Showing posts with label CYBERWARZONE. Show all posts
Showing posts with label CYBERWARZONE. Show all posts

Monday, July 2, 2012

National Bloggers Club Unmasked: Link from Breitbart Unmasked - MAY CONTAIN SBU INFORMATION

A number of right wing bloggers who claim they are the National Bloggers Club have recently been attacking Brett Kimberlin in mass accusing him of every dirty deed in the book. So, because of that, we here at BU decided to check into this National Bloggers Club to see who was behind it, and what their mission is, and also who funded who, or where the money came from to run this loose knit operation of right wing bloggers who use the internet to raise money for causes they create, and or basically wreck havoc with anyone considered an enemy of their little group.

 

First up is Ali A. Akbar.

Ali and his childhood friends are directors of the National Bloggers Club. However they don’t all live at this address above. I find it strange they all do not live or even work at this address, yet file corporate forms with the State and IRS that claim that they all live or reside or work at this address. The issue here is that most of these people running this company are just young kids in their early 20′s who have scant to zero business experience and seem to not know the landscape of the business world or how to operate in it. But that is just my opinion.

Then there is the affable John Dennis Pedrie as one of the Directors of The National Bloggers Club. His claim to fame was that he worked until 2010 at the Onyx Ice Arena as an Ice Rink Maintenance Man. So he went from Ice Maintenance worker to Vice President of Technology and Development at Vice & Victory, which is another Ali Akbar creation, to one of the Directors of The National Bloggers Club. Wow, sounds like he has some real corporate experience behind him.

 

Then we go to Devon Wills, who’s claim to fame was that he was a personal shopper at J Crew before he became the CEO at Wills Group LLC, and then later a Director of The National Bloggers Club.

Right now he is going to the all christian stud Liberty University which was founded by the Reverend Jerry Falwell, and which claims in its mission statement that it trains Champions for Christ.

There are a number of others who are in the process of signing up for a National Bloggers Club board seat; such as Michele Malkin who has also been a front runner in leading the charge against Brett Kimberlin in the media. Of course we will post more data on this organization as the crow flies here at BU. The one interesting connection was who was the money man that seeded the National Bloggers Club? Well, that just so happens to be Foster Friess. Foster is another right wing corporate billionaire who has given money to the Koch Brothers, and also claims he also helps out American Crossroads which is run by Karl Rove.

 

Friess has been an active patron of religious and conservative causes. He has been instrumental in keeping the political campaign of the 2012 presidential hopeful Rick Santorum alive by financing a super PAC, the Red, White and Blue Fund, which runs television advertisements on behalf of Santorum, who was unable to run a television campaign with his own funds. According to campaign filings with the Federal Election Commission, Friess’s contributions to the Red, White and Blue Fund amount to more than 40% of its total assets – or, $331,000 as of 31 December 2011.[5][6]He had donated $250,000 to Santorum’s re-election campaign in 2006, and at least that amount to the Republican Governors’ Association.[7] In the wake of the New Hampshire Republican primary, 2012, and before the South Carolina primary, Friess told Politico that he was “putting together a challenge grant to encourage other wealthy donors to give to the Red, White and Blue Fund, … he said [the fund] received a $1 million check” the day after the New Hampshire vote.[8] The Million-dollar donation was conveyed in four checks between November, 2011 and January, 2012.[6]

In addition to Santorum’s faith, pro-life stance, and hawkish foreign policy leanings, the possibility of defeating incumbent President Barack Obama was a major component of Friess’s decision to back Santorum’s campaign.[9] Friess is reportedly considering major contributions to American Crossroads in hopes to influence key 2012 senate races.[10]

Friess has also donated $100,000 to Wisconsin Governor Scott Walker to help defeat the Democrats’ recall effort in 2011. In addition, he has reportedly donated more than $3 million to the conservative commentator Tucker Carlson‘s The Daily Caller website.[7] At one of the semi-annual, private seminars held by the Koch brothers in June 2011, Friess was recognized for his donation exceeding $1 million to the Kochs’ political activities.[11]

The other interesting connection was this Yahoo News article on the private invite only meeting that started the National Bloggers Club.

James O’Keefe attending the opening bash of the National Bloggers Club and claiming Fuck the media? Well James I think you have that wrong, it’s not fuck the media, it’s the media fucks you. But that is just how I look at it.

So what do we have here? We have Foster Friess starting the National Bloggers Club with James O’Keefe attending, with connections to the Koch Brothers and Karl Rove. We also have media personalities such as Michele Malkin who is also connected to Robert Stacy McCain. We also have Ali Akbar who is connected to the rest of the right wing bloggers, and who have all been attacking in mass one guy by the name of Brett Kimberlin, who I might add has been on a many years long crusade to expose the corruption behind Karl Rove and the Koch Brothers and James O’Keefe. I would call these connections very interesting indeed. What I also find even more interesting is that they have recently been raising money for a few bloggers who they claim are under the threat of some future lawsuit, yet, they have a billionaire funding them. So my question is why do they need to raise funds for some future legal challenges when they have such heavy guns seeding them with huge resources of money? Why not just call up Foster Friess and ask him for the money to support Robert Stacy McCain and Mandy Nagy and the millionaire John Patrick Frey? Those are very interesting questions which we will probe into in the days ahead.

Stay Tuned..

 

 

 

god know they did it to me...

posted my address, my parents address and phone numbers. medical and financial records that were illegally obtained, ALTERED, and placed in a public folder on at least 6 servers.

that's bullshit!

Posted from DailyDDoSe

Saturday, June 30, 2012

Fake Security Firms Will Be Exposed || CyberWarzone #404

Thursday, June 09, 2011


Boris Sverdlik

Ca292bdd9ad8d8228833ce1f1a44a052

UPDATE: BlackbergSecurity is NOT A DEFENSE CONTRACTOR according to E-VERIFY.

I’d like to preface this again by saying I don’t condone the activities of Lulzsec. I do fall into the crowd of security professionals who Patrick Gray described as secretly loving him. Patrick has written a great piece on the awareness the group has brought to the weaknesses in information security.

I suggest you go out and read it immediately and you’ll see why.

Attrition.org broke a story back in February on how Joe Black has used social media to create his “Security God” image. Needless to say, they debunked the entire image.

Unfortunately, real security guys are the only ones who actually read Attrition, and Joe Black was able to continue in his path to self proclaimed security god.

image

In his efforts to legitimize his site, he has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT in his Bachelors degree program in Omaha.

Calls to ITT have not been returned as of this writing, but Joe did post his associates degree on his flickr page. While we are on the topic of education, his profile also states that he is expecting to complete his Masters in Security Management  at Bellevue University in 2013.

According to the registrar he has withdrawn from every single course he had enrolled in since January of 2009. Guess the worlds greatest hacker, didn’t realize information is public. Oh well.

With his reputation on the line he had called out our neighborhood Lulz maker with the following message on his website:

“Cybersecurity For The 21st Century, Hacking Challenge: Change this website’s homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black.”

Guess what happens next?

image

Again, not that I condone any of this, but you know me any chance to prove that security certifications are useless can’t be ignored. Wow, look at all of those interesting certifications on his website.

This guy must be a Security Megastar. Lets see what he has:

image

All can be seen thanks to our brainiac on his Flickr:

  • Project+ COM70010068307772 A+ 1/08
  • Remote Support COMP001006830772 1/09
  • Security+ COMP001006830772 1/08
  • Network+ COMP00100683C772 1/08
  • Linux+ COMP001006830772 2/08
  • CEH ECC926927 09/08CISSP 318010 12/08

What I don’t see is the ISACA CISM & CISA certifications.

Please Joe, if you have them send the numbers my way...

So are we still confident how certifications do not equate to competency? This is just another example of false advertising, and I’m glad it has been brought to light. Black has even used Facebook to advertise his services.

I love his About statement “At Black & Berg Cybersecurity Consulting we leverage our close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense.”

Wait speaking of his federal contacts he does have a CAGE# on his LinkedIn Profile. Wow, legit eh... EXPIRED.

In closing I’m sure you paper security guys would be more than happy to hire him, real security guys well we don’t find our vendors at bus stops.

image

Cross-posted from Jaded Security


Post Rating:

(Rate this Post)

Comments:


728dce02fbc900cb75609c4660de7bf6
Elyssa Durant The CyberSecurity business is a rapidly growing field.

Recruitment has been fast and furious since the United States became aware that we have a serious problem on our hands.

In that process, many firms are taking on interns to test the aptitude for those who are well suited for intelligence and counterintelligence work.

As Joe Black knows. This is a field where you need to prove your skills, and the only way to truly test them is in the field. From there, you either sink or swim.

In addition, that recruitment process has been untraditional; calling on experts from all walks of life.

As we all know, extraordinary times call for extraordinary measures. We live in extraordinary times and operate under extraordinary measures.

Black & Berg CyberSecurity Consulting, LLC is a new firm and failure is not an option.

I think Joe Black is handling the situation with real class responding to directed questions and placing his credentials out there for the world to see.

Joe Black has surrounded himself with a good team, and that is half the battle. This team will stand by him, until we hear otherwise. Our methods, background and training are diverse and atypical. Our dedication and commitment beyond reproach.

Nobody makes it in this business overnight, but Joe Black has, experienced excellent advisers to support him.

What exactly do we know about Lulzsec other than their desire to wreak havoc on the world wide web and their ability to to launch CyberWarfare on those who "dare" to challenge them?

I always get a chuckle when people make [want] to make the assumption that I attended Columbia Community College as opposed to my "real" alma matter, Columbia University in the City of New York.

If people are desperate to see Ivy League Credentials and a few advanced Masters degrees... just send them my way.

5 days ago
728dce02fbc900cb75609c4660de7bf6
Elyssa Durant megacommunities@blackbergsecurity.us
to elyssa.durant@gmail.com
date Wed, Jun 15, 2011 at 7:22 PM
subject Fwd: About your website defacement/compromise.
Important mainly because of the people in the conversation.

hide details 7:22 PM (1 hour ago)

via e-mail from Joseph Black:

Thought you should see this email that I received.

~Joe


---------- Original Message ----------
From: Victor Vennt
To: Megacommunities@blackbergsecurity.us
Date: June 8, 2011 at 8:44 PM
Subject: About your website defacement/compromise.

To whom it may concern:

I believe that "LulzSec" - The notorious hacking group responsible for recent Sony & FBI hacks may have given themselves away & identified themselves with their recent defacement and compromise of your site.

Last year cryptome.com was similarly compromised by a splinter group of "Anonymous" whom went by the name of "DIDITFORTHELULZ", one of that groups 'tag lines" was "We do it for the lulz", the members of that group were eventually exposed, see:

http://cryptome.org/0002/cryptome-hack4.htm

It is believed in certain circles of "Anonymous", that the ringleader of LulzSec is one Corey "Xyrix" Barnhill, further research may yet provide confirmation of this.

One friend of his, and "notable" member of this group has previously been charged with computer tampering, computer trespass, and criminal possession of computer material for an attack on AOL, see: http://www.infoworld.com/d/security-central/ny-teen-hacks-aol-infects-systems-818.

I hope this information is of some interest to you,

A concerned citizen.

48 minutes ago

Black and Berg Cybersecurity Consulting
Black and Berg Cybersecurity Consulting is an early 21st century response to the United States Senate's request for private sector intervention in order to raise our National security posture.

The US government, business, and civil sectors are working directly with Black & Berg to ensure the success of our aggressive campaign to combat Cyberterrorism. We cannot fail in our mission to secure American Cyberspace with the application of a Megacommunity. For if we do fail, then, we really have no choice but to recommend the hand over of complete control of privately owned systems to the Executive Branch of the United States Government.
0 Topics
0 Posts
No posts

The page you were looking for doesn't exist!

It may have been removed or you may have arrived here by using a bad URL

Try searching for the article you are looking for.
Visit the Homepage to see the most recent stories.
Browse categories and tags to find a related story.
Or try the forum at forum.cyberwarzone.com

blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.

Top users
Rank User News Published Comments Total votes
1 CWZ 398 398 (100%) 4 406 399 (98%) 34403.00
2 Lovely 45 45 (100%) 0 45 45 (100%) 9701.00
3 cybercopsindia 10 10 (100%) 0 10 10 (100%) 7203.00
4 nigroeneveld 0 0 (-) 0 0 0 (-) 6000.00
4 blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.00
6 mgd 3 3 (100%) 0 3 3 (100%) 1198.00
7 vagabondhuman35 1 1 (100%) 0 1 1 (100%) 66.00
7 ArnanRecruiter 1 1 (100%) 0 1 1 (100%) 66.00
9 dvlaho 0 0 (-) 0 0 0 (-) 1.00

http://www.forum.cyberwarzone.com/

http://www.network.cyberwarzone.com/404error.php

http://www.cyberwarzone.com/cyberwarfare/advertising

Posted from DailyDDoSe

Thursday, June 23, 2011

"Why We Secretly Love Lulzsec" || Black & Berg Cyberdefense

Why We Secretly Love Lulzsec

Posted by blackandberg - June 22, 2011 - Cybersecurity, Hacks - No Comments

Screen shot 2011-06-21 at 7.05.35 PM

By Patrick Gray
Originally posted here


Although large sections of the security community will deny it if you ask them, they’re secretly enjoying watching LulzSec’s campaign of mayhem unfold.

So far the “hacker group” has penetrated systems owned by Sony, PBS, the “FBI affiliate site” Infragard, Black and Berg Cyberdefense, Unveillance and Nintendo, among others.

They’re posting proprietary developer code. They’re bringing back Tupac and Biggie. They’re advising Nintendo on more secure httpd configurations. And they’re issuing funny press releases via Twitter and Pastebin.

In the last few weeks these guys have picked up around 96,000 Twitter followers. That’s 20,000 more than when I looked yesterday. Twitter has given LulzSec a stage to show off on, and showing off they are.

The Internetz, largely, are loving it.

It might be surprising to external observers, but security professionals are also secretly getting a kick out of watching these guys go nuts.

I wrote my first article on information security around May 2001. It was about the Sadmind worm and it ran on the letters page of the IT section of The Age newspaper in Melbourne.

“Geez,” I thought to myself. “If awareness isn’t raised about the unsuitability of these computamajiggies for srs bizness, we could encounter some problems down the track.”

So for the last ten years I’ve been working in media, trying to raise awareness of the idea that maybe, just maybe, using insecure computers to hold your secrets, conduct your commerce and run your infrastructure is a shitty idea.

No one who mattered listened. Executives think it’s FUD. They honestly think that if they keep paying their annual AV subscriptions they’ll be shielded by Mr. Norton’s magic cloak.

Security types like LulzSec because they’re proving what a mess we’re in. They’re pointing at the elephant in the room and saying “LOOK AT THE GIGANTIC FUCKING ELEPHANT IN THE ROOM ZOMG WHY CAN’T YOU SEE IT??? ITS TRUNK IS IN YR COFFEE FFS!!!”

There is no security, there will be no security. The horse has bolted, and it’s not going to be the infrastructure that’s going to change, it’s going to be us.

LulzSec is running around pummelling some of the world’s most powerful organisations into the ground… for laughs! For lulz! For shits and giggles! Surely that tells you what you need to know about computer security: there isn’t any.

The mainstream media are having fun criticising Sony for its poor security, but do we honestly think for a second that the XBox Live network can’t be similarly pwnt? (I know the PSN breach hasn’t been pinned on LulzSec, but the point stands.) Is there any target out there that can’t be “gotten”?

State-sponsored attackers, likely Chinese, have even wormed their merry way through the networks of the US military industrial complex, buggering off with the blueprints for the next Lockheed Martin death-ray-lasermatron or similarly diabolical, geo-strategically altering super-weapon.

Yay! Human rights abusers with US-designed military technology! w00t w00t!

Thanks, RSA. <3

Don’t even get me started on them. As BlackHat organiser turned US Department of Homeland Security advisor Jeff Moss Tweeted yesterday, “When I heard RSA had a shiny new half million dollar HSM to store seed files I wondered where had they been stored before”.

We’re relying on these boneheads to lock down our most sensitive R&D? Shoot me now.

What about privacy? Oh, well that’s out the window too. Did you hear Facebook has facial recognition now? Great, huh? Plus the bloatware that is Facebook’s Web application is full of bugs anyway, so we really do just have to assume all our Facebook accounts are pwnt. Our telcos are owned, our mobile devices track us, as the iPhone/Android tracking scandal showed us. Privacy is dead.

So why do we like LulzSec?

“I told you so.”

That’s why.

http://www.blackandberg.com/?p=190

C'mon, people! It doesn't get much more obvious than this!

Inside job. This is bullshit! #jadedexposure (@jadedexposure) is in on the whole thing! As much I admire the crazy little squirrel dude at trition dot org I'm sad to admit, he too is in on the Lulz.

@JadedSecurity knows my e-mail and identity were compromised shortly after I began working with Black & Berg, yet he is selling T-shirts with my soc on it? Give me a fucking break.

Ligatt press release was faked, set up, framed, dismissed.

Adrian Lamo set up, framed, blamed on aspergers. Totally irrelevant.

Joseph Black "WE ARE LULZ. Shhhhhhhhhhhhhhhhh!"

Well no fucking shit! You could have told me before the whole world started hacking the shit out of every corner of the world wide web of deception.

This is a total set up, and I sick and tired of being exploited.

We all have vulnerabilities. At least I'm not profiting by exploiting yours!

PUT THESE PEOPLE IN PRISON!

That's my daily dose.

Just me,

@ElyssaD

June 23, 2011 8:50 am

Posted via email from Whistleblower

"Elyssa will probably be going away" #jadedexposure EXPOSED #datamining @infosecisland

Boris's Latest activity


Ca292bdd9ad8d8228833ce1f1a44a052
Boris Sverdlik added a new blog Attackers Love Your Organization's HR Department

Companies use every available resource in their recruiting. They hire third party recruiters, post job listings on LinkedIn, Dice, Monster and numerous other places. While this will bring in a plethora of qualified candidates, it also provides attackers a wealth of information......
3 days ago · Comment Comment
7ff7b9daf5a7bb448a822d95d28153a5
JT Edwards And I just thought my resume was trash! I guess the issue is these measures help prevent you from being a target of opportunity. They may make an attacker’s job harder, but if you have been singled out as a target it is a moot point. I look forward to your Linkedin article. One point I have been wondering about is former employees. I list company X on my profile or resume and state that I worked with technology Y or implemented Z. I have provided similar information as the HR department just did for the job opening (maybe the job I just left). I wonder legally how far you can go with an NDA to prevent some of that. Totally different ball game if you work in the classified world, so just pondering this from a corporate standpoint.
3 days ago
Fc28f257ebcfd3cf20d7bd5dec0d0146
Terry Perkins I, too, look forward to the LinkedIn article.
3 days ago
Ca292bdd9ad8d8228833ce1f1a44a052
Boris Sverdlik added a new blog Fake Security Firms Will Be Exposed

Joe Black has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT......
3 days ago · Comment Comment
Ca292bdd9ad8d8228833ce1f1a44a052
3 days ago
D36ee0cca23f96f032490d1ce8494520
Krypt3ia Excellent.
3 days ago
Ca292bdd9ad8d8228833ce1f1a44a052
Boris Sverdlik updated blog You Can't Buy DLP

To implement a data loss solution, you must take a holistic approach to identify the problem, threat vectors and vulnerabilities. You must understand where your sensitive data lives within your organization. This can’t be done with a tool, regardless of how good they claim it is......
4 days ago · Comment Comment
Default-avatar
Johnny Wong You rightly mention DLP is a PROGRAM, not a solution. A program's outcomes/objectives can be met by one or many solutions. I think Data Classification itself should be classified as a program; because this is something that should not be taken lightly. And I think enterprises should start small, take baby steps. Identify a business unit that handle sensitive data, for example, HR. Start from there and determine the kind of data it handles, what classification, the "in use, in store, in transit" data states, understand the end-to-end flow of data, consider areas or choke points where data seems the most vulnerable... and so on. It is good we have like-minded folks here :)
1 week ago
Ca292bdd9ad8d8228833ce1f1a44a052
Boris Sverdlik Thanks for reading guys..
4 days ago

Boris Sverdlik aka @jadedexposure "Elyssa, will probably be going away... http://jadedsecurity.net/2011/06/20/who-is-elyssa-durant/

Posted via email from Whistleblower

Wednesday, June 22, 2011

21 year old Iranian hacker tagets CIA and Israel with stuxnet attack | Cyber Warzone #FAIRWARNING

21 year old Iranian hacker & think tank has avenged the stuxnet attack | Cyber Warzone

Media_httpcyberwarzon_cqggd

Submitted by Reza Rafati on Mon, 03/28/2011 - 14:48

1.Hello
2.
3.I'm writing this to the world, so you'll know more about me..
4.
5.At first I want to give some points, so you'll be sure I'm the hacker:
6.
7.I hacked Comodo from InstantSSL.it, their CEO's e-mail address mfpenco@mfpenco.com
8.Their Comodo username/password was: user: gtadmin password: [trimmed]
9.Their DB name was: globaltrust and instantsslcms
10.
11.GlobalTrust.it had a dll called TrustDLL.dll for handling Comodo requests, they had resellers and their url was:
12.http://www.globaltrust.it/reseller_admin/
13.
14.Enough said, huh? Yes, enough said, someone who should know already knows...Am I right Mr. Abdulhayoglu?
15.
16.Anyway, at first I should mention we have no relation to Iranian Cyber Army, we don't change DNSes, we
17.
18.just hack and own.
19.
20.I see Comodo CEO and others wrote that it was a managed attack, it was a planned attack, a group of
21.
22.cyber criminals did it, etc. etc. etc.
23.
24.Let me explain:
25.
26.a) I'm not a group of hacker, I'm single hacker with experience of 1000 hackers, I'm single programmer with
27.
28.experience of 1000 programmers, I'm single planner/project manager with experience of 1000 project
29.
30.managers, so you are right, it's managed by a group of hackers, but it was only I with experience of 1000
31.
32.hackers.
33.
34.b) It was not really a managed hack. At first I decided to hack RSA algorithm, I did too much
35.
36.investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not
37.
38.able to do so, at least not yet, but I know it's not impossible and I'll prove it, anyway... I saw
39.
40.that there is easier ways of doing it, like hacking a CA. I was looking to hack some CAs like Thawthe,
41.
42.Verisign, Comodo, etc. I found some small vulnerabilities in their servers, but it wasn't enough to
43.
44.gain access to server and sign my CSRs. During my search about InstantSSL of Comodo which signs CSRs immediately I found
45.
46.InstantSSL.it which was doing it's job under control of Comodo.
47.
48.After a little try, I analyzed their web server and easily (easy for me, so hard for others) I got FULL access on the server, after a little investigation on their
49.
50.server, I found out that TrustDll.dll takes care of signing. It was coded in C# (ASP.NET).
51.
52.I decompiled the DLL and I found username/password of their GeoTrust and Comodo reseller account.
53.
54.GeoTrust reseller URL was not working, it was in ADTP.cs. Then I found out their Comodo account works
55.
56.and Comodo URL is active. I logged into Comodo account and I saw I have right of signing using APIs. I
57.
58.had no idea of APIs and how it works. I wrote a code for signing my CSRs using POST request to those
59.
60.APIs, I learned their APIs so FAST and their TrustDLL.DLL was too old and was not working properly, it doesn't send all needed parameters,
61.
62.it wasn't enough for signing a CSR. As I said, I rewrote the code for !AutoApplySSL and !PickUpSSL
63.APIs, first API returns OrderID of placed Order and second API returns entire signed
64.
65.certificate if you pass OrderID from previous call. I learned all these stuff, re-wrote the code and
66.
67.generated CSR for those sites all in about 10-15 minutes. I wasn't ready for these type of APIs, these
68.
69.type of CSR generation, API calling, etc. But I did it very very fast.
70.
71.Anyway, I know you are really shocked about my knowledge, my skill, my speed, my expertise and entire attack.
72.
73.That's OK, all of it was so easy for me, I did more important things I can't talk about, so if you have to
74.
75.worry, you can worry... I should mention my age is 21
76.
77.Let's back to reason of posting this message.
78.
79.I'm talking to the world, so listen carefully:
80.
81.When USA and Israel creates Stuxnet, nobody talks about it, nobody blamed, nothing happened at all,
82.
83.so when I sign certificates nothing should happen, I say that, when I sign certificates nothing should
84.
85.happen. It's a simple deal.
86.
87.I heard that some stupids tried to ask about it from Iran's ambassador in UN, really? How smartass you are?
88.Where were you when Stuxnet created by Israel and USA with millions of dollar budget, with access to SCADA systems and Nuclear softwares? Why no one asked a question from Israel and USA ambassador to UN?
89.So you can't ask about SSL situtation from my ambassador, I answer your question about situtation: "Ask about Stuxnet from USA and Israel", this is your answer, so don't waste my Iran's ambassador's worthy time.
90.
91.When USA and Isrel can read my emails in Yahoo, Hotmail, Skype, Gmail, etc. without any simple
92.
93.little problem, when they can spy using Echelon, I can do anything I can. It's a simple rule. You do,
94.
95.I do, that's all. You stop, I don't stop. It's a rule, rule #1 (My Rules as I rule to internet, you should know it
96.
97.already...)
98.
99.Rule#2: So why all the world worried, internet shocked and all writers write about it, but nobody
100.
101.writes about Stuxnet anymore? Nobody writes about HAARP, nobody writes about Echelon... So nobody
102.
103.should write about SSL certificates.
104.
105.Rule#3: Anyone inside Iran with problems, from fake green movement to all MKO members and two faced
106.
107.terrorists, should afraid of me personally. I won't let anyone inside Iran, harm people of Iran, harm
108.
109.my country's Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you
110.
111.won't be able to do so. as I live, you don't have privacy in internet, you don't have security in
112.
113.digital world, just wait and see...By the way, you already have seen it or you are blind, is there any larger target than a CA in internet?
114.
115.Rule#4: Comodo and other CAs in the world: Never think you are safe, never think you can rule the
116.
117.internet, ruling the world with a 256 digit number which nobody can find it's 2 prime factors (you think so), I'll show
118.
119.you how someone in my age can rule the digital world, how your assumptions are wrong, you already understood it, huh?
120.
121.Rule#5: To microsoft, mozilla and chrome who updated their softwares as soon as instructions came from
122.
123.CIA. You are my targets too. Why Stuxnet's Printer vulnerability patched after 2 years? Because it was
124.
125.needed in Stuxnet? So you'll learn sometimes you have to close your eyes on some stuff in internet,
126.
127.you'll learn... You'll understand... I'll bring equality in internet. My orders will equal to CIA orders,
128.
129.lol
130.
131.Rule#6: I'm a GHOST
132.
133.Rule#7: I'm unstoppable, so afraid if you should afraid, worry if you should worry.
134.
135.My message to people who have problem with Islamic Republic of Iran, SSL and RSA certificates are broken, I did it one time, make sure I'll do it again, but this time nobody will notice it.
136.I see some people suggests using VPNs, some people suggests TOR, some other suggests UltraSurf, etc. Are you sure you are safe using those? RSA 2048 was not able to resist in front of me, do you think UltraSurf can?
137.
138.If you was doing a dirty business in internet inside Iran, I suggest you to quit your job, listen to sound of most of people of Iran, otherwise you'll be in a big trouble, also you can leave digital world
139.and return to using abacus.
140.
141.A message in Persian: Janam Fadaye Rahbar
142.
143.
144.[UPDATE 1]: Also check this: http://pastebin.com/DBDqm6Km

Trackback URL for this post:
http://www.cyberwarzone.com/trackback/464

THIS GUY HAS ADMIN RIGHTS FOR THE BLACK & BERG SITE AND HAS LAUNCHED A VICIOUS ATTACK ON ME WHEN I CALLED HIS BLUFF.

SO THERE YOU HAVE IT. I SAW THIS COMING, I PUT OUT FAIR WARNING, AND NOW I'M BEING BY EVERY HACKER IN THIS WHOLE MISERABLE PLANET.

I AM NOT THRILLED WITH THE UNITED STATES GOVERNMENT BY ANY STRETCH OF THE IMAGINATION. ESPECIALLY NOW THAT I AM UNDER ATTACK, AND I DON'T SEE ANYONE TRYING TO ASSIST ME IN GETTING DE-HACKED.

THE BOTTOM LINE IS THIS, I LIVE IN AMERICA, SO IF THIS COUNTRY GETS HIT, I DIE ALONG WITH MY ENTIRE FAMILY. IDGAF ABOUT MOST OF YOU, BUT THERE A FEW PEOPLE THAT DESERVE A FIGHTING CHANCE.

THAT IS ALL FOR NOW. I AM PHYSICALLY ILL OVER THIS, AND ALL MY COMMUNICATIONS ARE COMPROMISED. I DON;T DRIVE SO I CAN'T JUST "GO THE LIBRARY" AND EVEN IF I COULD, THEY ARE NOT ABOUT TO HELP ME SORT OUT THIS DISGUSTING MESS.

GOOD BYE FOR NOW. IF THIS SITE GOES DOWN, JUST KNOW THAT IT CONTAINS NOW ONLY MY PERSONAL PUBLICATIONS, BUT ALL OF MY WORK TRYING TO SORT OUT THIS UGLY MESS BEFORE IT IS TOO LATE.

JUST ME,

@ElyssaD

Posted via email from Whistleblower

LulzSec Hacks Black & Berg Cyber Security Firm | Geekosystem

LulzSec Hacks Security Firm Black & Berg, Turns Down $10,000 Prize


No reward necessary, the Lulz are enough. When cybersecurity consulting firm Black & Berg issued a challenge to hackers to change the picture on their website for a $10K reward and a position working with senior advisor Joe Black, LulzSec was more than happy to oblige. But LulzSec has said they won’t be collecting the reward, leaving the message “Done, that was easy. Keep your money. We do it for the Lulz.” on the Black & Berg homepage.

Joe Black needn’t worry about his reputation in light of the hack, as he is in good company with other LulzSec victims. The group also claims responsibility for hacks of PBS, Fox, a UK ATM, the television show X-Factor’s contestant database, and InfraGuard (notable for its affiliation with the FBI) in addition to its highly publicized hack of Sony.

LulzSec rose to attention after the Sony hack, when they broke into SonyPictures.com and compromised over one million users’ personal information, publishing passwords, email addresses, and dates of birth from the sites’ users. They say their goal was to expose Sony’s weakness to cyber attack, though LulzSec’s Sony hack came on the heels of an April attack on Sony that had already exposed the information of more than a million PlayStation Network users (the hackers in that case have not been publicly identified).

Whoever they are, it is obvious that LulzSec is highly amused by their own antics. One visit to their website, whose homepage features a shout out to Rebecca Black’s “Friday” and you’ll understand that these hackers are having ”fun, fun, fun, fun” at the expense of companies and consumers alike. The homepage also has a picture of the “LulzBoat,” complete with “Love Boat” soundtrack and replacement Lulz Lyrics. Should the Love Boat not be your thing, don’t worry there is a link to mute the sound. But wait, clicking it makes Love Boat play lounder. Of course it does. Lulz. Despite the seemingly humorous antics of this group, what LulzSec is doing is, of course, illegal.

Much of aftermath of the Black & Berg hack played out on Twitter, with Joe Black first saying “No Comment” followed by the tweet ” Wait, we do have a comment. Please unf**k our website. Thank you. ~Joe.” Black then returned to give some credit to the hackers, comparing them to ninjas “We’re not sure what happened, we’re looking into it. It seems whoever is responsible was very good at covering their tracks #ninja.”

http://www.geekosystem.com/lulzsec-black-berg-hack/

Posted via email from Whistleblower

LulzSec vs. CIA "Tango down- cia.gov - for the lulz || DDoS 33137 /b/tards

Internet LulzSec Downs CIA's Public Site, Appears to be Subject of Framing Attempt

Jason Mick (Blog) - June 15, 2011 7:20 P

Late this afternoon the CIA homepage was DDoSed.

The hacker group LulzSec claimed responsibility. They also did a phone attack on the FBI today. It's clear they think they're untraceable. (Source: LulzSec)

Aaron Barr, disgraced former CEO of HBGary appears to be involved in an attempt to implicate LulzSec in Bitcoin theft. It does not appear LulzSec did anything of the sort. It is unclear whether a series of posting are designed to discredit/attack LulzSec, Bitcoin, or both. (Source: Nerd Merit Badges)
Group's attack continue to grow more flagrant, as do its detractors

At around 6 p.m. Wednesday night after a busy day of distributed denial of service (DDoS) attacks some "31337" 2005-era "/b/tards" posted a microblog to Twitter. But these weren't just any "/b/tards"; these were the most infamous hackers of the year -- LulzSec.

And they didn't just post any old message. They typed:

Tango down - cia.gov - for the lulz.

Indeed the U.S. Central Intelligence Agency's homepage was unreachable.

I. Brazen Hacks, Phone DOS

The apparent takedown of the CIA homepage is merely the latest in the griefers' audacious run of high profile system intrusions and DDOS attacks on gaming services, government entities, and more.

The hack outraged th3j35t3r ("The Jester" in leetspeak), a pro-American "hacktivist". He swore to LulzSec:

@lulzsec - re: your last hit. Gloves off. Expect me. My silence is not an indication of weakness, as your mouth is an indication of yours.

But if The Jester or anyone else can stop the group, they haven't yet. LulzSec appears to think itself untraceable, given its flagrant hacks -- infiltrating the U.S. Senate servers, hacking an U.S. Federal Bureau of Investigations affiliate, and now hacking the public presence of the world's "most powerful" intelligence agency.

And it's using new tactics. LulzSec has set up two phone lines -- 614-LULZSEC or 732-993-7703 -- and is taking thousands of calls a day. Some it actually answers, asking guests questions for prizes or regaling them in a faux French accents. But it's also redirect the calls to phone denial of service (DOS) attacks -- something rarely seen today.

Today it direct this phone wrath at the online MMORPG World of Warcraft's customer support, the FBI's Detroit headquarters, and "a certain hosting company" (many suspect it was GoDaddy). Last, but not least it direct attacks at disgraced security firm HBGary who was the subject of much lashing at the hands of Anonymous earlier this year.

II. Framing Attempt?

LulzSec has been the subject of what appears to be wildly bizarre framing attempt involved the increasingly popular peer-to-peer digital currency Bitcoins. Former HBGary CEO, Aaron Barr, posted to Twitter:

Lulzsec manages to pilfer nearly a half million dollars in bitcoins while running their tele-DDOS-athon today. tinyurl.com/3mfngql

Only the link in question didn't receive the funds today -- it received them on Monday (6/13). And while it did send a donation to LulzSec's public donations account:
176LRX4WRWD5LWDMbhr94ptb2MW9varCZP

It only sent the typical token gesture: 0.31337 ("elite" in leetspeak) -- worth about $7 USD.

So where did this bizarre rumor begin? It appears to trace back to a Pastebin:
http://pastebin.com/88nGp508" rel="nofollow

Which was a repost of the Bethesda press release, with one important alteration -- the account was altered to make it look like:
1KPTdMb6p7H3YCwsyFqrEmKGmsHqe1Q3jg

...was a LulzSec donations account.

Clearly that account appears to be involved with some mass fraud or is a clever social engineering project to offer the appearance of a mass fraud. Either way, the attempt to tie LulzSec to it seems clearly flawed and like a clear framing. No official LulzSec press release has ever carried that number.

It's unclear whether Mr. Barr is merely a uninformed observer, or is more deeply involved with this possible framing attempt. But it's clear that his wild claims appear unfounded.

It's also possible that the postings are some sort of attempt to discredit Bitcoin itself. In recent weeks several news agencies have been spreading posts with dubious claims, attempting to discredit the digital crypto-currency.

For example The Guardian's Ruth Whippman writes:

An odd alliance of libertarians, geeks, businesspeople and drug kingpins hail Bitcoin as the future of the internet – global, private and immune from national economic crises and the whims of reckless bankers. Its critics in the political sphere fear that it could give rise to an online Wild West of gambling, prostitution and global bazaars for contraband.

Previously dismissed as a nerdy curiosity, the untaxable Bitcoin may soon be due for a crackdown.

And Gawker adds:

Not all Bitcoin enthusiasts embrace Silk Road. Some think the association with drugs will tarnish the young technology, or might draw the attention of federal authorities. "The real story with Silk Road is the quantity of people anxious to escape a centralized currency and trade," a longtime bitcoin user named Maiya told us in a chat. "Some of us view Bitcoin as a real currency, not drug barter tokens."

Silk Road and Bitcoins could herald a black market eCommerce revolution. But anonymity cuts both ways. How long until a DEA agent sets up a fake Silk Road account and starts sending SWAT teams instead of LSD to the addresses she gets? As Silk Road inevitably spills out of the bitcoin bubble, its drug-swapping utopians will meet a harsh reality no anonymizing network can blur.

Seemingly, some people are suggesting that Bitcoin is more villainous than the far more anonymous form of currency -- cash. The source of this misinformation/smear campaign is unknown, though, news agencies seem happy to spread it gleefully.

III. Insecure World

Much has been made to explain how LulzSec is doing what it does. But the fact of the matter is that the group isn't using new tactics, new tools, or new exploits. It's just getting more attention because it's good at advertising what it does and its affecting lots of people.

But the fact of the matter is that many corporate and government systems today are incredibly insecure and the vast majority of users are utterly incompetent when it comes to security [1][2][3] -- even some system administrators [1].

Combine these factors and you get an infinitely abusable system.

The abuses have occurred in years past. They may be happening at a faster rate this year. But the system has been insecure for years. And it will likely still be insecure next year, as well.

http://www.dailytech.com/LulzSec+Downs+CIAs+Public+Site+Appears+to+be+Subject...

Posted via email from Whistleblower

LulzSec hacks Black and Berg Security

Wednesday, June 15, 2011

Fake Security Firms Will Be Exposed || CyberWarzone #404

Thursday, June 09, 2011


Boris Sverdlik

Ca292bdd9ad8d8228833ce1f1a44a052

UPDATE: BlackbergSecurity is NOT A DEFENSE CONTRACTOR according to E-VERIFY.

I’d like to preface this again by saying I don’t condone the activities of Lulzsec. I do fall into the crowd of security professionals who Patrick Gray described as secretly loving him. Patrick has written a great piece on the awareness the group has brought to the weaknesses in information security.

I suggest you go out and read it immediately and you’ll see why.

Attrition.org broke a story back in February on how Joe Black has used social media to create his “Security God” image. Needless to say, they debunked the entire image.

Unfortunately, real security guys are the only ones who actually read Attrition, and Joe Black was able to continue in his path to self proclaimed security god.

image

In his efforts to legitimize his site, he has built a reputation around certifications and misinformation. He has a very interesting career, that we can trace back to his days at Wright Printing in 2005 according to his LinkedIn Profile which is also about the time he was supposedly enrolled at ITT in his Bachelors degree program in Omaha.

Calls to ITT have not been returned as of this writing, but Joe did post his associates degree on his flickr page. While we are on the topic of education, his profile also states that he is expecting to complete his Masters in Security Management  at Bellevue University in 2013.

According to the registrar he has withdrawn from every single course he had enrolled in since January of 2009. Guess the worlds greatest hacker, didn’t realize information is public. Oh well.

With his reputation on the line he had called out our neighborhood Lulz maker with the following message on his website:

“Cybersecurity For The 21st Century, Hacking Challenge: Change this website’s homepage picture and win $10K and a position working with Senior Cybersecurity Advisor, Joe Black.”

Guess what happens next?

image

Again, not that I condone any of this, but you know me any chance to prove that security certifications are useless can’t be ignored. Wow, look at all of those interesting certifications on his website.

This guy must be a Security Megastar. Lets see what he has:

image

All can be seen thanks to our brainiac on his Flickr:

  • Project+ COM70010068307772 A+ 1/08
  • Remote Support COMP001006830772 1/09
  • Security+ COMP001006830772 1/08
  • Network+ COMP00100683C772 1/08
  • Linux+ COMP001006830772 2/08
  • CEH ECC926927 09/08CISSP 318010 12/08

What I don’t see is the ISACA CISM & CISA certifications.

Please Joe, if you have them send the numbers my way...

So are we still confident how certifications do not equate to competency? This is just another example of false advertising, and I’m glad it has been brought to light. Black has even used Facebook to advertise his services.

I love his About statement “At Black & Berg Cybersecurity Consulting we leverage our close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense.”

Wait speaking of his federal contacts he does have a CAGE# on his LinkedIn Profile. Wow, legit eh... EXPIRED.

In closing I’m sure you paper security guys would be more than happy to hire him, real security guys well we don’t find our vendors at bus stops.

image

Cross-posted from Jaded Security


Post Rating:

(Rate this Post)

Comments:


728dce02fbc900cb75609c4660de7bf6
Elyssa Durant The CyberSecurity business is a rapidly growing field.

Recruitment has been fast and furious since the United States became aware that we have a serious problem on our hands.

In that process, many firms are taking on interns to test the aptitude for those who are well suited for intelligence and counterintelligence work.

As Joe Black knows. This is a field where you need to prove your skills, and the only way to truly test them is in the field. From there, you either sink or swim.

In addition, that recruitment process has been untraditional; calling on experts from all walks of life.

As we all know, extraordinary times call for extraordinary measures. We live in extraordinary times and operate under extraordinary measures.

Black & Berg CyberSecurity Consulting, LLC is a new firm and failure is not an option.

I think Joe Black is handling the situation with real class responding to directed questions and placing his credentials out there for the world to see.

Joe Black has surrounded himself with a good team, and that is half the battle. This team will stand by him, until we hear otherwise. Our methods, background and training are diverse and atypical. Our dedication and commitment beyond reproach.

Nobody makes it in this business overnight, but Joe Black has, experienced excellent advisers to support him.

What exactly do we know about Lulzsec other than their desire to wreak havoc on the world wide web and their ability to to launch CyberWarfare on those who "dare" to challenge them?

I always get a chuckle when people make [want] to make the assumption that I attended Columbia Community College as opposed to my "real" alma matter, Columbia University in the City of New York.

If people are desperate to see Ivy League Credentials and a few advanced Masters degrees... just send them my way.

5 days ago
728dce02fbc900cb75609c4660de7bf6
Elyssa Durant megacommunities@blackbergsecurity.us
to elyssa.durant@gmail.com
date Wed, Jun 15, 2011 at 7:22 PM
subject Fwd: About your website defacement/compromise.
Important mainly because of the people in the conversation.

hide details 7:22 PM (1 hour ago)

via e-mail from Joseph Black:

Thought you should see this email that I received.

~Joe


---------- Original Message ----------
From: Victor Vennt
To: Megacommunities@blackbergsecurity.us
Date: June 8, 2011 at 8:44 PM
Subject: About your website defacement/compromise.

To whom it may concern:

I believe that "LulzSec" - The notorious hacking group responsible for recent Sony & FBI hacks may have given themselves away & identified themselves with their recent defacement and compromise of your site.

Last year cryptome.com was similarly compromised by a splinter group of "Anonymous" whom went by the name of "DIDITFORTHELULZ", one of that groups 'tag lines" was "We do it for the lulz", the members of that group were eventually exposed, see:

http://cryptome.org/0002/cryptome-hack4.htm

It is believed in certain circles of "Anonymous", that the ringleader of LulzSec is one Corey "Xyrix" Barnhill, further research may yet provide confirmation of this.

One friend of his, and "notable" member of this group has previously been charged with computer tampering, computer trespass, and criminal possession of computer material for an attack on AOL, see: http://www.infoworld.com/d/security-central/ny-teen-hacks-aol-infects-systems-818.

I hope this information is of some interest to you,

A concerned citizen.

48 minutes ago

Black and Berg Cybersecurity Consulting
Black and Berg Cybersecurity Consulting is an early 21st century response to the United States Senate's request for private sector intervention in order to raise our National security posture.

The US government, business, and civil sectors are working directly with Black & Berg to ensure the success of our aggressive campaign to combat Cyberterrorism. We cannot fail in our mission to secure American Cyberspace with the application of a Megacommunity. For if we do fail, then, we really have no choice but to recommend the hand over of complete control of privately owned systems to the Executive Branch of the United States Government.
0 Topics
0 Posts
No posts

The page you were looking for doesn't exist!

It may have been removed or you may have arrived here by using a bad URL

Try searching for the article you are looking for.
Visit the Homepage to see the most recent stories.
Browse categories and tags to find a related story.
Or try the forum at forum.cyberwarzone.com

blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.

Top users
Rank User News Published Comments Total votes
1 CWZ 398 398 (100%) 4 406 399 (98%) 34403.00
2 Lovely 45 45 (100%) 0 45 45 (100%) 9701.00
3 cybercopsindia 10 10 (100%) 0 10 10 (100%) 7203.00
4 nigroeneveld 0 0 (-) 0 0 0 (-) 6000.00
4 blackbergsecurity 0 0 (-) 0 0 0 (-) 6000.00
6 mgd 3 3 (100%) 0 3 3 (100%) 1198.00
7 vagabondhuman35 1 1 (100%) 0 1 1 (100%) 66.00
7 ArnanRecruiter 1 1 (100%) 0 1 1 (100%) 66.00
9 dvlaho 0 0 (-) 0 0 0 (-) 1.00

http://www.forum.cyberwarzone.com/

http://www.network.cyberwarzone.com/404error.php

http://www.cyberwarzone.com/cyberwarfare/advertising

Posted via email from Whistleblower