Category: Hacking

The Colonial Pipeline Was Unaffected by the Ransomeware Attack

It turns out that the systems controlling the pipeline continued to function as intended, it was only the billing systems were hit, which means that the decision to shut down the pipeline, which threw much of the East Coast of the US into a panic, was not about safety, and critical infrastructure was not impacted, it was just that collecting payments from customers became more inconvenient.

The technical term for what Colonial did was irresponsible, and possibly negligent.

Why am I not surprised that Koch Industries, aka, the Koch Brothers, are a major shareholder?

This, “F%$# you, pay me,” attitude is integral to their warped souls:

The cyber attack that shutdown the Colonial pipeline causing a gas panic and stoking fears of gasoline shortages, didn’t actually shut down the pipeline. It impacted the billing system at the Colonial Pipeline Co., which shut it down because they were worried about how they’d collect payments. 

Yes, the fuel-carrying pipeline was shut down last week in order to prevent a company that is entrusted with what should be a public utility from enduring an accounting headache.

I really hope that someone, I’m looking at you Katie Porter, to whip out the old white board, and cut the executives running a new asshole at hearings.

For the problem described, they could have set up a paper system, and faxes, (or scanners and Gmail) to handle billing temporarily in perhaps 48 hours.

Ha Ha!

Right wing hate site Gab just got hacked, big time.

DDOSecrets, who previously had leaked racist and Islamophobic police training materials got almost everything, public posts, private posts, user info, passwords, etc.

These guys really do have spectacularly poor IT skills don’t they?

It’s the revenge of Bobby Droptables all over again

On the bright side, it save lots of aviation fuel.

Black helicopters are notorious fuel guzzlers: 

When Twitter banned Donald Trump and a slew of other far-right users in January, many of them became digital refugees, migrating to sites like Parler and Gab to find a home that wouldn’t moderate their hate speech and disinformation. Days later, Parler was hacked, and then it was dropped by Amazon web hosting, knocking the site offline. Now Gab, which inherited some of Parler’s displaced users, has been badly hacked too. An enormous trove of its contents has been stolen—including what appears to be passwords and private communications.

On Sunday night the WikiLeaks-style group Distributed Denial of Secrets is revealing what it calls GabLeaks, a collection of more than 70 gigabytes of Gab data representing more than 40 million posts. DDoSecrets says a hacktivist who self-identifies as “JaXpArO and My Little Anonymous Revival Project” siphoned that data out of Gab’s backend databases in an effort to expose the platform’s largely right-wing users. Those Gab patrons, whose numbers have swelled after Parler went offline, include large numbers of Qanon conspiracy theorists, white nationalists, and promoters of former president Donald Trump’s election-stealing conspiracies that resulted in the January 6 riot on Capitol Hill.

DDoSecrets cofounder Emma Best says that the hacked data includes not only all of Gab’s public posts and profiles—with the exception of any photos or videos uploaded to the site—but also private group and private individual account posts and messages, as well as user passwords and group passwords. “It contains pretty much everything on Gab, including user data and private posts, everything someone needs to run a nearly complete analysis on Gab users and content,” Best wrote in a text message interview with WIRED. “It’s another gold mine of research for people looking at militias, neo-Nazis, the far right, QAnon, and everything surrounding January 6.”

DDoSecrets says it’s not publicly releasing the data due to its sensitivity and the vast amounts of private information it contains. Instead the group says it will selectively share it with journalists, social scientists, and researchers. WIRED viewed a sample of the data, and it does appear to contain Gab users’ individual and group profiles—their descriptions and privacy settings—public and private posts, and passwords. Gab CEO Andrew Torba acknowledged the breach in a brief statement Sunday.

………

According to DDoSecrets’ Best, the hacker says that they pulled out Gab’s data via a SQL injection vulnerability in the site—a common web bug in which a text field on a site doesn’t differentiate between a user’s input and commands in the site’s code, allowing a hacker to reach in and meddle with its backend SQL database. Despite the hacker’s reference to an “Anonymous Revival Project,” they’re not associated with the loose hacker collective Anonymous, they told Best, but do “want to represent the nameless struggling masses against capitalists and fascists.”

It’s reassuring that all the Nazis so far seem to be Colonel Klink, but we cannot rely on that forever.