Feeds

HACKLASH! Syrian Electronic Army's website hacked by angry rivals

Turks pwn SEA, media targets savour the schadenfreude

Internet Security Threat Report 2014

The notorious hacktivists of the Syrian Electronic Army have received an unwelcome dose of their own medicine, after their official website was defaced by a Turkish hacking crew.

TurkGuvenligi compromised the Syrian Electronic Army’s official sea.sy website after the pro-Assad group’s hosting firm was breached. It's unclear whether TurkGuvenligi used attacks based on phishing, weak passwords or software vulnerabilities (three examples of possible mechanisms) to gain illicit access to the SEA's website.

The SEA is notorious for a long run of attacks, the most high profile of which have involved taking over the blogs and social media profiles of media organisations (AP, National Public Radio, Al Jazeera, The Daily Telegraph, The Washington Post, The Onion etc.) as well more recent high profile attacks along the same lines against Microsoft and Skype over recent days.

The SEA's normal modus operandi for hijacking accounts involves multi-stage phishing attacks. At first they aim to trick workers within a targeted organisation into handing over their email passwords before targeting those in charge of maintaining social media accounts with secondary attacks that take advantage of already compromised internal email accounts.

The SEA has also turned its hand to website defacement and hacking since 2011, when it first came to widespread notice.

TurkGuvenligi sprayed digital graffiti on the SEA's homepage which chastised the Syrian Electronic Army (extract below) for their activities.

You imbecils [sic] will attack our country with fake phishing emails and we’ll accept your lies and dont [sic] do anything? That is the end you deserve

The SEA’s website remains offline at the time of writing on Wednesday afternoon. A screencap of the defacement, along with related commentary, can be found in a blog post by veteran security industry expert Graham Cluley here.

TurkGuvenligi has form for these sort of shenanigans. In late December the Turks defaced the official OpenSSL website, leaving a message which read "TurkGuvenligiTurkSec Was Here @turkguvenligi + we love openssl". OpenSSL blamed the defacement on “insecure passwords at the hosting provider”.

"The source repositories were audited and they were not affected," OpenSSL reassured users in a statement issued in the immediate aftermath of the defacement.

"Other than the modification to the index.html page no changes to the website were made. No vulnerability in the OS or OpenSSL applications was used to perform this defacement. Steps have been taken to protect against this means of attack in future." ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.