<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>insanesecurity &#187; Anti-sec</title>
	<atom:link href="http://insanesecurity.info/blog/tag/anti-sec/feed" rel="self" type="application/rss+xml" />
	<link>http://insanesecurity.info/blog</link>
	<description>security through a distorted eye</description>
	<lastBuildDate>Thu, 25 Feb 2010 22:31:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>ImageShack was hacked&#8230;</title>
		<link>http://insanesecurity.info/blog/imageshack-was-hacked</link>
		<comments>http://insanesecurity.info/blog/imageshack-was-hacked#comments</comments>
		<pubDate>Sat, 11 Jul 2009 12:08:04 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Discussion]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Anti-sec]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/?p=214</guid>
		<description><![CDATA[As some of you may have noticed, news about ImageShack being hacked has started to circulate today. While I tried to see this for myself, part of the damage has been fixed; I say part because the ImageShack blog still throws database connection errors&#8230; Even if this may have been worse for users who store [...]]]></description>
			<content:encoded><![CDATA[<p>As some of you may have noticed, news about <a href="http://imageshack.us">ImageShack</a> being hacked has started to circulate today. While I tried to see this for myself, part of the damage has been fixed; I say part because the <a href="http://blog.imageshack.us/">ImageShack blog</a> still throws database connection errors&#8230;</p>
<p>Even if this may have been worse for users who store their images there (myself included), there is more to it than meets the eye.<br />
<span id="more-214"></span><br />
Like the attack on <a href="http://www.cgisecurity.com/2009/06/astalavistacom-hacked.html">Astalavista</a>, this one was also performed by the anti-sec group (groups, there could be more) and only makes me think there will be more attacks.</p>
<p>The message which was present on ImageShack&#8217;s website after the attack.<br />
<img src="http://insanesecurity.info/blog/wp-content/uploads/imageshack_hacked.gif" width="500" /></p>
<p>As you may have read their manifesto, hacking ImageShack does not conform to their goal&#8230;</p>
<blockquote><p>
How do we plan to achieve this? Through the full and unrelenting, unmerciful elimination of all supporters of full-disclosure and the security industry in its present form. If you own a security blog, an exploit publication website or you distribute any exploits&#8230;
</p></blockquote>
<p>Furthermore, they don&#8217;t see the irony of their actions. The more they are going to hack security unrelated websites (like ImageShack) the more are they going to spread FUD. And it&#8217;s needles to say that more FUD equals more work for the whitehats that they so much despise.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4879499347590889";
/* 468x60, created 1/22/09 */
google_ad_slot = "0361207255";
google_ad_width = 468;
google_ad_height = 60;
// --></script><br />
<script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script><br />
And they are good at spreading FUD! After the <a href="http://zone-h.org/mirror/id/8961233">Astalavista hack</a> OpenSSH exploit FUD <a href="http://news.softpedia.com/news/New-OpenSSH-Exploit-Possibly-Used-in-the-Wild-116247.shtml">spread online</a> like plague.</p>
<p>The only way I would go about vulnerability disclosure would be trough responsible one&#8230; Mentioning that I would be responsible only if the given vulnerability could affect me; otherwise I wouldn&#8217;t really care&#8230; that&#8217;s just me.</p>
<p>Even with all that said, there is one common ground where I can relay with them, concerning PoC code that script kiddies copy-pasta for mass sploitation&#8230; PoC should be only left for innovative/new techniques and not for every *dangerous* exploit out there.</p>
<p>Like any online movement it has it&#8217;s pros and cons; some didn&#8217;t/don&#8217;t understand the: VX, Zeitgeist, Anonymous (it is a movement, sort of) or any other movement; so why understand the Anti-sec one, right?</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/imageshack-was-hacked/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
