SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 11-05-12, 01:54 PM   #1
the_tyrant
Admiral
 
Join Date: Jun 2010
Location: Canada
Posts: 2,272
Downloads: 58
Uploads: 0
Default anonymous strikes again!

Quote:
NBC's site wasn't the only one to have been hacked because of Guy Fawkes Day. Over the past day, a number of apparently Anonymous-affiliated hackers have gone after LG, ImageShack, Symantec, and other sites, either defacing them or publishing what they claim is private data. In the former category, Argentina's Caja Popular bank temporarily bore an AntiSec banner and a manifesto supporting Jeremy Hammond, who was arrested as part of a sweep against LulzSec in March. The site now appears to be down. In the latter group, the evidence of hacking is less clear but the implications potentially worse.
Internet security people, get your !*%# together!
The police should crack down on them, when they get caught, charge them with bank robbery, a long jail term or a bullet in the brain would kill this soon enough.

http://www.theverge.com/2012/11/5/36...-symantec-hack
__________________
My own open source project on Sourceforge
OTP.net KGB grade encryption for the rest of us
the_tyrant is offline   Reply With Quote
Old 11-05-12, 01:57 PM   #2
Betonov
Navy Seal
 
Betonov's Avatar
 
Join Date: May 2009
Location: Slovenia
Posts: 8,647
Downloads: 26
Uploads: 0


Default

Remember remember, the fifth of november...

I've wondered where they have been.
Betonov is offline   Reply With Quote
Old 11-05-12, 02:06 PM   #3
nikimcbee
Fleet Admiral
 
nikimcbee's Avatar
 
Join Date: Jul 2003
Location: Patroling the Slot.
Posts: 17,952
Downloads: 90
Uploads: 0


Default

Quote:
Originally Posted by the_tyrant View Post
Internet security people, get your !*%# together!
The police should crack down on them, when they get caught, charge them with bank robbery, a long jail term or a bullet in the brain would kill this soon enough.

http://www.theverge.com/2012/11/5/36...-symantec-hack
Lobotomy would fix it. Maybe some old school Russian, Ivan the Terrible punisment, gouge their eyes out.
__________________
nikimcbee is offline   Reply With Quote
Old 11-05-12, 02:24 PM   #4
CCIP
Navy Seal
 
Join Date: Apr 2005
Location: Waterloo, Canada
Posts: 8,700
Downloads: 29
Uploads: 2


Default

Why so much love for banks and big corporations, though?
__________________

There are only forty people in the world and five of them are hamburgers.
-Don Van Vliet
(aka Captain Beefheart)
CCIP is offline   Reply With Quote
Old 11-05-12, 02:27 PM   #5
Sailor Steve
Eternal Patrol
 
Sailor Steve's Avatar
 
Join Date: Nov 2002
Location: High in the mountains of Utah
Posts: 50,369
Downloads: 745
Uploads: 249


Default

Quote:
Originally Posted by the_tyrant View Post
Internet security people, get your !*%# together!
But the minute they crack down on something we're doing, we cry about freedom of the internet.
__________________
“Never do anything you can't take back.”
—Rocky Russo
Sailor Steve is offline   Reply With Quote
Old 11-05-12, 03:38 PM   #6
the_tyrant
Admiral
 
Join Date: Jun 2010
Location: Canada
Posts: 2,272
Downloads: 58
Uploads: 0
Default

Quote:
Originally Posted by CCIP View Post
Why so much love for banks and big corporations, though?
They provide a beloved service for many, like imageshack, or PSN. I would of course resent the attackers they have taken down the services I use regularly.
__________________
My own open source project on Sourceforge
OTP.net KGB grade encryption for the rest of us
the_tyrant is offline   Reply With Quote
Old 11-05-12, 03:51 PM   #7
Jimbuna
Chief of the Boat
 
Jimbuna's Avatar
 
Join Date: Feb 2006
Location: 250 metres below the surface
Posts: 190,500
Downloads: 63
Uploads: 13


Default

Quote:
Originally Posted by Sailor Steve View Post
But the minute they crack down on something we're doing, we cry about freedom of the internet.
Precisely!!
__________________
Wise men speak because they have something to say; Fools because they have to say something.
Oh my God, not again!!

Jimbuna is offline   Reply With Quote
Old 11-05-12, 04:53 PM   #8
the_tyrant
Admiral
 
Join Date: Jun 2010
Location: Canada
Posts: 2,272
Downloads: 58
Uploads: 0
Default

My analysis is this: internet criminals do not usually get caught when they fail. Consider a bank robbery, if I try to pick let’s say the lock on a bank vault and fail, the alarm would trigger, and the cops will arrest me within minutes. However, hackers who try to hack websites, if they mess up, they would not be arrested. Most IDS (intrusion detection systems) systems would simply ban the attacker’s IP for 24 hours. Thus really, if the attacker hides his/her IP address, infinite attack attempts could be made.
Compare that with traditional physical crime, say robbing a bank. If a bank robber fails to rob a bank, and say trips the security system, or gets into a shootout with security, he would most likely get arrested and get "taken out of action". In comparison, if hackers fail, nothing happens to them. I run a windows 2008 server and a cent OS server as a hobby, both are internet facing, and used as web servers. My logs tell me that I get "attacked" almost 20 times a day on each server, even though these are just some personal sites with almost no traffic. Mostly they are brute force attacks, sql injection attempts, port scans, etc, attacks that have no chance of succeeding. However, these attackers are not "taken out of action" by their failure, they simply move on to the next possible victim (the majority of the attacks are done by automated scripts, but as a guy who likes to read logs, you can quickly recognize which ones are done by newbies).
Over a scale of infinite time, even the most secure servers would succumb to attacks. After all, the attackers always have the initiative, they can try infinite times. If I fail today, I can come back tomorrow and try again.
Now we have to discuss the concept of "vulnerable time". Just as how downtime describes the amount of time a server is "down", I use the term vulnerable time to discuss the time in which the server is vulnerable to attack. Consider this: consider an internet facing application like IIS or Apache. Let’s say a huge 0-day has just been created and is currently spreading through the internet (a 0-day is an attack technique that has not been patched). If I manually apply patches, my vulnerable time would be from when the attack first appeared, to when I finally get around to patching my server. If I used an automatic patching system, my vulnerable time would be reduced to from when the attack first appeared, to when the vendor rolls out a patch.
If I have say an IDS system, the vulnerable time to would be drastically reduced. I would only be vulnerable to the attack when my application is vulnerable, and when my IDS system is vulnerable. With each layer I pile on, my vulnerable time is reduced further.
However, on a scale of infinite time, when the attacker has infinite tries, the attacker would always succeed. Consider this: If I have infinite tries to rob a bank, I would eventually get it right some time. If I try to rob a bank, and I fail, I would get a long jail term, and maybe a few new bullet holes. However, if I try to hack a server and I fail, I can just try again tomorrow.
This leads me to believe, that the only effective permanent solution against internet crime is effective policing. Since on an infinite time frame, the attacker would always succeed. Unlike murders and assault, internet crime is not a spur of the moment thing. Cracking down on internet crime will deter the perpetrators on internet crime.
Most of the "pro hackers" started off as script kiddies; I would say that the absolute majority started off that way. Using scripts you can easily find off the internet, you can deal quite a bit of damage. It is in fact not too hard to hack a large amount of websites using commonly found scripts. Often, the big website hackers we read about in the news start off by defacing small sites. It’s not like the police will even bother to persecute a tiny website hacker. Yet, give him enough time, and he will move on to bigger things. If I see on my logs, a kid trying his best to clumsily exploit a SQL injection vulnerability (its easy to recognize this kind of thing, you usually see misspelled SQL commands and what not), I would check if the IP is from a residential IP address and not a known proxy or VPN. I usually just pop off an abuse complaint to the ISP. I don’t really think they would do anything, but if some script kiddie gets a warning from his ISP, it would hopefully deter him from going down that path.
__________________
My own open source project on Sourceforge
OTP.net KGB grade encryption for the rest of us

Last edited by the_tyrant; 11-05-12 at 05:29 PM.
the_tyrant is offline   Reply With Quote
Old 11-05-12, 05:13 PM   #9
Sailor Steve
Eternal Patrol
 
Sailor Steve's Avatar
 
Join Date: Nov 2002
Location: High in the mountains of Utah
Posts: 50,369
Downloads: 745
Uploads: 249


Default

1) Is there a reason you felt the need to shout your whole post this time?

2) You could at least go back and clean up all the ***XXXX crap so it looked a little like your own words.
__________________
“Never do anything you can't take back.”
—Rocky Russo
Sailor Steve is offline   Reply With Quote
Old 11-05-12, 05:23 PM   #10
Tchocky
Navy Seal
 
Join Date: Jul 2004
Posts: 5,874
Downloads: 6
Uploads: 0
Default

Quote:
Originally Posted by Sailor Steve View Post
1) Is there a reason you felt the need to shout your whole post this time?

2) You could at least go back and clean up all the ***XXXX crap so it looked a little like your own words.
It was fun back in the day, calling out eejits for reposting copied rants as their own work

(I've Googled and I think tyrant typed it up himself...... but in Microsoft Potato 1989)
__________________
[SIGPIC][/SIGPIC]
Tchocky is offline   Reply With Quote
Old 11-05-12, 05:28 PM   #11
the_tyrant
Admiral
 
Join Date: Jun 2010
Location: Canada
Posts: 2,272
Downloads: 58
Uploads: 0
Default

Quote:
Originally Posted by Sailor Steve View Post
1) Is there a reason you felt the need to shout your whole post this time?

2) You could at least go back and clean up all the ***XXXX crap so it looked a little like your own words.
Sorry, i wrote it up in one note, I'll clean it back up.
__________________
My own open source project on Sourceforge
OTP.net KGB grade encryption for the rest of us
the_tyrant is offline   Reply With Quote
Old 11-05-12, 05:29 PM   #12
Tchocky
Navy Seal
 
Join Date: Jul 2004
Posts: 5,874
Downloads: 6
Uploads: 0
Default

Quote:
Originally Posted by the_tyrant View Post
They provide a beloved service for many, like imageshack, or PSN.
ImageShack makes my head hurt. Imgur is so nice and easy
__________________
[SIGPIC][/SIGPIC]
Tchocky is offline   Reply With Quote
Old 11-05-12, 08:55 PM   #13
Sailor Steve
Eternal Patrol
 
Sailor Steve's Avatar
 
Join Date: Nov 2002
Location: High in the mountains of Utah
Posts: 50,369
Downloads: 745
Uploads: 249


Default

Quote:
Originally Posted by the_tyrant View Post
Sorry, i wrote it up in one note, I'll clean it back up.
Thank you.
__________________
“Never do anything you can't take back.”
—Rocky Russo
Sailor Steve is offline   Reply With Quote
Old 11-05-12, 09:33 PM   #14
SaintEpsilon
Bilge Rat
 
Join Date: Apr 2005
Posts: 1
Downloads: 63
Uploads: 0
Default

Sometimes what they do, I can agree with, othertimes it's just plain moronic.
Unfortunately democracy is as much an illusion these days as religion.
SaintEpsilon is offline   Reply With Quote
Old 11-05-12, 09:54 PM   #15
Cybermat47
Willing Webfooted Beast
 
Cybermat47's Avatar
 
Join Date: Aug 2012
Location: Australia
Posts: 5,408
Downloads: 300
Uploads: 23


Default

Quote:
Originally Posted by SaintEpsilon View Post
Unfortunately democracy is as much an illusion these days as religion.
Dude, this isn't Facebook, you can't just go around insulting everyone just because they believe in an omnipotent being. And anyway, if you're an atheist, then how come your username is SaintEpsilon!
__________________
Historical TWoS Gameplay Guide: http://www.subsim.com/radioroom/showthread.php?p=2572620
Historical FotRSU Gameplay Guide: https://www.subsim.com/radioroom/sho....php?p=2713394
Cybermat47 is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 03:56 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.