Welcome to the New Statesman website. Please sign in or register to participate in the conversation.

The Staggers

The New Statesman’s rolling politics blog

Syndicate contentRSS

Hacks hacked: how the Sun reported Murdoch's "death"

Groups such as LulzSec have security teams on the run.

News yesterday that the Sun was hacked by LulzSec is just the latest in a long line of impressive hacks, but it again shows how hard it is to protect sites from such sustained, sophisticated attack.

LulzSec , a group of hackers which describes itself as, "a team of entertainment and security experts that specialise in the production of malicious comedic cybermaterials", managed to redirect visitors to the Sun's website yesterday evening to a hoax page falsely reporting that Rupert Murdoch had been found dead.

It's not the first time a major UK newspaper has been hacked. Last April the Daily Telegraph saw its site hacked, apparently by a group angered by that paper's identification of Romanians as "gypsies" (they added a comment to one of paper's web pages that read, "Guess what, gypsies aren't romanians, morons.")

LulzSec was linked to the hacking of Sony's PlayStation Network, a hack thought to be motivated by Sony's legal action against George Hotz for 'jailbreaking' the PlayStation 3 - bypassing the device's security software in order to enable users to run unauthorised software on it. LulzSec has not accepted responsibility for the PSN hack, but it has taken responsibility for hacking PBS' site and posting a news story saying that deceased rappers Tupac Shakur and Biggie Smalls were actually still alive and living in New Zealand.

Previous LulzSec victims include websites of the Brazilian Government, energy giant Petrobras, Nintendo, Fox.com and even a database of X Factor contestants.

So why are so many websites such easy pickings for groups like LulzSec and Anonymous? There are a number of factors at work. For one, these groups of hackers can draw on just as sophisticated programmers as you will find in the security team at a typical organisation. These are no amateurs.

But the big problem for website security is change. The security systems protecting a website may well be good enough today, but as administrators make changes to the website - adding new features and functionality, disabling old campaigns and so on - they need to be incredibly rigorous about ensuring that the same security technologies, processes and policies remain in place. With large IT teams working on increasingly complicated websites, and often drawing on a mixture of in-house and off-site contactor skills, the potential for an old server or new feature to lack the adequate security mechanisms is high.

It's thought in the case of the Sun's site, LulzSec was able to compromise a "retired" server, which then gave them access to other parts of the News International network. All they had to do then was insert a script into the Sun's homepage that redirected visitors to their hoax page.

It's unlikely this all happened in the space of a few minutes or even hours: it was reported that another hacker group, Anonymous, had been 'rattling the Sun's doorknobs' for at least a week - finding vulnerabilities that could be used in a later exploit.

As I've said before, right now, the bad guys are winning. Their sophisticated, prolonged attacks on carefully-chosen targets are nothing like the one-off, individually-perpetrated and largely opportunistic attacks that we used to see.

As Eric Howes, research manager at security technology lab GFI Labs said recently when I asked if he believes the "bad guys" are winning, "I would have to say the bad guys are doing pretty well for themselves. We hope to be able to turn that around, but I would hesitate to make a prediction as to exactly when."

Jason Stamper is NS technology correspondent and editor of Computer Business Review

11 comments

greg's picture

The bad guys are winning? Are you 12? While I disagree with many of Lulzsec's early exploits against gamers, I'd say hacking the a scummy newspaper like the Sun's website is a good thing.

Besides get your facts straight, Anonymous attacked the PSN originally then said sorry because they were disrupting their own people. The second, and most damaging, hack was never pinned on anonymous, in fact most members denied that they would do anything to steal credit card data. None of this was Lulzsec.

sangeairen's picture

==== http://www.vogue7.us ====
==== http://www.vogue7.us ====
==== http://www.vogue7.us ====

==== http://www.vogue7.us ====
==== http://www.vogue7.us ====
==== http://www.vogue7.us ====

Roy's picture

These aren't the 'bad guys'. These guys are vigilante heroes.

uhdfu's picture

---- http://www.proxy4biz.com ------
---- http://www.proxy4biz.com ------

Firefighter's picture

@greg

LulzSec were known to have a grudge against Sony, they denied the PSN hack when they realised the gravity of the situation and Sony had got the FBI involved.

As to whether the hackers, or The Sun are the bad guys, depends on your point of view. Hackers who cause criminal damage as they did against The Sun are breaking the law. Are they the good guys then? If they don't like the actions of some organisations they have carte blanche to break the law? MMMkay.

joyce's picture

"Media moguls body discovered" cool grammar on a newspaper

ab1's picture

I believe its justified, all you sheeple commenting have no idea whats going on in the world, best you go to sleep and wake up when its over.

Danny's picture

@ab oh do grow up. Calling people sheeple does you no favours.

BlackSheep's picture

@Danny - ab may need to grow up but the thing is, he's right. Baaa

MrCheeky's picture

last nights hacking of the sun was the best news that scumbag rag of a paper was the best news weve seen in many years.shame on you murdoch for wat you have done to the british press.the best way to applogise to our nation is to resign and as for the pepople you hurt its unforgivable and then you have our brave troops who fight for our nation you have let them down

Gewyne's picture

"shame on you murdoch for wat you have done to the british press."

You mean his rescuing papers, investing 100's of millions into them, employing 10,000's British Journalist over a few decades ?

"then you have our brave troops who fight for our nation you have let them down"

I forgot it was News Inc who sent our troops of to fight in dubious wars... seems Politicians get of scot free, what's that hundred of British Troops dead, over 200,000 innocent civilians dead... fear not MPs, MrCheeky is reflecting blame from you to Rupert... after all why not know everyone else is lacing up their jackboots to join in the kicking.

Post new comment

By submitting this form, you accept the Mollom privacy policy.

Latest tweets