Categories: HackingSecurity

Anonymous #OpVendetta, 11/5 day of meditation for information security

The world is holding its breath, the cyber threat is announced by the Anonymous group who has decided to celebrate November 5th in its own way, attacking a wide selection of targets. Anonymous celebrates Guy Fawkes Day, the British holiday commemorating a failed 17th-century plot to blow up British Parliament, with an incredible media operation, news on a series of attacks, real or alleged, are flocking to the web sites around the world.

The campaign launched by the hacktivists, named #OpVendetta, reaffirms the commitment of the group in favor of freedom of expression and information security.

The web sites of principal press agencies give rise to the great story, the world of hackers cries out for vengeance against corrupt governments and private companies. Great names between the victims such as PayPal, Symantec, Australian government, NBC and many other, the case of PayPal appears the most controversial, Anonymous in fact announced that it hacked 28000 PayPal user’s passwords.

Immediate the denial of the company, Anuj Nayar, a PayPal spokesman, declared PayPal company had been investigating the attack since Sunday night without finding evidence that its data had been breached.

“It appears that the exploit was not directed at PayPal after all, it was directed at a company called ZPanel. The original  story that started this and was retweeted by some of the Anonymous Twitter handles has now been updated.”

The Anonymous group all over the world are operating moving a coordinate attacks against announced targets, Anonymous Australia seems appears the most active at this time.

Anonymous collective also convened his supporters to take part in a public protest named “V For Vendetta” at The Houses of Parliament, at 8 p.m. in London.

Following the content of a couple of tweets announcing the operations:

“Paypal hacked by Anonymous as part of our November 5th protest”

#Anonymous is not the work of one, or a few, it is an idea, the symbol of resistance, dissent made digital. #5Nov

Under discussion also the surveillance systems TrapWire and Indect deployed by many governments that represent an unacceptable threats to privacy and a violation of human rights.

Hackers claim to have exploited a zero day vulnerability to attack ImageShack server and expose all the files online, they published the content of few most important files of the server (e.g. like /etc/passwd).

As written also antivirus company Symantec’s portal was hacked exposing a complete database of all 1000’s of researchers, subsequently dumped in a Pastebin File, but  in that case the responsible for the hack, the @Doxbin group, has declared that they aren’t affiliated with Anonymous.

NBC web site and also Lady GaGa fan page have been defaced with the following message:

“Remember, remember the fifth of November. The gunpowder treason and plot.”

The events demonstrate once again the media power of Anonymous group, the Paypal case is emblematic. The hacktivism is a serious menace and could cause the exposure of sensible data, but in many cases the success of the attacks is caused by the adoption of inadeguate security countermeasures.
Anonymous is just one of the different cyber threats, probably the most noisly and this is good for security analysts, in many cases cyber attacks exploit sensible information for long period procuring extensive damage.
These events must induce a series of reflections on the efficiency of defense systems and also on the proper response to data breach.

Personally I feel stupid and counterproductive to try to make war to an ideology such as that soul groups of hacktivists, these events must be analyzed under a technician perspective:

“instead of asking who is behind the mask we have to think about what vulnerabilities Anonymous has exploited and try to ensure the security of our IT infrastructures.”

The reality shows that the majority of attacks were successfully due distraction and neglect of IT managers, outdated software, passwords stored in plain text or easy to crack are just some of the nasty surprises that we read every day.

Let me suggest the day 11/5 as a day of meditation for information security.

Pierluigi Paganini

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

MITRE revealed that nation-state actors breached its systems via Ivanti zero-days

The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by…

17 hours ago

FBI chief says China is preparing to attack US critical infrastructure

China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher…

1 day ago

United Nations Development Programme (UNDP) investigates data breach

The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack…

1 day ago

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

2 days ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

2 days ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

2 days ago

This website uses cookies.