• privacycommission and belgian parliamentarian want Belgian breach notification law after Rex Mundi announcement

    After the announcement of the hack of a Belgian firm with half a million members by rex mundi on twitter last week the privacycommission and the Belgian parliament are coming into action

    tired of waiting on the valuable but heavily counterlobbied effort by the European Commission for an European Data Breach Notification Directive - of which rumours say that it could take 2 to 6 years to implement - some Belgian Parliamentarians like Roel Deseyn want now to implement Belgian law that later can be adapted to the European Directive if necessary.

    the hack of a database of half a million belgians of which only a few people now what really happened (I don't know what really happened) may be the trigger to get the Belgian parliament and the government maybe moving very fast

    half a million data is off course a 'big one', the one that would lead to chaos if half a million people would have to change their password, sometimes their emailaddress, telephone numbers and so on

    the question is if we are prepared to treat a 'big one' just as we prepare for a big nuclear disaster, a food crisis, a big fire or accident and what if we have a big data leakage, who will be responsable

  • IEEE is breached and a hacker has all the 100.000 passwords

    IEEE suffered a data breach which I discovered on September 18 (UPDATE: the breach is now confirmed). For a few days I was uncertain what to do with the information and the data. On September 24, I let them know, and they fixed (at least partially) the problem. The usernames and passwords kept in plaintext were publicly available on their FTP server for at least one month prior to my discovery. Among the almost 100,000 compromised users are Apple, Google, IBM, Oracle and Samsung employees, as well as researchers from NASA, Stanford and many other places. I did not and will not make the raw data available to anyone else.

    so what does this say

    that they left the logins (login and password) unencrypted in the logs of the access to the site and didn't hash the logs or stock them away somewhere else to archive

    that European and American privacyregulations and laws have been breached

    that someone has the files on his or her computer and nobody can guarantee what he will or won't do with them

    the passwords give access to researchers all over the world of the biggest military, scientific and industrial networks

    in those networks, researchers are the ones that are the least preoccupied with security (free flow of information and all that)

  • Oplichtingsemails voor ING (banken sturen niet dergelijke emails - hoop ik)

    Veiligheidsupdate Home Banking / ING

    Marnixlaan 24, 1000 Brussel - 26-09-2012

    Sinds woensdag 25 Augustus 2012 werken wij met een nieuw beveiligingssysteem.

    Dit nieuwe systeem zorgt ervoor dat er geen misbruik kan worden gemaakt van uw rekening door bijvoorbeeld kwaadwillende software of een virus dat zich ongemerkt op uw computer heeft geïnstalleerd.

    Om ervoor te zorgen dat ook uw rekening wordt beveiligd door ons nieuw systeem,

    verzoeken wij u hieronder eenmalig de hyperlink te volgen om vervolgens uw gegevens te verifiëren.

    Zodra u dit heeft gedaan, zullen wij contact met u opnemen en stappen doornemen om uw account te updaten met onze nieuwe beveiligingssoftware.

    Klik hier om uw gegevens te verifiëren

    Bedankt voor uw medewerking

    Met vriendelijke groet,

    ING België

  • European Commission abuses online antiterrorism to propose to control everything from all of us (leaked document)

    A leaked document from the CleanIT project shows just how far internal discussions in that initiative have drifted away from its publicly stated aims, as well as the most fundamental legal rules that underpin European democracy and the rule of law.

    The European Commission-funded CleanIT project claims that it wants to fight terrorism through voluntary self-regulatory measures that defends the rule of law.

    The initial meetings of the initiative, with their directionless and ill-informed discussions about doing “something” to solve unidentified online “terrorist” problems were mainly attended by filtering companies, who saw an interesting business opportunity. Their work has paid off, with numerous proposals for filtering by companies and governments, proposals for liability in case sufficiently intrusive filtering is not used, and calls for increased funding by governments of new filtering technologies.

    The leaked document contradicts a letter sent from CleanIT Coordinator But Klaasen to Dutch NGO Bits of Freedom in April of this year, which explained that the project would first identify problems before making policy proposals. The promise to defend the rule of law has been abandoned. There appears never to have been a plan to identify a specific problem to be solved – instead the initiative has become little more than a protection racket (use filtering or be held liable for terrorist offences) for the online security industry.

    The proposals urge Internet companies to ban unwelcome activity through their terms of service, but advise that these “should not be very detailed”. This already widespread approach results, for example, in Microsoft (as a wholly typical example of current industry practice) having terms of service that would ban pictures of the always trouserless Donald Duck as potential pornography (“depicts nudity of any sort ... in non-human forms such as cartoons”). The leaked paper also contradicts the assertion in the letter that the project “does not aim to restrict behaviour that is not forbidden by law” - the whole point of prohibiting content in terms of service that is theoretically prohibited by law, is to permit extra-judicial vigilantism by private companies, otherwise the democratically justified law would be enough. Worse, the only way for a company to be sure of banning everything that is banned by law, is to use terms that are more broad, less well defined and less predictable than real law.

    Moving still further into the realm of the absurd, the leaked document proposes the use of terms of service to remove content “which is fully legal”... although this is up to the “ethical or business” priorities of the company in question what they remove. In other words, if Donald Duck is displeasing to the police, they would welcome, but don't explicitly demand, ISPs banning his behaviour in their terms of service. Cooperative ISPs would then be rewarded by being prioritised in state-funded calls for tender.

    CleanIT (terrorism), financed by DG Home Affairs of the European Commission is duplicating much of the work of the CEO Coalition (child protection), which is financed by DG Communications Networks of the European Commission. Both are, independently and without coordination, developing policies on issues such as reporting buttons and flagging of possibly illegal material. Both CleanIT and the CEO Coalition are duplicating each other's work on creating “voluntary” rules for notification and removal of possibly illegal content and are jointly duplicating the evidence-based policy work being done by DG Internal Market of the European Commission, which recently completed a consultation on this subject. Both have also been discussing upload filtering, to monitor all content being put online by European citizens.

    CleanIT wants binding engagements from internet companies to carry out surveillance, to block and to filter (albeit only at “end user” - meaning local network - level). It wants a network of trusted online informants and, contrary to everything that they have ever said, they also want new, stricter legislation from Member States.

    Unsurprisingly, in EDRi's discussions with both law enforcement agencies and industry about CleanIT, the word that appears with most frequency is “incompetence”.

    The document linked below is distributed to participants on a “need to know” basis – we are sharing the document because citizens need to know what is being proposed.

    Key measures being proposed:

    • Removal of any legislation preventing filtering/surveillance of employees' Internet connections
    • Law enforcement authorities should be able to have content removed “without following the more labour-intensive and formal procedures for 'notice and action'”
    • “Knowingly” providing links to “terrorist content” (the draft does not refer to content which has been ruled to be illegal by a court, but undefined “terrorist content” in general) will be an offence “just like” the terrorist
    • Legal underpinning of “real name” rules to prevent anonymous use of online services
    • ISPs to be held liable for not making “reasonable” efforts to use technological surveillance to identify (undefined) “terrorist” use of the Internet
    • Companies providing end-user filtering systems and their customers should be liable for failing to report “illegal” activity identified by the filter
    • Customers should also be held liable for “knowingly” sending a report of content which is not illegal
    • Governments should use the helpfulness of ISPs as a criterion for awarding public contracts
    • The proposal on blocking lists contradict each other, on the one hand providing comprehensive details for each piece of illegal content and judicial references, but then saying that the owner can appeal (although if there was already a judicial ruling, the legal process would already have been at an end) and that filtering such be based on the “output” of the proposed content regulation body, the “European Advisory Foundation”
    • Blocking or “warning” systems should be implemented by social media platforms – somehow it will be both illegal to provide (undefined) “Internet services” to “terrorist persons” and legal to knowingly provide access to illegal content, while “warning” the end-user that they are accessing illegal content
    • The anonymity of individuals reporting (possibly) illegal content must be preserved... yet their IP address must be logged to permit them to be prosecuted if it is suspected that they are reporting legal content deliberately and to permit reliable informants' reports to be processed more quickly
    • Companies should implement upload filters to monitor uploaded content to make sure that content that is removed – or content that is similar to what is removed – is not re-uploaded
    • It proposes that content should not be removed in all cases but “blocked” (i.e. make inaccessible by the hosting provider – not “blocked” in the access provider sense) and, in other cases, left available online but with the domain name removed.

    http://www.edri.org/cleanIT  (leaked documents)

  • My take on Anonymous and Lulzsec

    it seems I have to clarify or repeat this

    1. THere is no one Anonymous, Anonymous is a platform, a shouting name for a whole bunch of different groups, individuals, causes and actions with their own agenda but who would never get the same attention if they did it on their own, so in this way every activist is in some part Anonymous but at the same time he or she is not part of all the different actions that are done in name of Anonymous. But that doesn't make them hackers.

    2. Anonymous has a crappy ideology. This is what I said from the beginning. We are not one and united, we are all different and we have all different ideas, objectives and strategies and methods. So saying that we are one doesn't wash all these differences away. I like the Occupy movement more than Anonymous because it is more ideological and more clear. But that doesn't make me a hacker.

    3. Anonymous is evolving and changing all the time. If you see for example how Lulzsec (a police operation in the end) and Anonymous moved (or the discussion about the black block) than you can't stay that their relationship was clear and permanent. If you want to continue to understand the movement in movement, you have to continue to follow it up.

    4. I am an activist for the cybercauses so I follow them and a lot of other causes and as a newsjunkie I rassemble data, links, information and publications

    5. Also it is sometimes too much hype and boasting about itself and it sometimes loses all sense of critical thinking, just storming forward like a mob or a bunch of herds

    I don't need Anonymous here. I don't see the need for Anonymous here. I don't approve of the hacking by the Belgian Anonymous (the factory is still being planned to close)

    What we do need in reality is less hype about Anonymous and more digital actions about privacy, security and liberty in our Belgian society and on the web.

  • 10 reasons why I am not a hacker

    1. I have a life, a family, a home and a career (sort of)

    2. I hate prisons even if I haven't been in them

    3. I believe that hacking in or from Belgium is very risky, most of Belgian hackers have been arrested after a while

    4. I don't have to hack to proof my point that the belgian web is insecure, others show it every day

    5. I want to protect the innocent and ridiculize the stupid who think that they may get away with their crappy security (publicizing their hacked websites does this)

    6. I don't believe it will change anything, if you want to change the securitysituation in Belgium you have to change  the laws (see responsable disclosure for example). I have done that in the past.

    7. There is no responsable disclosure in Belgium so even with securityresearch you have to be very careful

    8. I have the trust of a whole lot of people and I don't want to shame them

    9. I am working on some new securityprojects that may change the securitysituation in Belgium very fast and these are more important than some demonstration

    10. I like the internet too much to be able to enjoy life as much without it

  • website mayor Brugge Moenaert hacked


    Code The Arts

    İ Love Mercedes :)

    Hacked By ZiyaretCi


    JeOPaRDY - Nettoxic - Powerdream - Xarnuz - BuzuLL - Shekkolik


  • active in an election - so except from this kind of operation like today

    it is going to be less stress here

    happy that we solved something today

    even if it is not our job

    but if we don't do it

    to protect the innocent

    who will

  • doing the right thing is responsable disclosure

    don't hurt the innocent bystanders who are the individuals who trusted the blablabla marketing and supposed that they were secure even if the online service provider didn't give a shit responsable disclosure is informing the cert and for the cert to set things up to make that possible Lulzsec is fine, but keep the lulz for the fat cats not the mouse that we are

    thanks rex mundi (if you are right of course, which is now for the cert to find out)

  • rex mundi extends the release of the data till next week, but doesn't give a clue yet

    Anyway, we won't release data on Fri. Just announce the leak. Data will b posted next week if no money is received.

  • rex mundi, the blackmailed belgian firm and the rest of us

    rex mundi says

    We will not publish the data. If they pay us in time.

  • rex mundi and why he shouldn't leak the half a million accounts on friday

    On Friday, details about our new target. A MUCH larger company, this time. Actually, our biggest op so far.




    In other words, Webassur case is closed. We promised the Webassur DB. U can use the passwords in leak to login to their clients' websites.



    Leak for next Friday is a DIFFERENT leak. We have acquired data from a large BE company w/ over 500,000 customer records


    in most of the cases before you asked for money, here I don't say that demand, do you mean it is for honor ?

    when firms didn't pay, you didn't always publish which means that some may be a bit skeptical about the possibility that you have them - which you could see as a provocation  because sometimes you did publish data (or parts of it) and sometimes some other geezers tried to grab the headlines with stupid tricks and big declarations without delivering

    if it is for honor than you wouldn't need to publish them, you can publish the name of the company and a cleaned sample of data that is easy to recognize as data from that firm (do never publish RRN or rijksregisternumbers nor SIS numbers pls), you would still be the hacker of that firm and the firm will still publicly be slashed for its insecurity but there would be a big difference. You wouldn't be - in the eyes of the media, people and history - be a leaker or chaotic hacker but a 'responsable leaker' (like responsable disclosure)

    you would get more respect - now and in the hackers history - than you would ever get with any other act that you have done so far (and still make the online world news if that is important to you)

    and if you don't want to do the responsable thing of not publishing them (do not harm the innocent) than there is plenty of other information that could be used to file a complaint against the firm and than we could use this case to make the case for more cycersecurity

    so it is up to you and you alone what you do

    I am sure there are ways with secret passwords or some file or technical info and so on to get a sample or more information

    you should at least give the cert and the other cyberdefenders the time to prepare for this if you are going to release this file (supposing you have it) Do you imagine what it would cost just to email half a million people that there passwords are published and that they would have to change their passwords anywhere where they uses the same ones ? And that would be just one of the things that people like me - trying to protect the innocent and help them through breaches and leakages - do. This is too big not to think twice again.

    and yes the firm that has such an irresponsable insecurity of its infrastructure and data will get grilled and audited and publicly shamed.

    do the right thing


  • rex mundi gives more information about the friday belgian insurer leak of thousands of personal info of Belgians

    first he didn't have 300 databases, he has hacked 300 websites, this is according to him a big difference

    secondly he says that the way he got in is still online and hackable

    @mailforlen Just read ur post. We said we hacked 400 websites,not 400DB.. the Modulink backend can b accessed w/ passwords in today's leak.

    @mailforlen Well, Tor yourself up and check some of those passwords! They do indeed work. Dummy table? nope.

    it is one of the sites on the server of the developer of websites for insurance agents (co-hosting is bullshit if you have personal or confidential data)

    @mailforlen Or better, yet. (and legal this time): Call some of the companies listed in our release. PS: You don't wnt 2miss our Friday leak

    oh and what about all these other databases they have said they have but they finally didn't publish (of which some belgian)

    @mailforlen Finally: We never bluffed. The fact that we didn't publish some of our data doesn't mean that we didn't have it.
    01:57 PM - 18 Sep 12

    this is the declaration

    1. We have been busy little bees this week, hacking our way into over 300 Belgian lending and insurance websites (full list below).
    2. What do all of these websites have in common?
    3. Well, they have all been designed by the same company called Webassur (http://www.webassur.be). The geniuses running this company apparently thought it would be a bold, brave idea to store all of their websites'data into the same SQL database. In other words, once we managed to hack into one of them, we immediately got access to each and every other website designed by Webassur.
    4. The data we stole includes the personal details of each customer of Webassur, along with details about insurance and loan applications made of the websites.
    5. We have offered Webassur not to release this data for the paltry sum of five thousand Euros, but, unfortunately, as of today, they have not complied with our demands.
    6. If someone trusts you with the security of their data, the least you could do, in our opinion, is to man up if your server gets breached and pay up.
    7. Webassur has until next Monday to pay us. If not, well, their customers' data will end up on the Internet, just like Credipret's and AmeriCash Advance's.

    This is the list of firms that had confidence in webassur and is now on the hitlist


    393. SAMPLE DATA  (belsec has deleted some)
    394. -----------
    396. Client ID:900    
    397. Name:Verzekeringskantoor J. Decubber - Daneels 
    398. Email: stef     
    399. Password: 
    400. City: Maarkedal
    401. Zip Code: 9681 
    402. Address:     
    403. URL:www.decubber-daneels.be    
    404. Phone: 055   
    405. Fax: 055/
    406. Name: Stefaan Decubber 
    407. Cell phone: 0475
    409. Client ID: 807
    410. Name: Swaegers Verzekeringen
    411. Email:     
    412. Password:      
    413. City: Turnhout 
    414. Zip Code: 2300 
    415. Address: Kempenlaan      
    416. URL: www.veiligsparen.be       
    417. Phone: 014    
    418. Fax: 014/      
    419. Name: Koen Van Hees    
    420. Bank number: 320-


  • 300 SQL databases hacked from Belgian lenders - insurers or bluff from Rex Mundi

    Rex mundi has a history of doing some really freigthening stuff and publishing parts of it and at the other side bluffing and not publishing anything so it is difficult to make a difference between what is true and what is bluff and what he has and what was published

    he is also some-one who like to play mindgames (tries it with me sometimes) so you have to think twice about everything he says (and besides the leaks there are enough time that he didn't deliver to be fair)

    I don't underestimate him and I don't believe by security by obscurity so I think it is possible that sql attacks can nowadays still deliver the kind of data he is talking about (some even don't use https connections) just because it is not a tradition or obligation to test external databases against all the different kinds of sql attacks (now not only the automated ones, but also the manual, complicated, human ones).

    that is why I think it is possible. He plays mindgames. So aside the automated stupid sql attacks he will probably do the things also manually when more expertise is necessary.

    the first thing published is webassur.be but they say that it is a testdatabase of agents and not from clients


    in another pasting he says he has hacked more than 300 insurance databases (in the database of the agents are also websites with probably databases and these are 400 in number and even if the passwords are wrong maybe they are all built the same (wrong) way and some are hosted on the same virtual cohost server so get one and you get many.

    as these insurance agents are probably not really securityminded ITprofessionals and have maybe not enough security on their laptops they maybe have clicked on infected emails with zerodays giving him easy access to the pc and the website(s).

    so do not underestimate him and do not believe all his bluff but sometimes he gets it rights and as in Poker, you can take your chance when somebody is bluffing but you can also lose everything

    for the moment this means I have work to do, set things in motion, alert some bells

    and if you have an sql database, than you should run to your website developer and get him to answer the following questions

    * do you have the last versions

    * did you install the security stuff

    * do we only have information we really need (not the nice to have which is everything)

    * do we have encrypted anything or is it dummy stuff

    * do we have backups of everything

    * do we have a take-down procedure

    * what do we do if client information is published

    * did you let it test by securitytesters and why not

    depending on the answers, you will be happy to have really qualified people in charge or be in panick

  • international fed of pharmacists hacked and data released

    International Pharmaceutical Federation (FIP) The global federation of national associations representing 3 million pharmacists and pharmaceutical scientists around the world.  Fip.nl

    the file with all the names and passwords and emails is here


    a few thousand and about 1.5 MB

  • the necessary silence of 11 september in Chile and NY

    democracy and socialist experiment killed by CIA supported military (1973)

    more than 30 years later Chile is still recovering

    Chileans ask : where were you that day and what did you do afterwards ?

    democracy and open society attacked by islamic fundamentalists (2001)

    the US and democracy is still recovering

    Americans and the world watching ask : where were you that day ?

    it are defining moments in the history of a people, a nation, its democracy, its concepts of security and freedom

    Securitypeople learned that every detail can be important and has to be followed up but since than privacypeople have learnt that securitypeople want to follow all of us in a too detailed manner

  • Apple UID, it is in fact an mobile application firm that lost it (and didn't know)

    So we know already about malware and spyware mobile apps sitting in the libraries (and even more on the web)

    we have learned about the privacy concerns of all that data going to mobile developers

    but as they were American we supposed they were guaranteeing the security and privacy of it all

    it now is becoming clear that it is not a FBI agent responsable for recruiting new informers and agents on Facebook and boasting about it but the firm that was hacked and lost its clients connection data (and more according to Anonymous, probably all client data (but they forget to mention this in this article as source)

    and after the release and even after the declaration of the source by Anonymous (like a Len Deighton novel, you never know who is doing what why for who) app developers were scrambling to find out if it was their data

    not this firm, they had to be contacted by an independent security researcher (nice work) to go themselves to their database and compare the two to see that for more than 90% it was the same data and they contacted the FBI and don't release more information because of the 'ongoing investigation'

    so what is clear from all this

    * the information was not professionally encrypted or scrambled

    * the information was not enough protected with data leakage prevention

    * there was probably more information than strictly needed

    * some parts of the information were not seperated according to use (billing, usage and login, profile)

    time to modernize that wild mobile west



    oh and remember there are 12 million UID's stolen and all other member data also financial is also in the possession of them, they only released one million and only the UID's (they claim)

  • DNS is really professional business GO Daddy (and others) not some add on

    "The more problematic part is that any domain registered with GoDaddy that uses its nameservers and DNS records are also down," Mashable wrote. "That means that even if you host your site elsewhere, using GoDaddy for DNS means it is inaccessible."


    The company, which says it hosts 53 million domain names, has acknowledged the outage on its Twitter feed but has not commented on the cause of the problem.

    so some facts

    * this isn't a ddos (or it is against the DNS infrastructure specifically)

    * and it isn't by the whole Anonymous operations, just some person of it claiming its name or abusing it, but that is also what Anonymous is

    what does it mean

    * dns is very serious business in which you should invest and for which you should or use professional services (who invest a lot of it because it is their core business) or invest personnel, monitoring and protecting in it

    otherwse you are just a King without clothes, ready to be shown naked every time some dude around the web thinks it is time to do so

  • how to search All emails to the Syrian Ministry of Foreign Affairs with Google

    WikiLeaks has released all emails (32,476) to and from the Syrian Ministry of Foreign Affairs as part of the Syria Files.

    this is only part of the enormous collection (give us the database with all to search)

    it is not searchable (if you find something Belgian, let me know :))

    You will find them here


    and now how to use Google to search them

    well use this Googledork

    site:http://wikileaks.org/syria-files/releasedate/2012-09-10-13-ministry-of-foreign-affairs-and-expatriates (and put behind it whatever term, name, emailadres, ..... you would like) and open the results in a different tab so you can go back

    mails are in .obj format sometimes  http://www.fileinfo.com/extension/obj

    there is also a lot of spam in it which means their mailboxes weren't properly secured and they use Kaspersky for those who want to know :)

    nice hunting


  • stratfor (private CIA) thinks Israel is spying on industrial and economic complex in the US

    Email-ID 1109886
    Date 2011-01-18 14:35:07
    From burton@stratfor.com
    To analysts@stratfor.com
    List-Name analysts@stratfor.com


    We can't loose site of the Mossad penetration and theft via industrial
    espionage, meaning the U.S. fell victim due to shoddy oversight, govt
    contracts, etc.

    The high-tech areas in CONUS (to include Austin) are crawling w/Israeli
    operatives, false flag companies and agents of interest.


    that is what friends are for .....