Hacktivism moves from pranks to problems

Far from being "sophisticated" attacks, LulzSec and Anonymous are run of the mill, say experts. But companies need to look to their defenses.

By Robert Lemos

July 14, 2011CSO

Agricultural technology firm Monsanto became the latest target of hacktivists this week, when hackers donning the mantle of the distributed protest group Anonymous claimed that it had penetrated the firm's network and leaked personal information on 2,500 of the company's employees.

The same day another group, also calling themselves part of Anonymous, leaked about 90,000 military email addresses allegedly taken from the servers of accounting firm and government contractor Booz Allen Hamilton. On Tuesday, the company acknowledged that some of the information circulating on the Internet was taken from its servers.

Also see: Hacktivists put the entire Intel community in its crosshairs

The attacks are the latest in a spate of cyber unrest that started last year with attacks by the group Anonymous on companies that took a stand against Wikileaks, a group dedicated to outing government secrets. While companies and government agencies had derided the efforts as pranks, the success that hactivists have had in penetrating networks has increasingly caused concern.

"In the past, I would say that this is just a bunch of kids -- it's just graffiti," says James Lewis, senior fellow for cybersecurity at the Center for Strategic and International Studies. "Yet, if we are unable to catch enough of them, then it will become a problem."

Officials from the European Union have expressed concern that the series of attacks could indicate a resurgence of anarchy, a movement that has occasionally caused unrest within Europe and other nations, Lewis says.

Yet, companies should also take another lesson to heart: Poor network security is allowing these attacks, Lewis says. While reports on the Internet, including statements from targeted companies, have painted the attacks as sophisticated, the hacktivists are actually using simple techniques, such as scanning for exposed databases and inundating servers with data packets.

"For the level of stuff we have seen, people should not be falling victim to it," Lewis says. "A good defense should have been able to fend it off."

A survey of the tools and techniques used by LulzSec, an offshoot of Anonymous, and various hacktivists claiming be part of Anonymous, supports the assertions that companies are falling prey to easy attacks, says Daniel Clemens, principal security consultant with penetration testing and forensics firm PacketNinjas. Among the hacktivists' favored tools: The a denial-of-service tool known as the Low Orbit Ion Cannon (LOIC), known vulnerability scanners, and generic Web application scanning tools, such as the Web Application Attack and Audit Framework (WA3F) and an automated SQL injection and database compromise tool known as SQLMap.

RESOURCE CENTER