comcast, who is attacking
[04:14] <evilworks> :)
[04:14] <+heyguise> let her talk
04[04:15] <url> i think its a legal requirement for you or something
[04:15] #ophbgary You need voice (+v) (#ophbgary)
[04:15] <+Penny> Do I sound like a hacker, I didn't even have IRC chat on my computer
[04:15] <+Penny> I am on Comcast
[04:15] <@blergh> Penny: No, not blaming you..
[04:15] <&Sabu> no one is attacking you penny I PROMISE.
[04:15] <Eddy> blergh: maybe you can share logs with her, the attack came from a single domain, right?
[04:15] <+Penny> I can give them to someone techniccal
[04:15] <@blergh> Penny: What i am saying is that someone residing on your network attacked one of my boxes
[04:16] <evilworks> well Penny i'm sorry for your firm
[04:16] <+Isis> ^
[04:16] <+Agamemnon> ^
[04:16] <evilworks> but i guess thats what you get when you involve yourself with greedy fucks
[04:16] <Eddy> not hope IP Penny he's saying one of the servers
[04:16] <&Sabu> penny, your husband is greg hoglund or am I incorrect?
[04:16] <Eddy> home*
[04:16] <+Penny> OK how do I know who is on my comcast network?
[04:16] <+heyguise> lol
[04:16] <+heyguise> omg that is precious
[04:16] <Eddy> blergh try to explain better :)
[04:16] <+goober> He is talking about your work network.
[04:16] <&Sabu> its cute
[04:16] <&Sabu> aww penny<3
[04:16] <+heyguise> Penny, we like you.
[04:16] <+heyguise> I think
04[04:16] <url> ha
[04:16] #ophbgary You need voice (+v) (#ophbgary)
[04:17] <+Penny> OK, so someone from HBGary is attacking you?
[04:17] <evilworks> do we have pics of Penny yet?
[04:17] <Eddy> right
[04:17] <+Nessuno> tits?
[04:17] <evilworks> come on, deliver
[04:17] <~tflow> evilworks: there was a pic on hbgary.com
[04:17] <Neo> LOL
 

thepd7

Diamond Member
Jan 2, 2005
9,423
0
0
Here's the whole irc chat log between the president of HBGary and Anonymous:

http://pastebin.com/x69Akp5L

I cannot believe this was the first time she used IRC and she has no idea what bittorrent is, wtf... she kept on begging them to take down the file, as if that was possible with bittorrent, lol.

Also, arstech has a more detailed article about all of this

http://arstechnica.com/tech-policy/...m-tracked-anonymousand-paid-a-heavy-price.ars

edit:

Actually, you're wrong. The reason they did what they did was because this Aaron Barr guy was going to reveal identities at a conference he was giving and also to the FBI. Based on the articles and also the IRC chatlog, it seems Aaron got these identities via people who clicked the 'like' button for the Anonymous page on facebook and they're claiming a lot of those are innocent people who have nothing to do with hacking. Based on the pdf document, it wouldn't surprise me, it looked like really sloppy work.

I dig the arstechnica article, very interesting. It seems from the article that at the very least Barr was on to something. Maybe not what he thought, but one of the anon members admitted Barr had his gf's name from FB, so obviously the methods had some sort of success.

The whole situation seems surreal. I can't even imagine the shitstorm that guy is facing. The whole company, really. I'd crawl in bed and sleep for weeks.
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
Aaron Barr is an arrogant idiot. He really thought that the upper ranks of Anonymous would "Like" Anonymous on Facebook! LOfuckingL! :biggrin:

It's really funny, but the one guy who knew absolutely anything, the 'coder', kept warning him that his methods were bullshit and he anonymous was going to fuck them up, but he completely ignored him. Complete empty suit. (Typical executive)
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
Interesting, apparently the emails revealed that hbgary and several other companies were working in concert with a couple other companies to start a campaign to 'discredit' wikileaks and launch cyberattacks on them. Apparently, BOA is the bank who lost an executive's hard drive to wikileaks.

http://www.rawstory.com/rs/2011/02/data-intelligence-firms-proposed-attack-wikileaks/

More about the damage control BOA is doing:

http://www.rawstory.com/rs/2011/01/bank-america-scurries-mount-defense-wikileaks-revelation/
 

child of wonder

Diamond Member
Aug 31, 2006
8,307
176
106
Anonymous: "I can haz password?"
Sys Admin: "sure lol"
Anonymous: "and i can haz firewall downs?"
Sys Admin: "yup lol"

AWESOME security.
 

FelixDeCat

Lifer
Aug 4, 2000
31,018
2,685
126
If they had been using Microsoft Security Essentials, none of this would have ever happened.
 

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
It's really funny, but the one guy who knew absolutely anything, the 'coder', kept warning him that his methods were bullshit and he anonymous was going to fuck them up, but he completely ignored him. Complete empty suit. (Typical executive)

The coder was spot on, and Anonymous should recruit him. At the very least, he deserves a beer. :thumbsup:
 

crownjules

Diamond Member
Jul 7, 2005
4,858
0
76
It's really funny, but the one guy who knew absolutely anything, the 'coder', kept warning him that his methods were bullshit and he anonymous was going to fuck them up, but he completely ignored him. Complete empty suit. (Typical executive)

But but but....these guys are paid MILLIONS in bonuses because their skills and talents are way beyond the rest of us mere mortal workers.
 

silverpig

Lifer
Jul 29, 2001
27,703
12
81
But but but....these guys are paid MILLIONS in bonuses because their skills and talents are way beyond the rest of us mere mortal workers.

I loved the part about how he kept claiming he had done all this advanced analysis and it was all complicated and statistical and stuff, yet his coder called him on his BS and asked for an algorithm, SQL query, or some form of statistical proof that he could make his claims.
 

Barfo

Lifer
Jan 4, 2005
27,539
212
106
Back to my analogy.

If you insult me, I think I'm justified in insulting you back, and depending on the circumstances, I might even punch you in the face.

But I'm not justified in taking out a gun and shooting you. Or posting your SS# on the internet.

I'm not saying HBGary didn't deserve a punch in the face, but they didn't deserve to get shot either, and certainly their clients shouldn't have been dragged in either.
You don't go to the ghetto, insult some 7 feet black guy you find there to his face, and expect him to just insult you back or punch your face at the most. Just saying.
 

silverpig

Lifer
Jul 29, 2001
27,703
12
81
Back to my analogy.

If you insult me, I think I'm justified in insulting you back, and depending on the circumstances, I might even punch you in the face.

But I'm not justified in taking out a gun and shooting you. Or posting your SS# on the internet.

I'm not saying HBGary didn't deserve a punch in the face, but they didn't deserve to get shot either, and certainly their clients shouldn't have been dragged in either.

Nothing bad really happened to HBGary though, and AFAIK none of their emails were leaked.

HBGary Federal (a separate company which HBGary has a 15% stake in) was the company that got reamed. What's more, they didn't post all of HBGary Federal's emails, just all of the emails from the three top guys in that firm.
 

halik

Lifer
Oct 10, 2000
25,696
1
81
What the hell kind of computer security company sends root passwords via plaintext email?
 

iGas

Diamond Member
Feb 7, 2009
6,240
1
0
I dig the arstechnica article, very interesting. It seems from the article that at the very least Barr was on to something. Maybe not what he thought, but one of the anon members admitted Barr had his gf's name from FB, so obviously the methods had some sort of success.

The whole situation seems surreal. I can't even imagine the shitstorm that guy is facing. The whole company, really. I'd crawl in bed and sleep for weeks.
The theory does have some success, but IMHO the bulk of the people that they catch would be low level or random innocent people as said by Barr coder "guilt by association" and "gut" feeling is a fail method.
 
Last edited:

Phokus

Lifer
Nov 20, 1999
22,994
779
126
The theory does have some success, but IMHO the bulk of the people that they catch would be low level or random innocent people as said by Barr coder "guilt by association" and "gut" feeling is a fail method.

And that's why i feel they were justified in destroying him.
 

actuarial

Platinum Member
Jan 22, 2009
2,814
0
71
I loved the part about how he kept claiming he had done all this advanced analysis and it was all complicated and statistical and stuff, yet his coder called him on his BS and asked for an algorithm, SQL query, or some form of statistical proof that he could make his claims.

There was clearly no 'advanced' statistical analysis. It sounded more like he was doing some old fashioned sleuthing, internet style.
 

Gooberlx2

Lifer
May 4, 2001
15,381
6
91
Yeah, as unfortunate as the collateral damage might be regarding personal/work emails of other clients and whatnot, what this guy was trying to do was dangerous. Aside from trying to score important contracts by presenting exaggerated results with shoddy work, his information could have been very damaging and costly to a lot of innocent people had they been investigated by the FBI.

The public slaughtering of the companies' reputations was absolutely necessary, imo.

Hopefully more rational minds will prevail in the future and understand that the whole "guilt by association" aspect of social networking is rife with inaccuracies and assumptions.

Its just you.
so lonely :'(
 
Last edited: