They way they got that root pw is insane. That admin needs fired on the spot.
Even a small company should never reset a pw based simply on an email.
I've rang up a hospital before from outside, asked for IT. Spoken to tech support - Hi. I need a login and password for the Electronic Patient Record. I hadn't actually started work there, but was due to start on the 3rd day of a 3 day weekend. Given that there would be no way to do my job without access to the electronic record, and that IT support don't work weekends and holidays, I planned ahead about a week before I started.
- What's your username?
= Err. I don't have one. I need a new account
- What's your name?
- Mark R
- OK. What department do you work in?
- blah. blah
- I don't have a record of any account in your name. That's because I haven't started. I start on holiday Monday.
- Oh. OK then. I'll send a new password to your internal e-mail
- Oh. I don't think it's working, the account hasn't been set up. Can you send it to my hotmail?
- What's the address?
- asdfasdfasdf@hotmail.com
5 minutes later, login and password details arrive in my hotmail account.
Social engineering is a powerful tool.I've rang up a hospital before from outside, asked for IT. Spoken to tech support - Hi. I need a login and password for the Electronic Patient Record. I hadn't actually started work there, but was due to start on the 3rd day of a 3 day weekend. Given that there would be no way to do my job without access to the electronic record, and that IT support don't work weekends and holidays, I planned ahead about a week before I started.
- What's your username?
= Err. I don't have one. I need a new account
- What's your name?
- Mark R
- OK. What department do you work in?
- blah. blah
- I don't have a record of any account in your name. That's because I haven't started. I start on holiday Monday.
- Oh. OK then. I'll send a new password to your internal e-mail
- Oh. I don't think it's working, the account hasn't been set up. Can you send it to my hotmail?
- What's the address?
- asdfasdfasdf@hotmail.com
5 minutes later, login and password details arrive in my hotmail account.
:thumbsup:it's true, unadulterated, information freedom. sure 90% of what they do is absolutely senseless and juvenile, but we really could be witnessing the start of another phase of democratic revolution here
I would be more than happy to suggest - and document - a good target for Anonymous, for the sake of a good cause, and for social justice.
And I'm 100% serious.
I would be more than happy to suggest - and document - a good target for Anonymous, for the sake of a good cause, and for social justice.
And I'm 100% serious.
Are there any large scale attacks such as this one documented anywhere? I've never seen one happen and would be interested to see the production and how it's orchestrated. I have read short articles about "they laucnhed a ddos attack to bring the servers to their knees" but that's about as in depth as it goes..... i'm interested in a full write up, play by play action.
Anonymous: "I can haz password?"
Sys Admin: "sure lol"
Anonymous: "and i can haz firewall downs?"
Sys Admin: "yup lol"
Are there any large scale attacks such as this one documented anywhere? I've never seen one happen and would be interested to see the production and how it's orchestrated. I have read short articles about "they laucnhed a ddos attack to bring the servers to their knees" but that's about as in depth as it goes..... i'm interested in a full write up, play by play action.
Are there any large scale attacks such as this one documented anywhere? I've never seen one happen and would be interested to see the production and how it's orchestrated. I have read short articles about "they laucnhed a ddos attack to bring the servers to their knees" but that's about as in depth as it goes..... i'm interested in a full write up, play by play action.
I love their new home page. They are so utterly full of shit its funny.
http://www.hbgary.com/
I love their new home page. They are so utterly full of shit its funny.
http://www.hbgary.com/
I really enjoy their testimonials from "Big Consulting Company" and "Top 10 Financial Institution". LOL
Are there any large scale attacks such as this one documented anywhere? I've never seen one happen and would be interested to see the production and how it's orchestrated. I have read short articles about "they laucnhed a ddos attack to bring the servers to their knees" but that's about as in depth as it goes..... i'm interested in a full write up, play by play action.
I love their new home page. They are so utterly full of shit its funny.
http://www.hbgary.com/
We know that understanding the attacker and his methods is the only way to defeat him. This is the core strength of HBGary and why our technology and services outperform the competition. To us, it's personal.
This is what got them fucked the first time. I guess they haven't learned their lesson...
