background preloader

Security business

Facebook Twitter

Should I Change My Password? What to do regarding lulzsec dox : modnews. Take a bow everybody, the security industry really failed this time. I haven’t said anything about Lulzsec publicly yet and I don’t really have a good reason for the lack of comment.

Take a bow everybody, the security industry really failed this time

I have been watching their activities with great amusement. On Saturday I saw they released a large list of routers IP addresses and the username and passwords. The passwords looked like they were set to default values. This actually made me laugh out loud and I had two thoughts. Analyzing the Lulzsec Attacks. We analyzed the chat logs from Lulzsec that were provided in the Guardian.

Analyzing the Lulzsec Attacks

Specifically, we tried to analyze the technical approach used to bring down websites and steal data. Hopefully, our analysis can give security teams and even nontechies insights into how Lulzsec carried out their attacks and more importantly, help tune defenses. (We'd also recommend looking Byron's blog for some other lessons.) Lulzsec was a team of hackers focused on breaking applications and databases. There were no virus or malware experts.