Home > Security News > Security Blog Log: Israeli-Hezbollah war spills into cyberspace
Security News:
EMAIL THIS

Security Blog Log: Israeli-Hezbollah war spills into cyberspace

By Bill Brenner, Senior News Writer
11 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security Blog Log
The war between Israel and the Lebanon-based Hezbollah militia is spilling into cyberspace, where hackers from around the world are launching Web-based assaults against anyone perceived to be on the wrong side of the fight.

It's a side battle being watched closely by security bloggers, some of whom worry that site defacements could give way to more serious cyberattacks against vital infrastructure.

The Darknet blog cited a report from the Zone-H Web site about attacks against the Web sites of NASA, the University of California at Berkeley and several military sites, including the U.S. Navy's.

"The war in Lebanon is now showing its consequences in the digital world and a huge number of Web sites have been attacked and defaced as a protest against the invasion of Lebanon by Israel," Darknet said. In one case, two NASA Web sites were compromised by a Chilean group of crackers called the Byond Hackers Crew. The group entered an SQL injection into the system and then wiped out user names, passwords and emails from the NASA Web server.

About Security Blog Log

Senior News Writer Bill Brenner peruses security blogs each day to see what's got the information security community buzzing. In this column he lists the weekly highlights. If you'd like to comment on the column or bring new security blogs to his attention, contact him at bbrenner@techtarget.com.

Recent columns:
Has CSI/FBI survey jumped the shark?

Was the analyst a VA scapegoat?

Metasploit creator promises browser flaws galore

Darknet, a group specializing in password cracking, cryptography, programming and other areas of network security, expressed surprise that Web sites from a government agency like NASA could be vulnerable in this way. "[It] seems like a pretty straightforward attack … a high-profile government site being prone to SQL injection that allows admin escalation [is] pretty bad," Darknet said.

Darknet also noted that Israeli hackers have decided to "help and join the war against Palestine."

One group calls itself IDF, or Israeli Defense Force, and has hacked dozens of sites, erasing site content and replacing it with a photo of destruction from Lebanon, where Israeli and Hezbollah forces are doing the bulk of the fighting. Above the picture, the hackers left text that read, "You touch Israel, We touch you."

"Let's hope things don't boil over to attacking power stations or anything that will cause collateral damage," Darknet said.

The keeper of the FEWL.net blog, a 23-year-old IT specialist for the U.S. Navy who only uses his first name, Jim, wrote that while the hackers claim to be protesting the war, they'd probably be defacing sites without a war for the sake of fame. He's not as worried as Darknet about the potential for more destructive attacks.

The attacks, he said, are not an impressive feat. The NASA hacks were all done via simple SQL injection, as were most of the rest. He said the Navy site that was targeted had already moved and was probably going to be shut down, and another Department of Defense site that was targeted "was just the military television's version of TV Guide."

Rants against AOL data dump; VA security woes
As some bloggers focused on cyberattacks inspired by the Mideast conflict, others were busy taking AOL and the U.S. Department of Veterans Affairs (VA) to task for putting people at risk for identity fraud.

A self-described information security investigator who goes by the online name SecurityMonkey said he was calling this week "Clueless Monkey Week" because of breaches involving AOL and the VA.

This week AOL apologized for releasing keyword search data from about 658,000 anonymous AOL users, amid growing criticism from privacy rights advocates. AOL, a division of Time Warner Inc., released data on about 20 million searches from 658,000 users of its AOL software during a three-month period. AOL spokesperson Andrew Weinstein described the incident as a "screw up" involving a research project.

Meanwhile, the VA suffered its second major security breach in three months when a desktop PC with information on up to 36,000 veterans was stolen.

In the case of the VA security breach, SecurityMonkey noted that those affected include 2,000 deceased patients from a VA medical center in Pennsylvania.

"Holy smokes. Not only is that a lot of data, but some of the victims are dead!" he said. "This is an identity thief's dream!"

Tags: Application Attacks (Buffer Overflows, Cross-Site Scripting)Hacker Tools and Techniques: Underground Sites and Hacking GroupsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Application Attacks (Buffer Overflows, Cross-Site Scripting)
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
SSH key compromise shuts down Apache website
IBM finds sharp spike in malicious content on trusted sites
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

Hacker Tools and Techniques: Underground Sites and Hacking Groups
Metasploit Project acquisition ups ante for penetration testing market
Successful rogue antivirus hinges on social engineering
DEFCON survey suggests hacker community on vacation
DoD urges less network anonymity, more PKI use
New hacker skills optimize revenue
Maturing cybercriminal economy buoyed by business savvy hackers
Juniper pulls ATM hacking presentation from Black Hat
Botnet platform helps cybercriminals bid for zombie PCs
Man pleads guilty in online banking hacking scam
ATM malware lets attackers take over machines

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
buffer overflow  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
directory harvest attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
ping of death  (SearchSecurity.com)
stack smashing  (SearchSecurity.com)
SYN flooding  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts