Feeds

HACKLASH! Syrian Electronic Army's website hacked by angry rivals

Turks pwn SEA, media targets savour the schadenfreude

Build a business case: developing custom apps

The notorious hacktivists of the Syrian Electronic Army have received an unwelcome dose of their own medicine, after their official website was defaced by a Turkish hacking crew.

TurkGuvenligi compromised the Syrian Electronic Army’s official sea.sy website after the pro-Assad group’s hosting firm was breached. It's unclear whether TurkGuvenligi used attacks based on phishing, weak passwords or software vulnerabilities (three examples of possible mechanisms) to gain illicit access to the SEA's website.

The SEA is notorious for a long run of attacks, the most high profile of which have involved taking over the blogs and social media profiles of media organisations (AP, National Public Radio, Al Jazeera, The Daily Telegraph, The Washington Post, The Onion etc.) as well more recent high profile attacks along the same lines against Microsoft and Skype over recent days.

The SEA's normal modus operandi for hijacking accounts involves multi-stage phishing attacks. At first they aim to trick workers within a targeted organisation into handing over their email passwords before targeting those in charge of maintaining social media accounts with secondary attacks that take advantage of already compromised internal email accounts.

The SEA has also turned its hand to website defacement and hacking since 2011, when it first came to widespread notice.

TurkGuvenligi sprayed digital graffiti on the SEA's homepage which chastised the Syrian Electronic Army (extract below) for their activities.

You imbecils [sic] will attack our country with fake phishing emails and we’ll accept your lies and dont [sic] do anything? That is the end you deserve

The SEA’s website remains offline at the time of writing on Wednesday afternoon. A screencap of the defacement, along with related commentary, can be found in a blog post by veteran security industry expert Graham Cluley here.

TurkGuvenligi has form for these sort of shenanigans. In late December the Turks defaced the official OpenSSL website, leaving a message which read "TurkGuvenligiTurkSec Was Here @turkguvenligi + we love openssl". OpenSSL blamed the defacement on “insecure passwords at the hosting provider”.

"The source repositories were audited and they were not affected," OpenSSL reassured users in a statement issued in the immediate aftermath of the defacement.

"Other than the modification to the index.html page no changes to the website were made. No vulnerability in the OS or OpenSSL applications was used to perform this defacement. Steps have been taken to protect against this means of attack in future." ®

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.