Showing posts with label anti-sec. Show all posts
Showing posts with label anti-sec. Show all posts

Thursday, June 9, 2011

Indian Government web-sites need attention


The Hacker collective Anonymous joined the fight against Indian corruption by hacking the site of the Indian government IT website NIC, the National Informatics Center. Ostensibly the hack was a retaliation for the government’s violence against Indian activist Baba Ramdev, who had been staging a hunger strike to protest government corruption, which the government recently disbanded with violent force. The hack, which the group claims took just three minutes, displayed the above message on the site. NIC quickly moved to take the page offline, but a cached Google page confirmed the direct hit by Anonymous. The hack comes just days after Anonymous hacked the government database of Iran, exposing private emails from that country. While no data was stolen or exposed from this latest hack in India, Anonymous’ message was clear: the corruption of institutional forces runs against individual freedom.

A statement by Anonymous said, “Over fifty years ago, Indian Freedom Fighters laid down their lives for our freedom. In the end, what was it all for? Today our politicians ride slip-shod over our laws, corruption is rampant. If the brutal way Baba Ramdev’s hunger strike was crushed is anything to go by, it would seem that India is now on its way to becoming an undemocratic ‘democracy’.”
This is something really worth giving a thought, why all of sudden ANONYMUS has to voice for Indian issues, give a thought, you hackers may realize the fact and reason behind it.

In the past, we have witnessed many of our websites being hacked including India's Central Bureau of Investigation (CBI), colleges, NGOs, Indian companies and religious organisations among others by Pakistani Hackers. And, in the recent past, ONGC website too was hacked by them. And now, there are many chances that they would target SAIL (Steel Authority of India) website as it has many vulnerabilities and can be easily hacked.

The unfortunate part is that in spite of being warned by Kaizen India Info – Sec Solutions Pvt. Ltd (A cyber security firm that is working towards making our country free from cyber threats) about the loopholes to SAIL authorities, no necessary actions have been taken so far. Similarly, Kaizen had also informed higher authorities of ONGC about the vulnerabilities in their website but they too did not pay heed to the warning and ultimately landed up getting hacked by Pakistani hackers. Sadly, whenever a website gets hacked, fingers are always pointed towards the hackers but the fact is that the website owners themselves are responsible for not taking proper care and leaving their websites open with all the loopholes inviting hackers to attack.

A tit-for-tat campaign has been in practice by groups on both Indian and Pakistani sides dating back to the late 1990s when tensions over the disputed Himalayan territory of Kashmir brought the nuclear-armed neighbours to the brink of war.

In 2009, India’s one of the biggest banks Bank of Baroda, a global bank with a network of branches in India, and an international presence in 21 countries was hacked by Pakistani hacker group called Pakbugs.

“Indians place little or no value on the kind of data individuals and organisations in many countries prefer to keep confidential, like passport and bank account details or work contracts,” Cyber Expert Vijay Mukhi said.
"Privacy is a concept not rooted in India culture. I don't think we can change that and I don't think it's going to change in my lifetime," he added.
"The government doesn't care" about protecting information online. Corporates for some reason just don't want to spend the money. They don't think it happens often. Web security is a low priority," he said.

Very recently, the website of Sony BMG has been hacked and an anonymous poster has uploaded a user database to pastebin.com, including the usernames, real names and email addresses of users registered on SonyMusic.gr. This kind of company websites getting hacked not only affects the company itself but also the customers. Interestingly, many of the companies are insured and thus they get their losses recovered leaving the customers to suffer.

The question that arises is who will take action against these attacks? Government has been maintaining silence even though one after the other their websites are been attacked and details are been leaked or deleted. Is our government so weak? Now, after CBI, ONGC, Bank of Baroda and many other official websites, SAIL can be the next target. Hope that the SAIL authorities are listening and would take necessary steps towards protecting their website

Monday, May 23, 2011

Similarities of Underground and underworld




All these days I am doing research on Hackers, their communities, their way of functioning and their life style. I noticed lots of similarities between Underworld Criminals and hackers. For example hackers and mafia’s both uses handle and they are scared to disclose their original names. Their identity is either their group or their handle.


We have so many known criminals like chota rajan who’s actual name is Rajendra Nikhalje (nana), Dawood Ibrahim (Bhai) Pav Takla (Chota shakeel) Fahim mach mach, saleem langda, Arun Gavli (daddy) Doctor is handle of Gavli Gang criminal, who use to executive crime operations with hundred percent accuracy. That’s why they use to call him Doctor. Fahim has habbit of arguing that’s why he was called ‘mach mach’. Langda has one leg short due to polio. Chota shakil has wisdom hair cut so he was named as “Pav takla” (quarter portion of head balled).

I don’t know the specific reason for Hackers having their particular handles but they are known by that. R45c4l, micr0, H4x0r, c0de crack3r,silent poison, dark l00k, nirvana, snake, d4rk code…there are number of handles of these hackers.
There are mafia communities like D company, Rajan gang, Gavli gang, Naik gang, mudliar group, haji mastan group..Harya Narya gang...these are the groups and communities of mafia’s. Their community members use nicknames both to separate insiders from outsiders and to stymie potential executions into their. They use violence strategically by planning each action by their commanders. These commanders are like admin in charges or group leaders.

Likewise Hackers too have their groups ICA, ICW, l33t (original) l33t (fake Indian idiots) AH, Punjabi hackers. PCA, Pakbugs (Pakistan)and the other side the elite groups like ICW, Garage for hackers, Anonymous, Anti sec, Nirvana, Chaos (Germany), KHG (Kosovo), Iranian cyber army, Red Army ( china) th3j35t3r…

PCA and Paksbug are Pakistani hackers group, their prime target in India and their fight is over Kashmir. They never harm or hack their own country people or group. They are Pakistani patriots. Anonymous group fight for freedom of speech, freedom of media and freedom of press. One more reason of their fight is privacy and right of common man. You won’t have a single example where they have targeted common man or business group or specially such organizations where hackers are recruited or assigned jobs. They have no website; their messages are with cause and concrete statements addressing administration and system.

KHG fights for Kosovo and freedom of their country, Anti sec against the exploits writers and antivirus companies. Iranian cyber army for the freedom of their country, they have ethics and principals. These groups are highly skilled groups with no showsha, no personal attacks, or no bad business. Most of them are with patriotism.

African hackers are like Robin Hoods they are mostly in financial crimes, carding, money laundering. Their country is poor, they lack opportunities and scope. This is how they earn their living and support many by doing charity towards community and churches.
There are some groups of hackers work for charity. 80% hackers in Indian jail are Africans.

A famous group called “Hackers for Charity”, known for their utmost contribution towards underprivileged

The original l33t hacker community and forums are against piracy, porn and corruption. They are the most educated and skilled hackers with lethal techniques. Unfortunately some Indian goons are tarnishing their image by copying the name l33t.

Recently formed Indian l33ts are the bunch of arrogant brats, born in bank corrupt families; parents are in financial scams, one of the so called l33ts father is a government employee, other ones mother is caught in scam. Some of them call themselves panther, lion, wolfs and codes. The most pathetic amongst them are Gujrat and south ones. They copied name of famous l33t group but couldn’t even reach to any of their basic qualities. There is one Face book profile of this so called l33t, I wonder how can they survive so shamelessly by copying the name of legends? They prefer to send hard-to-fake signals about their badness and their inability to fit in any part of the larger world: hence the tendency toward showing incompetence at tasks other than criminality, as seen in the recent past. Their tendency toward extreme show off and the participation in criminal events is quite peculiar. They attack all famous people and try encashing out of them. They are Indian anti-nations groups of hackers. You can see some of the same behavior in almost any new group of Indian Hackers.

The other side’s there are Mafia’s like Chota Rajan is known as patriot don, because he provides information about underworld to intelligence department. That group is never into drugs or flesh trading and fake currency. No doubt he is criminal and is on the top of most wanted list. But still his crime has not affected innocent average Indians.
D’company Indian anti-national group, they are always in favor of Pakistan and support group of Taliban. They have caused maximum loss to our country and innocent citizens by bomb blast, drug peddling, and fake currency. Harboring terrorists and murders they damaged Indian securities.

The legend groups like ICW, HMG and the original members of it, always had agenda of securing nation. They never sabotaged their country interest. They never believed in cheap defacements, and their hacks were never in quantity or random that was quality, all high profile hacks.ICW is the group even signed peace deal with Pak hackers, bur letter on the new group of hacker damaged the deal and in reaction to action even Pakistani hackers start random defacements.

As we all know Garage (G4H) is community of professionals and they don’t support hacking they only support knowledge sharing and they can’t stop anyone to register with garage as its public community. So far I have never witnessed any defacement or any hacks by garage ever, but some registered members of garage are bringing bad name to this unique group and they need to be strict over registrations.because its open group and any one can be rejistered there.


Unfortunately there are some hackers from these well known groups joined hands with the groups like Indian fake l33ts, and bypassed the ethics of hacker’s community. There is so much to write on this, but rest of it you can read in my soon to be launched Cattechie book.

One more common factor, In 2003 a journalist Tirodkar who became tipper of police and double crossing mafia’s and police had helped the mafia locate potential victims for fake encounters and to settle nefarious deals. However, later he was charge sheeted under MCOCA,and released on bail. He violated journalistic ethics to gun down criminals and expose fakes in Police department. He suffered a lot there after by police and mafias. But his faith in judiciary and his national interest got him scot free from all such clutches.

Here again I being journalist facing all odds but one day will reach to my goal by eliminating odds and antinational elements from Hackers community.

All these days I worked as political and crime correspondent in various publications. Investigations and research is my favorite subject. Detecting crime and criminals is my passion; hitting headline with crime story is my Job. Once upon a time there use to be competition between Mid-day, Afteroon and Mumbai Mirror. Those days, remaining on front page with lead crime stories was a challenge. I used to bother so many officers for info, at the same time police informers and private detectives and intelligence sources use to give me tip off to reach my goal. I was blue eyed baby of by senior editor Mr.Pandit.
Now when I am working on hackers, my mission is yet to be accomplished because I am yet to reach my goal. Because the Codes of the Underworld and underground yet to be encoded.

Monday, April 11, 2011

When Hackers Penetrate Each Other

There is one article written by some hacker of Thailand Pe3z, “When hackers penetrate each other”. It’s really worth reading; he says (translated from thai by google) “This is not even any other drama this occurs when there is a group of hackers. The site of a hacker attack themselves, because due to a hacker site such that the "sales course" in exchange for money. The party then went further. Also stated that the "teaching shit hacking." Another very short one, so very careful, I bite find. Types of snakes very short money teaching other people to fish any other fraud Bla any other.” This was really an awesome statement.

But here I want to say in India there are hundreds of so called ethical hacking institutes and 60 of them are topers of this hacking training industry and doing great business. We are also against commercializing hacking, because as we all know plenty of open source resources are available for learning such stuff. The question here is “what if a person is slow learner or doesn’t have that much capacity to learn on his own? Why they should not be provided with the knowledge, hacking is not property of someone who can solely possess for himself. For that matter you are not even needed to attend school or college because the stuff you study in books is very well available on open source, knowledge is knowledge, let it be hacking or faking, its openly available everywhere. But the knowledge needs authentication. (again depends who will certify whom?).

One more question, there are many people who made hacking as an industry of producing hacker and randomly thousands of students seek courses from them? Do we have guts to physically stop this mockery or control over such business? NO, we can only deface or damage someone virtually which is nowhere related to his prosperity.


If all these classes are controlled or closed by some defacer friends of mine, then I will quit this business of cyber security and remain in the business of news that is what I am actually doing
(but till want to assure on my behalf).

Kaizen in a venture by a hacker and his friends, he tried doing something on his own by refusing to be a bonded labor. Where is he wrong? Whatever he is selling is his skill, and if he keeps on defacing pages to add glory to his skills as hacker who will take care of his living and bread butter? There are many such hackers working with him and he is definitely trying something different. The other side of hackers those who were working in some training institutes started new pattern of teaching because they don’t want to make this wisdom a mockery, where are they wrong?

Magazine is the only niche print which reaches stalls and corporate sectors and some hackers got the recognition and name out of it and this magazine is providing bread butter to vendor, circulation, printer, peon, office staff to the hackers those involved in it. Can anyone guarantee me providing living to these many people? Till today r45c4l used to struggle for getting his salary at the end of the month, now he must be definitely happy to be provider to some families…. that’s blessing and basic difference as provider and seeker.

Blogging, defacing, garages,groups,sects…oh my god there are many segments to one word HAKERS..I thought at least they are away from false pride, jealous, greed and politics but it’s quite unfortunate to say they are also victims of such evil tendencies. If hackers like r45c4l, trying to get hackers in main stream profession is crime then I support this criminal.

Last but not the least I thank “Anonymous” Group, it was really heartfelt message. They stood by hacker and warned mockers, those randomly harassing hacker by posing as one of the CBI thread. The one who are instigating young hackers to do defacement..they are scaring hackers against another group of hackers, they divide and trying to rule which is not possible because some hackers refuted such evil ideas.

Who does what, and why is big question, I don’t want to be a judge or moral custodian of someone’s behavior. When I cannot create or share. I have no right to destroy or snatch. I am happy to be a target of A HACKERS AND EVEN FEEL GREAT because now the focus of them is not rival countries or cyber securities or biggies of this business..It’s ME THE CAT…. Still some hacker are loud about saying it’s me who got the sites hacked for publicity, here I can just say..”I wish I could have been such a great hacker”...any ways I always had a great dream of having few dedications at Zone –H, someone gifted it to me..

Blessing in disguise..

Saturday, February 19, 2011

Anti-sec - group of hackers to keep security

Anti-sec is the group of underground hackers; and they are here with the cause. They say big no to promoting Hacking related open materials and making it a child’s play. This is probably the revulsion to combat evil trends in cyber arena and control over this deservedly elite occupation which has been encroached by larger commercial groups such as virus creators, antivirus producers, that the movement is more a rebellion against that. This group came in lime light after hacking “imageShack’ one of the most popular image hosting service in the cyber world. Anti-Sec Movement, staunchly dedicated to the eradication of “full disclosure” hacked this world’s largest image hosting site, played around with their own ideas and they replaced the images uploaded by users with that of their own, which is supposedly the image of the manifesto of ‘their movement’. The entire visual display was rounded off with the message “no images were harmed in the making of this.. Image.”

Anyways nobody could deny their abilities after the attack of milw0rm. Anti-secs want to keep security - in particular, exploits - private. In way they are right because inj3ct0rs were getting bad name because of open display of exploits. There are evidences that the exploits were used by antinationalist for elicit purpose. Milw0rm is their nemesis. There's a discernible political bent to their writings and ratings. While we see a general shift on the internet towards the idea that "information just wants to be free", the anti-sec people don't agree with this when it comes to matters of security. From a white-hat point of view, they're saying that full disclosure actually causes more damage than if only a select few, capable, and not necessarily malevolent, people were to know about any particular exploit. So far it’s not clear that there's a tad of immaturity and insecurity in these people or they really want to work in the interest of cyber security, and one should appreciate that. The common claim of the Movement is that “full disclosure is the disclosure of exploits publicly - anywhere.” the security industry for making profit due to “full-disclosure” with “scare tactics” that were intended to make the public purchase anti-virus software and firewalls. Well, with their daring “heist”, the members surely have managed to across loud and clear the gist of their intention.

In other terms you can say this movement is kind of fight or crusade against the traditional for-profit computer security industry. They think that publicizing security holes and those hole's exploits causes more pain than it helps. They also seem to be kind of anti-capitalist and are very talented security researchers. Antisec are the kind of amazing group of hackers who don't want profit from fear. Generally Hackers are known for creating deterrence, fear and penetrations. Here is this group to sabotage such intentions of Dark side of cyber world. There are so many myths and misconceptions about them but the fact is that they at least have credibility. These guys are sticking to their guns and keeping the hacking underground just that, underground. Anti-sec is a response to the fear-mongering era of 1998 - 2004 when every hanger-on wannabe computer guy became a security researcher and started publishing "advisories". Between dotcom bubble eras to 9/11, everybody was a security guy, and not only that, but the "security guy" was pointing the finger at the hacker community every time a script kiddie defaced some web page. Those most sec guys are snake-oil salesmen and absolutely deserve no sympathy. If they're gonna bad-mouth hackers and promise protection to everyone then let them protect themselves from the real Hackers; by and large, they're out-gunned and out-skilled.

There are many so called security ( tech or defense agencies) minting money over suing the tag of Hacker, they have made it business, every year thousand of hackers are (youngsters) manufactured in their so called industry but still nation lacks hundreds of security personals towards national security. This is irony and here is need of someone to stop these ‘manufacturers of hackers’, I think hackers like Anti sec are the proper takers on these morons. Anti-sec doesn't go after civilians, by the way. The another biggest threat today is there are hundreds of exploit writers around the globe, One group publishes exploits and carries out mayhem for fun so make such high profile hacks were attempted just because of open display of these exploits. It doesn't matter what they are or what they do and why they do the most important thing is they are here with the Cause, and that is nothing but the security at large.
The Anti Security Movement or popularly written as Anti-sec is a popular movement opposed to the computer security industry. It attempts to censor the publication of information relating to but not limited to: software vulnerabilities, exploits, exploitation techniques, hacking tools, attacking public outlets and distribution points of that information. Movement followers have cited websites such as Security Focus, Security team, Packet Storm Security, and milw0rm to be targets of their cause, as well as mailing lists like "full-disclosure", "vuln-dev", "vendor-sec" and bugtraq, as well as public forums and IRC channels. The start of most public attacks in the name of the anti-security movement started in around 1999 and 2000. The "anti-security movement" as it is understood today was coined by the following document which was initially an index on the anti.security.is website. The purpose of this movement is to encourage a new policy of anti-disclosure among the computer and network security communities. The goal is not to ultimately discourage the publication of all security-related news and developments, but rather, to stop the disclosure of all unknown or non-public exploits and vulnerabilities. In essence, this would put a stop to the publication of all private materials that could allow script kiddies from compromising systems via unknown methods.

A common misconception is that if groups or individuals keep exploits and security secrets to themselves, they will become the dominators of the "illegal scene", as countless insecure systems will be solely at their mercy. This is far from the truth. Forums for information trade, such as Bugtraq, Packetstorm, www.hack.co.za, and vuln-dev have done much more to harm the underground and net than they have done to help them. This was one of the first anti-security hacktivist groups. The group waged war on the security industry with their popular assault known asAnti-Sec. In a nutshell, this group doesn't like websites that promote security. If a website provides different methods for safety then Anti-Sec wants to blank their site. They want to take away the ability of organizations to sell their services.

No one knows about this group so far, they don’t have any sort of forum or website or any traces where the members can be located, and if someone clames about knowing them, then It can subject to doubt. The kinds of hacks they have performed and beguile they blown against bigwigs are not in a mood to spare them, maintaining anonymity is compulsion for them. Still it’s very much interesting and leaves the reason to think about their agenda and activities. Bravo guys..

Read in details ,soon to be published “Cat Techie”………………….