Showing posts with label 4Chan. Show all posts
Showing posts with label 4Chan. Show all posts

Who Are Anonymous?



Anonymous' organization


Anonymous isn’t truly an organization; not in any traditional sense. They are a large, decentralized group of individuals who share common interests and web haunts. There are no official members, guidelines, leaders, representatives or unifying principles. Rather, Anonymous is a word that identifies the millions of people, groups, and individuals on and off of the internet who, without disclosing their identities, express diverse opinions on many topics.


Being "Anonymous" is much more a quality or a self-definition than a membership. Each project under the Anonymous banner may have a whole different set of instigators. Leadership, when it exists, is informal and carried out in chat channels, forums, IM and public calls to action online. No one's meeting in a board room.

The name Anonymous itself is inspired by the perceived anonymity under which users post images and comments on the Internet. Usage of the term Anonymous in the sense of a shared identity began on imageboards.


Origin of Anonymous

They are loosely affiliated with 4chan and other smaller "chan" boards (like 7chan, 2chan and 711chan) due to these sites' anonymous posting feature, which allows them to plan attacks without revealing any identifying information.

A tag of Anonymous is assigned to visitors who leave comments without identifying the originator of the posted content. Users of imageboards sometimes jokingly acted as if Anonymous were a real person. As the popularity of imageboards increased, the idea of Anonymous as a collective of unnamed individuals became an internet meme.
They coordinate raids on forums like 4chan.org and ICQ chat rooms, among other venues. 4chan.org is a major hub, but I wouldn’t call it Anonymous’ home. Anonops.net was as close to an HQ as they had, but it has been shut down.

Some claim Anonymous to be the first internet-based superconsciousness. Anonymous is a group, in the sense that a flock of birds is a group. How do you know they're a group? Because they're travelling in the same direction. At any given moment, more birds could join, leave, peel off in another direction entirely.
Anonymous doesn't like to be called a 'group'. And much less do its members like to be called 'hackers'. They are, to use the manifesto's excitable, sci-fi-tinged terminology, an "Online Living Consciousness"

Anonymous hierarchy


They have been described as a leaderless, anarchic group of "hacktivists" but inside Anonymous, some have found that the organization is more hierarchical – with a hidden cabal of around a dozen highly skilled hackers coordinating attacks across the web.

One member said the group's "command and control" centers are invite-only, adding: "It's to protect people, but if you have proven trustworthy you get invited – it's not hard to do. It's not some elitist structure but a way to keep the press and the odd bit of law enforcement seeing who issues commands."

"Our project has no leader structure, only different roles. The degree of leadership and organization in the various projects various a lot," one long-term insider explained. "It's all very chaotic, but we communicate and co-operate with each other. I see us as different cells of the same organism."

The leaders of the group use internet relay chat (IRC) technology, which can allow groups of people to communicate clandestinely. Some in the upper echelons are understood to have control over "botnets" comprising more than 1,000 Windows PCs that have been infected with a virus and can be controlled without the user's knowledge to direct "distributed denial of service" (DDoS) attacks against target organizations.

History of Anonymous Hacktivism


We are Anonymous. We are legion. We do not forgive. We do not forget. Expect us.
-Anonymous

Long before they became vigilantes in the Wikileaks cyberwars, Anonymous was conducting large-scale “raids” against their enemies.

The Habbo Hotel raids


Probably the first time 4chan users banded together under the moniker Anonymous was in order to harass the users of Habbo Hotel, a cartoonish social network designed as a virtual hotel.
As early as 2006, Anonymous would "raid" Habbo, blocking its usual users from moving around. The first major raid is known as the "Great Habbo Raid of '06," and a subsequent raid the following year is known as the "Great Habbo Raid of '07."There appears to be some connection to the news of an Alabama amusement park banning a two-year-old toddler affected by AIDS from entering the park's swimming pool.

Habbo Hotel

Users signed up to the Habbo site dressed in avatars of a black man wearing a grey suit and an Afro hairstyle and blocked entry to the pool, declaring that it was "closed due to AIDS," flooding the site with internet sayings, and forming swastika-like formations. Then when all their black cartoon avatars got banned, they'd call Habbo racist. This was all done "for the lulz," or just for fun.
At this point, Anonymous’ actions had not taken on a political bent. Some members of Anon would argue it was better that way.

Hal Turner


Anonymous targeted this white supremacist with a talk radio show in December 2006. According to Hal Turner, in December 2006 and January 2007 individuals who identified themselves as Anonymous overloaded his website, costing him thousands of dollars in bandwidth bills.
Some Anons seem to have distaste for actual racism, though they express it frequently in jest. But of course you can never tell if it's the same people. "Anon is legion," they like to say.
As a result, Turner sued 4chan, eBaum's World, 7chan, and other websites for copyright infringement. He lost his plea for an injunction, however, and failed to receive letters from the court, which caused the lawsuit to lapse.

Chris Forcand


Anonymous helped catch an internet child predator, Chris Forcand, by reporting information to the police in 2007. By this time, Anonymous began to see themselves as a group of internet vigilantes fighting for assorted noble causes, rather than a band of merry pranksters.
On December 7, 2007, the Canada-based Toronto Sun newspaper published a report stating that Forcand was already being tracked by "cyber-vigilantes who seek to out anyone who presents with a sexual interest in children" before police investigations commenced. Forcand, 53, was charged with two counts of luring a child under the age of 14, attempt to invite sexual touching, attempted exposure, possessing a dangerous weapon, and carrying a concealed weapon
Anonymous contacted the police after some members were "propositioned" by Forcand with "disgusting photos of himself." The report also stated that this is the first time a suspected Internet predator was arrested by the police as a result of Internet vigilantism

The Church of Scientology


With these raids, Anonymous exploded into popular culture. The group gained worldwide press for Project Chanology, the protest against the Church of Scientology. 
Scientology
On January 14, 2008, a video produced by the Church featuring an interview with Tom Cruise was leaked to the Internet and uploaded to YouTube. When the Church tried to get this embarrassing footage taken down from YouTube, Anonymous formed a splinter group called Project Chanology that dedicated itself to stopping censorship and harassing the exploitative church.
Calling the action by the Church of Scientology a form of Internet censorship, members of Project Chanology organized a series of denial-of-service attacks against Scientology websites, prank calls, and black faxes to Scientology centers.

There were also several organized protests in many cities worldwide against Scientology. They took to the streets, protesting outside of Scientologist churches wearing "V-masks," the disguise used by Alan Moore's vigilante comic book hero, V, originally inspired by would-be British terrorist and folk hero Guy Fawkes.

Epilepsy Foundation


Anonymous has also trolled the Epilepsy Foundation of America, uploading seizure-inducing content to its forums.
On March 28, 2008, the epilepsy support forum run by the Epilepsy Foundation of America was assaulted and JavaScript code and flashing computer animations were posted with the intention of triggering migraine headaches and seizures in photosensitive and pattern-sensitive epileptics.

SOHH and AllHipHop


In late June 2008, users who identified themselves as Anonymous claimed responsibility for a series of attacks against the SOHH (Support Online Hip Hop) website. The attack was reported to have begun in retaliation for insults made by members of SOHH's "Just Bugging Out" forum against 4chan's users.

The attack against the website took place in stages, as Anonymous users flooded the SOHH forums, which were then shut down. On June 23, 2008, the group which identified themselves as Anonymous organized DDoS attacks against the website, successfully eliminating over 60% of the website's service capacity. On June 27, 2008, the hackers utilized cross-site scripting to alter the website's main page with satirical images and headlines referencing numerous racial stereotypes and slurs, and also successfully stole information from SOHH employees.

No Cussing Club


Anonymous also targeted the kid who started The No-Cussing Club, for obvious reasons. In January 2009 members of Anonymous targeted California teen McKay Hatch who runs the No Cussing Club, a website against profanity.



As Hatch's home address, phone number, and other personal information were leaked on-line, his family has received a lot of hate mail, lots of obscene phone calls, and even bogus pizza and pornography deliveries.

YouTube porn day


On May 20, 2009, members of Anonymous uploaded numerous pornographic videos onto YouTube. Many of these videos were disguised as children's videos or family friendly videos with tags such as "jonas brothers." YouTube has since removed all videos uploaded.



The BBC contacted one of the uploaders who stated that it was a "4chan raid" organized due to the removal of music videos from YouTube. BBC News reported that one victim posted a comment saying: "I'm 12 years old and what is this?" which went on to become an internet meme.

Iranian Election protests


Following allegations of vote rigging after the results of the June 2009 Iranian presidential election were announced, declaring Iran's incumbent President Mahmoud Ahmadinejad as the winner, thousands of Iranians participated in demonstrations.

Persian Bay

Anonymous teamed up with Pirate Bay and various Iranian hackers to offer Iranian dissidents a way to plan demonstrations and connect with the outside world. The result was Anonymous Iran, an Iranian Green Party Support site and a successful information-freedom project.

The site has drawn over 22,000 supporters worldwide and allows for information exchange between the world and Iran, despite attempts by the Iranian government to censor news about the riots on the internet. The site offers Iranian activists tools and advice on how to remain anonymous and avoid detection. Forums are provided for coordinating activities and communicating with the west.

Operation Didgeridie


In September 2009 the group reawakened "in order to protect civil rights" after several governments began to block access to its imageboards. The tipping point was the Australian government's plans for ISP-level censorship of the internet.

Early in the evening of September 9, Anonymous took down the prime minister's website with a distributed denial-of-service attack. The site was taken offline for approximately one hour.

Operation Titstorm


On the morning of February 10, 2010, Anonymous launched a more prepared attack hilariously-titled "Operation Titstorm."



It defaced the prime minister's website, took down the Australian Parliament House website for three days and nearly managed to take down the Department of Communications' website as a protest against the Australian Government over the forthcoming internet filtering legislation and the perceived censorship in pornography of small-breasted women (who are perceived to be under age) and female ejaculation.

Other entities they’ve tangled with include AT&T, Gene Simmons, KnowYourMeme, Hot Topic, Jessi Slaughter, and Tumblr. but I would consider these to be only skirmishes.





All of these without mentioning the recent Operation Payback, and the strikes againt Tunisia, Zimbabwe and Egypt.

Who knows where the next target might be...

Cyber War V - The Aftermath



Operation Payback


The wave of electronic assaults, referred to as "Operation Payback" led by the Anonymous group of activists as an effort to conduct denial of service attacks against a wide range of targets has experienced something of a setback and is now changing course. Yesterday's arrest of a Dutch teenager has caused some difficulties for the group as well, as he was apparently the operator of an IRC server coordinating the attacks. The result: a change in course and what appears to be diminished enthusiasm on the part of 4chan denizens who make up the Anonymous collective.
Operation Payback

These attacks were aimed at the home sites of the credit card companies. Those sites have high profiles but relatively low traffic levels -- traffic levels that make them more vulnerable to a distributed denial of service (DDoS) attack. Such attacks deliberately spike the traffic to a site and make it inaccessible. But those were just are their public-facing websites, not the transaction processing.
While the headlines Operation Payback has been able to generate with its attacks may be giving the credit card companies a black eye and are a source of embarrassment, they are distorting the actual security threat to the firms' financial systems. Where it counts, which is making sure that when you and I are at the mall buying gifts for our family for Christmas, they've got an amazingly robust infrastructure.
Operation Payback's attacks on Visa and MasterCard were undertaken in retaliation for the companies' decision to refuse to process donations to Wikileaks, a site that most recently made waves by leaking hundreds of thousands of private U.S. State Department messages, some of which were classified as "Secret."

PayPal, an online financial transaction company, took similar action, but its main site did not come under attack. They didn't try to take out PayPal itself because PayPal is way too large and distributed and able to resist the attack, and it wouldn't look good for the attacker so they went after Paypal's blog instead because it was an easier target.

Although the transaction systems of the credit card companies may have been insulated from the denial of service attacks on their home sites, the assaults may have some financial consequences for the firms. Both businesses have programs -- Verified By Visa and MasterCard SecureCode -- that require additional authentication when making online purchases with merchants participating in those programs. Those systems are being affected by these denial of service attacks because they rely on MasterCard's and Visa's websites to be there to type in your extra security code. There is the potential of holiday shoppers shopping online not being able to purchase anything with their MasterCard or Visa, and so it could hit the pocketbooks over at the credit card companies.

 

Operation Leakspin

But Operation Payback is yesterday's news. Today, it's all about Operation Leakspin. Now apparently  Anonymous  switched from trying to disrupt anti-Wikileaks sites to trying to spread the info from Wikileaks' secret diplomatic cables in as many ways as possible. This new tactic is called Operation Leakspin.
Operation Leakspin

The idea behind Leakspin is to pick out some of the less-publicized Wikileaks info and post it in innocuous locations, in YouTube videos and on message boards. Videos with popular keywords like "Bieber" could turn out be Anonymous members reading from the secret diplomatic cables. Why the sudden change in tactics? Because the mission all along has been to keep the Wikileaks documents online. "They don't fear the LOIC. They fear exposure," says the Op Leakspin poster.

This morning, Anonymous issued a press release in an attempt to explain its new position. The release states that Anonymous has no interest in compromising personal information or credit card details, but rather that its attacks on financial companies are motivated by a desire to draw attention to the way in which they are hurting WikiLeaks—taking "symbolic action" against the companies' "public faces." The announcement also recognizes that the group has not been doing a good job of explaining its motivation so far.

The authors of the press release also sought to distance themselves from calls made on Twitter yesterday to attack amazon.com—an attack that did not actually occur. A denial of service attack on Amazon was unlikely to succeed—the very reason that WikiLeaks itself used the company for its hosting for a brief period—but more than this, the writers say that such an attack would "affect people such as consumers in a negative way and make them feel threatened by Anonymous." As such, it would be counterproductive and "in bad taste."

In the meantime, several of the Anonymous IRC servers are offline, with some "down for maintenance," which could very well indicate that the group is looking for new hosting. At the very least, they're experiencing serious DNS issues. There also seems to be little enthusiasm for the new approach on 4chan.

Operation Payback has also been slowed down by Twitter and Facebook banning pages that broadcast Anon's plans and calls to action. Although Twitter has said they're not blocking Wikileaks tweets from the trending topics list, they did shut down the Anonymous Operations Twitter account. Facebook took down the equivalent page on its site, too. Naturally, several more have popped up in their place. There are conflicting claims about whether the US government has put pressure on financial services and social media sites to stifle support for Wikileaks.

High Orbit Ion Cannon


But this might not be the end of the DDoS Attacks, today a new tool was released and a new wave of attacks was somehow initiated using the High Orbit Ion Cannon. This new tool is supposed to be more effective, less prone to detection hence theoretically capable of greater damage to targeted websites.
HOIC

Cyber War IV - Operation Payback explained


These kind of hacking campaigns are not a new phenomenon triggered by the Wikileaks situation. Just to mention a well-known example, back in 2003, the Recording Industry Association of America (RIAA) had their site collapsed due to a series of online attacks after they’d launched a joint anti-file piracy campaign together the Motion Picture Association of America (MPAA). Now we have this so called “Operation Payback”, a new initiative allegedly from the same group of hackers that performed the attacks in 2003.
Operation Payback
It’s believed that other hacker groups have joined in on the efforts to ally themselves with WikiLeaks and attack those who’ve attacked out against WikiLeaks. Nobody on the outside knows just how big this network spans and especially if they’ve been banded together with communities like 4chan, it could very well be one of the largest unified hacking campaigns to date.
4chan




This type of attack typically involves flooding a target website with data. The attackers hope to overwhelm it in one way or another so it cannot serve its legitimate users. As its name implies it aims to deny service to those visitors.

How are the attacks made?


Using Twitter and probably hidden IRC channels, the group has managed coordinate their attacks in a very effective way. The majority of the attacks so far have all been mass DDoS (Distributed Denial-of-Service) attacks which on a big scale and have been effective in collapsing the websites of these organizations. In case you're unaware of the type of attack this is, it's a method that calls on multiple computers (usually networked as slave units) to connect all at once and continuously to the victim of the attack, causing their servers to collapse due to the weight of traffic demands.



There are many types of DDoS attacks; some exploit the basic protocols of the internet that define how your web browser talks to the webpage you want to visit while other attacks send fragments of data packets to a target so it spends all its time putting them back together rather than sending data to visitors. Against sites with a low bandwidth link to the wider web simply sending lots of data traffic can choke the connection and cut it off.
In essence, what is happening is that lots and lots of individuals are hammering specific websites with TCP or UDP packets or HTTP requests. There are only so many resources to go around, which means that with enough individuals involved, even large websites can be taken down very quickly.
The first denial of service attacks typically came from a single source. Now the data bombardment is typically carried out by lots of computers, usually running Windows, all over the world, hence distributed. Most attacks are carried out through a botnet.
DDoS




What is a botnet?


Botnets are groups of computers, unwittingly linked together via the internet, that can be remotely controlled to perform tasks. Typically they send out spam email, perform DDoS attacks, and gather personal information. Botnets are typically created through virus infection, or by installing malicious software (known as malware) on your machine. Malware can take many forms but are typically referred to as a 'trojan'. Named after the legendary Trojan horse, it is a piece of malicious code that hides inside another piece of software (in this instance illegally downloaded copies of software).

As the user installs the software, it is also installing the trojan program unware of the fact that might be creating a new zombie computer to be part of a botnet controled by who knows who....


Botnet




Most of the participants in Operation Payback are not hackers — at least not in the true sense of the word. Instead, these users are using computer programs — or more recently, simply visiting websites — in order to stage their attack.


Anonymous is using a botnet but one that is slightly different to the usual. The botnet is made up of machines that have been actively enrolled in it by their owners downloading and installing Anonymous' attack tool - known as the Low Orbit Ion Cannon (LOIC).
This tool, which was purportedly originally created to stress test networks, is written in C# and can be downloaded off open source code repositories like Github and Sourceforge.
LOIC can be used to target a website the user inputs, or using an option called Hive Mind, to connect to IRC or even Twitter, and grab information for a targeted web attack. Because C# will only work on Windows computers out of the box (Mac and Linux users have to install additional libraries and do extra configuration), a Java port of LOIC also exists. The most recent variant of LOIC is a new proof of concept that is floating around called JS LOIC. The “JS” in the title stands for JavaScript. This proof of concept, which doesn’t appear to have as many features as LOIC or Java LOIC — and may also be easier to stop — is actually pretty clever.
JS LOIC

Rather than requiring a user download program to run, someone can just visit a web page with a single HTML file and press a button to carry out their part of an attack. On the one hand, the trick of using JavaScript to carry out this kind of flooding attack is pretty clever. On the other hand, it’s also pretty scary.

From what we can gather, the majority of the attacks on Operation Payback targets are not coming from web clients. However, that could change. We would caution users against clicking on any links claiming to aid in this series of attacks. Not only is willfully participating in a DDoS illegal in many countries, you never know what is behind the file you download or what action clicking on that web button could trigger.
As with many other aspects of the WikiLeaks saga, the distributed and de-centralized nature of the Internet means that shutting down all mirrors for documents — or even for attack tools — is an exercise in futility.

This is easily the most public and mainstream hacking campaign to date and so far it must be said, has been largely successful. A spokesperson for the group behind Operation Payback posted that they’d attack all of those who were “bowing down to government pressure”.

So what does this say about the power of the internet? Nothing really that experts didn’t know about. But for the general public and for the media as a whole, I think it’s come to quite a shock to them knowing that hackers could be so influential and on the frontline of the news for a sustained period of time. Most people’s impressions of your average hacker is that of one who sits around and steals your credit card number and whilst this is still a major problem, it does put things into perspective when groups such as Anon manage to bring down Goliath companies like Mastercard and Swiss FinancePost to their knees.

Small defacement attacks by political reasons, or just for the fun of it, are very common and happen every day but this is a completely new phenomenon, we are now dealing with a potentially global cyber power and cyber war can trigger some heavy legislative responses from governments worldwide.

Cyber War III - Change in Tactics?

'Coldblood', a member of the group Anonymous, told a BBC reporter why he views its attacks on Visa and Mastercard as defence of Wikileaks. Web attacks carried out in support of Wikileaks are being wound down as activists consider changing tactics. Attacks against Amazon were called off late on 9 December and re-directed towards net payments firm Paypal and its computer systems which, according to a status page, has intermittently suffered "performance issues" ever since.


There have also been calls for attacks on official Dutch websites following the arrest of a 16-year-old boy suspected of involvement in the online campaign. But early today Moneybookers was chosen as the next target and its site was occasionally unreachable from about 1100 GMT.

The chances of success could be boosted by a new version of LOIC written in web programming language Javascript that allows anyone with a browser, including on a mobile phone, to launch attacks. However, defences against the attacks were being drawn up as security firms scrutinise the code behind LOIC to work out how attacks happen. Some suggest that well-written firewall rules would be able to filter out most of the harmful traffic.

The LOIC tool has been downloaded more than 46,000 times but, said Anonymous activists in a tweet, this did not translate into enough people using it to knock the retail giant off the web

One of those activists said he had a botnet of 30,000 machines under his control that he was planning to use on behalf of Wikileaks. A botnet is a network of hijacked home computers that have been compromised by their owners visiting a booby-trapped webpage that installs code to hand over control to a hi-tech criminal. A botnet with 30,000 machines in it is considered to be about average size. Most of the spam sent around the net is funnelled through machines that are in botnets.

There are also suggestions that the Anonymous group might be about to drop the web attacks in favour of another tactic. Its use of the term Anonymous comes from a series of websites frequented by members, such as the anarchic image board 4Chan. These allow users to post without having to register or provide a name. As a result, their comments are tagged "Anonymous".

A message posted on the 4chan image board, out of which Anonymous has grown, suggests dropping LOIC in favour of publicising information in the diplomatic cables that Wikileaks is releasing. Searching for the less-well publicised cables and spreading the information they contain around the web could be more effective than simply knocking out sites deemed to be enemies of Wikileaks, it said.

The message also suggests using misleading tags on posts and YouTube videos to trick people into reading or viewing the information.

"They don't fear the LOIC, they fear exposure," read the message.