Unreal Playground  

Go Back   Unreal Playground > Unreal Playground > Playground Cafe > News Radio

News Radio All the news that Radio sees fit to print!!!

Reply
 
Thread Tools Rate Thread Display Modes
Old 09-04-2012, 04:07 PM   #1
radio667
I R Happy Goat
 
radio667's Avatar
 
Join Date: May 2002
Posts: 10,752
Downloads: 2

Hackers leak '1 MILLION records' on Apple fanbois from FEDS

from theregister.co.uk .......... FBI laptop with data on 12m iThings 'pwned via Java hole'FBI laptop with data on 12m iThings 'pwned via Java hole'


Hackers have dumped online the unique identification codes for one million Apple iPhones and iPads allegedly lifted from an FBI agent's laptop. The leak, if genuine, proves Feds are walking around with data on at least 12 million iOS devices.

The 20-byte ID codes were, we're told, copied from a file extracted from the Dell notebook of a senior federal agent, who was tracking the activities of hacktivists in LulzSec, Anonymous and related groups. Supervisor Special Agent Christopher Stangl's machine was compromised via a AtomicReferenceArray vulnerability in Java in March, the black hats claim.

Once his computer was infiltrated by the hackers, a file was allegedly seized containing 12 million device records that included Unique Device Identifiers (UDIDs) , usernames and push notification tokens as well as a smaller number of names, mobile phone numbers, addresses and zip codes. Members of the AntiSec crew leaked edited extracts of this data, having mostly stripped it of fanbois' personal information, on Monday.

The listed UDIDs, which include gadget serial numbers and other data so apps can distinguish between individual devices, appear to be genuine. However, by themselves they may pose only a minimal privacy risk once leaked online, so the effect of the dump is largely confined to embarrassing the Feds - and raising questions as to why agents have the information in the first place.

The most likely source of the data was either an iOS app developer or multiple developers, Mac Rumours speculates .

The Java exploit used in the attack is unrelated to the mega-bugs finally patched by Oracle last week.

It's a matter of record that Stangl was among the agents invited to an FBI-Scotland Yard conference call about the progress of investigations into members of Anonymous back in January. Members of LulzSec infamously eavesdropped on this call and leaked a recording after intercepting an email arranging the chat.

Email addresses exposed by this breach may have been used in a follow-up targeted attack that tricked investigators into visiting a booby-trapped website exploiting an at-the-time Java 0-day vulnerability. Rob Graham of Errata Security expands this plausible theory in this How the FBI might've been owned blog post .

The AntiSec activists behind this week's leak suggest the device info data was used as part of some FBI tracking project involving iOS devices, such as iPhones. Even they are a bit vague on what that might be. However the group goes into some detail in explaining how it apparently swiped the data:

Quote:
During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of "NCFTA_iOS_devices_intel.csv" turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose.
The AntiSec group says it decide to published a portion of the leaked data in response to a keynote speech by the NSA's General Keith Alexander at the DefCon hacker convention in July. In part, Alexander sought to persuade hackers at the convention to consider a career at the NSA, a suggestion that predictably galled the black hats.

Click the image to open in full size.

__________________
,


"There is also a river called Helikon [in Pieria]. (...) But, they go on to say, the women who killed Orpheus wished to wash off in it the blood-stains, and thereat the River sank underground, so as not to lend its waters to cleanse manslaughter."

—Pausanias, Description of Greece 9. 30. 8
radio667 is offline   Reply With Quote
Old 09-04-2012, 08:12 PM   #2
Creeper
Shock n00b
 
Creeper's Avatar
 
Join Date: Jul 2001
Location: Wherever I may Roam
Posts: 5,570
Downloads: 6

Send a message via Yahoo to Creeper
Glad the feds keep our private info so safe.
__________________
Frag hard, laugh harder.
Creeper is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
20 Million Black Ops Players Log 600 Million Multiplayer Hours radio667 Gaming 0 01-04-2011 04:36 PM
Apple threatens hackers with karma radio667 News Radio 2 02-18-2006 06:36 PM
Apple vs Apple trial date set radio667 News Radio 2 05-09-2005 09:21 AM


All times are GMT -5. The time now is 02:35 AM.


Powered by: vBulletin Version 3 something...
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Style and Content © 2001-2009 Unreal Playground