Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Friday, July 8, 2011

Connexion Email Account Dump Includes Military and Government Accounts - Zeropaid

Connexion has already dumped data from a California government website to pastebin and now they have made another data dump. A statement within the release contains the following:

Dear Internetz,

We are the Connexion Hack Team. We are here to say that we are releasing approx. 16,959 emails and passwords. These are random and do not ask which website they came from. If you want to see if your email is there press CTRL+F on Windows and search for your email. If it is, well to bad, pick another email from the list. If it isn’t then you are one lucky bastard.

We want everyone to know that we mean business here. Have fun!

There’s numerous government e-mails from pretty much all over the map. There’s e-mail accounts from the NSA, Virginia, the DHS, and others. We’ve removed the passwords, but these are the list the group dubbed “Important people”:

ahooten@hrsa.gov
cavines2@niehs.nih.gov
craig.nicholson@ky.gov
dbarett@moorecountync.gov
Dbarnwell@augustaga.gov
deborah.a.jordan@ncesc.gov
dlhar11@nsa.ic.gov
elizabeth.pridgen@dot.gov
gdublin@cdc.gov
gloria.dotson@dss.virginia.gov
gxxmills@bop.gov
icq4@cdc.gov
james.ferguson@scc.virginia.gov
james.heck@nrc.gov
JANIE.HILL@VA.GOV
Joe.Manora@noaa.gov
jwr3@cdc.gov
karcher@cdc.gov
louise.stokes@norfolk.gov
MARSHA.PHILLIPS@NLRB.GOV
michael.anthony.blake@census.gov
Nicole.Merriweather@louisvilleky.gov
patwill@mdes.ms.gov
paul.griffin@dhs.gov
ROBINSONA@DNR.SC.GOV
shawn.armstead@ssa.gov
shchapman@dot.ga.gov
sminor@dot.ga.gov
sonya.beaver@vdh.virginia.gov

To some of these users credit, they did use a combination of letters, numbers and symbols, but those are only a select few. One did have a password “changeme” which the team commented, “mega lulz”.

In the next section, there was a list dubbed “more important people” Again, we’ve removed the passwords:

arnold.leeks@ng.army.mil
ashley.n.richmond@us.army.mil
brenda.s.davis@navy.mil
christine.johnson@amedd.army.mil
demetrius.spencer@us.army.mil
don.barbee@us.army.mil
flora.goldsbyturner@tinker.af.mil
glenda.mack@us.army.mil
hasani.hudson@navy.mil
joseph.perryman@us.army.mil
kelvin.blanton@us.army.mil
marshall.coaxun@usmc.mil
michael.lowry@med.navy.mil
michele.jackson@med.navy.mil
ora.phillips@afncr.af.mil
pauline.pituk@conus.army.mil
rober.a.cury@us.army.mil
Roberta.Kithcart@Charleston.af.mil

Again, to one persons credit, a combination of letters, numbers and symbols was used. The reason why this is good is because it is suppose to take exponentially longer to crack such a password when a combination of letters, numbers and symbols. I suspect these were obtained in another manner in this case.

The remaining e-mails and passwords are all over the map. The e-mails are in alphabetical order and, strangely, they end on the letter “s”. So anything after the letter “s” appears ot be safe for now (maybe an additional release will be made?). Domains that are found include Yahoo (lots), BellSouth, Gmail, MSN, Earthlink, Comcast, Sprint.Blackberry, vzpix, sbcglobal, Cox, Hotmail, Spartans.nsu (lots), Verizon, NSU, and AOL to name a few.

It’s very difficult to know for sure how these were obtained considering it’s just a random smattering of e-mails. No doubt, these accounts will appear elsewhere for those wondering if their account was compromised or, more easily, it can be downloaded on MediaFire while it’s still up.

Have a tip? Want to contact the author? You can do so by sending a PM via the forums or via e-mail at drew@zeropaid.com.


View the original article here

Rojadirecta Sues US Government, Homeland Security & ICE Over Domain Seizure - Techdirt

Puerto 80 does not host any infringing material on the websites which operate under the subject domain names... In the same way a search engine or other site which aggregates links to existing material on the Internet, Rojadirecta provides an index of links to streams of sporting events that can already be found on the Internet through a search for those sites or simply by typing the URL for the site directly. Id. Such activity does not constitute direct copyright infringement, much less criminal infringement. See supra, at note 8. Indeed, United States Senator Ron Wyden (D-Or) made this point in a letter he wrote to ICE Director John Morton and Attorney General Holder expressing concern over the government?s seizure of the subject domain names....

Puerto 80?s operation of the Rojadirecta site does not constitute contributory infringement because the subject domain names are capable of?and are, in fact, used for? substantial non-infringing uses. Sony Corp. v. Universal City Studios, Inc., 464 U.S. 417, reh?g denied, 465 U.S. 1112 (1984); Arista Records LLC v. Lime Group LLC, 715 F. Supp. 2d 481, 517-18 (S.D.N.Y. 2010) (summary judgment inappropriate where material fact existed as to whether file-sharing program, which was ?used overwhelmingly for infringement,? is ?capable of substantial non-infringing uses.?).

Nor is Rojadirecta a site devoted simply to linking to such streams. In addition to providing a forum for discussion on sports, politics, and a variety of other topics, the Rojadirecta site enables users to post links to authorized sports broadcasts. For example, on Saturday, February 12, 2011, the Rojadirecta site (hosted on the rojadirecta.es domain name) provided a link to ?9:30am Hockey (NHL): Los Angeles ? Washington.?... Clicking on this link opened a new window for the Yahoo! sports website for the National Hockey League, and provided a live stream of the match between the Los Angeles Kings and Washington Capitals. Id.

Nor does Puerto 80?s operation of the Rojadirecta site constitute vicarious liability because it does not have ?a right and ability to supervise that coalesce[s] with an obvious and direct financial interest in the exploitation of copyrighted materials.? Softel, Inc. v. Dragon Med. & Sci. Commc?ns Inc., 118 F.3d 955, 971 (2d Cir. 1997) (quoting Shapiro, Bernstein & Co. v. H.L. Green Co., 316 F.2d 304, 307 (2d Cir. 1963) (emphasis added)). Puerto 80 does not receive any revenue that is derived from specific content hosted on, or streamed by, the sites to which it links.... In other words, Puerto 80 does not receive any revenue from any site to which a user can link from the subject domain names based upon the content of that site. Id. To the extent there is any site to which Rojadirecta links that contains infringing material, Puerto 80 receives no specific financial benefit from a user clicking through to that site and viewing such content.... Because Puerto 80?s revenues are not tied to whether or not infringing material is linked to or accessed, the government cannot show that Puerto 80 has a ?direct financial interest in the exploitation of copyrighted materials? which ?coalesce[s] with? any right or ability to supervise what is linked to on the site. See Artists Music, Inc. v. Reed Publ?g (USA), Inc., Nos. 93 civ. 3428(JFK), 73163, 1994 WL 191643, at *6 (S.D.N.Y. May 17, 1994) (direct financial benefit not established where defendant leased space at a trade show for a fixed fee to exhibitors who played infringing music, but defendant?s revenues were not dependant on whether exhibitors actually played music or what they played); Viacom Int?l Inc. v. YouTube, Inc., 718 F. Supp. 2d 514, 521 (S.D.N.Y. 2010) (in DMCA safe-harbor context, ?financial benefit directly attributable to the infringing activity? not established ?where the infringer makes the same kind of payment as non-infringing users of the provider?s service?) (quoting Senate Judiciary Committee Report and the House Committee on Commerce Report, H.R. Rep. No. 105-551, pt. 2 (1998)).


View the original article here

Hackers publish 17000 e-mail addresses and passwords from US government and ... - ComputerWeekly.com

Connexion Hack Team e-mail passwords US government military

A hacker group has stolen and published around 17,000 e-mail addresses and passwords from the US government and military sources.

The group, calling itself the Connexion Hack Team, did not disclose the source of the information, according to Australian reports.

Although the group published passwords for accounts held with online services such as Yahoo, Gmail and Hotmail, passwords military and other similar domains were withheld.

Earlier in the week, the Connexion Hack Team published information about benefactors gleaned from the website of the California Fair Political Practices Commission.

"We have hacked your website, because it needed to have a checkup with the SecDoctors. We have found many errors with your website," the group said in a statement.

The group indicated the action was part of a campaign by hackers, called Anti Security or AntiSec, to steal and leak classified government and company information to expose security flaws.

The AntiSec campaign was spearheaded by hacker groups Anonymous and the now-disbanded Lulzsec, which in its latest efforts in the campaign hacked and defaced Turkish government websites in protest against internet filtering rules to be introduced in August.


View the original article here