ArsTech reveals the technical details of the Anonymous hack on HBGary

Phokus

Lifer
Nov 20, 1999
22,994
779
126
Who the eff is HBGary??? should I care?

If you don't follow the INTERWEBS, probably not. Actually, the story has turned into a whole conspiracy shitstorm involving Wikileaks, bank of america, the chamber of commerce, and several security companies targeting journalists who support wikileaks, thanks to the hack (and subsequent bittorrent distribution of like 40,000 emails from HBGary). This was completely by accident. It's becoming like a John Grisham novel.

Edit: Not to mention plans to take down wikileaks with cyberattacks and forged documents, among other things.
 
Last edited:

Ns1

No Lifer
Jun 17, 2001
55,420
1,600
126
Who the eff is HBGary??? should I care?

"When Barr told one of those he believed to be an Anonymous ringleader about his forthcoming exposé, the Anonymous response was swift and humiliating. HBGary's servers were broken into, its e-mails pillaged and published to the world, its data destroyed, and its website defaced. As an added bonus, a second site owned and operated by Greg Hoglund, owner of HBGary, was taken offline and the user registration database published."
 

crownjules

Diamond Member
Jul 7, 2005
4,858
0
76
Who the eff is HBGary??? should I care?

HBGary is a private Internet security firm that was contracted by the FBI to dig up information on the hacker group Anonymous. If you read the story, you'll learn that HBGary is pretty incompetent as far as security goes and shouldn't be paid a dime of taxpayer money.
 

punjabiplaya

Diamond Member
Nov 12, 2006
3,495
1
71
read this last night. Needs to be made into a book and/or movie (will probably be cheesy, but whatever).
 

DesiPower

Lifer
Nov 22, 2008
15,299
740
126
If you don't follow the INTERWEBS, probably not. Actually, the story has turned into a whole conspiracy shitstorm involving Wikileaks, bank of america, the chamber of commerce, and several security companies targeting journalists who support wikileaks, thanks to the hack (and subsequent bittorrent distribution of like 40,000 emails from HBGary). This was completely by accident. It's becoming like a John Grisham novel.

aaaahhhhhhh oooohhhhhhh uuuummmmm that sounds interesting, i will read now. I LOVE conspiracy theories, specially the ones that demonize the govt and big corps!! not sure how the eff I missed this...
I do remember hearing a program in NPR, where they interviewed a anonymous guy who modded a chat room where the wikileak supporters (how raided the MC other bank that stopped Wilikeak payments) hung out. This dude's house was raided by FB of I and all his stuff were confiscated. An now he was scared that the vigilantes were after him... as someone leaked his name (NPR did not tell us his name).

Is this all related? where can I read more?
/drool
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
read this last night. Needs to be made into a book and/or movie (will probably be cheesy, but whatever).

It'll be great: despite everything done mostly on a command line OS, it'll be 3D holographic display where the 'hacker' manipulates objects to gain entry into the computer systems.
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
aaaahhhhhhh oooohhhhhhh uuuummmmm that sounds interesting, i will read now. I LOVE conspiracy theories, specially the ones that demonize the govt and big corps!! not sure how the eff I missed this...
I do remember hearing a program in NPR, where they interviewed a anonymous guy who modded a chat room where the wikileak supporters (how raided the MC other bank that stopped Wilikeak payments) hung out. This dude's house was raided by FB of I and all his stuff were confiscated. An now he was scared that the vigilantes were after him... as someone leaked his name (NPR did not tell us his name).

Is this all related? where can I read more?
/drool

Well, the other ATOT thread has a LITTLE bit of it. It's extremely convoluted though. Theres like 10 different things going on.

The main thing is that they were targeting probably the most prominent civil liberties journalist, Glenn Greenwald, because of his support for wikileaks.

http://www.salon.com/news/opinion/glenn_greenwald/2011/02/11/campaigns/index.html

http://www.salon.com/news/opinion/glenn_greenwald/2011/02/15/palantir/index.html

You sorta have to follow news/politics to understand it though. Apparently, wikileaks obtained a hard drive from a BOA executive that contains lots of juicy emails exposing corruption. This is the whole reason for this campaign. Wikileaks is supposedly going to reveal the contents sometime soon. BOA is in damage control and wants to hurt wikileaks credibility.

The amazing thing is, this is all accidental to the original hack, which was just meant to get back at the security company that was threatening anonymous.

Edit: I forgot to mention the high power DC law firm that was coordinating all of this. It IS a Grisham novel.
 
Last edited:

Cogman

Lifer
Sep 19, 2000
10,286
147
106
It'll be great: despite everything done mostly on a command line OS, it'll be 3D holographic display where the 'hacker' manipulates objects to gain entry into the computer systems.

Don't forget transparent display screens, Images of circuit boards, and a 3d video of the camera following a wire to the hive mind like computer. And extreme zooms, Can't forget those.

I can see it now

Anonymous: Lets hack that security camera across the street..... Great, we have access, now zoom in so we can get the IP address for our VB GUI.
 

sdifox

No Lifer
Sep 30, 2005
100,643
18,003
126
Don't forget transparent display screens, Images of circuit boards, and a 3d video of the camera following a wire to the hive mind like computer. And extreme zooms, Can't forget those.

I can see it now

Anonymous: Lets hack that security camera across the street..... Great, we have access, now zoom in so we can get the IP address for our VB GUI.

are you copying Star Trek Generations?
 

Ns1

No Lifer
Jun 17, 2001
55,420
1,600
126
article was awesome

"Most frustrating for HBGary must be the knowledge that they know what they did wrong, and they were perfectly aware of best practices; they just didn't actually use them. Everybody knows you don't use easy-to-crack passwords, but some employees did. Everybody knows you don't re-use passwords, but some of them did. Everybody knows that you should patch servers to keep them free of known security flaws, but they didn't."
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
Don't forget transparent display screens, Images of circuit boards, and a 3d video of the camera following a wire to the hive mind like computer. And extreme zooms, Can't forget those.

I can see it now

Anonymous: Lets hack that security camera across the street..... Great, we have access, now zoom in so we can get the IP address for our VB GUI.

Hack the Gibson!
 

quikah

Diamond Member
Apr 7, 2003
4,209
752
126
HBGary deserves to be hacked for having such a stupid name...

To be fair, Anonymous doesn't sound all that sophisticated themselves. They had to ask what the guys username was in that email string. Duh, try the obvious, could have blown their cover with that...
 

TheTony

Golden Member
Jun 23, 2005
1,418
1
0
Edit: I forgot to mention the high power DC law firm that was coordinating all of this. It IS a Grisham novel.

Which is where the whole story began - they were originally contracted by the law firm, along with two other security firms to submit a proposal to the firm, who supposedly had been retained by the chamber, to do online investigation, infiltration and misinformation on groups or individuals they were concerned with. And doing so with all kinds of questionable practices, especially for a "security" firm, including many zero day exploits and malware.

That whole storyline, and the others came together...very interesting read. And more than a little concerning.
 

TheTony

Golden Member
Jun 23, 2005
1,418
1
0
A company that was researching the stuxnet worm... which some of the code is now in the hands of the hackers.

Although it would make the story even more interesting, I believe this has been suggested to be incorrect. They have binaries, but not actual source code. Not that it is out of the realm of possibility - they did do work with governmental agencies (who are suggested to have been involved with the worm) but industrial control seems to be beyond their level of expertise.
 

Phokus

Lifer
Nov 20, 1999
22,994
779
126
Which is where the whole story began - they were originally contracted by the law firm, along with two other security firms to submit a proposal to the firm, who supposedly had been retained by the chamber, to do online investigation, infiltration and misinformation on groups or individuals they were concerned with. And doing so with all kinds of questionable practices, especially for a "security" firm, including many zero day exploits and malware.

That whole storyline, and the others came together...very interesting read. And more than a little concerning.

It's creepy, they were stalking some pro-union anti-chamber leader and emailing each other photos of his kids and shit.
 

darkewaffle

Diamond Member
Oct 7, 2005
8,152
1
81
HBGary deserves to be hacked for having such a stupid name...

To be fair, Anonymous doesn't sound all that sophisticated themselves. They had to ask what the guys username was in that email string. Duh, try the obvious, could have blown their cover with that...

I keep thinking it stands for Hot Boy Gary. Which then sounds all too similar to Hot Boy Gravy.
 

bignateyk

Lifer
Apr 22, 2002
11,288
7
0
That was a good read. HBGary put together a pretty nice string of fail, especially for a company who is supposed provide expert services to prevent the exact thing that happened.
 

MaxFusion16

Golden Member
Dec 21, 2001
1,512
1
0
It's creepy, they were stalking some pro-union anti-chamber leader and emailing each other photos of his kids and shit.

that's actually the kids of one of the partners at the law firm. Barr was trying to impress the law firm with his facebook stalking skillz. typical scare tactic.
 

TheTony

Golden Member
Jun 23, 2005
1,418
1
0
It's creepy, they were stalking some pro-union anti-chamber leader and emailing each other photos of his kids and shit.

It was interesting to see the immediate and strong reaction the other two security firms had when this all broke. They were quick to distance themselves, as if HBG was a lone player and they were unaware. It's obvious they had to have known and were complicit, as some of their own presentations include statements first included by HBG's piece of the proposal.