Feeds

HACKLASH! Syrian Electronic Army's website hacked by angry rivals

Turks pwn SEA, media targets savour the schadenfreude

Intelligent flash storage arrays

The notorious hacktivists of the Syrian Electronic Army have received an unwelcome dose of their own medicine, after their official website was defaced by a Turkish hacking crew.

TurkGuvenligi compromised the Syrian Electronic Army’s official sea.sy website after the pro-Assad group’s hosting firm was breached. It's unclear whether TurkGuvenligi used attacks based on phishing, weak passwords or software vulnerabilities (three examples of possible mechanisms) to gain illicit access to the SEA's website.

The SEA is notorious for a long run of attacks, the most high profile of which have involved taking over the blogs and social media profiles of media organisations (AP, National Public Radio, Al Jazeera, The Daily Telegraph, The Washington Post, The Onion etc.) as well more recent high profile attacks along the same lines against Microsoft and Skype over recent days.

The SEA's normal modus operandi for hijacking accounts involves multi-stage phishing attacks. At first they aim to trick workers within a targeted organisation into handing over their email passwords before targeting those in charge of maintaining social media accounts with secondary attacks that take advantage of already compromised internal email accounts.

The SEA has also turned its hand to website defacement and hacking since 2011, when it first came to widespread notice.

TurkGuvenligi sprayed digital graffiti on the SEA's homepage which chastised the Syrian Electronic Army (extract below) for their activities.

You imbecils [sic] will attack our country with fake phishing emails and we’ll accept your lies and dont [sic] do anything? That is the end you deserve

The SEA’s website remains offline at the time of writing on Wednesday afternoon. A screencap of the defacement, along with related commentary, can be found in a blog post by veteran security industry expert Graham Cluley here.

TurkGuvenligi has form for these sort of shenanigans. In late December the Turks defaced the official OpenSSL website, leaving a message which read "TurkGuvenligiTurkSec Was Here @turkguvenligi + we love openssl". OpenSSL blamed the defacement on “insecure passwords at the hosting provider”.

"The source repositories were audited and they were not affected," OpenSSL reassured users in a statement issued in the immediate aftermath of the defacement.

"Other than the modification to the index.html page no changes to the website were made. No vulnerability in the OS or OpenSSL applications was used to perform this defacement. Steps have been taken to protect against this means of attack in future." ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.