Showing posts with label HBGary. Show all posts
Showing posts with label HBGary. Show all posts

Monday, February 21, 2011

Hacked and now of vandalism, RSA HBGary pulls out

California security company at the center of a controversy over a plan to discredit WikiLeaks and his supporters abruptly pulled itself outside the RSA Security Conference in San Francisco this week, citing security concerns.

The company's subsidiary, HBGary federal, canceled a speech that had planned to give Internet activist group, anonymous. Was the news of this speech that riled up anonymous and precipitate the controversy last week.

HBGary has been under fire for several days now after their own websites, the corporate e-mail system and Twitter accounts were hacked and details of a business proposal to discredit WikiLeaks society were sent to the Internet. Apparently, the attack was launched by Anonymous in reply to talk about CEO Aaron Barr of HBGary federal, which had been scheduled for Monday morning. Barr said that he had discovered the identity of many of the leaders of anonymous and had planned to discuss his investigation in a speech to the Conference BSides San Francisco, which runs in tandem with RSA.

Barr, "I was receiving death threats," he said in an interview Tuesday. "There was a lot of talk that was being formed in anonymous harassing us IRC channels at our booth and sending people to heckle [HBGary speakers of the Conference]."

The company has decided to strike at RSA Conference booth from the floor, however, after that it was vandalized on Sunday, said Jim Butterworth, Vice-President of HBGary services. "We ... came back the next morning and was very obvious that the group responsible for the activities in the news had decided to make another statement," he said.

The IDG News service obtained a photo of booth broken HBGary. Someone had put a large poster paper at the stand of HBGary that read, "anonymous ... in it 4 the lulz.. " Lulz is Ride ' Internet slang meaning.»

Instead of a stand of the exhibition, HBGary's place on the floor is now empty RSA show, except for a small sign saying the company has decided to withdraw from the show.

HBGary founder Greg Hoglund had been scheduled to speak at RSA, but those talks have now been cancelled too, Barr said. He declined to comment further controversy for his work, or the cyber attacks in his company.

But according to the published email company, Barr knew last month that his speech would make HBGary a target.

Clearly, however, has no idea how bad things would get. HBGary--less protection but once-respected society-ben--has now suffered what could be a fatal blow to its reputation.

For a security company to suffer a similar breach is embarrassing, but buried in email 67000 society published by Anonymous had even more bad material as a proposal to help the right of Bank of America company, Hunton & Williams, discredit WikiLeaks in front of the awaited release of secret documents. In the proposal, Barr has suggested that HBGary Federal could work with two other security companies--Palantir technologies Berico--and to launch it, seed WikiLeaks with forged documents and dig dirt and his supporters.

BofA publicly distanced itself from HBGary after the incident, while Palantir technologies Berico have cut off and ties with the company.

Robert McMillan covers the security of your computer and General technology breaking news for the IDG News Service. Follow Robert on Twitter at @ bobmcmillan. E-mail address is robert_mcmillan@idg.com, Robert



Friday, February 18, 2011

HBGary Federal closes RSA email anonymous WikiLeaks

By Richi Jennings. 16 February 2011.

HBGary Federal has been the subject of counterattacks by the anonymous group-s-not-a-group. The insecure security companies authorised his email to losses for the supporters of WikiLeaks. And now has had to pull out the RSA Conference and related unconference, HBGary security B-Sides. In IT Blogwatch, bloggers, laugh and laugh and laugh.

Your humble blogwatcher curated by these bits bloggy for your entertainment. Not to mention what they put into Ukrainian water? ...

Josh Halliday reports:

Apparently leaked emails suggest that three private security undertakings – HBGary federal, Palantir technologies and Berico – they pitched a plan to undermine ... WikiLeaks ... for a law firm that represented the Bank of America ... thought to be the next target of WikiLeaks. ... Anonymous began to tens of thousands of emails sent to Federal HBGary last weekend, after the release of the ... group attacked the company's computer systems security.
...
Bank of America ... they said they hadn't known about ... strategy to undermine WikiLeaks ... and that HB Gary Federal was never taken on their behalf. Berico technologies and Palantir also attempted to distance themselves from leaked emails. ... HBGary, an affiliate company at HBGary Federal ... said that the actions of Anonymous were "criminal".


Peter Bright adds:

HBGary Federal CEO Aaron Barr thought that he had tipped off the hordes of anonymous hacker and was preparing a name and shame those responsible for the coordination of actions of the group. ... When Barr said one of those who believed to be a music man anonymous on his upcoming exposé ... HBGary's servers were broken into, sacked and published his email in the world, its data is destroyed and its website defaced. ... A second site owned and operated by Greg Hoglund, HBGary owner, was taken offline and published user registration database.
...
HBGary Federal HBGary and position yourself as an expert in computer security. ... You might think that this organization estimated would prove insurmountable challenge for a lot of guys disaffected hack. ... Unfortunately for HBGary ... recruiting expertise [not] accurate, as the story of how was hacked HBGary will clarity.


Ryan Naraine observes the empty space on the show floor of RSA Conference:

HBGary start-up security withdrew from the RSA Conference here after the recent hacking attack which included the release of 20,000 email. ... On the show floor of RSA Conference, booth HBGary has been replaced with this sign to explain the circumstances.
...
HBGary people received many threats of violence. ... In an effort to protect our employees, customers and the community of RSA Conference, HBGary has decided to remove the stand and cancel all the talks.


Andy greenbergsays that not only is the show that lacks HBGary:

Rarely in the history of cybersecurity industry has a society become so toxic so quickly as HBGary Federal. ... [I] scandal ... seems to grow every day of his dubious practices come to light.
...
The company is canceling talks of all its directors at the RSA Conference, the largest cybersecurity industry confab of the year. ... Hoglund had planned to give two presentations at the Conference. ... Barr last week has canceled her speech at Conference B-Sides simultaneously, you would put on his expose to anonymous.


and Andrea Petroudirty dishes:

According To ... Crowdleaks.org ... by Greg Hoglund emails show that HBGary could have worked on a new type of Windows rootkit. If it was released in the wild may have caused many security problems due to the fact that it was nearly impossible to remove and undetectable. ... Other emails show the work that has been performed for defense contractor General Dynamics ... HBGary said to have developed, Trojans, rootkits and other spyware programs. ... These codes have been appointed as Project C, Z activities and task M.


Meanwhile,DJ Walter-Morganhas more bad news for the company of "security":

The scale of the disaster that has passed ... HBGary ... is slowly becoming clear. ... It turns out that Aaron Barr, CEO of controlled HBGary federal, offered his services to illuminate the darkness surrounding anonymous the FBI. ... Barr collected information on the accounts of activists suspected IRC, Facebook and Twitter.
...
Seem that attackers have used fake emails to get an administrator to allow SSH access. Attackers had previously had access to the root password. ... However, in view of the practice of sending HBGary even sensitive data in plain text (unencrypted) email to the fact that passwords are that their way into the wrong hands is not particularly surprising.

 
And finally ...
What they are putting in Ukrainian water?

Don't miss out on IT Blogwatch:

You can also read Richi full profile and disclosure of his industry affiliations.



Tuesday, February 15, 2011

HBGary retires from RSA after embarrassing ' Anonymous ' hack

Daniel Kennedy leads initiatives in politics and in the management of operational safety, conducts the certification strategy and risk assessment and is head of business continuity planning and disaster recovery to the Praetorian security group, LLC.

Praetorian Security Group first, Daniel was the global head of information security at D.B. Zwirn & co where he managed the company's information security. He was specifically responsible for the development, implementation and maintenance of information security policy of the company. Managed security metrics reporting, also the program of awareness raising and education of safety, security incident response, security control and develop the company's strategy for the security technology. In this role he worked closely with the firm's CIO, COO, head of compliance, head of legal, head of infrastructure, head of client services overseas and IT managers.

Before D.B. Zwirn, Daniel was Vice President and program director for the security application program at Pershing LLC, a division of the Bank of New York. Responsibilities of Daniel including management of the firm's application security, coordination of application vulnerability assessments and testing, application security, training, documentation of the secure coding guidelines and application security development firm SDLC penetration. He was the primary liaison for application security concerns among teams as the Information Security Office, Internal Audit, risk of Information Management (IRM) and teams of business and application development. He served on several committees, including the security infrastructure, Workgroup and chartered security architecture and chaired the Security Council of the enterprise application, an interdisciplinary team consisting of application developers and security experts on the subject.

His previous positions include the Pershing and development management positions in systems engineering of web applications creation company to facilitate the online brokerage. He was also employed at Donaldson, Lufkin & Jenrette Inc., a technology analyst for the Treasury.

Daniel Degree Master of Science in information systems from Stevens Institute of Technology, a Master of Science in information assurance from Norwich University and a Bachelor of Science in Information Management and Technology from Syracuse University. He is certified as a CEH (Certified Ethical Hacker) of the EC-Council, a CISSP and an NASD Series 7 license.

You can also follow him on Twitter, and the Praetorian Prefect of blog.