Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Demeter

(85,373 posts)
56. Syria’s Other Army: How the Hackers Wage War by Matt Buchanan
Sun Sep 1, 2013, 07:04 PM
Sep 2013
http://www.newyorker.com/online/blogs/elements/2013/08/syrian-electronic-army-hackers-new-york-times-tactics.html?mbid=nl_Daily%20%289%29

At 5:41 P.M. on Tuesday, a tweet from the account of the hacker collective known as the Syrian Electronic Army, which supports the regime of Syria’s President, Bashar al-Assad, said, “Media is going down…” It had been a couple of hours since the Web site of the Times had gone offline for the second time this month. Roughly forty-five minutes later, the account asked Twitter, “Are you ready?” Some users had noticed that the backgrounds of their Twitter profiles had been transformed to Syria-related pictures. While Twitter quickly recovered, the Times continued to be inaccessible to some users for a day; as of 6:20 P.M. on Wednesday, the Times’s Twitter account was still advising those readers to use an alternate Web address.

The S.E.A.’s attacks on media organizations and journalists have been remarkably successful—in terms of collecting trophies, if nothing else. In 2012, it struck Al Jazeera several times, breaking into its English Web site, its Twitter accounts, and the network’s S.M.S. text service, which the S.E.A. used to broadcast multiple fake news alerts. This past March, it gained control of several BBC Twitter accounts. In April, it hijacked the Twitter account of the Associated Press, and tweeted, “Breaking: Two Explosions in the White House and Barack Obama is injured,” sending the Dow down around a hundred and fifty points that afternoon. It also defaced NPR’s Web site, and commandeered the Twitter accounts of “60 Minutes” and the Guardian. In May, it compromised the Twitter account of the Onion, tweeting vaguely Onion-ish headlines like “UN’s Ban Ki Moon condemns Syria for being struck by israel: ‘It was in the way of Jewish missiles’ onion.com/104PKAs.” That same month, it hacked the Financial Times’s Web site and several associated Twitter accounts, as well as the account of E! News. Then it took over the Reuters Twitter feed. And earlier this month, it broke into Outbrain, a third-party service that recommends stories on news sites, allowing the S.E.A. to vandalize the Web sites of Time, CNN, and the Washington Post “in a single strike.” And it redirected Post readers to one of its own sites; that attack had been its most sweeping to date.

On Tuesday, the S.E.A. did not hack the Times or Twitter directly. Rather, it breached Melbourne IT, a domain-name registration service that the Times and Twitter both used to manage their Web addresses. Once it had access to Melbourne IT, it altered the domain records of the Times and Twitter. In the Times’s case, it sent some users who went to the newspaper’s Web site to one controlled by the S.E.A.; for Twitter, it listed itself as the owner of twitter.com, and redirected one of the company’s addresses, twimg.com, which Twitter uses to host backgrounds for profiles, to one of the S.E.A.’s addresses. As the networking company CloudFlare explained in a detailed post about the attack, the Times suffered a prolonged outage because the changes made by the S.E.A. resulted in a chain reaction, breaking things at multiple levels.

The chief information officer of the New York Times Company told the paper that compared to previous attacks, the assault on the Times and Twitter through Melbourne IT was like “breaking into Fort Knox. A domain registrar should have extremely tight security because they are holding the security to hundreds if not thousands of Web sites.” Formed in 1996, Melbourne IT is the largest domain name registrar in Australia, and one of the oldest and largest globally; it manages millions of domain names. It did, moreover, “have a reputation of being one of the more secure, business-oriented registrars,” said Jaeson Schultz, a threat-research engineer at Cisco Systems who has been following the S.E.A.’s activities, which is one of the reasons the registrar counts the Times, Twitter, and other large organizations among its customers.

But the S.E.A.’s method, though its execution was sophisticated, was rather simple conceptually: it began by gaining access to Melbourne IT’s system using the log-in of a U.S.-based domain reseller, which it obtained using a technique known as spearphishing. This is as much an exploitation of human weakness as it is a technical accomplishment: it’s a gambit designed to trick people into voluntarily revealing information in response to what appears to be a message from a legitimate Web site or service. For example, a link in an e-mail transports a user to what looks like Google’s log-in page, and then captures the user’s Google name and password.

Spearphishing through e-mail has consistently been the S.E.A.’s tactic of choice, Schultz said in a phone call. The S.E.A.’s attempts can be “tough to spot” for the average user because they’re so carefully crafted. It’s not just that the fake log-in screens are well executed; Schultz notes that, at this point, “they’ve broken into several different media organizations’ inboxes, and there’s probably a lot of good info in there,” like names and places that can be used to make e-mails seem legitimate. For instance, in the attack on the Onion, one of the booby-trapped e-mails purported to be from Elizabeth Mpyisi at the U.N. Refugee Agency—a real person—and the one on the A.P. used the name of an A.P. staffer, according to Jim Romenesko. Still, Schultz does believe the S.E.A. will “face diminishing returns” if it continues to use the same kind of attacks. After the latest breach, for instance, Domain Name System providers—which do the work of translating the recognizable Web address you type into a browser to its actual address (nytimes.com translates to 170.149.168.130, for example)—could hunt for addresses used by the S.E.A. to re-register domains, and prevent further damage from occurring. Moreover, it’s likely that organizations will put in place additional measures to secure their domains—requiring, for instance, any change to the domain record to be authorized by one of a small number of individuals. “They’re going to have to adapt,” Schultz said.

The S.E.A. already has adapted in a way that makes its attacks more punishing: while previous assaults focussed on media organizations directly, the S.E.A. has recently begun targeting third-party services and infrastructure that the media rely on, allowing it to hit multiple targets at once. The widespread use of third-party services for things like commenting or content recommendations makes each site only as secure as its weakest service. Last week, the S.E.A. compromised the GoDaddy domain account of ShareThis, a content-sharing company whose widget is on more than two million Web sites, and changed its domain records. Its occupation of Outbrain a couple of weeks ago is another example, as was its incursion into SocialFlow, a social-media management service used by a number of publishers.

Few concrete facts are known about the S.E.A., but it has the appearance of a loose hacker collective. It formed in 2011, in the midst of the Syrian uprisings, and it is assuredly pro-Assad. It has targeted Web sites and services associated with dissidents and organizations it believes are aligned with rebels, as well as media organizations. It said, of Tuesday’s attack, that it “placed twitter in darkness as a sign of respect for all the dead #Syria-ns due to the lies tweeted it.” In what it called “an anti-war message” posted on Pastebin, the group stated, “The Syrian army, which has lost tens of thousands of soldiers who were defending their homeland with nothing more than a rifle, would never have been the one to use chemical weapons.”

Whether the S.E.A. is under the control of the Syrian government is unclear. The Times notes that Syrian rebels and some security researchers consider the S.E.A. to be the “outward-facing campaign of a much quieter surveillance campaign focused on Syrian dissidents,” and note that Assad has publicly touted the group as “a real army in a virtual reality.” Moreover, the Syrian Computer Society, which regulates the Internet within Syria—and was headed by Assad before he became President—at one pointed hosted the group’s Web site at the address sea.sy, after its original domains were seized by a U.S.-based domain registrar. In May, the S.C.S. cut the group off, and in interviews, self-proclaimed leaders of the group have claimed to have no direct ties to the government, monetarily or otherwise. (While the S.E.A.’s Web sites are currently down, the security researcher Brian Krebs notes that the domains are now hosted in Russia.) In a recent interview with the Daily Beast, a supposed leader of the group, calling himself “SEA the Shadow,” said that the S.E.A. is made up of nine college students living in Syria. While Motherboard and Brian Krebs each claim to have unmasked a member of the group, the S.E.A.’s Twitter account has mocked them and called the Motherboard article “false.” (E-mails sent to the group have so far gone unreturned.)

Regardless, it’s clear that the individuals who make up the S.E.A. are not simply technically savvy in a rote way. They are fully native products and producers of Internet culture. They use English, both on social media and in their phishing attacks, in the manner of young people who’ve spent their entire lives online; they deploy well-known memes when they hijack accounts; they crack jokes about Justin Bieber; and, of course, they relentlessly broadcast all of their doings on social media. (Their current Twitter account, @Official_SEA16, is, as the number implies, their sixteenth consecutive account, as previous ones were suspended. A Twitter spokesperson explained in an e-mail that the account remains active because “Our Trust and Safety team takes action only after someone reports a violation of our Rules and the report is investigated.”) Most profoundly, the S.E.A.’s campaign reflects the vigilantism of young aggressors steeped in the Web: it’s conducted not simply on widely viewed media sites or on social media itself but for them; the SEA knows how to capture a precise kind of attention from a particular kind of audience. This is in part, one suspects, because they are that kind of audience, one who lives on Facebook and Twitter. That’s what ultimately makes this group so remarkable: it has shifted the battleground from a single place to an infinite number of them, because it’s battling for attention, not power—even if it can be hard to tell the difference.
No Bank Failures This Weekend, I'll Wager Demeter Aug 2013 #1
Detroit seeking to borrow $350 mln, terminate swaps deal Demeter Aug 2013 #2
Swaps deal? Detroit? dkf Sep 2013 #76
They sold it to everyone they could gull Demeter Sep 2013 #77
So what do you feel about Larry Summer, swaps and Harvard? dkf Sep 2013 #78
Larry Summers is the greatest threat to our national security, bar none Demeter Sep 2013 #81
If you are saying he will be a disaster I agree. dkf Sep 2013 #82
U.S. consults oil experts as it weighs action against Syria Demeter Aug 2013 #3
Microsoft, Google Say They're Moving Forward With NSA Lawsuit Demeter Aug 2013 #4
Syria, officially the Syrian Arab Republic Demeter Aug 2013 #5
Carry on, Weekenders Demeter Aug 2013 #6
Federal Reserve: Choosing The Chairman xchrom Aug 2013 #7
Summers’ Lending Club makes money by bypassing the Equal Credit Opportunity Act Demeter Sep 2013 #85
The Obama Administration Isn't Answering The Most Important Question About Attacking Syria xchrom Aug 2013 #8
more from article DemReadingDU Aug 2013 #10
I liked andy borowitz's take on it (see friday's SMW) Demeter Aug 2013 #15
The link for anyone to read again DemReadingDU Aug 2013 #24
Developer Says $100 Million Sculpture At Hudson Yards Will Be 'New York's Eiffel Tower' xchrom Aug 2013 #9
Two new targets! Demeter Aug 2013 #13
in his case -- i'm more afraid of an attack of the Ugly. nt xchrom Aug 2013 #18
India’s Rupee Has Worst Month Since 1992 on Slowdown Concern xchrom Aug 2013 #11
Air on the G String xchrom Aug 2013 #12
I'm sending this to the budget and finance committee! Demeter Aug 2013 #14
(try to) Prevent an Attack on Syria Now (petition) Demeter Aug 2013 #16
THE BABY AND THE BAATH WATER--MODERN HISTORY OF SYRIA Demeter Aug 2013 #17
Jordi Savall plays the Celtic Viol - The Nathaniel Gow Set xchrom Aug 2013 #19
That is too marvelous, X - TY (n/t) bread_and_roses Aug 2013 #31
Cooler Spending in U.S. Signals Slow Start for Quarter: Economy xchrom Aug 2013 #20
Consumer Sentiment in U.S. Fell Less Than Forecast in August xchrom Aug 2013 #21
What Syria Teaches Us About Hyperinflation xchrom Aug 2013 #22
Why China Will Oppose Any Strike on Syria xchrom Aug 2013 #23
ANCIENT HISTORY OF SYRIA Demeter Aug 2013 #25
Destroying the roots of civilization - as in Iraq bread_and_roses Aug 2013 #32
Syria, with such stalwart history sure has descended golfguru Aug 2013 #44
Musical Interlude, reprised hamerfan Aug 2013 #26
Musical Interlude II, more on-topic hamerfan Aug 2013 #27
America Totally Discredited By Paul Craig Roberts Demeter Aug 2013 #28
Chemical Hallucinations By William Bowles Demeter Aug 2013 #29
all too true (n/t) bread_and_roses Aug 2013 #30
But, Will TRUTH make any difference in Real Time in this case? Must we always wait for History? Demeter Aug 2013 #34
6 Things To Keep In Mind As Obama Confronts Syria Demeter Aug 2013 #33
Frustrated Obama: I won't be ‘paralyzed’ on Syria Demeter Aug 2013 #35
David Koch: Attacking Syria would be 'dead wrong' Demeter Aug 2013 #36
I'm taking a break to make peach pie now Demeter Aug 2013 #37
Mmmm! hamerfan Aug 2013 #41
Standing invitation--just RSVP--to Weekenders and Marketeers Demeter Aug 2013 #46
YOU MUST SEE THIS GREAT NEWS! Demeter Aug 2013 #38
Muslims challenging 'no fly' list win partial court victory Demeter Aug 2013 #43
TWOFER! Syrians in Ghouta Claim Saudi-Supplied Rebels Behind Chemical Attack Demeter Aug 2013 #39
Meet The Saudi Prince Who Finances the Murderous Egyptian Military, and Crushes Democracy in the Mid Demeter Aug 2013 #40
Pentagon Can’t Afford Syria Operation; Must Seek Additional Funds Demeter Aug 2013 #42
There's no doubt about it. Fuddnik Aug 2013 #45
The 1% Keep Trying to Repeal the Law--Even Nature's Law Demeter Aug 2013 #47
Employment Probably Picked Up in August: U.S. Economy Preview xchrom Sep 2013 #48
Wall Street’s Rental Bet Brings Quandary Housing Poor xchrom Sep 2013 #49
US flatters France as ‘oldest ally’ after UK vote on Syria xchrom Sep 2013 #50
Why Americans Aren't as Willing to Intervene Overseas as They Used to Be xchrom Sep 2013 #51
The Military as 'Abusive Parent': The View Toward Syria From an Exhausted Army xchrom Sep 2013 #52
The Authority to 'Declare War': A Power Barack Obama Does Not Have xchrom Sep 2013 #53
Famed designer Oscar De la Renta criticizes ‘circus’ surrounding Fashion Week xchrom Sep 2013 #54
Under $652 million project code-named ‘GENIE’ U.S. conducted 231 ‘offensive cyberoperations’: xchrom Sep 2013 #55
Syria’s Other Army: How the Hackers Wage War by Matt Buchanan Demeter Sep 2013 #56
City of the Lost In the world’s second-largest refugee camp, Syrians find that it’s not easy to flee Demeter Sep 2013 #57
Syria Intervention Plan Fueled by Oil Interests, Not Concern About Chemical Weapons Demeter Sep 2013 #58
GOD BLESS (SAVE) AMERICA SUB THREAD--LOOKING INTO VARIOUS CRYSTAL BALLS... Demeter Sep 2013 #59
AMERICAN LABOR DAY SUBTHREAD--OH, YEAH, GUESS IT SHOULD BE MENTIONED IN PASSING... Demeter Sep 2013 #60
Freedom From Jobs by ELLIOT SPERBER Demeter Sep 2013 #65
Longshore union pulls out of national AFL-CIO, citing attacks at Northwest grain terminals Demeter Sep 2013 #66
ObamaCare Staggers Toward the October 1 Finish Line (2) By Lambert Strether Demeter Sep 2013 #86
Obamacare Delay? What Obamacare Delay? Demeter Sep 2013 #95
Conflict in Syria: President Pulls Lawmakers Into Box He Made Demeter Sep 2013 #61
America's private prison companies have expanded across the globe Demeter Sep 2013 #62
Raise the (OFFICIAL) Crime Rate (COUNT THE VIOLENCE IN PRISONS) Demeter Sep 2013 #69
Google Received NSA Money, but That’s Not All By Natasha Hakimi Demeter Sep 2013 #63
WIKILEAKS RELEASE Syria: 84,067 sensitive emails from US intelligence contractor Stratfor Demeter Sep 2013 #64
The Troodos Conundrum Demeter Sep 2013 #74
Scary Thought on Labor Day Weekend: Obama's Economic Team Think They Are Doing a Good Job Demeter Sep 2013 #67
Why Wall Street Wants Larry Summers (and Why the Rest of Us Should Not) By Laurence Kotlikoff and Demeter Sep 2013 #68
San Bernardino Becomes 3rd California City to Get Bankruptcy Protection Demeter Sep 2013 #70
Wall Street’s Rental Bet Brings Quandary Housing Poor Demeter Sep 2013 #71
Income Gap Grows Wider (and Faster) Demeter Sep 2013 #72
Senate to vote on Syria resolution no later than week of September 9: Reid Demeter Sep 2013 #73
The ONION features Commentary from Assad: So, What’s It Going To Be? Demeter Sep 2013 #75
KEEPING UP WITH THE NSA SCANDAL--THERE'S JUST SO MUCH OF IT! Demeter Sep 2013 #79
AND EDWARD SNOWDEN GETS HIS OWN SUBTHREAD Demeter Sep 2013 #80
Financial Psalm No. 16 Demeter Sep 2013 #83
in honor of the funeral for seamus heaney today xchrom Sep 2013 #84
Liam O'Flynn - Eire xchrom Sep 2013 #87
MARIA PINTO LAUNCHES NEW COLLECTION ON KICKSTARTER xchrom Sep 2013 #88
SELLING FARMS SOMETIMES CALLS FOR CREATIVE DEALS xchrom Sep 2013 #89
Donal Lunny Andy Irvine Liam O'Flynn Paddy Glackin The Blacksmith xchrom Sep 2013 #90
Falling Indian factory activity adds to rupee's woes xchrom Sep 2013 #91
Regulators ease derivatives rule to avoid harming economy xchrom Sep 2013 #92
BOJ to hold policy, debate emerging market risks xchrom Sep 2013 #93
look out now -- cause i might get my belly dance on xchrom Sep 2013 #94
Whew! Just taking a break from yard work. Fuddnik Sep 2013 #96
So, we went to see Elysium Demeter Sep 2013 #97
Latest Discussions»Issue Forums»Economy»Weekend Economists Get Sy...»Reply #56