The Unknowns
The Unknowns were a self-proclaimed ethical hacking group that came to attention in May 2012 after exploiting weaknesses in the security of NASA, CIA, White House, the European Space Agency, Harvard University, Renault, the United States Military Joint Pathology Center, the Royal Thai Navy, and several ministries of defense.[1] The group posted their reasons for these attacks on the sites Anonpaste & Pastebin including a link to a compressed file which contained a lot of files obtained from the US Military sites they breached. The Unknowns claim that "...our goal was never to harm anyone, we want to make this whole internet world more secured because, simply, it's not at all and we want to help." [2] The group claims to be ethical in their hacking activities, but nonetheless lifted internal documents from their victims, posting them online. They claim this was because they had reported the security holes to many of their victims, but did not receive a response back from any of them. The whole point was to show that these government-run sites have loopholes in their code and anyone can exploit them. The group used methods like (advanced) SQL injection to gain access to the victim websites. NASA and the ESA have both confirmed the attack. They claimed that the affected systems were taken offline and have since been patched.[3] At the time this was one of the most wanted hacking groups in Europe and also wanted by the FBI, although they refused to tell if they were investigating the hacks.
Members
The team had 5 core members,
Those members would include:[4]
- The Unknown, Founder, spokesperson, and leader.
- Mr. P-Teo, Programmer
- GrickoTheNoob, Programmer
- Zyklon B (Fabien Léac), a French researcher that looked for the vulnerabilities in websites, and passed it to the other members.
- MrSecurity, a Black-hat hacker, Programmer and Ghostwriter of The Unknowns.
Jail
Zyklon B, who lives in France, was arrested by the French Intelligence Service on June 24, 2012. He was later released because he was just sixteen years old at the time. He has trials taking place in 2014 supposedly.[5] His life is related in a book written by his mother Sophie Léac "L'histoire vraie d'un jeune hacker français" (in October 2013) or "the true story of a french teen-hacker". A second book is in preparation.
Hacked Websites and Applications
The group has hacked many websites and applications using a series of different attacks. The most notable, however, being SQL injection.[6] There have been a lot of companies affected by the group, but some of the hacks even for big companies did not make the media (probably due to keeping the multi-country legal investigation a secret). However, the most notable hacks done by The Unknowns, mostly government related websites, did make mass media.[7]
SQL injection attacks were used on the following:[6]
- Asian College of Technology
- Bahrain Defense Force
- California State University
- Christian Mingle
- Deutsche Federal Government
- European Space Agency
- ESET
- French Ministry of Defense
- Harvard University
- Jordanian Yellow Pages
- Lawrence Livermore National Laboratory
- United States Navy
- Renault
- Royal Thai Navy
- Sempra Energy
- Social Democratic Party of Germany
- United Kingdom Ministry of Defense
- University of Rhode Island
- United States Military
- United States Air Force
- United States Department of Commerce
- United States Department of the Treasury
- PayPal, no information was released. The Unknown contacted PayPal with the exploits he/she found and received $1,000 as a reward.
However they have used different attacks:
- Two United Kingdom police servers were exploited and root access was gained to the systems. Not much is known about this attack.[8]
Abolished
The purpose of The Unknowns was to find security issues in high-profiled websites and to get them patched.[9] The information from the hacked sites was released because The Unknowns attempted to make contact with all their targets informing them of the security issues, but they did not receive a response back from any of the websites targeted. Some data was leaked to force these websites to patch their systems.
After a period of hacking high profiled websites, The Unknown disbanded the group on June 9, 2012.
References
List of hacked websites/companies
- ↑ "NASA, ESA confirm they were hacked by 'The Unknowns'". Retrieved May 7, 2012.
- ↑ "The Unknowns Pastebin post". Retrieved May 7, 2012.
- ↑ "NASA, ESA confirm hacks; The Unknowns says systems patched". Retrieved May 7, 2012.
- ↑ "An article about the group". Retrieved 2014-01-18.
- ↑ "Zyklon B claiming to have been arrested". Retrieved 2014-01-10.
- 1 2 "A news article talking about the use of SQL injection attacks". Retrieved 2014-01-10.
- ↑ "A news article about the group by ABC". Retrieved 2014-01-10.
- ↑ "A news article talking about UK police servers getting hacked by The Unknowns". Retrieved 2014-01-10.
- ↑ "Another news article that had emailed The Unknowns, and received a response back.". Retrieved 2014-01-10.