Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Advertisement

You are here: Home arrow EH-Netarrow Ethical Hacktivismarrow The inside story of the HBGary hack
EH-Net
May 20, 2013, 11:56:50 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: The inside story of the HBGary hack  (Read 19879 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« on: February 17, 2011, 06:54:58 AM »

The Social Engineering part is especially good!  Grin

http://arstechnica.com/tech-policy/news/2011/02/anonymous-speaks-the-inside-story-of-the-hbgary-hack.ars/
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
AndyB
Full Member
***
Offline Offline

Posts: 100



View Profile
« Reply #1 on: February 17, 2011, 11:49:58 AM »

A brilliant piece of work by Anon and a damming enditment of HBGary!
Logged

Net+ Sec+ More to come
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #2 on: February 17, 2011, 12:00:39 PM »

Uau!

Nicer than an action movie Smiley
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
anoninde
Guest
« Reply #3 on: February 17, 2011, 12:33:03 PM »

I find this situation insanely entertaining, is that wrong? It appears the initial vectors of attack were pretty straight forward, the social engineering aspect of it is almost ridiculous. The biggest portion of this attack that is so alarming is how many private companies, government agencies and foreign interests had some involvement with HBGary, and now they are suddenly exposed.......the kinetic damage from the poor security practices by HBGary.
Logged
maxpeck
Newbie
*
Offline Offline

Posts: 21



View Profile
« Reply #4 on: February 20, 2011, 08:26:36 PM »

Like a guy that runs a Dojo getting his butt kicked by a group of 10 year olds Wink
Logged

Max
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #5 on: February 22, 2011, 08:55:12 AM »

There have a number of security companies pwned in the last few years. I'd be shocked if a number of the bigger companies wouldn't also be pwnable, especially when you count the SE attacks. The SE attacks aren't a pass/fail, its a question of what percentage of the people will fall for it.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
digitalsecurity4u
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #6 on: February 22, 2011, 12:19:50 PM »

 Making yourself the poster child of how not to run a security company, nice. If they ever recovery its going to be a while and no steak is going to remove that black eye. The using of the same password accross domains (company and internet) really kills me.
Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #7 on: March 01, 2011, 09:01:36 PM »

Making yourself the poster child of how not to run a security company, nice.

I actually appreciate someone trying to take on Anonymous. Whether you support the cause that Anonymous stands for, what they are doing *is* illegal. And we supporting an "ends justify the means" approach is very dangerous.

Quote
If they ever recovery its going to be a while and no steak is going to remove that black eye.

They are dead. My understanding is that they have two employees left.

Quote
The using of the same password accross domains (company and internet) really kills me.

Yeah, not a great idea, but I can guarantee they they aren't the only security company doing it.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #8 on: March 03, 2011, 03:05:42 AM »

Quote
If they ever recovery its going to be a while and no steak is going to remove that black eye.

They are dead. My understanding is that they have two employees left.

Aaron Barr has finally resigned.  When you say only 2 employees left, is that just HBGary Federal, or HBGary?  Reading the chat logs from when Penny Leavy was pleading with Anonymous in their IRC channel, she made it clear that HBGary had only invested money in HBGary Federal, that they were separate companies.  I haven't heard much about HBGary and was wondering how they were doing compared to HBGary Federal.
« Last Edit: March 03, 2011, 08:58:05 AM by lorddicranius » Logged

GSEC, eCPPT, Sec+
red rail
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #9 on: March 03, 2011, 07:00:21 AM »

It seems as though his compromise for usability vs security met a sad fate.  I assume that he set his websites/accounts up thinking that he had no reason to be excessively secure.  For a security company, this is unacceptable.  Most of us make these common mistakes in the sake of thinking, "Its good enough".... and it usually is... because were not starting trouble for ourselves with a group known to be successful with disrupting services.  I still fail to see what he was trying to accomplish?  Even if he was completely secure (by theory), he would still be susceptible to DDoS attacks, that they are known to use, that would disrupt the day to day operations of his websites.. there really was no 'winning' outcome.  His arrogance caused his downfall.. and he will have that story to tell for the rest of his life.
Logged

BA Information Systems Security, Linux+, A+
yatz
Full Member
***
Offline Offline

Posts: 222


View Profile WWW
« Reply #10 on: March 11, 2011, 07:55:54 AM »

Not to beat a dead horse, but I got a kick out of this one.  It came across Twitter this morning.

The HBGary saga, depicted as a Spy v. Spy cartoon.

http://www.businessweek.com/magazine/content/11_12/b4220066673859.htm
Logged

"Live as though you would die tomorrow, learn as though you would live forever."

CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #11 on: March 11, 2011, 01:28:03 PM »

Thanks yatz, it is very funny!!! Smiley
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #12 on: March 11, 2011, 04:47:30 PM »

You guys see the email about Hbgary trying to out-nmap nmap?

http://seclists.org/nmap-dev/2011/q1/767

Quote
This scanner would not take us very long to write, and it would BLOW
THE BALLS OFF OF NMAP.

 Roll Eyes
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #13 on: March 11, 2011, 05:10:27 PM »

That cartoon and especially that email regarding nmap, too funny Grin
Logged

GSEC, eCPPT, Sec+
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #14 on: March 11, 2011, 06:39:25 PM »

Schneier put together a great list of Ars Technica articles that went in-depth and contain some pretty interesting information: http://www.schneier.com/blog/archives/2011/02/anonymous_vs_hb.html
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.