Feeds

Gawker rooted by anonymous hackers

Passwords, chats, source code aired

High performance access to file storage

A band of anonymous hackers has rooted the servers of Gawker Media – turning the tables on one of the internet's most ruthless gossip rags by leaking half a gigabyte's worth of its private laundry.

Known as Gnosis, the band gave props to 4chan and last week's Operation Payback, which targeted PayPal, MasterCard, Visa, and other companies that severed ties with WikiLeaks. A 20,000-word manifesto available by BitTorrent over the weekend contained email and Twitter log-in credentials for Nick Denton and other top brass at Gawker, not to mention logins for thousands of Gawker's registered readers.

It also included a sharp rebuke of Gawker's security hygiene.

“You would think a site that likes to mock people, such as gawker, would have better security and actually have a clue what they are doing,” wrote the authors, who made repeated references to previous skirmishes between the site and the Anonymous hacking collective.

“You would think someone like Nick Denton who likes to run his mouth and taunts such an unforgiving mass like Anonymous, would use a more secure password than '24862486,'” they write elsewhere. “The sad thing is he probably believes this password is 'secure' because he likes to use it everywhere!”

Gawker's front page on Sunday night contained this warning saying: “Our user databases appear to have been compromised.” It advised readers to consider their accounts compromised across all of Gawker's federation of websites and to change passwords as soon as possible.

“We're deeply embarrassed by this breach,” the advisory stated. “We should not be in the position of relying on the goodwill of the hackers who identified the weakness in our systems. And, yes, the irony is not lost on us.”

The 486 MB file claimed that 1.5 million passwords were protected with DES, or Data Encryption Standard, a feeble enough hashing algorithm that the attackers were able to recover the first eight characters of the corresponding password.

The hackers claim that even after Denton discovered that one of his online accounts may have been compromised, he continued to use the same weak password with other accounts. The download also includes what purports to be Gawker source code, a sneak peek at a Gawker site redesign, and what are said to be passwords for dozens of sensitive Gawker accounts.

Gawker and Anonymous have been at odds since July, when miscreants waged web attacks that intermittently knocked the site offline. Anonymous's fury is said to have been sparked over Gawker's defense of an 11-year-old girl who came in for a fair amount of online harassment.

The miscreants said that instant messaging accounts for numerous employees were accessed and their missive included what were claimed to be chat transcripts to prove the claim. ®

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.