Posts

Showing posts from July, 2015

Team Ghost Shell returns

While doing a bit of reading recently I ran across this interesting story about Teamghostshell an active hacking group that has come back to life on June 29th after a couple of years of silence. The groups recent exploited an extensive list of sites, which they disclosed on pastbin .  If you read the hacker team's extensively long diatribe you will get an impression that their motives are pure and for the benefits of society, but like all disclosures the only people that suffer are the victims found in the data drop. You can also distill from the dialog that they probably used several COTS exploit kits, and it seems that these involved extensive use of cross site scripting attacks. What interested me in particular is that in 2012 when the team supposed 'peace treaty' and extensive hiatus they included a data dump of a host that they compromised.  The host information was listed as -    Server Type: Apache/2.2.3 (Red Hat) What is noteworthy to me is that t