Categories: HackingSecurity

Anonymous #OpVendetta, 11/5 day of meditation for information security

The world is holding its breath, the cyber threat is announced by the Anonymous group who has decided to celebrate November 5th in its own way, attacking a wide selection of targets. Anonymous celebrates Guy Fawkes Day, the British holiday commemorating a failed 17th-century plot to blow up British Parliament, with an incredible media operation, news on a series of attacks, real or alleged, are flocking to the web sites around the world.

The campaign launched by the hacktivists, named #OpVendetta, reaffirms the commitment of the group in favor of freedom of expression and information security.

The web sites of principal press agencies give rise to the great story, the world of hackers cries out for vengeance against corrupt governments and private companies. Great names between the victims such as PayPal, Symantec, Australian government, NBC and many other, the case of PayPal appears the most controversial, Anonymous in fact announced that it hacked 28000 PayPal user’s passwords.

Immediate the denial of the company, Anuj Nayar, a PayPal spokesman, declared PayPal company had been investigating the attack since Sunday night without finding evidence that its data had been breached.

“It appears that the exploit was not directed at PayPal after all, it was directed at a company called ZPanel. The original  story that started this and was retweeted by some of the Anonymous Twitter handles has now been updated.”

The Anonymous group all over the world are operating moving a coordinate attacks against announced targets, Anonymous Australia seems appears the most active at this time.

Anonymous collective also convened his supporters to take part in a public protest named “V For Vendetta” at The Houses of Parliament, at 8 p.m. in London.

Following the content of a couple of tweets announcing the operations:

“Paypal hacked by Anonymous as part of our November 5th protest”

#Anonymous is not the work of one, or a few, it is an idea, the symbol of resistance, dissent made digital. #5Nov

Under discussion also the surveillance systems TrapWire and Indect deployed by many governments that represent an unacceptable threats to privacy and a violation of human rights.

Hackers claim to have exploited a zero day vulnerability to attack ImageShack server and expose all the files online, they published the content of few most important files of the server (e.g. like /etc/passwd).

As written also antivirus company Symantec’s portal was hacked exposing a complete database of all 1000’s of researchers, subsequently dumped in a Pastebin File, but  in that case the responsible for the hack, the @Doxbin group, has declared that they aren’t affiliated with Anonymous.

NBC web site and also Lady GaGa fan page have been defaced with the following message:

“Remember, remember the fifth of November. The gunpowder treason and plot.”

The events demonstrate once again the media power of Anonymous group, the Paypal case is emblematic. The hacktivism is a serious menace and could cause the exposure of sensible data, but in many cases the success of the attacks is caused by the adoption of inadeguate security countermeasures.
Anonymous is just one of the different cyber threats, probably the most noisly and this is good for security analysts, in many cases cyber attacks exploit sensible information for long period procuring extensive damage.
These events must induce a series of reflections on the efficiency of defense systems and also on the proper response to data breach.

Personally I feel stupid and counterproductive to try to make war to an ideology such as that soul groups of hacktivists, these events must be analyzed under a technician perspective:

“instead of asking who is behind the mask we have to think about what vulnerabilities Anonymous has exploited and try to ensure the security of our IT infrastructures.”

The reality shows that the majority of attacks were successfully due distraction and neglect of IT managers, outdated software, passwords stored in plain text or easy to crack are just some of the nasty surprises that we read every day.

Let me suggest the day 11/5 as a day of meditation for information security.

Pierluigi Paganini

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 84

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

17 minutes ago

Security Affairs newsletter Round 563 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

49 minutes ago

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

21 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

22 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

This website uses cookies.